Category Archives: AllPosts
How To: Investigate risk
Identity Protection provides organizations with three reports they can use to investigate identity risks in their environment. These reports are the risky users, risky sign-ins, and risk detections. Investigation of events is key to better understanding and identifying any weak points in your security strategy.
All three reports allow for downloading of events in .CSV format for further analysis outside of the Azure portal. The risky users and risky sign-ins reports allow for downloading the most recent 2500 entries, while the risk detections report allows for downloading the most recent 5000 records.
Organizations can take advantage of the Microsoft Graph API integrations to aggregate data with other sources they may have access to as an organization.
The three reports are found in the Azure portal > Azure Active Directory > Security.
What is FedRAMP?
The Federal Risk and Authorization Management Program (FedRAMP) provides a standardized approach to security authorizations for Cloud Service Offerings.
Why You Are Who You Arw
CEH – Hacker Etico Certificado
MS-700 Exam – Teams Administrator Associate
Exam AZ-500: Microsoft Azure Security Technologies – Exam Review
Exchange Server attacks: Run this Microsoft malware scanner now, CISA tells government agencies
The Microsoft scanner can use up a lot of a server’s processing capacity, so CISA recommends running the scan during off-peak hours.
"By 12:00 pm Eastern Daylight Time on Monday, April 5, 2021, download and run the current version of Microsoft Safety Scanner (MSERT) in Full Scan mode and report results to CISA using the provided reporting template," it notes.
Critical F5 BIG-IP Bug Under Active Attacks After PoC Exploit Posted Online
The flaws affect BIG-IP versions 11.6 or 12.x and newer, with a critical remote code execution (CVE-2021-22986) also impacting BIG-IQ versions 6.x and 7.x. CVE-2021-22986 (CVSS score: 9.8) is notable for the fact that it’s an unauthenticated, remote command execution vulnerability affecting the iControl REST interface, allowing an attacker to execute arbitrary system commands, create or delete files, and disable services without the need for any authentication.
https://thehackernews.com/2021/03/latest-f5-big-ip-bug-under-active.html
Burnt by SolarWinds attack? US releases tool for post-compromise detection
CISA says CHIRP currently looks for:
- The presence of malware identified by security researchers as TEARDROP and RAINDROP;
- Credential dumping certificate pulls;
- Certain persistence mechanisms identified as associated with this campaign;
- System, network, and M365 enumeration; and
- Known observable indicators of lateral movement.
CHIRP is available on GitHub as a compiled executable or as a Python script.
FireEye in January also released a free tool on GitHub called Azure AD Investigator.
Burnt by SolarWinds attack? US releases tool for post-compromise detection | ZDNet
