Desktop

Step-by-step workflow guide for investigators

Organizational Risk Assessment

Starting from a single domain, this guide walks you through establishing what an organisation is already exposing — employee credentials circulating in infostealer logs, the full scope of what a compromised device gave up, and the identities behind the records. Run it against your own domain to find where staff data has leaked and what operational risk that creates, or against a prospective partner or supplier to establish whether their exposure would become your supply chain problem.

Before you start:

Identify the starting point

Domain you are trying to investigate.

Access

Note: Stealer log data is restricted to Enterprise plans. Basic users have limited access to the data providers used in this workflow more generally — some transforms may be unavailable or return restricted results depending on your plan tier.

Resources

This guide assumes basic familiarity with Graph (Desktop). Feature names link to the documentation where needed. It helps to have the following pages open before you start: 


Video Overview

Watch an organizational risk assessment workflow demonstration. Then follow the step-by-step guide below to build your own, or skip the video and jump straight to the steps.

To enlarge, double-click on the video.

Step-by-Step Guide

What's next?

Give us your Feedback!