Latest Insights and Cybersecurity Resources

Token Theft Part 2 - Defensive

Token Theft Part 2 - Defensive


Marius Maciuitis

Defenders should focus on those users who trigger multiple alerts rapidly. For example, a risky sign-in followed closely by indicators of persistence techniques, such as mailbox rule creation.

Two detection sources are very helpful in detecting and alerting of token theft attacks, for example: Azure Active Directory Identity Protection and Microsoft Defender for Cloud Apps

Continue
Azure
Token Theft Part 1 - Offensive

Token Theft Part 1 - Offensive


Marius Maciuitis
An increasing number of cyber-attacks employ techniques to bypass multi-factor authentication (MFA) which allows criminals the ability to access corporate networks with limited ability by security teams to detect these threats.
Continue
AiTM
Importance of IOC Detection Rules

Importance of IOC Detection Rules


Marius Maciuitis
Continue
(Another) Business Email Compromise (BEC) Story

(Another) Business Email Compromise (BEC) Story


Marius Maciuitis
Continue
A foundational Threat Hunting framework

A foundational Threat Hunting framework


Marius Maciuitis
Continue
The difference between a SOC and a SIEM and do you need both?

The difference between a SOC and a SIEM and do...


Marius Maciuitis
Organisations looking to improve their cybersecurity posture are faced with many buying decisions, terminology and technology. The terms SIEM and SOC are sometimes incorrectly used interchangeably so what is the difference between them and do you need both?
Continue