After SolarWinds (Dec 2020): Attackers Abuse Azure AD Application Credentials
After SolarWinds was discovered in December 2020, Microsoft and incident responders described a key technique the attackers used in Microsoft 365: abusing...
Insights
Articles in Retrospectives.
After SolarWinds was discovered in December 2020, Microsoft and incident responders described a key technique the attackers used in Microsoft 365: abusing...
Service principals and app registrations can hold powerful permissions with little oversight. Here is how to audit them in Entra ID.
Attackers who compromise applications or service principals can access data across a tenant without user sign-ins. Detecting credential and permission...
The short version: In the SolarWinds attack, intruders read email by hijacking applications connected to Microsoft 365 rather than user accounts. Apps and...
In November 2020, AWS Network Firewall became generally available — a managed, stateful network firewall and intrusion prevention service for Amazon VPCs.
A centralized inspection VPC lets one AWS Network Firewall deployment filter traffic for many VPCs. Here is the common architecture and setup sequence.
Egress filtering is one of the most effective controls against data exfiltration and malware. Use this checklist to put it in place across AWS VPCs.
The short version: Cloud servers can usually connect to anywhere on the internet by default. Attackers rely on that to steal data and control compromised...
In August 2020, Microsoft patched CVE-2020-1472, a critical flaw in the Netlogon Remote Protocol used by Windows domain controllers. In September,...
Domain controllers hold the keys to your on-premises identity — and, in hybrid environments, a path to the cloud. Here is how to patch and monitor them...
Attacks on Active Directory — including Zerologon exploitation, DCSync and Kerberos abuse — leave specific traces. Microsoft Defender for Identity and...
The short version: In 2020, a flaw called Zerologon let attackers take over a company's core identity system — Active Directory — in seconds, without a...
At Microsoft Ignite in September 2020, Microsoft reorganized its security products under a single brand: Microsoft Defender. The change reflected its...
Microsoft's security product names have changed many times. Here is a practical map of the Microsoft Defender family — what each product does and how to...
Owning Microsoft Defender licenses isn't the same as being protected. Use this checklist to onboard the Defender XDR products properly.
The short version: Many companies pay for Microsoft 365 E5 or similar licenses that include a full suite of security tools — and use only part of it....
On July 15, 2020, the Twitter accounts of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple and others posted a cryptocurrency scam. Attackers had taken...
Microsoft Entra Privileged Identity Management (PIM) makes administrative access temporary, approved and audited. Here is how to use it to protect admin...
Attackers who social-engineer employees often go straight for administrative tools. Detecting unusual admin access helps you catch them before they act.
The short version: In 2020, attackers took over the Twitter accounts of world leaders and celebrities — not by hacking Twitter's systems directly, but by...
In July 2020, Microsoft warned about a rise in consent phishing (also called illicit consent grant) campaigns, many using COVID-19 themes. Instead of...
Malicious OAuth apps can read mail and files without a password. Here is how to find and remove them in Microsoft 365.
Illicit consent grants give attackers persistent access to Microsoft 365 data. Detecting them quickly is essential because password resets don't remove them.
The short version: In 2020, attackers began tricking employees into clicking "Accept" on a Microsoft permission screen for a fake app. The employee signs in...