Sample report

Threat hunt and response readiness

A sample investigation showing how exposure and threat advice guide the questions we test, the findings we report and the response decisions your team needs to make. The response procedures are a draft for approval, not an exercised plan.

Fictional example. The business, observations, evidence references, dates and decisions are invented to demonstrate the deliverable. This is not a customer assessment or evidence of a real incident.

Prepared for
Example Office · 28 staff · one office
Report reference
EO-HUNT-2026-01 · version 1.0
Assessment / coverage
12–21 September 2026 · collection: 22 September · AEST (UTC+10)
Issued / status
23 September 2026 · findings and follow-up actions open

Executive summary

The hunt identified an unexplained forwarding rule on a finance mailbox. The finance owner did not recognise it, and no approved change was found. The rule could copy matching finance correspondence to another address, creating a risk of information disclosure and more convincing payment fraud if that address is controlled by an attacker.

The rule and its creation event were confirmed. Who created it and whether any messages were delivered to the destination remain unresolved. A separate unusual sign-in was explained by an authorised support session.

The hunt could not assess use of the legacy portal because its access records were unavailable. That leaves the potential entry point identified in the exposure report unresolved; a lack of records cannot show whether it has been used.

Recommended decisions

  • Have the incident lead preserve the rule and audit evidence, then approve appropriate containment and further account investigation.
  • Have finance independently verify any disputed payment-change requests.
  • Resolve portal ownership and available history, and decide how to address the missing records.
  • Approve response responsibilities and test the draft incident procedure with the nominated staff.

The hunt covered five accounts over ten days. It found an issue requiring investigation, but did not confirm data theft. Containment and further investigation remain outstanding.

How to read the references

Reference codes connect the report's records so you can trace a conclusion back to its source. The numbers distinguish individual records; priority, confidence and completion status are stated separately.

  • Hunt hypothesis H-01: A question the investigation attempts to answer. H-01 concerns finance-account misuse; H-02 concerns use of the legacy portal.
  • Hunt finding HUNT-01: An issue supported by the reviewed records: the unexplained mailbox forwarding rule.
  • Coverage gap GAP-01: A question that could not be answered because the required evidence was missing. Here, the portal history was unavailable.
  • Resolved observation OBS-01: An investigated lead explained by authorised activity: the support-session sign-in.
  • Follow-up action HA-01: A proposed decision or task arising from the hunt. The action table names the owner and evidence needed for completion.
  • Evidence H-E01: A supplied record supporting the investigation, described in the evidence index.
  • Threat scenario TB-01 / exposure finding EXP-01: References to the preceding threat briefing and OSINT report, not additional findings from this hunt.

Colour key: Red act promptly · Orange needs attention; plan the fix · Green working, resolved or worth keeping. Each signal also carries its written label.

The report reference in the document details identifies the report as a whole. Client evidence references in these public examples are illustrative; no private evidence files are attached.

Authorisation, sources and available history

The illustrative written scope covers one cloud tenant, five named accounts and the two hypotheses below. The hunt reviews 12 September 00:00 to 21 September 23:59 AEST, with collection on 22 September and reporting on 23 September 2026. All times in this report are AEST (UTC+10). The 28-person business’s other accounts are outside the selected account scope.

Covered sources and known limits
SourceCoverage and historyStatus / limitation
Identity sign-in exportFive accounts; 12–21 September.Available. Source count reconciled to the export; no visibility before the available window.
Cloud administration and mailbox audit exportsRelevant changes involving the five accounts; 12–21 September.Available. Only configured and retained event classes can be reviewed.
Mailbox configuration snapshotFive mailboxes; collected 22 September at 09:00.Available. Describes current settings; audit records are needed to establish when they changed.
Legacy portal access and administration logsRequested for the same window.Unavailable. No event-level portal hypothesis can be completed.
Endpoints, message bodies and network trafficNot collected.Excluded. No malware inspection, content review or packet analysis is implied.

Collection is limited to agreed exports and configuration records. There is no active exploitation, password testing or automatic containment. Any additional collection or potentially disruptive action requires the nominated contact’s approval.

