Detection Opportunities
Learn how to decipher the Microsoft Unified Audit Log (UAL) from a Digital Forensics & Incident Response (DFIR) perspective with Purav Desai, an experienced M365/Azure Incident Responder. In today's episode, we explore the Add-RoleGroupMember operation in Exchange Online. Purav's LinkedIn [ https://www.linkedin.com/in/purav-da346393/] Deciphering UAL [https://github.com/PuravsPoint/DecipheringUAL] Microsoft Application IDs [https://learn.microsoft.com/en-us/troubleshoot/azure/entra/entra-id/governance/verify-first-party-apps-sign-in] Permission Alert Policy [https://learn.microsoft.com/en-us/purview/alert-policies#permissions-alert-policies] _____________ TIMESTAMPS: 00:00 Intro 00:48 Add-RoleGroupMember Overview 03:22 The Result Status 04:53 The Application IDs 08:59 Key Fields of Note 10:39 Fields to Decipher 20:14 Detection - Permission Alert Policies 23:18 Custom Alerting 24:32 Final Thoughts 25:39 Outro _____________ ⚡️JOIN 6,000+ CWX MEMBERS ON DISCORD [https://discord.gg/cyberwoxacademy] 📰 SUBSCRIBE TO THE CYBERWOX UNPLUGGED NEWSLETTER [https://cyberwoxunplugged.com] 🥶 CYBERWOX MERCH [https://store.cyberwox.com] _____________ 🧬 CYBERWOX RESOURCES 🔹 Cyberwox Cybersecurity Notion Templates for planning your career [https://daycyberwox.gumroad.com/l/cyberlearningframework]🔹 Cyberwox Best Entry-Level Cybersecurity Resume Template [https://daycyberwox.gumroad.com/l/cybersecurityresume] 🔹 Learn AWS Threat Detection with my LinkedIn Learning Course [https://www.linkedin.com/learning/introduction-to-aws-threat-detection/] _____________ 📱 LET'S CONNECT → IG [https://www.instagram.com/daycyberwox ] → Threads [https://www.threads.net/@daycyberwox] → Substack [https://substack.com/@cyberwox] → Twitter [https://twitter.com/DayCyberwox ] → Linkedin [https://www.linkedin.com/in/dayspringjohnson/] → Tiktok [https://www.tiktok.com/@cyberwox] Email: day@cyberwox.com _____________ ⚠️DISCLAIMER This description has some affiliate links, and I may receive a small commission for purchases made through these links. I appreciate your support!
9 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y forma parte de la comunidad de Detection Opportunities!