| Web | https://jamesbmarshall.com |
| GitHub | https://github.com/jamesbmarshall |
| Cloud Target Calculator | https://targetcalculator.cloud |
| Web | https://jamesbmarshall.com |
| GitHub | https://github.com/jamesbmarshall |
| Cloud Target Calculator | https://targetcalculator.cloud |
So you have #MFA... so how in the heck are bad guys bypassing it?
One of the more common methods is 'token theft' & it's dangerous because it requires very little expertise, is hard to detect, & few organizations have token theft mitigations in their incident response plan.
Read about how it works & how to address it in your #Microsoft #Azure #AzureAD environment:
"Token tactics: How to prevent, detect, and respond to cloud token theft" - Microsoft Security Blog
http://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/
As organizations increase their coverage of multifactor authentication (MFA), threat actors have begun to move to more sophisticated techniques to allow them to compromise corporate resources without needing to satisfy MFA. Recently, the Microsoft Detection and Response Team (DART) has seen an increase in attackers utilizing token theft for this purpose.
I love closing out the year with this. 😊
On December 31, 1995, exactly 27 years ago today, legendary cartoonist Bill Watterson published his final 'Calvin and Hobbes' comic strip.
How beautiful and appropriate it was, and a timeless reminder of what we have before us in 2023. ❤️
Happy New Year, ya'll!