1、Microsoft at your BEC and(API)CallRichard Smith,Senior Consultant(Security Risk Advisors)October 20242WHOISIm Richard Smith,a Senior Consultant with Security Risk Advisors.4 years cybersecurity experience-SOC defense&leadership-CySA+-DevOps engineering10 years infrastructure IT experience-Desktop IT
2、-Systems and Network Administration-Virtualization(VMware,Nutanix,Citrix)Email:richard.smithsra.io1.StorytimeAre you sitting comfortably?Meet JimJim is the CISO at St Quentins Hospital,a medium-sized health care organization.They use Microsoft 365 for email.Theyre cost-conscious,but in a highly-regu
3、lated industry.Securing PHI/PII is of vital importance.Jim is very concerned5about the number,scope,and costof Business Email Compromise attacks.The cost of a breach can becripplingly high.If there is a cyber incidentLike,say,a compromised user accountthat has access to a mailboxthat contains sensit
4、ive information6How do you knowwhat the hacker saw?Previously,due to audit gaps caused by licensing issuesyou had to assume the intruder saw EVERYTHINGand you had to report that they saw EVERYTHINGand you would be fined as if they saw EVERYTHING7Most data breachesare affected by this auditing gap.8P
5、erry Johnson&Associates,May 2023:8,952,212 impactedMIE(Medical Informatics Engineering),July 2015:3.9 million impactedIts likely that in a lot of cases,the actual number of records accessed is much lower than reported.Jim has an idea!9What if we could show exactly which emails were accessed in a bre
6、ach?What if Microsoft made these logsavailable for export to any platform?What if there were indicators of compromise that could be leveraged for SIEM alerts?2.Accessing Email Audit LogsIts not quite as simple as it soundsFirst,make sure the logs are enabledGo to https:/ use PowerShell:Connect to Ex