Features

Modern identity defense for Microsoft 365.

Petra is the ITDR built for the BEC and token theft era. Every attack is caught, contained, investigated, and reported.

01 / Detection

Petra detects intent across every M365 surface to stop even the most complex attacks.

Petra reads what an attacker is doing across logins, Exchange, and SharePoint, not just where they're coming from. This approach catches the attacks that slip past location-based detection, like those using residential proxies, valid sessions, and credentials that have already passed MFA.

Behavioral detection across logins, Exchange, and SharePoint
Detects residential proxies and known-bad infrastructure
Catches credentials that already passed MFA or Conditional Access
Zero configuration, including no allowlists to maintain

"We tested both Blackpoint and Huntress, but Petra is so far the only real solution to the massive increase in BECs we are seeing."

David Rafsky
David Rafsky, Hansen Gress
Petra attack timeline view
02 / Remediation

An alert is the end of your work, not the beginning.

Petra removes every trace of the compromise. That includes registered devices and attacker-added MFA methods, malicious inbox rules across affected mailboxes, and the original phishing emails wherever they landed. The environment goes back to its pre-attack state.

Reverses attacker-added MFA methods and device registrations
Removes malicious inbox rules and forwarding completely
Fleet-wide phishing email retraction in one action
Reverses attacker activity inside SharePoint

"Petra detected and quarantined within 2 minutes. What else can I say? Petra made us look like heroes. Thanks for building an amazing product."

Daniel Byrd
Daniel Byrd, TeamLogicIT
Petra one-click remediation view
03 / Forensics

Petra traces every attack from phish to contained.

Petra automatically reconstructs the full attack. It finds the root-cause phishing email, identifies the attacker's IP and infrastructure, and produces a chronological timeline of every action across logins, mail, files, and Teams. You can quickly close the ticket with the full picture.

Finds the root-cause phishing email automatically
Full attacker timeline across logins, mail, files, and Teams
Surfaces the IP, ISP, and infrastructure behind the attack
12 months of searchable M365 telemetry, hot

"Seeing the Autopsy results, my first thought was, 'Duh, we need this in place.' People see that report and immediately get it."

Robert Shank
Robert Shank, Office Information Systems
Petra attack impact view
04 / Reporting

Show your clients they're protected.

Petra automatically compiles an exec-friendly report that spotlights how you discovered and stopped an attack before damage.

Client-ready PDF generated automatically per incident
White-labeled reports covering every attack and anomaly per client
Pre-sales incident scan to size the gap for new prospects
Anonymized incident library to use in sales conversations

"My customers are really impressed at the speed and the visibility of the incident, and the reports are crystal clear. Thank you Petra!"

Pascal Pelletier
Pascal Pelletier, MicroAge Rimouski
Petra incident report view

See what's in your environment.

A free scan of your M365 environment, deployed in two clicks.

start a scan