Главная
Study mode:
on
1
Introduction
2
Overview
3
DNS
4
Password Spraying
5
Cloud Administration
6
App Permissions
7
Conditional Access
8
Breach Replay
9
Password Hashing
10
MFA
11
Monitoring
12
TFS
13
Password Policy
14
Azure AD Ban Password Policy
15
Azure AD Domain Controllers
16
Password Spray
17
How to Block Password Spray
18
Authorization Rules
19
Blocking Legacy Authentication
20
Wrap Up
Description:
Dive into a comprehensive exploration of attack vectors and defense strategies for the Microsoft Cloud, focusing on Office 365 and Azure AD, in this 50-minute Black Hat presentation. Learn about common threats such as password spraying, DNS attacks, and breach replay, while discovering effective countermeasures including conditional access, multi-factor authentication, and robust password policies. Gain insights into cloud administration, app permissions, and monitoring techniques to enhance your organization's security posture. Although centered on Microsoft's ecosystem, many concepts apply to other cloud providers as well. Equip yourself with the knowledge to protect your cloud infrastructure and stay ahead of potential threats in this informative session presented by Sean Metcalf and Mark Morowczynski.

Attacking and Defending the Microsoft Cloud - Office 365 & Azure AD

Black Hat
Add to list