EK
37 posts











Here is where things take an even stranger turn. According to the Texas Secretary of State Website, this is ZBN LLC’s physical address. 9180 Forest Ln. APT. 202. Dallas, Tx. 75243. Which leads us back to an apartment complex in Dallas. Millennium Dallas apartments.














At a minimum, even if you are using some other logging solution for security intelligence. Everyone should be collecting the first two bullet points into Azure Sentinel. I’m not even saying you have to setup alerts in sentinel or starting monitoring alerts there. Minimum retention should be increased to 6 months. Yes, that does cost money to do. My warning here is that if you ever have to activate your incident response plan, BEC or all the above. IR teams will be better equipped with how the intrusion started and can better focus on containment/prevention. Dont get caught discovering logging gaps in the cloud. I’m not trying to upsell Microsoft products. I simply want folks to be prepared for cloud related events as attackers start shifting thier focus on cloud. Source: learn.microsoft.com/en-us/azure/se…






















