Member of the Microsoft Global Hunt, Overwatch, and Strategic Triage (GHOST): Jumping into customer cybersecurity incident response situations day after day.
@KoprowskiT@lukasberancz I think that the important thing here is that you need to understand the implications of allowing devices to be joined to the environment.
The financially motivated threat actor Storm-0539 pursues financial gain via payment card theft and gift card fraud. They gain access to target organizations and target employees with access to gift cards or have permissions to issue them. https://t.co/ib7yDzZbnQ
@reprise_99 I think it is equal part art and science to be able to search for something and quickly find it by knowing that unique combination of terms that will lead you to "that thing you saw" ... and of course, sometimes you stumble across something else and get list down the rabbit hole
@rucam365 I think that the standard consultant answer of "it depends". While ideally you have a level of confidence in the overall trust chain ( all of the other dependencies) it in many cases is not reasonable. So, focus on the things that have high levels of privilege.
We recently investigated a supply chain attack which occurred several months ago. We were able to piece together the story from the Unified Audit Log using the techniques described in this article. https://t.co/bn82P6mDNu
SMS phishing is something that many users are not aware of... and used extensively by threat actors like Octo Tempest and Storm-0539. Educate your users!
Microsoft has observed a significant surge in activity associated with the threat actor Storm-0539, known to target retail organizations for gift card fraud and theft using highly sophisticated email and SMS phishing during the holiday shopping season.
Properly configuring Microsoft Entra ID can help avoid cloud identity compromise that could lead to malicious attacks or even tenant destruction. The Microsoft Incident Response team provides guidance based on past engagements here: https://t.co/oWGbQiYPHi
I frequently see vendors and devs asking customers to lower their security posture for their apps to work.
What are the crazy asks you've heard from vendors and devs?
Here's my maturity rating from worst to best 👇🏾
😱 Ask to create user accounts to be used as 'service accounts' for their apps.
😱 Ask to exclude user 'service' account from CA policies.
😲 Ask to create apps/service principals with password credential.
👍 App uses certificates to authenticate.
👌 App uses managed identities.
🙏 Cross cloud apps using workload federation with cloud native managed identities.
@MadeleyJosh Not disagreeing, but sometimes organizations are under pressure to "do something" in order to say they responded. A password reset is a visible thing they can do... Again, not saying it is the right thing to do, just that the motivation might not be based on the technical merits.
If you are a security professional or incident responder, CVE-2023-23397 and the attacks we have analyzed utilizing this CVE are fairly unique. Here, my colleagues and I are sharing learnings from the investigation where we first discovered this vulnerability.
Microsoft Incident Response has published a guide for investigating attacks that use CVE-2023-23397, providing steps organizations can take to assess whether users have been targeted or compromised by threat actors exploiting the vulnerability. https://t.co/Izwm5CIU5I
Microsoft Incident Response has published a guide for investigating attacks that use CVE-2023-23397, providing steps organizations can take to assess whether users have been targeted or compromised by threat actors exploiting the vulnerability. https://t.co/Izwm5CIU5I
If you want to force the best #MFA method as default on each sign-in you can now test "System-preferred multifactor authentication" in #AzureAD
https://t.co/NrI16ggTHO
1/2
Folks, today we are launching the 'App instance lock 🔐' public preview.
This feature will block the tampering of multi tenant apps by attackers.
https://t.co/AQBm68rQHx
Remember Solorigate? This helps ISVs and customers protect themselves from the app hijack.
How?🧵👇