Hunt hypotheses and investigation method

From threat scenario to testable question
HypothesisReason for testingSearch and validationOutcome
Hunt hypothesis H-01 · misuse of a finance-related accountThreat scenario TB-01 identifies the payment-fraud risk. Public finance information makes targeting plausible, but does not establish account access.Correlate available sign-ins with account changes and mailbox forwarding rules; check owner explanations and approved changes.Unexplained rule raised as HUNT-01. A separate sign-in lead was resolved as OBS-01.
Hunt hypothesis H-02 · use of the legacy portalTB-02 identifies an exposed service with unresolved ownership.Obtain portal access and administration history, map accounts and correlate relevant events if the records exist.Not testable from supplied evidence. Recorded as GAP-01, not a negative result.

The analyst normalises timestamps, preserves original values, checks account identifiers and searches the full available interval before narrowing to relevant events. A lead is checked against alternative explanations and the source record. Missing event classes, export limitations and inaccessible systems remain in the coverage ledger.

The temporary, contained investigation environment collects the agreed exports and makes them searchable for the hunt. It is retired after the engagement under the agreed handling arrangements. Report and evidence retention are separate decisions; this sample does not claim that client records have already been deleted.

A real evidence pack records source export parameters, collection times, file integrity values, record counts, field mappings and the actual queries used. This public sample deliberately supplies no real tenant identifiers, account secrets or customer evidence.

Findings and resolved leads

Hunt finding HUNT-01 · High action priority · unexplained forwarding could expose finance correspondence

Observed: the 22 September configuration snapshot shows a forwarding rule on the scoped finance mailbox, directing matching messages to an address at the reserved domain supplier-review.test. Audit record H-E02 records creation on 18 September at 14:06. The account identifier in that record identifies the account used, not the human responsible.

Validation: the finance owner denies requesting the rule; the provider’s change register contains no matching approval (H-E03). An associated sign-in at 13:58 appears in H-E01. These records support an investigation, but do not prove how access was obtained or link the activity to a particular actor.

How this could be used: An attacker controlling the configured destination could receive matching finance emails if the rule runs and messages are delivered. The content could expose business information or make a fraudulent payment request more convincing. Reading a copy need not create another interactive sign-in to the original mailbox.

If left unresolved: The rule could continue selecting future messages while the owner believes the mailbox is operating normally. Changing a password alone would not remove the rule. The business may need to investigate a longer period and more transactions if it waits. The sample confirms the setting, not actual delivery, loss of information or control of the destination by a particular person.

Confidence and limits: High confidence that the rule existed at collection and was recorded as created within the window. Moderate confidence that it was unauthorised, based on the supplied owner and change evidence. Message delivery records and contents were not in scope, so the analyst cannot establish whether information left the business.

Action: escalate to the nominated incident lead, preserve the settings and audit trail, and seek authority to disable the rule and review sessions and account access. Review other mailboxes only under an expanded scope. High priority reflects potential continuing disclosure and finance relevance, not a confirmed loss estimate.

Escalation record: the illustrative incident lead was notified on 22 September at 10:15 and acknowledged at 10:24 (H-E05). The initial report leaves containment and further investigation Open. Closure requires an authorised change record, repeat configuration check and a documented decision on the unresolved account activity.

Coverage gap GAP-01 · High investigation priority · portal history unavailable

No portal access or administration records were supplied despite the request in H-E06. EXP-01’s ownership gap remains unresolved at the hunt’s collection date. No conclusion can be reached about historical portal access.

Why this matters: If someone has tried credentials or gained access to the legacy portal, the hunt has no supplied portal history to test that possibility, establish when it happened or identify affected records. The absence of provided logs does not prove that the host never recorded events; recoverable evidence may still exist with its provider.

If left unresolved: A potential entry point can remain in use without the business being able to demonstrate whether it was accessed. Investigation may be delayed until visible harm occurs, and any remaining provider records may expire in the meantime. That can leave leadership deciding on account restrictions, restoration and other precautions with much less evidence.

Assign the business owner and hosting provider to recover ownership and determine whether historical records exist. If they cannot be recovered, document the irrecoverable interval and agree prospective logging or retirement. Starting collection now does not close the historical gap.

Resolved observation OBS-01 · Resolved lead · authorised support activity

A successful sign-in on the scoped support account on 16 September at 08:41 initially differed from the usual working pattern. The provider supplied a matching support ticket and session record, and the business owner confirmed the work (H-E04). That specific lead is closed as explained activity. A familiar provider or source address is not permanently excluded from subsequent review.

