
Storm-0558 - Attack on Exchange Online
Mahesh Paswan
Description
<p>On this week's episode, Adam and Andy talk Storm-0558, the China-based actor, that compromised Exchange Online. They go through the attack chain and CISA's guidance on how you can better protect your organization going forword.</p> <p>-------------------------------------------</p> <p>Youtube Video Link: <a href="https://youtu.be/N7dRPCCU25A">https://youtu.be/N7dRPCCU25A</a></p> <p>-------------------------------------------</p> <p>Documentation: <a href="https://blogs.microsoft.com/on-the-issues/2023/07/11/mitigation-china-based-threat-actor/" target="_blank" rel="noopener noreferer">https://blogs.microsoft.com/on-the-issues/2023/07/11/mitigation-china-based-threat-actor/</a></p> <p><a href="https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/" target="_blank" rel="noopener noreferer">https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/</a></p> <p><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-193a" target="_blank" rel="noopener noreferer">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-193a</a></p> <p><a href="https://learn.microsoft.com/en-us/compliance/assurance/assurance-audit-logging" target="_blank" rel="noopener noreferer">https://learn.microsoft.com/en-us/compliance/assurance/assurance-audit-logging</a></p> <p><a href="https://learn.microsoft.com/en-us/microsoft-365/compliance/audit-log-enable-disable?view=o365-worldwide" target="_blank" rel="noopener noreferer">https://learn.microsoft.com/en-us/microsoft-365/compliance/audit-log-enable-disable?view=o365-worldwide</a></p> <p><a href="https://learn.microsoft.com/en-us/microsoft-365/compliance/audit-premium?view=o365-worldwide" target="_blank" rel="noopener noreferer">https://learn.microsoft.com/en-us/microsoft-365/compliance/audit-premium?view=o365-worldwide</a></p> <p><a href="https://learn.microsoft.com/en-us/microsoft-365/compliance/audit-log-search?view=o365