#cloudforensics — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cloudforensics, aggregated by home.social.
-
"I SPy" Entra ID Global Admin Escalation Technique
Datadog's Security Labs identified an abuse of Office 365 Exchange Online service principal (SP) allowing escalation to Global Admin. MSRC considers it "expected misconfiguration" so don't expect a fix.
🚨 Alert on new credentials added to SPs.
🔥 Monitor changes to federated domains (federationConfiguration).
🕵🏼♂️ Hunt unusual Graph API calls to /domains, /credentials, and /federationConfiguration.🔗 https://securitylabs.datadoghq.com/articles/i-spy-escalating-to-entra-id-global-admin/
#DFIR #ThreatHunting #EntraID #CloudForensics #M365 #ThreatDetection
-
#Ransomware threat actors are increasingly abusing AWS's Server-Side Encryption (SSE-C) to encrypt S3 buckets without needing to drop malware. Most recently a TA known as #Codefinger is using this technique.
🕵 Make sure you're monitoring S3 and encryption activity via CloudTrail & GuardDuty.
https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c
-
With a rise in Adversary in the Middle (AiTM) phishing, we've seen attackers leverage trusted compromised accounts to launch multi-stage attacks and follow-on BEC activity. Too often, investigations end with "If only this data had been available!"
We are kicking off our 3-part series on handling Business Email Compromise (BEC) incidents in Microsoft 365! 📧 In Part 1, Rachel dives into the key artefacts for investigating a BEC in M365 and where to find them.
This includes:
Why enabling Unified Audit Logging is essential for tracking attackers.
How to use Purview Content Search to analyse compromised mailboxes.
Pro tips for using Defender's Advanced Hunting to quickly scope the scale of an attack.
Stay tuned for more actionable insights in Parts 2 & 3!
#CyberSecurity #BusinessEmailCompromise #M365 #IncidentResponse
#MicrosoftDefender #EmailSecurity #DigitalForensics #DataRetention #ThreatHunting #CloudForensics -
UPCOMING WEBINAR – Empowering Investigations With Data From The Cloud https://www.forensicfocus.com/news/upcoming-webinar-empowering-investigations-with-data-from-the-cloud/ #Cellebrite #cloudforensics
-
UPCOMING WEBINAR – Empowering Investigations With Data From The Cloud https://www.forensicfocus.com/news/upcoming-webinar-empowering-investigations-with-data-from-the-cloud/ #Cellebrite #cloudforensics #dfir
-
UPCOMING WEBINAR – Fireside Chat: Navigating The Cloud – Expert Insights On Emerging Cloud Threats And Complexities https://www.forensicfocus.com/news/upcoming-webinar-fireside-chat-navigating-the-cloud-expert-insights-on-emerging-cloud-threats-and-complexities/ #CadoSecurity #cloudforensics #dfir
-
UPCOMING WEBINAR – Fireside Chat: Navigating The Cloud – Expert Insights On Emerging Cloud Threats And Complexities https://www.forensicfocus.com/news/upcoming-webinar-fireside-chat-navigating-the-cloud-expert-insights-on-emerging-cloud-threats-and-complexities/ #CadoSecurity #DFIR #cloudforensics
-
Cado Security releases its H2 2023 Cloud Threat Findings Report to help security teams secure against cloud-focused threat actors. https://www.forensicfocus.com/news/cado-security-releases-h2-2023-cloud-threat-findings-report/ #CadoSecurity #cloudforensics
-
Chris Doman, Co-Founder of Cado Security, joins the Forensic Focus podcast to discuss cloud forensics and incident response. https://www.forensicfocus.com/podcast/how-cado-security-is-revolutionizing-forensics-and-incident-response-for-the-cloud/ #CadoSecurity #cloudforensics #dfir
-
Oxygen Forensic® Detective v.16.0 Introduces Decryption Of VeraCrypt Containers https://www.forensicfocus.com/news/oxygen-forensic-detective-v-16-0-introduces-decryption-of-veracrypt-containers/ #OxygenForensics #mobileforensics #cloudforensics #DFIR
-
Congratulations to our #FOR509 Day 6 Capstone winners in #Singapore last week.
It was one of the closest challenges between the competing teams I've seen.
#CloudForensics
#DFIR @sansapac -
I've been presenting with @megan@infosec
.exchange about #DFIR evidence collection at a few conferences now, but I still get people asking for the presentation, so here's one of the better recordings from the 2023 RSA Conference.
#CloudForensics -
#DEFCONTraining Las Vegas Spotlight: Join #KerryHazelton
Aug 14-15 for a 2-day hands-on training called "Cloud Forensics Workshop & CTF Challenge: Lab Rat Edition"http://training.defcon.org for more info
From the abstract: "Now in its sixth iteration since its initial launch at BSides DC in October 2017, the Cloud Forensics Workshop and CTF Challenge have been a regular feature at multiple security conferences across the country where security professionals learn the core concepts of digital forensics and incident response in a Cloud computing environment."
#defcon #defcontraining #defcon31 #cloudforensics #ctf #kerryhazelton
-
This is one the most comprehensive collection of log sources for #AWS #CloudForensics, along with a summary of each log source, and some simple details on storage and searching data.
If you regularly do #DFIR in #AWS this is a perfect resource.
https://aws.amazon.com/blogs/security/logging-strategies-for-security-incident-response/
-
One of my brilliant coauthors Megan Roddie did a write up from our SANS #FOR509 #CloudForensics class on how to extract #AWS logs for analysis.
#DFIR #CSIRT #CERT
https://www.sans.org/blog/aws-cloud-log-extraction/ -
Cloud Forensics: Obtaining iCloud Backups, Media Files and Synchronized Data by @ElcomSoft #DFIR #CloudForensics https://www.linkedin.com/posts/juantorresibanez_cloud-forensics-obtaining-icloud-backups-activity-7001102745994686464-b4iU