Microsoft Security Copilot Announced (Mar 2023): Generative AI Comes to the SOC
On March 28, 2023, Microsoft announced Microsoft Security Copilot, a generative AI assistant for security teams built on OpenAI's GPT-4 and Microsoft's...
Insights
Articles in Retrospectives.
On March 28, 2023, Microsoft announced Microsoft Security Copilot, a generative AI assistant for security teams built on OpenAI's GPT-4 and Microsoft's...
AI assistants for security operations can speed up triage and investigation — or add cost and noise. Here is a practical way to evaluate them.
Use this checklist before and during a pilot of an AI security assistant.
The short version: In 2023, Microsoft launched Security Copilot, an AI assistant for security teams. Many vendors followed. AI can make security analysts...
On January 5, 2023, AWS began automatically applying server-side encryption with Amazon S3 managed keys (SSE-S3) to all new objects uploaded to S3, at no...
All new S3 objects are encrypted by default with SSE-S3. For sensitive data, you may want more control. Here is how to choose between SSE-S3, SSE-KMS and...
KMS key policies decide who can decrypt your sensitive S3 data. Use this checklist to audit encryption and key policies.
The short version: Since January 2023, AWS automatically encrypts all new files stored in S3. That's good — but encryption by default doesn't stop someone...
On January 4, 2023, CircleCI, a widely used continuous integration and delivery platform, told customers to rotate all secrets stored in its platform...
When a provider tells you to rotate everything, the hardest part is knowing what "everything" is. A rotation fire drill — practiced in advance — makes it...
After a CI/CD provider breach, attackers use stolen secrets to access your cloud. Detecting that use — and use of secrets after rotation — tells you whether...
The short version: In January 2023, CircleCI — a service many companies use to build and deploy software — told every customer to change every password and...
In August 2022, password manager LastPass disclosed that an attacker had accessed its development environment. In December 2022, it revealed that the...
In the LastPass breach, attackers stole backups from cloud storage using credentials taken from an engineer's home computer. Backups need their own...
Attackers increasingly target backups — to steal data or to delete it before ransomware. These detections watch for unusual backup access and changes.
The short version: In 2022, attackers stole encrypted copies of LastPass customers' password vaults by hacking an engineer's home computer and using it to...
At AWS re:Invent in November 2022, AWS announced previews of Amazon Security Lake and AWS Verified Access, alongside other security updates.
Amazon Security Lake centralizes and normalizes security logs from AWS and other sources into OCSF format in your own S3 buckets. Here is how to set it up.
Use this checklist to plan which data goes into Amazon Security Lake and how long you keep it.
The short version: In 2022, AWS introduced Security Lake, which stores your security logs in your own cloud account, in a standard format any security tool...
Beginning October 1, 2022, Microsoft started permanently disabling Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Remote...
Microsoft retired Basic Authentication for most Exchange Online protocols in 2022, but legacy authentication can still appear through SMTP AUTH, other...
After Basic Authentication was turned off in Exchange Online, many organizations found lingering dependencies. Use this checklist to clean up.
The short version: In October 2022, Microsoft permanently turned off older sign-in methods for its cloud email after a three-year warning. Some printers,...