Detection Opportunities
Visit my sponsor [https://snhu.edu/cyberwox] to view the current average annual salary for a Cybersecurity degree and learn how to get started. Purav's LinkedIn [ https://www.linkedin.com/in/purav-da346393/] Deciphering UAL [https://github.com/PuravsPoint/DecipheringUAL] Exchange Admin Audit Logging [https://learn.microsoft.com/en-us/purview/audit-log-activities#exchange-admin-activities] Office365 Management Activity API [https://learn.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema#enum-auditlogrecordtype---type-edmint32] Connect-IPPSSession [https://learn.microsoft.com/en-us/powershell/module/exchange/connect-ippssession?view=exchange-ps] _____________ TIMESTAMPS: 00:00 Intro 00:36 Get-RoleGroup Operation 01:37 Enumeration is not logged?? 05:53 SNHU 07:22 Using the Security Compliance Center EOPCmdlet 08:54 Abusing Purview Compliance & E-Discovery 10:21 Useful Log Fields & Key Fields of note 12:48 Attack Demo 14:45 Fields to Decipher 15:51 How To Detect/Analyse 17:59 Get-RoleGroupMember 19:39 Useful Log Fields 20:30 Attack Demo 23:01 Segmentation Of Behaviors 23:57 Connect-IPPSSession 26:07 Final Thoughts 27:40 Outro _____________ ⚡️JOIN 6,000+ CWX MEMBERS ON DISCORD [https://discord.gg/cyberwoxacademy] 📰 SUBSCRIBE TO THE CYBERWOX UNPLUGGED NEWSLETTER [https://cyberwoxunplugged.com] 🥶 CYBERWOX MERCH [https://store.cyberwox.com] _____________ 🧬 CYBERWOX RESOURCES 🔹 Cyberwox Cybersecurity Notion Templates for planning your career [https://daycyberwox.gumroad.com/l/cyberlearningframework]🔹 Cyberwox Best Entry-Level Cybersecurity Resume Template [https://daycyberwox.gumroad.com/l/cybersecurityresume] 🔹 Learn AWS Threat Detection with my LinkedIn Learning Course [https://www.linkedin.com/learning/introduction-to-aws-threat-detection/] _____________ 📱 LET'S CONNECT → IG [https://www.instagram.com/daycyberwox ] → Threads [https://www.threads.net/@daycyberwox] → Substack [https://substack.com/@cyberwox] → Twitter [https://twitter.com/DayCyberwox ] → Linkedin [https://www.linkedin.com/in/dayspringjohnson/] → Tiktok [https://www.tiktok.com/@cyberwox] Email: day@cyberwox.com _____________ ⚠️DISCLAIMER This description has some affiliate links, and I may receive a small commission for purchases made through these links. I appreciate your support!
9 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Detection Opportunities!