Doug Bienstock

483 posts

Doug Bienstock

Doug Bienstock

@doughsec

IR Leader @Mandiant. Hacking things and responding to things being hacked. Opinions my own

参加日 Şubat 2018
111 フォロー中2.5K フォロワー
固定されたツイート
Doug Bienstock
Doug Bienstock@doughsec·
🚨🚨 New technique to steal AD FS secrets over the network. Defenders need to block internal traffic to AD FS servers over port 80 now! Read more: fireeye.com/blog/threat-re… shoutout to @DrAzureAD who had the same though to look into AD FS replication and all his great work! 1/3
English
6
258
518
0
Doug Bienstock
Doug Bienstock@doughsec·
@NathanMcNulty Also to make sure these events can actually be retrieved from the purview portal, api, or PoSH you need to toggle auditing off and then back on for all mailboxes!
English
1
2
1
771
Nathan McNulty
Nathan McNulty@NathanMcNulty·
Fortunately, I have written a script that will ensure all mailboxes have all available auditing enabled, but note you will see errors on shared/resource mailboxes without licenses I try to keep it up to date in GitHub here: github.com/nathanmcnulty/… x.com/NathanMcNulty/…
Nathan McNulty@NathanMcNulty

#Requires ExchangeOnlineManagement # Connect to Exchange Online Connect-ExchangeOnline # Enable all advanced auditing (Get-Mailbox -ResultSize Unlimited -Filter { RecipientType -eq "UserMailbox" -and RecipientTypeDetails -ne "DiscoveryMailbox"}).PrimarySmtpAddress | ForEach-Object { Write-Output $_ Set-Mailbox -Identity $_ -AuditEnabled $true -AuditLogAgeLimit 365 -AuditAdmin @{add='Update, Copy, Move, MoveToDeletedItems, SoftDelete, HardDelete, FolderBind, SendAs, SendOnBehalf, Create, UpdateFolderPermissions, AddFolderPermissions, ModifyFolderPermissions, RemoveFolderPermissions, UpdateInboxRules, UpdateCalendarDelegation, RecordDelete, ApplyRecord, MailItemsAccessed, UpdateComplianceTag, Send, AttachmentAccess, PriorityCleanupDelete, ApplyPriorityCleanup'} -AuditDelegate @{add='Update, Move, MoveToDeletedItems, SoftDelete, HardDelete, FolderBind, SendAs, SendOnBehalf, Create, UpdateFolderPermissions, AddFolderPermissions, ModifyFolderPermissions, RemoveFolderPermissions, UpdateInboxRules, RecordDelete, ApplyRecord, MailItemsAccessed, UpdateComplianceTag, AttachmentAccess, PriorityCleanupDelete, ApplyPriorityCleanup'} -AuditOwner @{add='Update, Move, MoveToDeletedItems, SoftDelete, HardDelete, Create, MailboxLogin, UpdateFolderPermissions, AddFolderPermissions, ModifyFolderPermissions, RemoveFolderPermissions, UpdateInboxRules, UpdateCalendarDelegation, RecordDelete, ApplyRecord, MailItemsAccessed, UpdateComplianceTag, Send, SearchQueryInitiated, AttachmentAccess, PriorityCleanupDelete, ApplyPriorityCleanup'} }

English
3
2
25
3.9K
Doug Bienstock
Doug Bienstock@doughsec·
Great news for DFIR 🕵️ Except! These logs won’t be searchable from the Unified Audit Log for E3 licensees unless you manually toggle auditing for every mailbox in your tenant… 💀🤦🏽‍♂️ @Microsoft365 likes to make things difficult #search-for-mailbox-activities-performed-by-users-with-non-e5-licenses" target="_blank" rel="nofollow noopener">learn.microsoft.com/en-us/purview/… #DFIR
Matt Zorich@reprise_99

For those who were waiting for the additional logging and events to be available in the standard audit logging in Microsoft 365, like MailItemsAccessed, they should be available now in public preview for you - techcommunity.microsoft.com/t5/security-co…

