Detecting Teams External Chat Phishing: Defender XDR and Sentinel Hunting Queries
Teams chat phishing arrives outside email defenses. These detections help spot suspicious external chats and their consequences.
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
Teams chat phishing arrives outside email defenses. These detections help spot suspicious external chats and their consequences.
The short version: In 2023, Russian state hackers used Microsoft Teams chat — not email — to trick people into approving login requests. Companies have...
Storm-0558 was detected because a customer had detailed mailbox access logs. Here is how to make sure your Microsoft 365 audit logging captures what you'd...
Forged or stolen tokens let attackers access mailboxes without normal sign-ins. Mailbox access audit events are often the only evidence.
The short version: In 2023, Chinese hackers read US government email by forging digital keys in Microsoft's systems. A government agency caught it — because...
On July 11, 2023, Microsoft announced that Azure Active Directory would be renamed Microsoft Entra ID. The change rolled out across portals, documentation...
The rename from Azure AD to Microsoft Entra ID didn't change functionality, but it's a good reason to update documentation and retire legacy tooling —...
Use this checklist to review the health of your Microsoft Entra ID configuration.
The short version: In 2023, Microsoft renamed Azure Active Directory to Microsoft Entra ID. Nothing about security changed with the name. But renames are a...
Attackers repeatedly target internet-facing file transfer, integration and remote access services. Here is how to inventory them so you can patch, restrict...
Mass exploitation of file transfer products typically targets web interfaces and ends with bulk data downloads. These detections help catch both stages.
The short version: In 2023, a ransomware gang exploited a flaw in MOVEit, a file transfer product, stealing data from over 2,000 organizations — many of...
In April 2023, AWS changed the default settings for all new S3 buckets: S3 Block Public Access is enabled, and access control lists (ACLs) are disabled...
New S3 buckets have ACLs disabled by default, but older buckets may still rely on them. Migrating to "Bucket owner enforced" simplifies access control. Here...
Use this checklist to clean up legacy S3 ACLs and ownership settings.
The short version: In April 2023, AWS changed the defaults so new cloud storage buckets are private and simpler to secure. That's a big improvement — but it...
On March 28, 2023, Microsoft announced Microsoft Security Copilot, a generative AI assistant for security teams built on OpenAI's GPT-4 and Microsoft's...
AI assistants for security operations can speed up triage and investigation — or add cost and noise. Here is a practical way to evaluate them.
Use this checklist before and during a pilot of an AI security assistant.
The short version: In 2023, Microsoft launched Security Copilot, an AI assistant for security teams. Many vendors followed. AI can make security analysts...
On January 5, 2023, AWS began automatically applying server-side encryption with Amazon S3 managed keys (SSE-S3) to all new objects uploaded to S3, at no...
All new S3 objects are encrypted by default with SSE-S3. For sensitive data, you may want more control. Here is how to choose between SSE-S3, SSE-KMS and...
KMS key policies decide who can decrypt your sensitive S3 data. Use this checklist to audit encryption and key policies.
The short version: Since January 2023, AWS automatically encrypts all new files stored in S3. That's good — but encryption by default doesn't stop someone...