How Threat Actors Persist In Your Microsoft 365

How Threat Actors Persist In Your Microsoft 365

Source: YouTube · SANS Digital Forensics and Incident Response · published Aug 15, 2025 · 23:49

Incident Response
No ratings yet Log in to rate
Transcript Available
Description

The speaker discusses persistence mechanisms in Microsoft 365, specifically focusing on backdoors and breadcrumbs during incident response investigations.

Key Takeaways:
• The presentation covers persistence techniques used by adversaries within the Microsoft 365 environment, including backdoors and breadcrumbs 0:11.
• The speaker, Federico Sedolini, is a senior consultant specializing in digital forensics and incident response, with expertise in M365 security automation 0:20.
• Incident response objectives vary, and investigators must understand the specific persistence methods to effectively track adversary activity 0:51.

This session provides foundational knowledge for securing M365 environments against persistent threats.

Sources:

  • 0:11 Introduction to persistence topics: backdoors and breadcrumbs in M365.
  • 0:20 Speaker introduction and professional background in digital forensics.
  • 0:51 Overview of incident response objectives and investigation goals.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Incident Response. Commonly maps to: Security Operations, Security Assessment and Testing. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

and very happy to be here sharing about this. So let's get started. Uh back doors and and breadcrumbs. We're going to be talking about just as was mentioned persistence across the Microsoft 365 environment. So who am I? My name is Fedrico Sedolini. I'm a senior consultant in Toronto with Estros Freedberg Digital Forensics and Incense Response. um several interest in cyber ranges from club forensics, M365 to security automation. I have a few several uh sand certifications and then I really enjoy hiking and sailing and there is a picture of me there showing that do I do in fact go outside and please do not confuse me with Bigfoot if you see me out there. So what are we going to be talking about today? During your IR investigations, you're going to have different objectives. Um here are four …