Skip to content

2024

Sentinel basics

Thought I may as well begin to share some Microsoft Sentinel Basics I have learnt over the last few months amongst other studies that I am currently completing.

This article is about Analytic Rules and creating a basic rule to alert on the creation of Malicious mailbox rules within an environment. Attackers use compromised accounts to create mailbox rules, a simple process that enables the attackers to maintain a quiet persistent access to the mailbox - they can use this for a whole variety of malicious purposes.

If your organisation isn't following a security control framework, this is why I believe they should...

With the cost of data breaches at an all-time high and regulators imposing steeper penalties for compliance failures, organisations that aren't implementing necessary security controls are sitting ducks.

𝗛𝗲𝗿𝗲 𝗶𝘀 𝗮𝗻 𝗲𝘅𝗮𝗺𝗽𝗹𝗲... DarkGate is using phishing campaigns that distributes malware through Microsoft Teams messages to there victims. Using compromised external Office 365 accounts, phishing messages are sent through Microsoft Teams to various organisations.