More dates

Payment plans

How does it work?

  • Reserve your order today and pay over time in regular, automatic payments.
  • You’ll receive your tickets and items once the final payment is complete.
  • No credit checks or third-party accounts - just simple, secure, automatic payments using your saved card.

WS8 - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response

Share
DEF CON Workshops
Add to calendar
 

Description

Instructed by:  Vince “bitpusher” Weppner

Level of Difficulty: Beginner, Intermediate

Abstract:

A compromised mailbox. An inbox rule named ".". An OAuth consent to an unknown application. A sign-in from a cloud-hosting ASN with user-agent "axios" and MFA status "satisfied by claim in token". Somewhere in there is the story - and somewhere in the Microsoft 365 logs is the evidence.

This four-hour hands-on workshop teaches Business Email Compromise investigation in the tenants most responders actually see: M365 Business Premium or E3. No Sentinel. No SIEM. No problem. Using only native admin centers, PowerShell modules, and a few scripts, you will run a complete BEC investigation end to end.

Working through several progressive scenarios, from single-user compromise, through lateral-pivot case with MailItemsAccessed analysis, to multi-account incident with a malicious enterprise app and transport rule. You will learn how to contain, collect, triage, pivot, expand scope, remediate, and produce the three common reporting deliverables: investigation report, attestation letter, internal post-mortem.

This is Living off the Land Incident Response. Through chronology and topology, come correlate some logs with me and see what story they tell.

Pre-Requisites:

Familiarity with Excel, M365, Entra ID, and PowerShell are recommended.



Powered by

Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity

Register

This event has passed

Register

This event has passed
DEF CON Workshops