Concerned about business email compromise (BEC) attacks? Until recently, organizations using Office 365 for email had no way to audit access to individual mailbox items unless they paid for the premium E5-level license. Microsoft has recently enabled all customers to access these logs - but accessing them and getting the data into an actionable format is still a daunting task. In this talk, I'll show how you can leverage readily-available technologies to pull the mailbox audit logs into your SIEM and datalake solution, giving visibility into individual mailbox item access logs, and potentially reducing your PHI/PII exposure risk in the event of a cybersecurity incident.