Get BEC Forensics Quickly with Autopsy
Petra Autopsy provides full forensics for a BEC, available in just 24 hours.

This is some text inside of a div block.

This is some text inside of a div block.

“The [Autopsy] results were eye-opening to say the least. I didn’t want to believe it at first, but then I saw all of the forensic details and double checked them in Microsoft. I just thought to myself, ‘oh crap’... We were definitely surprised, and now we get to pass along this superpower to our clients.”
“For me, what's surprising is that it finds all this stuff... All this attacker activity from past compromises, just after turning it on... Where did it come from? How did it happen? Who clicked what? What did the attacker do? Petra shows all of that. The detail level on [Autopsy] has been really good, even on past attacks.”

%202.png)
“We had a customer compromise yesterday… Petra [Autopsy] found the attack, showed the attacker's activity, and cleaned up an additional phishing email we had missed. When the user got re-compromised a few days later, Autopsy showed all those details too.”

What an Autopsy does:
Gathers and analyzes 6 months of activity.
Once approved for a tenant, Petra gathers the last 6 months of activity (even for a Business Basic tenant). Petra then analyzes all accounts to identify current/past attackers

Flags attackers,
past or present.
Any attacks in the last 6 months, Petra will surface, along with complete forensics including how the attacker got in (even if they got past MFA).

Surfaces how attackers got in
and what they did.
Autopsy will surface all emails accessed by the attacker, all files accessed by the attacker, all persistence methods added, any malicious emails sent, and more.

Produces PDF report and Forensic Excel
in 24 hours
All Autopsy results combine into a client-ready, white-labeled PDF along with detailed forensics in an Excel file so that you’re ready to present to the client.

What an Autopsy looks like:
Autopsy delivers a full forensic PDF report within 24 hours. See an anonymized version below.

1,849
accounts analyzed
2
compromises found
1
leftover persistence found and removed
Frequently asked questions
You have questions? We have answers. We're here to help.
How long does an Autopsy take to finish?
Typically just 24 hours after initiated, analysis is finished and an Autopsy Report is ready to review.
Does an Autopsy process email contents?
No. An Autopsy just processes the metadata of your Exchange activity, not the contents.
We have email security. Would it still be helpful to run an Autopsy?
Yes. Most of today’s successful attacks bypass email security, often via trusted third-party phishing and U.S. IPs. Most Autopsies that find attackers occur on companies with email security.
Do I need an admin account to initiate an Autopsy?
Yes, but you don’t need to give us access. We can give you a link to kick off the Autopsy directly.
Try Autopsy for free
Autopsy produces BEC forensics in 24 hours, showing you everything the attacker did and producing a client-ready PDF report.



