Microsoft Incident Response has published a guide for investigating attacks that use CVE-2023-23397, providing steps organizations can take to assess whether users have been targeted or compromised by threat actors exploiting the vulnerability. https://t.co/Izwm5CIU5I
The Unified Audit Log can help build a full story of a threat actor’s activity in #Office365, but its sheer size and detail can be daunting. Are you equipped to hunt through this forensic artifact effectively? Read our latest blog to find out: https://t.co/wlKo7Rx9Wv
Microsoft Security Threat Intelligence teams have published additional analysis on observed exploitation of Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082 with security product mitigations and detections to help protect against further attacks https://t.co/5jcROyyBEz
Are you interested in learning how you can leverage Microsoft Security APIs for incident response? Part 1 of this 3-part series is now available: https://t.co/Os07Msgk1Q #MicrosoftDART#DFIR#IncidentResponse
@brooksrunning with a solid today! Replaced my barely broken in running shoes (that cause massive blisters and blood just walking) that I bought elsewhere 6 months ago! #runhappy
Question for incident responders... You are asked to do an investigation related to an incident in "the cloud"... How do you scope the investigation? Do you only look at the data in the cloud environment? Do you include endpoint devices? Should you include endpoint devices?
The “breastfeeding is free” narrative in the midst of an infant formula shortage is a great example of public ignorance of what it actually takes to successfully breastfeed.