Incident Response: Azure Log Analysis

Incident Response: Azure Log Analysis

Source: YouTube · John Hammond · published Nov 30, 2023 · 19:16

Incident Response
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates a complete cyber attack investigation on an MSP using Azure Active Directory logs 0:00. Attackers initially gained access through a password spray attack targeting multiple user accounts 4:57. They successfully compromised Paul Bowman's account after discovering his credentials 7:25.

Key Takeaways:
• Attackers used password spraying across multiple user accounts from a single IP address 4:57
• They laterally moved between workstations, executing malware from one machine to another 13:02
• The attackers stole browser cookies to bypass MFA and access the RMM tool 15:08
• Full domain compromise was achieved by pushing malware to all endpoints via the compromised RMM 17:17

The investigation showcases how a single compromised account can lead to complete domain takeover through proper log analysis.

Sources:

  • 0:00 Introduction to cyber attack investigation
  • 4:57 Password spray attack detection
  • 7:25 Account compromise identification
  • 13:02 Lateral movement evidence
  • 15:08 Cookie stealing technique
  • 17:17 Full domain compromise via RMM

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Incident Response. Commonly maps to: Security Operations, Security Assessment and Testing. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

let's go through a little cyber crime mystery let's do some incident response and investigate a hack only by using logs from the environment I want to walk you through the scenario of a hacked MSP or managed service provider that's using an Azure active directory and we'll go through all these different components from the initial intrusion pivoting in between different machines stealing cookies and browser sessions and then a full domain compromise so I am inside of a Linux terminal and I have all of these logs pulled down for us I want to be able to take a look through them we'll open it up in an editor but first let's get through the story first things first our goal is to figure out how the hackers gained initial access into our domain and environment we know this is azure based we're …