当前位置:首页 > 报告详情

Microsoft在您的BEC和(API)调用中:审核事件响应的邮箱项目访问 (Richard Smith).pdf

上传人: a****d 编号:402754 2025-01-10 46页 1.17MB

1、Microsoft at your BEC and(API)CallRichard Smith,Senior Consultant(Security Risk Advisors)October 20242WHOISIm Richard Smith,a Senior Consultant with Security Risk Advisors.4 years cybersecurity experience-SOC defense&leadership-CySA+-DevOps engineering10 years infrastructure IT experience-Desktop IT

2、-Systems and Network Administration-Virtualization(VMware,Nutanix,Citrix)Email:richard.smithsra.io1.StorytimeAre you sitting comfortably?Meet JimJim is the CISO at St Quentins Hospital,a medium-sized health care organization.They use Microsoft 365 for email.Theyre cost-conscious,but in a highly-regu

3、lated industry.Securing PHI/PII is of vital importance.Jim is very concerned5about the number,scope,and costof Business Email Compromise attacks.The cost of a breach can becripplingly high.If there is a cyber incidentLike,say,a compromised user accountthat has access to a mailboxthat contains sensit

4、ive information6How do you knowwhat the hacker saw?Previously,due to audit gaps caused by licensing issuesyou had to assume the intruder saw EVERYTHINGand you had to report that they saw EVERYTHINGand you would be fined as if they saw EVERYTHING7Most data breachesare affected by this auditing gap.8P

5、erry Johnson&Associates,May 2023:8,952,212 impactedMIE(Medical Informatics Engineering),July 2015:3.9 million impactedIts likely that in a lot of cases,the actual number of records accessed is much lower than reported.Jim has an idea!9What if we could show exactly which emails were accessed in a bre

6、ach?What if Microsoft made these logsavailable for export to any platform?What if there were indicators of compromise that could be leveraged for SIEM alerts?2.Accessing Email Audit LogsIts not quite as simple as it soundsFirst,make sure the logs are enabledGo to https:/ use PowerShell:Connect to Ex

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文介绍了Security Risk Advisors公司的Richard Smith高级顾问,他在网络安全和基础设施IT领域拥有超过14年的经验,专注于SOC防御、DevOps工程和虚拟化技术。文章提到,许多组织使用Microsoft 365进行电子邮件通信,但对其安全性的监管可能导致高昂的成本。因此,如何确保个人健康信息(PHI)/个人识别信息(PII)的安全成为关键问题。 文章提出了一个解决方案,即开发一个应用程序,通过Microsoft的API获取电子邮件审计日志,并将其导出到任何平台,以便更好地分析和监控。该应用程序可以检测到邮件服务器的阈值限制,并将其报告给SIEM,以便构建高保真的检测规则。 最后,文章以一个案例为例,说明了如何在实际安全事件中使用这种方法。通过该方法,可以准确地知道黑客访问了哪些电子邮件,从而有效地减少违规范围。 总之,本文主要介绍了如何利用Microsoft的API获取和分析电子邮件审计日志,以提高网络安全性和降低成本,并通过实际案例展示了该方法的有效性。
"如何准确识别黑客访问的电子邮件?" "如何利用Microsoft审计日志降低数据泄露风险?" "如何通过Node.js应用程序实现邮件审计日志的自动化处理?"
客服
商务合作
小程序
服务号
折叠