# MAES: The M365 Analyzer & Extractor Suite

URL: https://www.ionsec.io/resources/maes-the-m365-analyzer-extractor-suite
Category: Tools
Author: IONSEC Team
Published: 2025-08-20
Updated: 2026-08-07
Tags: open-source, dfir, microsoft-365, cloud-forensics

At IONSEC, we’re excited to introduce MAES: The M365 Analyzer & Extractor Suite — an open-source platform purpose-built to simplify and accelerate Microsoft 365 (M365) forensic investigations.

---
## Automating Microsoft 365 Forensics & Incident Response

At IONSEC, we’re excited to introduce **MAES: The M365 Analyzer & Extractor Suite** — an open-source platform purpose-built to simplify and accelerate **Microsoft 365 (M365) forensic investigations**.

MAES provides DFIR teams with the ability to **extract, analyze, and preserve** critical evidence from M365 environments — all while maintaining forensic-grade integrity.

[Video](https://player.vimeo.com/video/1110003664)

## Since Release

MAES has grown substantially since its initial launch (updated Aug 2026). Recent work focuses on hardening, real reporting, and operational visibility:

- **Real TOTP two-factor authentication** and broader RBAC hardening (role-filtered navigation, an alerts guard, `canManageIncidents` role handling) to lock down who can access what.
- **Persisted SIEM configurations and real report generation**, plus job cancellation and service-health endpoints so long extractions are observable and stoppable.
- **UEBA trend views** in the UI, alongside dead-code cleanup for a leaner codebase.
- The extractor and analyzer modules aligned to the **latest upstream suites**, with a cleared dependency audit.

## Why MAES?

Security teams often struggle with **manual, inconsistent, or incomplete evidence collection** from M365 tenants during incidents. MAES was designed to solve that gap:

- **Forensic-Ready Extraction** – Automates acquisition of M365 logs, mailboxes, SharePoint, OneDrive, and Teams artifacts.
- **Analyzer Modules** – Built-in parsers for investigating email headers, login anomalies, and suspicious activity.
- **Chain of Custody Enforcement** – Every artifact is hashed (SHA-256) and timestamped to preserve evidentiary integrity.
- **Automation Without Blind Spots** – Reduces manual effort while ensuring nothing critical is overlooked.

## Key Capabilities

![graphical user interface](/assets/blog/maes-the-m365-analyzer-extractor-suite/68a6240d3e16ea900c746094_1752179708500.webp)

- **Audit Log Collection** – Pulls Unified Audit Logs (UAL) for timeline reconstruction.
- **Mailbox & Message Extraction** – Targeted acquisition of suspicious or compromised accounts.
- **SharePoint/OneDrive Evidence** – Capture and preserve file access and modification trails.
- **Teams Activity Analysis** – Extracts chat histories and file-sharing metadata.
- **Reporting Outputs** – JSON, CSV, and HTML reports suitable for SIEM ingestion or executive summaries.

## For DFIR Practitioners, By Practitioners

MAES is built by responders who know the pain points of M365 investigations. With MAES, your team can:

- Respond faster to suspected account takeovers and insider threats
- Standardize evidence collection across cases
- Scale investigations in large tenants without losing visibility
- Share modules and workflows with the wider DFIR community

## Join the Project

We’re making MAES available as an **open-source suite**, and we invite the security community to extend, test, and improve it. Together, we can raise the bar for **Microsoft 365 forensics and incident response**.

🔗 Get started on GitHub: <https://github.com/ionsec/maes-platform>  
🎥 Watch the demo video: https://vimeo.com/1110003664
