ANNOUNCEMENT!! We’re extremely #excited to share 4 (!) new features TODAY #Windows365 app, #switch, #boot - #offline will make accessing Windows great for ANY hybrid remote work (device) scenario! A incredible moment - as multiple teams are involved! ⤵️
https://t.co/0u1lQkRMgS
A special #MicrosoftIdentityPGChat on moving from AAD Graph to MS Graph and moving from ADAL to MAAL. A thread of docs and links below: https://t.co/iYOJjLN1eZ
For Office 365 orgs, it's recommended you configure advanced delivery policies in the M365 Defender portal to allow phishing simulation platforms
https://t.co/jifUWwpmEd
If you used older methods, be sure to go back and clean up your transport rules ;)
Keyboard walking or pattern passwords are easily guessed. Attackers include these types of password since admins use them (they certainly look random and complex) and are often used as service account passwords.
Image reference article: https://t.co/fTezlR9B2K
If you want to understand the impact of #Log4Shell read this excellent @Cloudflare post https://t.co/2mqY7G1POz but also check out @_JohnHammond Minecraft hack where he walks you through it all https://t.co/X6nWMlZM80
#log4j#log4jRCE
Microsoft has observed multiple Iranian threat actors targeting the IT services sector. As India and other nations rise as major IT services hubs, nation-state actors follow the supply chain and target providers’ customers, matching nation-state interests. https://t.co/fY6EmBl9vR
In human-operated ransomware attacks, threat actors use predictable methods to enter a device but eventually rely on hands-on-keyboard activities to move inside a network. Learn how AI-driven adaptive protection fortifies defenses against complex attacks: https://t.co/FzWyHNGkU5
Over the past year, Microsoft Threat Intelligence Center (MSTIC) has observed an evolution of the tools, techniques, and procedures employed by Iranian nation-state actors. Learn more from this blog summarizing these trends, as presented at #CyberWarCon: https://t.co/nRqLZaRUjf
Just a reminder. You will probably never see me refer to myself as an expert. I just work in cybersecurity.
Remember that this field has all of these verticals and I doubt anyone on the planet knows all of them.
I can speak to a lot of these, but there is so much I don’t know.
Following the 25th anniversary of Microsoft Sysinternals, we're announcing the availability of a new Microsoft Sysmon report in @VirusTotal. Learn how this report expands community threat intelligence: https://t.co/XMdlDLPQxN
Sr. IR Consultant @cyberGoatPsyOps is presenting "Windows Internals for Defenders" at @texascyber on Oct. 30!
Bastidas will discuss #Windows internals from the perspective of a defender, specifically an Incident Responder.
https://t.co/Wb6o9oXwp5
1\ #MalwareAnalysis Evasion Technique: Detection of security tools by locating DLLs loaded by processes.
Most security tools inject their DLLs into running processes to “monitor” behaviour.
Malware calls these APIs to detect this:
> GetModuleHandleW
> GetModuleHandle
What would it look like for an attacker to use a malicious #OAuth web app to attack Azure AD users? “Creating a Malicious Azure AD OAuth2 Application” breaks down how deploying a malicious web app isn’t overly complex and can be used in an attack #blog
https://t.co/Z5pLoL6HdP
Elevate your cmd.exe to LOCAL_SYSTEM?
\\https://t.co/nfsz2BNI7z\tools\PsExec.exe -s -c cmd.exe
Have you ever seen this being used by an adversary? I haven't but I like it.
Attackers are already using OAuth (too few orgs are monitoring this), seen it a lot in IR
This is why your end users shouldn't be granting applications permissions to access your company data
Disable user grant and create an approval process to review security/privacy concerns