English
0
3
9
1K
Doug Bienstock
Doug Bienstock@doughsec·
Anyone have resources or insights into Windows code integrity driver.stl file? I’m trying to parse it… 🕵️ #DFIR #Windows
English
0
2
1
1.1K
Doug Bienstock
Doug Bienstock@doughsec·
@KorstiaanS @Microsoft365 Ah nice thanks! Interesting in your tests the graph API while consistent returned fewer results than the old method 🙃
English
1
0
1
58
Doug Bienstock
Doug Bienstock@doughsec·
Audit log query graph API for @Microsoft365 rolling out in May. Has anyone found the actual documentation for the new API? Asking for a friend 💀#m365 #DFIR
English
1
3
10
2.8K
Doug Bienstock
Doug Bienstock@doughsec·
@DrAzureAD I thought it was mostly gone and now am being punished for that thought with an IR where attacker stole the ADFS signing key and is doing golden SAML 😀
English
2
0
11
1.2K
Doug Bienstock
Doug Bienstock@doughsec·
@_dirkjan This is a huge step back for the security community. I know many who use the developer tenant to stay up to date on security features and hone their skills investigating and securing m365
English
0
0
2
270
Dirk-jan
Dirk-jan@_dirkjan·
I've always recommend the free Microsoft 365 developer subscription as a great way to learn. Having it locked behind a 600 EUR to 3k EUR minimum cost is going to hurt Identity Security learning capabilities for everyone. Very sad to see it like this. devblogs.microsoft.com/microsoft365de…
English
10
36
122
20.5K
Doug Bienstock がリツイート
PIVOTcon
PIVOTcon@pivot_con·
"Microsoft Signed my Malware" Doug Bienstock (@JWilsonSecurity), Mandiant Jared Wilson (@doughsec) , Mandiant Barry Vengerik (@BarryV), Mandiant 14/15
PIVOTcon tweet media
English
1
9
29
2.5K
Doug Bienstock
Doug Bienstock@doughsec·
@reprise_99 Are IP addresses for cross tenant access still redacted? It breaks just about everything 😬😬
English
1
0
1
687
Matt Zorich
Matt Zorich@reprise_99·
Microsoft has seen an uptick in organizations having their M365 & Microsoft Entra ID tenants compromised as a result of supply chain compromise of a partner. We put together some guidance on using the Unified Audit Log as part of these investigations - techcommunity.microsoft.com/t5/microsoft-s…
English
7
112
369
41K
Sebastian Walla
Sebastian Walla@SebastianWalla·
@_dirkjan @joslieben What kind of security mechanism are you thinking of? I tried assigning password credentials to preexisting service principals a few weeks ago and the assignment worked fine (I.e. triggering a "Add service principal credentials" event). I haven't tried to actually use them though.
English
2
0
0
79
Doug Bienstock
Doug Bienstock@doughsec·
🚨 NetScaler vulnerability CVE-2023-4966 is being actively exploited. It can lead to VDI session hijacking, including MFA bypass. There are no logs on the appliance to monitor for exploitation. Upgrade now and investigate your environment! mandiant.com/resources/blog… #DFIR
English
0
26
41
7.5K
Doug Bienstock
Doug Bienstock@doughsec·
@ZawadiDone We don’t use bash often but for Unix systems it is often the most convenient and consistent
English
0
0
0
46
Doug Bienstock
Doug Bienstock@doughsec·
Today we launched a 🔎 scanning tool for orgs to search their Citrix netscalers for evidence of CVE-2023-3519 post-exploration. You can run this direct on the ADC or against a forensic image. With public POCs out there expect more exploitation! mandiant.com/resources/blog… #DFIR
English
2
32
51
8.4K
Doug Bienstock
Doug Bienstock@doughsec·
Turns out most of the documentation references a legacy APi endpoint that doesn’t work 🙄 the “tenant” URL should not be used
English
0
0
0
349