Business consequence of the review: The corroborating ticket and session record explain this specific event, avoiding unnecessary disruption of legitimate support work. This closes the lead, not every possible use of the account. Future changes or sign-ins still need assessment against their own context and evidence.

Response readiness for the priority scenario

The following is a draft account-misuse playbook for owner approval. It has not been exercised and is not a complete incident response plan. The nominated roles must be replaced with named contacts, deputies, tested routes and approved authority before operational acceptance.

If the draft is never made operational: A future suspicious rule or sign-in may reach several people without anyone knowing who can preserve records, restrict access or speak for the business. Waiting for authority could allow further misuse; an improvised account shutdown could also interrupt legitimate work. Named decision-makers, deputies and a tested contact route turn the written steps into something the business can use under pressure.

Draft responsibilities and decision points
RoleResponsibilityRequired decision / evidence
Incident lead / business ownerCoordinate the incident and authorise actions that could interrupt work.Approve account restrictions, allocate an investigation owner and record business dependencies.
IT or security providerPreserve records, investigate account and configuration changes, and implement authorised containment.Retain before/after settings, event references, session decisions and change outcomes.
Finance leadCheck disputed payment instructions through established independent contact channels.Record which transactions or requests were checked and any unresolved discrepancy.
Leadership / communications ownerCoordinate internal and external communications with relevant advisers.Record verified facts and unresolved questions; obtain specialist advice where needed.
  1. Triage and preserve: record the event, time, affected account and reporter; preserve the configuration and available audit records before making changes.
  2. Decide on containment: assess whether access or forwarding may continue and obtain the agreed authority for restrictions. Consider service accounts and operational dependencies.
  3. Investigate scope: establish available history, related activity and evidence gaps. Keep confirmed observations separate from assumptions about loss or attacker identity.
  4. Recover and verify: validate authorised settings and access, confirm normal work can resume, and record remaining uncertainty and follow-up monitoring ownership.
  5. Review: update the procedure, collection requirements and contact details after the investigation or exercise.

No staffed after-hours response or emergency response time is included. The business needs to agree who receives urgent findings outside the normal service window before accepting the procedure.

Action plan and closure criteria

Proposed actions — no remediation is claimed complete
ActionResponsible ownerAcceptance evidence
Follow-up action HA-01 · decide on the unexplained forwarding ruleIncident lead and IT providerPreserved evidence; approved containment decision; configuration and access rechecked.
Follow-up action HA-02 · scope further account investigationIncident leadAgreed additional sources, affected accounts and questions; unresolved exposure recorded.
Follow-up action HA-03 · resolve portal ownership and historyBusiness owner and hosting providerOwner confirmed; available logs recovered or missing interval formally recorded; future logging or retirement decision.
Follow-up action HA-04 · approve response roles and runbookBusiness owner and providerNamed contacts, deputies, authority and agreed service window.
Follow-up action HA-05 · test the draft procedureBusiness owner and nominated participantsExercise record, observed gaps, action owners and retest dates.

The work informs where to spend next: investigate the evidenced account issue and resolve the missing portal records before expanding searches or buying more tools. Additional investigation, remediation and exercises require separate scoping; the report does not assign a fictional fee or guarantee incident containment.

Evidence index, handover and limitations

Illustrative evidence references
Evidence referenceRecordSupports
Evidence H-E01Scoped sign-in export; collected 22 September.Timing and account correlation, with no human attribution.
Evidence H-E02Mailbox audit export and 09:00 configuration snapshot.Rule creation event and setting observed at collection.
Evidence H-E03Finance-owner validation and provider change-register check.No recognised business approval for the rule.
Evidence H-E04Support ticket, session record and owner confirmation.Resolution of the specific 16 September sign-in lead.
Evidence H-E0522 September notification and acknowledgement record.Escalation of HUNT-01; not proof of remediation.
Evidence H-E06Portal record request and evidence-availability response.Recorded gap in the portal hypothesis.

The handover contains the source and hypothesis ledger, findings, controlled evidence index, proposed action tracker and draft scenario procedure. The walkthrough confirms what is known, what cannot be answered and who owns each decision. Version 1.0 is the initial illustrative report.

The selected accounts, event classes and ten-day interval do not represent the whole business. There is no endpoint inspection, message-content review or portal history. Absence of another finding cannot establish absence of compromise. Investigation records and customer identifiers belong in the agreed controlled delivery channel, not this public sample.

Explore logging, threat hunting and incident response planning