I work as an InfoSec and Infrastructure specialist living in the U.K. In my spare time, I enjoy football and boxing! All views expressed here are my own.
@techspence Companies need to evolve VM to be exposure management! With an expectation not everything can be patched and it shouldnβt need to be, focus on attack paths and where you can cut off attacks most effectively. Then review compensating controls and risk acceptance!
@IAMERICAbooted Can you find a partner in crime, someone like minded from a team that also likes to get stuff done? Iβve found that works, also raising issues to your CISOs or boss, if itβs a niche no one is owning can you claim it and drive resolution?
@UK_Daniel_Card@akses_0x00 Turn off all the automated summaries in settings / copilot. We had it summarising everything for all SOC analysts every time someone entered an incident.. thankfully they fixed it.
@ainp0t@NathanMcNulty@IAMERICAbooted How are you monitoring this via entra idp or XDR? I think they gave some options to suppress lower fidelity detections within XDR. Which could explain what you are seeing.
@_xDeJesus@NathanMcNulty@merill@fabian_bader Feels like a step in the right direction, sadly its too broad and captures all app consent granted within the tenant. I struggled to see any identifier that highlighted the consent came from Implicit grant flow :-s
I'm trying to determine how widespread usage of Implicit Grant flow is, has anyone determined a good way to identify this from the entra portal / KQL? @NathanMcNulty@merill@fabian_bader any ideas?
@Kostastsale Totally get it, my point was more collecting data is great. But itβs only useful if insightful and usable. Ticking a collection box is one thing, it leading to a detection, response action or supporting an investigation are somewhat different.
@techspence Needs buy in from top down. Passwordless w/ Authenticator and WhfB super simple and a rare win.. for both usability and security. Level set itβs less passwords initially with passwordless the destination
@techspence Totally, however inspection is becoming harder and harder with TLS1.3. Also devices are less frequently on corp networks due to hybrid working. Of course you still need to have inspections there too