Petra Security

ITDR2.0

Full BEC Forensicsin 48 hours

Get insurance-grade forensics for the last 6 months of your M365 logs, including past and active attacks, in 48 hours.

Trusted by hundreds of MSPs and 10,000+ businesses.

Hansen GressmCubedIntelligent Technical SolutionsEver NimbleFutureSafeThe AME GroupCyberStreamsKPMGIntrusionOpsAlignLayerNineBNMCCompu-SOLVEFC DallasImpactJ&B Technologies
“The Scan results were eye-opening to say the least. I didn’t want to believe it at first, but then I saw all of the forensic details and double checked them in Microsoft. I just thought to myself, ‘oh crap’... We were definitely surprised, and now we get to pass along this superpower to our clients.”
Ken Curtis
Ken CurtisBNMC
Read case study →

Sample Report

See what a Scan report looks like.

Every report includes all attacks from the last 6 months with full forensics: root cause, reconstructed timeline, and every action taken.

“I think a lot of people are in the same position that we were — they just don’t know what’s really happening until all the forensic analysis is done. We’d thought attacks were being caught fast, but we had a rude awakening, and now we know what fast really looks like. Now we get to pass that huge speed increase along to our clients.”
David Xiong
David XiongCTO, M-Cubed Technologies
Read case study →

The Process

How a Scan works.

5-Minute Setup

Connect all your tenants in 2 clicks.

Petra Scan setup mockup: connecting every Microsoft 365 tenant in two clicks via Partner Center

Kick off your Scan in minutes via Microsoft Partner Center. Petra works with all license tiers, including Business Basic, and can scan all your tenants at once.

6 Months of Activity

See every attack, past and present.

Petra Scan dashboard mockup surfacing past and present attacks across analyzed accounts

We ingest six months of activity and analyze every account for current and past attackers, across logins, mail, files, and Teams.

Comprehensive Forensics

Understand the root cause and all attacker activity.

Petra Scan forensics mockup reconstructing an attack's root cause and full attacker activity

For every attack surfaced, we reconstruct the full story: the root-cause phishing email, the IP and infrastructure, every email accessed, every file touched, every persistence method added, and every malicious message sent.

48-Hour Delivery

Download your ready-to-share reports.

Petra Scan mockup of the white-labeled PDF report and forensics Excel ready to share

All results combine into a white-labeled PDF and forensics Excel, ready to hand to a client, share with leadership, or submit to an insurance carrier.

“We had a customer compromise yesterday… Petra [Scan] found the attack, showed the attacker’s activity, and cleaned up an additional phishing email we had missed. When the user got re-compromised a few days later, Scan showed all those details too.”
Josh Mendel
Josh MendelTeamLogic IT of Torrance
Read case study →

Frequently asked questions

What licenses does Petra work with?

Petra works with all Microsoft licenses, including Business Basic.

How long does a Scan take to finish?

Typically just 24-48 hours. IR Firms working on tighter timelines should contact us directly.

Does a Scan process email contents?

No. A Scan just processes the metadata of your Exchange activity, not the contents.

We have email security. Would it still be helpful to run a Scan?

Yes. Most of today’s successful attacks bypass email security, often via trusted third-party phishing and U.S. IPs. Most Scans that find attackers occur on companies with email security.

Do I need an admin account to initiate a Scan?

Yes, but you don’t need to give us access. We can give you a link to kick off the Scan directly.

See what's in your last six months of logs.

Run six months of M365 logs through Petra and get insurance-grade forensics within 24 hours. Five minutes to set up with no sales call.