A security incident is rarely investigated by a forensics professional. Most often, it is done by whoever happens to be present. This is exactly where AI helps the most. At Above IT’s Afterwork on October 8, 2026, we will carry as the central theme “Do more with less,” as AI brings efficiency to the daily work of IT management experts. In this blog, Above IT partner and security expert Matias Haapaniemi provides a teaser for the event by discussing the utilization of AI in security forensics.
Incidents Are Usually Investigated by Someone Other Than an Expert
An SME does not have its own SOC. When an account is hijacked on Friday at 4 PM, the investigator is the company’s own IT manager or the local IT partner’s on-call technician. They know Windows, networks, and Microsoft 365. However, forensics is not their day job.
The difference compared to an expert is not in intelligence. The difference is in routine. A cybersecurity expert knows which log to look at first and which field is decisive. An IT generalist spends the same amount of time just searching for it.
AI bridges exactly this gap. It does not make anyone an expert. It makes the first hour significantly more productive, and the first hour is usually what determines the extent of the damage.
Where Does the Time Go in a Security Incident Investigation?
Investigating a single hijacked Microsoft 365 account typically involves these four different views:
- sign-in logs and their source IPs
- mailbox rules and forwarding
- application consents and valid tokens
- file access and sharing logs
Each is in a different place and a different format. A week’s sign-in log for a single user can be thousands of rows, as it also includes background session renewals.
Building a timeline usually fails due to time zones. The Microsoft 365 audit log is in UTC. A workstation’s event log is in local time. In summer, the difference is three hours; in winter, two. The wrong time zone produces the wrong story of the sequence of events, and wrong decisions are quickly made based on it.
This work is not difficult. It is slow. Slowness is the actual risk in an incident situation.
Four Areas Where AI Helps the Most
1. From Raw Log to Timeline
Export the log to CSV or JSON format and ask the language model for a timeline. A good prompt is precise: time in UTC, time in Finnish time, source IP, action, and assessment of anomaly. An export of a thousand rows is thus condensed into a few dozen rows that a human has time to read.
The language model also notices repetition that the eye does not. The same IP in eight different events stands out from the table immediately.
2. Formulating the Right Question
The hardest part is not the answer. The hardest part is the question. The query language for Defender and Sentinel is powerful, but writing it under pressure is slow.
Describe the situation in your own words and ask for a ready-made query. “Find successful sign-ins for this user from the last 14 days from outside Finland.” You get the answer in seconds and can run it directly after verification. The same applies to phishing email header information, base64-encoded commands, and alert names that may mean nothing to a layman.
3. Order of Initial Actions
The wrong order destroys evidence. This is where inexperience costs the most.
Two errors we repeatedly encounter:
- A password change alone does not terminate an attacker’s session. Existing tokens must be revoked separately; otherwise, access remains. Malicious OAuth app consent also persists through a password change.
- Shutting down a workstation destroys the contents of the memory. The device should be isolated from the network instead, so that evidence is preserved.
AI can produce an ordered action list based on the situation description. The list is not followed blindly, but it prevents forgetting a step in a hurry.
4. Reporting and deadlines
Notification obligations run against the clock. A personal data security breach must be reported to the Data Protection Ombudsman within 72 hours. For those within the scope of the Cyber Security Act, an early warning is 24 hours and the actual notification 72 hours, in addition to which a final report must be submitted within a month. It is worth checking whether your organization falls within the scope of the Cyber Security Act.
AI writes a draft from the findings quickly. It also produces an understandable message to users and management from the same material. In an incident, communication is otherwise always left last, even though it is often the part from which the customer forms their impression.
Four Limits You Should Know in Advance
A language model might invent fields and commands. It might produce a plausible-looking cmdlet that does not exist. Every command should only be run after it has been checked.
A language model might name the cause too early. It is happy to tell you what happened, even if the data is insufficient. This is the most dangerous single trait in an investigation. Always keep separate what has been established and what is an assumption.
Collecting evidence should always be prioritized over speed. For example, save the content of a malicious mailbox rule before you delete it. Otherwise, you lose information about where the messages were redirected.
Data should not be fed into a publicly available AI model. Logs contain personal data, IP addresses, and sometimes secrets. The language model should therefore preferably be run in your own tenant or a service where the location and use of data are restricted by agreement.
How We Use This
We deliver holistic security to our customers, ourselves operating as part of their IT organization. For us, AI is the first reader in an investigation, not the decision-maker. It reads the exports, builds the timeline, and suggests actions. A human checks every claim against the raw log before it becomes a conclusion. The language model is run in our own Azure environment, so customer data does not leave our control.
The practical impact has been measurable on the time axis. An hour of reading work has typically been condensed to about fifteen minutes. The saved time can then be used for what is actually needed: containment and decisions.
Where Should You Start?
First, ensure that all necessary logs are available to your organization. Without a log there is no forensics, and retention times are by default shorter than many think. Entra ID sign-in logs are retained for typically 7-30 days depending on the license. The Microsoft 365 audit log is typically retained for 180 days. An incident is often detected only after some of the logs have already been lost.
Three things you should do before the next situation:
- Check the retention periods for all logs and extend them if necessary
- Ensure the process. Write down the initial actions in advance, including who decides on isolation
- Try the language model in an exercise, not during the first real incident
The most important thing to remember is that AI does not replace a security expert. It replaces the situation where no one knows where to start. The benefit it brings may be a significantly larger change for an SME than any single new tool.
Security forensics is, however, just one example. AI does the reading and the human makes the decisions, and the same model works everywhere where IT management time is spent on slow but not difficult work. We will go through these examples more extensively at the Above IT Afterwork on October 8, 2026 with the theme Do more with less. There, we will also look at agentic forensics from the perspective of contracts and data protection: what needs to be considered regarding data processing before an agent can be allowed into the logs. The event is free of charge, and places are limited.
As your IT management’s trusted advisor, our task is to ensure that the IT environment you manage remains secure and is not compromised. So book a meeting using the link below if you would like to discuss, for example, the utilization of AI in security forensics within your own environment.



