Petra Security

Insurance-grade BEC forensics in hours.

Petra traces every M365 attack from root cause to resolution and produces a complete forensic report with the full attacker timeline. Get your complete forensic report within hours with just 5 minutes of setup.

“It finds all this stuff... all this attacker activity from past compromises, just after turning it on. Where did it come from? How did it happen? Who clicked what? What did the attacker do? Petra shows all of that.”
David XiongCTO, M-Cubed Technologies

Why IR firms choose Petra

01

Increase margins on every BEC engagement.

Cut your cost per BEC engagement without compromising on report quality and forensic depth. What used to be a labor-heavy investigation becomes a predictable, automated deliverable.

02

Guarantee delivery in days, not weeks.

Every engagement delivers in hours no matter the scope of the attack, so you have enough predictability to quote flat rates to carriers.

03

Spend more time on your highest-value work.

Your team takes on more BEC engagements without losing ransomware capacity. Our agents handle the deep BEC forensics, so your analysts stay focused on high-value work.

Get Started

Run your last six months through Petra.

Get insurance-grade forensics for the last 6 months of your M365 logs, including past and active attacks, in hours.

5-min setup · same-day turnaround

Take the pain out of BEC forensics.

01

Full attacker tracking

We follow attackers as they pivot between apps, IP addresses, and residential proxies. No matter how they try to obscure their trail, Petra reconstructs every action.

02

Everything in one place

All forensic data is consolidated in a single view. Your team no longer needs to jump between Purview, Exchange, and SharePoint logs to piece together what happened.

03

Complete reporting, ready to deliver

Every engagement produces a client-ready forensic report and an Excel export with all IOCs (IPs, sessions, ASNs), plus every SharePoint and OneDrive file the attacker touched.

04

No more manual work or access limitations

We automate all forensic investigation, so you no longer need message traces or e-discovery queries. We work with all M365 licenses and reconstruct incidents up to six months old.

See what's in your last six months of logs.

Get insurance-grade forensics on the last 6 months of your M365 logs. Setup takes 5 minutes with results in hours.