ITDR2.0
Full BEC Forensicsin 48 hours
Get insurance-grade forensics for the last 6 months of your M365 logs, including past and active attacks, in 48 hours.
Trusted by hundreds of MSPs and 10,000+ businesses.















“The Scan results were eye-opening to say the least. I didn’t want to believe it at first, but then I saw all of the forensic details and double checked them in Microsoft. I just thought to myself, ‘oh crap’... We were definitely surprised, and now we get to pass along this superpower to our clients.”

“I think a lot of people are in the same position that we were — they just don’t know what’s really happening until all the forensic analysis is done. We’d thought attacks were being caught fast, but we had a rude awakening, and now we know what fast really looks like. Now we get to pass that huge speed increase along to our clients.”

The Process
How a Scan works.
Connect all your tenants in 2 clicks.

Kick off your Scan in minutes via Microsoft Partner Center. Petra works with all license tiers, including Business Basic, and can scan all your tenants at once.
See every attack, past and present.

We ingest six months of activity and analyze every account for current and past attackers, across logins, mail, files, and Teams.
Understand the root cause and all attacker activity.

For every attack surfaced, we reconstruct the full story: the root-cause phishing email, the IP and infrastructure, every email accessed, every file touched, every persistence method added, and every malicious message sent.
Download your ready-to-share reports.

All results combine into a white-labeled PDF and forensics Excel, ready to hand to a client, share with leadership, or submit to an insurance carrier.
“We had a customer compromise yesterday… Petra [Scan] found the attack, showed the attacker’s activity, and cleaned up an additional phishing email we had missed. When the user got re-compromised a few days later, Scan showed all those details too.”

Frequently asked questions
What licenses does Petra work with?
Petra works with all Microsoft licenses, including Business Basic.
How long does a Scan take to finish?
Typically just 24-48 hours. IR Firms working on tighter timelines should contact us directly.
Does a Scan process email contents?
No. A Scan just processes the metadata of your Exchange activity, not the contents.
We have email security. Would it still be helpful to run a Scan?
Yes. Most of today’s successful attacks bypass email security, often via trusted third-party phishing and U.S. IPs. Most Scans that find attackers occur on companies with email security.
Do I need an admin account to initiate a Scan?
Yes, but you don’t need to give us access. We can give you a link to kick off the Scan directly.
See what's in your last six months of logs.
Run six months of M365 logs through Petra and get insurance-grade forensics within 24 hours. Five minutes to set up with no sales call.




