Device Code Login Phishing Presentation Attack, Detect, Mitigate

Device Code Login Phishing Presentation Attack, Detect, Mitigate

Source: YouTube · IppSec · published Apr 11, 2025 · 30:19

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video provides an educational overview of Device Code Phishing, covering its mechanics, real-world examples like the Storm 2372 campaign, and defensive strategies for detection and prevention 0:00.

Key Takeaways:
• The presenter introduces the topic of Device Code Phishing by referencing a Microsoft Threat Intelligence article about the Storm 2372 campaign 0:06.
• The session includes a guest speaker to discuss historical context, setup methods, and a live demonstration of the attack in action 0:12.
• Blue team strategies are emphasized, focusing on specific techniques to detect and prevent Device Code Phishing attacks 0:23.

This content serves as a practical guide for security professionals to understand and mitigate modern OAuth-based phishing threats.

Sources:

  • 0:00 Introduction to the video topic and device code phishing.
  • 0:06 Reference to Microsoft Threat Intelligence article on Storm 2372.
  • 0:12 Overview of the presentation structure including guest and demo.
  • 0:23 Discussion on blue team detection and prevention strategies.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What's going on YouTube? This is IPSC and we're going to do something a little bit different today and just talk about device code fishing. Starting with this article from Microsoft Thread Intelligence. After this article, I'm going to bring on a friend. We'll go over a presentation we made on device code fishing. A little bit of the history, how to set it up and other things. Then we'll do a live demo, show you what it looks like in the field. And then after the demo, we're going to talk about some blue team things like how to detect and prevent it. So, with that being said, let's just get into the article titled, "Storm 2372 conducts device code fishing campaign." And right off the bat, I kind of dismissed the article because I'm a bit numb to fishing campaigns. It's hard to do fishing a…