Over the years Microsoft DART has put together an immense amount of valuable information about preventing, detecting and responding to threats, from blogs to forensic guides. They are all now available to you in one spot via their very own Ninja Hub - https://t.co/XtIbiIXKLB
If you have spent time investigating MFA logs in Microsoft Entra ID, you may have seen the 'update user' event that follows changes to MFA on a user. Curious about what the various codes and data means in those events? Microsoft DART has you covered - https://t.co/5flCTZDoNA
This table in the Microsoft Digital Defense Report is always fascinating, these stats are taken from DART engagements and other IR teams, it shows the common issues seen across our customers. Brilliance in the basics isn't easy, but worth it. Full report - https://t.co/9qTi4mW4Vy
When an unpatched server allowed ransomware to exploit a known vulnerability, the Microsoft Incident Response team moved swiftly to contain it and regain control.
Read how in part three of our Cyberattack series: https://t.co/jR5bAiD5Le #MicrosoftIR#MSFTSecurityExperts
#Sysmon 15 is out and brings a new event type, FileExecutableDetected, which allows for much more detection opportunities.
I've wrote up some of my thoughts on what this feature brings and where it could be even better in this blog post https://t.co/duc6z64vnp
Thanks for joining us at #MSSecure today. If you missed it, check out the demo of Microsoft Security Copilot—the new product announced earlier: https://t.co/xAxQHcGn6S #AI
A repo worth starring if you investigate business email compromise as part of your job, Awesome-BEC by @phillmoore, which covers research, tooling and adversary simulation - https://t.co/oKCUAiNinQ
In nearly all of our on-premises engagements, a threat actor has taken total full control of Active Directory. If you are interested in the kind of things @MicrosoftDART finds, and how we recommend you secure Active Directory, then this blog is for you - https://t.co/D7fdIbsUn0
We have released updated customer guidance for reported zero-day vulnerabilities in Microsoft Exchange Server. Please see the MSRC Blog for details - https://t.co/Z1us58O6xL
Are you interested in learning how you can leverage Microsoft Security APIs for incident response? Part 1 of this 3-part series is now available: https://t.co/Os07Msgk1Q #MicrosoftDART#DFIR#IncidentResponse
#MSTIC 🛡️ & #DART 👻 are now hiring Hunt Analysts who live at the intersection of incident response and threat intelligence.
Have experience in both areas? Come join us!
Hunt Analyst 🕵️:
https://t.co/72IKr9GbDY
https://t.co/jvmCzYYtUG