O365- Current Attack Trends, David Stubley, 7 Elements
Offered By: The Cyber Academy via YouTube
Course Description
Overview
Explore current attack trends targeting Office 365 in this informative 29-minute conference talk by David Stubley of 7 Elements. Gain insights into why attackers compromise systems, the mastery required for successful attacks, and the various areas of vulnerability. Learn about initial compromise techniques, including MFA bypass, phishing, voicemail exploitation, and Dropbox manipulation. Discover how attackers leverage basic authentication, mailbox access, and mail rules for onward compromise. Understand individual motives behind phishing emails and explore effective countermeasures. Discover the importance of enabling MFA, auditing logs, implementing basic MFA, blocking suspicious mail, and practicing compromise detection. Conclude with a Q&A session addressing O365 mailbox security concerns.
Syllabus
Intro
Agenda
Why Compromise
Mastery of an Attack
Initial Compromise
Areas of Attacks
MFA
Phishing
Voicemail
Dropbox
Phishing Contacts
Basic Auth
Mailbox
Mail Rules
Audit Log
VPN Traffic
Onward Compromise
Individual Motive
Phishing Emails
What can we do
Enable MFA
Audit logs
Basic MFA
Blocking Mail
Practice Log
Compromise
Questions
O365 Mailbox Bleeding
Taught by
The Cyber Academy
Related Courses
Microsoft Azure IdentityMicrosoft via edX Microsoft Azure Authentication Scenarios for Developers
Pluralsight Identity and Access Management on AWS: Users
Pluralsight AWS for Developers: Identity Access Management (IAM)
LinkedIn Learning Azure for Architects: Design an Authentication and Data Security Strategy
LinkedIn Learning