
Device Code Login Phishing Presentation Attack, Detect, Mitigate
Source: YouTube · IppSec · published Apr 11, 2025 · 30:19
The video provides an educational overview of Device Code Phishing, covering its mechanics, real-world examples like the Storm 2372 campaign, and defensive strategies for detection and prevention 0:00.
Key Takeaways:
• The presenter introduces the topic of Device Code Phishing by referencing a Microsoft Threat Intelligence article about the Storm 2372 campaign 0:06.
• The session includes a guest speaker to discuss historical context, setup methods, and a live demonstration of the attack in action 0:12.
• Blue team strategies are emphasized, focusing on specific techniques to detect and prevent Device Code Phishing attacks 0:23.
This content serves as a practical guide for security professionals to understand and mitigate modern OAuth-based phishing threats.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
What's going on YouTube? This is IPSC and we're going to do something a little bit different today and just talk about device code fishing. Starting with this article from Microsoft Thread Intelligence. After this article, I'm going to bring on a friend. We'll go over a presentation we made on device code fishing. A little bit of the history, how to set it up and other things. Then we'll do a live demo, show you what it looks like in the field. And then after the demo, we're going to talk about some blue team things like how to detect and prevent it. So, with that being said, let's just get into the article titled, "Storm 2372 conducts device code fishing campaign." And right off the bat, I kind of dismissed the article because I'm a bit numb to fishing campaigns. It's hard to do fishing a…