Detecting Help Desk MFA Reset Abuse: Entra Sign-In Logs and Sentinel KQL
After help desk social engineering, attackers typically reset MFA, register their own method and sign in. These detections connect those events.
Insights
Articles in Retrospectives.
After help desk social engineering, attackers typically reset MFA, register their own method and sign in. These detections connect those events.
The short version: In 2025, attackers reportedly tricked an IT help desk into resetting access, then shut down Marks & Spencer's online store for weeks. The...
On March 14, 2025, security researchers discovered that tj-actions/changed-files, a popular GitHub Action used in tens of thousands of repositories, had...
The tj-actions compromise showed that referencing GitHub Actions by tag lets an attacker change your pipeline without touching your code. Here is how to pin...
Supply-chain attacks on CI/CD dependencies often reveal themselves in workflow behavior and logs. These detections help spot compromised actions and secret...
The short version: In March 2025, a popular add-on used in tens of thousands of software build pipelines was hijacked. It quietly printed companies' secret...
In March 2025, a threat actor using the name "rose87168" claimed to have stolen millions of records from Oracle Cloud's single sign-on (SSO) login...
When a credible report claims your identity or cloud provider was breached — but the provider hasn't confirmed it — you still need to act. Here is a...
When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections...
The short version: In 2025, a hacker claimed to have stolen login data from Oracle's cloud. Oracle denied it; researchers said the evidence looked real....
The Bybit theft began with a compromised developer machine and stolen AWS session tokens. Here is how to protect developer workstations and limit the value...
Stolen AWS session tokens let attackers act as a legitimate user without signing in. Detection focuses on where and how sessions are used.
The short version: In 2025, North Korean hackers stole about $1.5 billion from crypto exchange Bybit. They didn't attack Bybit directly — they hacked a...
Codefinger ransomware encrypted S3 objects with SSE-C keys only the attacker held. Here is how to block SSE-C and make your S3 data recoverable.
Cloud-native ransomware like Codefinger leaves clear traces in CloudTrail — if you're logging S3 data events and watching for them.
The short version: In early 2025, attackers used stolen AWS keys to lock companies' cloud storage files with encryption keys only the attackers had — using...
On December 30, 2024, the US Treasury Department told Congress that a China state-sponsored actor had accessed some Treasury workstations and unclassified...
API keys for remote support and management tools can provide direct access to your devices. Here is how to inventory them and rotate them safely.
Stolen API keys for remote support tools grant access without user sign-ins. These detections focus on unusual key use and remote sessions.
The short version: At the end of 2024, Chinese state hackers accessed US Treasury computers through BeyondTrust, a company whose software lets IT staff...
At Microsoft Ignite in November 2024, security announcements centered on resilience and exposure. Two stood out: the Windows Resiliency Initiative, a...
Not all vulnerabilities and misconfigurations matter equally. Attack path analysis shows which ones an attacker could chain to reach your critical assets....
Use this checklist to start an exposure management program with Microsoft Defender tools.
The short version: Security teams are drowning in alerts and vulnerability lists. In 2024, Microsoft and other vendors pushed a different approach:...