SigninLogs - what is the difference between AuthenticationDetails[0].authentication method and Authentication Details[1]authenticationMethod?
[1] is not always present in the logs. Question - which is more accurate to use to determine auth methods used over time?
#KQL
@DylanInfosec@NathanMcNulty That or could query within the LA and bypass the WL - it’s just secondary collection. To clarify, I’m aware of using Defender tables but am curious if there are any others that could be referenced.
Hoping for if you have MDE, do this, else here’s some non MDE options.
@NathanMcNulty@DylanInfosec Do you have any additional enrichment to try and identify the user that triggered the AiTM LA, such as using network activity from Defender?
Have a similar setup LA - capture the referer header, add to a WL, creates a Sentinel incident but am stuck trying to identify the user.
💥 Exciting update and launch competition! 📢
Folks, I'm happy to announce another important milestone for @PwnedLabs - the launch of the 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗖𝗹𝗼𝘂𝗱 𝗔𝘁𝘁𝗮𝗰𝗸 𝗮𝗻𝗱 𝗗𝗲𝗳𝗲𝗻𝘀𝗲 𝗕𝗼𝗼𝘁𝗰𝗮𝗺𝗽 - and our first certification!
𝗧𝗼 𝘄𝗶𝗻 𝗮 𝘃𝗼𝘂𝗰𝗵𝗲𝗿, 𝗷𝘂𝘀𝘁 𝗹𝗶𝗸𝗲 𝗮𝗻𝗱 𝗿𝗲𝘁𝘄𝗲𝗲𝘁 𝘁𝗵𝗶𝘀 𝗽𝗼𝘀𝘁. 5 vouchers are available and will be drawn randomly.
This comprehensive 4-week bootcamp and its structured learning path provide students with foundational concepts, essential security tools and techniques, and instruction in attacking and defending Azure and Microsoft 365 environments.
Students who successfully complete the 4-week bootcamp and structured learning path can then attempt the exam lab to try and earn the 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗖𝗹𝗼𝘂𝗱 𝗥𝗲𝗱 𝗧𝗲𝗮𝗺 𝗣𝗿𝗼𝗳𝗲𝘀𝘀𝗶𝗼𝗻𝗮𝗹 (𝗠𝗖𝗥𝗧𝗣) certification.
This has been one of the main things that our community has been asking for.
What can you expect to learn? -> https://t.co/uA0foIsKQw
Still haven’t had any luck finding any documentation listing what this matches to…may need to switch gears and start manually lining these up to the actual sign in logs to determine. To be continued…
Looking for any reference/guidance on what the “RiskEventTypes” values are - when querying against AADSignInEventsBeta in Defender Adv Hunting.
Example: RiskEventType 100. Looking to determine what this value is. #KQL
Despite being on the security team - somehow I spend more time in AD/Group Policy than the systems team…
Starting to feel like I never really left the Systems side despite switching roles a while ago.
Devices onboarded for Defender and Security Administrator = fast track to owning them. Applies in general to Security Administrator and or custom roles with adv live response with unsigned scripts.
Especially important to pay attention to if DCs are onboarded.
Information overload - vuln scans are great if the info is actionable. Scans from multiple sources for the sake of additional info and to compare against is just wasteful.
Shiny object syndrome kicking hard these days with all these vendors promising the latest+greatest.
Demo’d to my coworkers an escalation path to Domain Admin and showcase why logging/alert alone isn’t sufficient.
Reactions were mixed but overall we learned as a team…(but seriously it was a cool path to exploit)
For the past 3 years I’ve worked in security until recently. I felt that a change was needed opted for a sys admin role elsewhere.
Didn’t realize how much I really enjoyed InfoSec until now that I’m on the other side of the glass looking in…