The recording of my @defcon@ReconVillage talk "Azure AD OSINT" (applies also to Entra ID) is out now: https://t.co/tqWt1dXx1X
Slides 👉 https://t.co/aTUTlqttYy
How most ransomware incidents actually work 🔻
Access brokers sell access to compromised networks to ransomware-as-a-service affiliates, who conduct the intrusions.
Ransomware-as-a-service affiliates prioritize targets based on intended impact or perceived profit
Intrusion operators take advantage of preferred security weaknesses they are able to find, so intrusion techniques vary between affiliates. Adversaries often conduct data theft in support of extortion during this phase.
If deployed, an affiliate-chosen ransomware payload is the culmination of a chain of malicious activity & criminal relationships.
-------
📄 excerpt from our 2022 blog @ https://t.co/7ivUdsb58l
"As ransomware deployment becomes a gig economy, it has become more difficult to link the tradecraft used in a specific attack to the ransomware payload developers.
Reporting a ransomware incident by assigning it with the payload name gives the impression that a monolithic entity is behind all attacks using the same ransomware payload and that all incidents that use the ransomware share common techniques and infrastructure. However, focusing solely on the ransomware stage obscures many stages of the attack that come before, including actions like data exfiltration and additional persistence mechanisms, as well as the numerous detection and protection opportunities for network defenders."
SCATTERED SPIDER / 0ktapus / UNC3944 is alive and well. Don’t make it easy for them:
◦ MFA everywhere
◦ Disable MFA push; use number-matching, OTP, or hardware token
◦ Disable external IP and unsupervised MFA self-enrollment or self-reset
◦ Allow only one trusted MFA device per user
https://t.co/SaZUjXT4xK
https://t.co/VcVidg9dZ2
https://t.co/2Hyes6RHGI
https://t.co/54Jtn5bxWZ
I just released a tool I wrote awhile back called Gold Digger. It's nothing fancy but can be pretty helpful when needing to scan through a lot of files looking for credentials and other sensitive information. I use it on cloud pentests. https://t.co/rxp385ff3F
Are you looking for an #infosec Twitter alternative?
Over 33,000+ members have joined the Discord server we created to help you share your knowledge and learn from us and others... https://t.co/LC3CY3y66H
You are welcome any time.
There are many great #PowerShell modules and other tools available for #AzureAD automation and security research. I've tried to create a link collection with some essential utilities from Microsoft and the community for #AzureAD admins and #SecOps.
🔗https://t.co/9WRKWF4cZe
After completing the MITRE ATT&CK Defender path (https://t.co/I0bProbgOW) it's time to take TTPs into action.
The next goal is to update (with @Thomas_Live) 'Azure AD Defense & Attack Playbook' attack scenarios to contain the TTPs, stay tuned!
https://t.co/wFbsFV1KDY
I've added the material from my Black Hat US talk yesterday to my blog. If you are interested in Azure AD security, love account hijacks, MFA bypass, persistence techniques and privescs, give it a read: https://t.co/qyKRWfGoY9
Recording & slides of my today's talk "Deep-dive to Azure AD join" at #GlobalAzure 2022 available at https://t.co/tJ98KvnmMU
* What happens under-the-hood during AAD Join 🤓
* How to steal device identity 😬
* How to fake device identity 😉
1\ How to detect file timestomping 👀
APT28, APT29, APT32, APT38 have all used this defence evasion technique to modify malicious file creation times. 😈
Did you also know it's possible to timestomp $FN time?
👇👇 BLOG & TL;DR BELOW 👇👇
https://t.co/B2oUtA5owF
Users in Azure deserve attention from attackers and defenders. But Service Principals deserve as much attention, and actually maybe deserve much more attention than users. A quick thread on why, and resources for attackers and defenders:
This @Secureworks report reveals various APIs that allowed unauthorized access to internal information of any Azure AD tenant.
1/4
https://t.co/cetumEmCIk
1\ Windows Event Log Evasion via Native APIs 👀🧠
Some native Windows API calls can be used to install services WITHOUT generating correlating entries in the event log. This was seen in Stuxnet.
This blog covers the technique + detection.
https://t.co/xJ9U49OIld
TL;DR 👇👇
In just under 24 hours, we've raised nearly $6,000 for @ASPCA. We're on track to beat all of our previous fundraising records, and it's all thanks to YOU! Thank you so much everyone for supporting this fundraiser.
With 29 days left to go, who knows how much money we can raise?