How to Govern Azure Storage SAS Tokens and Disable Shared Key Access
SAS tokens grant time-limited access to Azure Storage — but poorly scoped tokens can expose entire accounts for years. Here is how to govern them and remove...
Insights
Articles in Retrospectives.
SAS tokens grant time-limited access to Azure Storage — but poorly scoped tokens can expose entire accounts for years. Here is how to govern them and remove...
Overly permissive or leaked SAS tokens provide direct access to Azure Storage. These detections help find token exposure and misuse.
The short version: In 2023, Microsoft's own AI researchers accidentally exposed 38 terabytes of internal data — including passwords and private messages —...
The help desk is now a primary target for social engineering. Here is how to harden identity verification and password/MFA resets.
Help desk social engineering usually ends with a password or MFA reset followed by an attacker sign-in. These detections connect the two.
The short version: In 2023, a phone call to MGM's IT help desk reportedly led to a ransomware attack that shut down casinos and hotels for days and cost...
On August 2, 2023, Microsoft reported that Midnight Blizzard — the Russian state actor also known as APT29 or Nobelium, linked to SolarWinds — was using...
Microsoft Teams external access lets users chat with people in other organizations. Attackers use it for phishing. Here is how to restrict it to what your...
Teams chat phishing arrives outside email defenses. These detections help spot suspicious external chats and their consequences.
The short version: In 2023, Russian state hackers used Microsoft Teams chat — not email — to trick people into approving login requests. Companies have...
Storm-0558 was detected because a customer had detailed mailbox access logs. Here is how to make sure your Microsoft 365 audit logging captures what you'd...
Forged or stolen tokens let attackers access mailboxes without normal sign-ins. Mailbox access audit events are often the only evidence.
The short version: In 2023, Chinese hackers read US government email by forging digital keys in Microsoft's systems. A government agency caught it — because...
On July 11, 2023, Microsoft announced that Azure Active Directory would be renamed Microsoft Entra ID. The change rolled out across portals, documentation...
The rename from Azure AD to Microsoft Entra ID didn't change functionality, but it's a good reason to update documentation and retire legacy tooling —...
Use this checklist to review the health of your Microsoft Entra ID configuration.
The short version: In 2023, Microsoft renamed Azure Active Directory to Microsoft Entra ID. Nothing about security changed with the name. But renames are a...
Attackers repeatedly target internet-facing file transfer, integration and remote access services. Here is how to inventory them so you can patch, restrict...
Mass exploitation of file transfer products typically targets web interfaces and ends with bulk data downloads. These detections help catch both stages.
The short version: In 2023, a ransomware gang exploited a flaw in MOVEit, a file transfer product, stealing data from over 2,000 organizations — many of...
In April 2023, AWS changed the default settings for all new S3 buckets: S3 Block Public Access is enabled, and access control lists (ACLs) are disabled...
New S3 buckets have ACLs disabled by default, but older buckets may still rely on them. Migrating to "Bucket owner enforced" simplifies access control. Here...
Use this checklist to clean up legacy S3 ACLs and ownership settings.
The short version: In April 2023, AWS changed the defaults so new cloud storage buckets are private and simpler to secure. That's a big improvement — but it...