Investigating a hacked or misused login comes down to reading the trail it leaves, and account forensics is the practice of doing that in the right order. You’ll learn which logs hold the evidence, how to build a timeline of what an intruder touched, and why resetting the password too early can destroy the best clues. The steps below fit a personal email account, a company Microsoft 365 or Google tenant, or a Windows user profile. Nothing here needs expensive software, only patience and a habit of saving evidence first. By the end, you’ll be able to tell what happened, when it started, and what still needs cleaning up.
Short Answer
Account forensics is the structured review of an account’s sign-in history, permission changes, and activity logs to work out who accessed it, what they did, and when. The core method is to preserve the logs, build a timeline from the first anomaly, then remove access and reset credentials.
What Account Forensics Covers in Practice
Account forensics sits between security monitoring and full digital forensics. Monitoring tells you something looks wrong right now, while forensics reconstructs what already happened using records the system kept without being asked. The questions are always the same three: how did someone get in, what did they do with the access, and are they still there.
Most people meet it after a scare, such as a sign-in alert from another country or a friend saying they got an odd message from your address. Companies meet it after a phished employee, a diverted payroll payment, or an audit request. The tools differ, but the logic carries from a personal Gmail account to a Windows domain user, because every system records logins, changes, and actions somewhere.
Where the Evidence Lives
Every platform keeps its own history, and how long it keeps that history decides how much you can recover. The sources below answer the most questions for the least effort.
- Windows Security log. Event ID 4624 records a successful logon and 4625 a failed one, while 4720 marks a new account, 4732 a member added to a local group, and 4672 special privileges assigned. The logon type inside 4624 matters too, since type 3 is a network logon and type 10 is a remote desktop session.
- Microsoft 365 and Entra ID. Sign-in logs, the unified audit log, and mailbox rules show where logins came from and what was changed afterward. Retention depends on your license, and sign-in history is often kept for 30 days or less, so check your own tenant.
- Google accounts. The security page lists recent activity and signed-in devices, and Workspace admins get login audit logs on top of that.
- The mailbox itself. Forwarding addresses, filters, delegates, and connected third-party apps are the favorite hiding places.
- The device. Newly installed remote-access tools, unfamiliar browser extensions, and saved sessions all belong on the checklist.
Retention is the quiet clock behind everything here. A busy Windows server can overwrite its Security log in a matter of hours if nobody raised the size limit, and cloud logs age out on a schedule you didn’t choose. That’s why the first move is always to export, not to investigate.
An Investigation Order That Protects the Evidence
The sequence matters more than the tooling, because some steps destroy information the others depend on. Work through these in order.
- Export the logs first. Save sign-in, audit, and mailbox rule data before changing anything, and write down the exact time you exported it.
- Cut off live access without wiping the trail. Revoke active sessions and refresh tokens, then change the password, since on many services a password change alone leaves existing sessions running.
- Find the earliest anomaly. Look for the first sign-in from an unfamiliar IP address, device, or country, and treat it as the likely start.
- Build the timeline. List each event with its time, source, and action, and convert everything to one time zone before comparing anything.
- Check persistence. Look for forwarding rules, delegates, authorized app grants, newly added multi-factor methods, and changed recovery emails or phone numbers.
- Measure the impact. Work out which messages were read, sent, or deleted, which files were downloaded, and whether any payment or contact details were touched.
- Document and notify. Record what you found, tell anyone whose data was exposed, and report it to the platform or your security team.
Professionals follow the same shape, which the four-phase process of collection, examination, analysis, and reporting in NIST’s guide to integrating forensic techniques into incident response lays out in detail. The difference is mostly rigor about evidence handling, not a different method. For a personal account, this list is enough.
Patterns That Separate an Intruder From Normal Noise
A single odd login rarely means much. Travel, a new phone, and a VPN all produce sign-ins that look suspicious and aren’t, so a fair investigation compares activity against the owner’s own baseline rather than against some generic idea of normal. Ask what this person’s usual devices, hours, and locations look like, then look for what falls outside that.
The pattern worth worrying about is sequence. On a Windows system, a burst of failed logons (4625) from one source followed by a success (4624) from the same source is the classic guessed-password signature. In a cloud mailbox, a sign-in from a new location followed within minutes by a new inbox rule is a much stronger signal than either event alone.
How the intruder got in also shapes what you do next. If the trigger was a link from a site you didn’t recognize, plain-language breakdowns of unfamiliar websites can help you judge where it came from before you decide whether the credentials leaked through phishing or through a reused password elsewhere.
The Part Most Guides Skip
The most common mistake is believing that changing the password ends the incident. It feels final, and platforms encourage that feeling by nudging you toward a reset first. But an attacker who already created a forwarding rule, authorized a third-party app, or added their own phone number as a recovery method keeps access after the password changes.
There’s a second trap, and it’s about time. Logs from different systems often use different time zones, and comparing a UTC audit entry with a local-time Windows event can shift your timeline by hours and put the intrusion on the wrong side of an unrelated event. Normalize everything to UTC before you draw a single conclusion.
One habit that helps more than it sounds is anchoring on the last known-good sign-in rather than hunting for the break-in itself. If you can say with confidence that the account was clean on the 3rd and compromised by the 9th, that six-day gap is your exposure window. Everything read, sent, or downloaded inside it needs review, and everything before it can usually be set aside.
When a Professional Is Worth Paying For
For a personal account with no money or legal exposure, doing this yourself is reasonable and the steps above cover it. Once the stakes rise, my position is that you should stop and bring in a specialist. Financial loss, regulated data such as health or payment records, an insurance claim, suspected employee misconduct, or anything that could reach a courtroom all fall in that group.
The reason is evidence handling, not skill. Investigators work from forensic copies of drives and exported logs, keep a record of who handled what, and avoid touching the original system. If you poke around the live machine first, you can overwrite timestamps and weaken the evidence before anyone qualified has looked at it.
Authorization matters as well. Examining a company account without the employer’s written approval, or looking into someone else’s personal account, can be illegal in many places, so get the permission in writing before you open a single log.
Where to Start Today
Account forensics rewards the person who slows down. Before you touch the password, export the sign-in and audit logs, note the time, and mark the first sign-in you don’t recognize. That one date tells you how far back to look and what to clean. Then revoke sessions, change credentials, and check for forwarding rules and app grants. Start with the export today, even if you think the account is fine.
FAQ
How is account forensics different from general digital forensics?
Digital forensics covers whole devices, disks, and networks, while account forensics narrows to one identity and the records tied to it. It’s usually faster and relies on logs rather than disk images.
How long do sign-in logs stay available?
It varies by platform and license, and some cloud services keep only 30 days or less of sign-in history. Export what you can as soon as you suspect a problem.
Does resetting my password kick out an attacker?
Not always. Existing sessions, app authorizations, and inbox forwarding rules can survive a password change, so revoke sessions and review those settings too.
Can I check whether someone else accessed my email account?
Yes. Review the recent security activity and signed-in devices page, then check forwarding addresses, filters, and connected apps for anything you didn’t add.
Is it legal to investigate an employee’s account?
Only with proper authorization, usually written approval from the employer and sometimes legal sign-off. Unauthorized access to someone’s account can be a crime in many jurisdictions.