

Octo Tempest Threat Actor Profile
Nov 1, 2023
The podcast discusses the activities and tactics of a threat actor called Octo Tempest, such as SIM swapping, SMS phishing, and living off the land. It highlights their bespoke and persistent nature, as well as the importance of separating high-privileged accounts. Other topics include assuming compromised passwords, testing security controls, and the need for help desk protocol.
Chapters
Transcript
Episode notes
1 2 3 4 5 6
Introduction
00:00 • 2min
Octo Tempest: Tactics and Techniques
02:25 • 15min
Octo Tempest: Tactics and Characteristics
17:50 • 15min
Importance of Help Desk Protocol and Stringent Controls for Highly Privileged Users
32:25 • 4min
Separating High-Level Permissions Accounts from Normal User Accounts
36:07 • 7min
Assuming Compromised First Factor and Leveraging Access Management Gaps
42:44 • 2min