Soap Box: A deep dive on how Russia's SVR is hacking Microsoft 365 tenants
Feb 18, 2024
auto_awesome
Cybersecurity expert Andy Robbins from SpecterOps discusses Russia's SVR hacking Microsoft 365 tenants. Topics include Entra ID security, detecting attack paths, managing permissions, hacking tactics for email inboxes, and the importance of permissions auditing in Azure environments.
Properly securing Entra ID tenants is crucial due to Russia's SVR attacks, highlighting the use of Bloodhound Enterprise for vulnerability assessment.
Permissions auditing in Azure is critical to prevent foreign application privilege escalation, necessitating streamlined auditing processes for enhanced visibility.
Deep dives
Overview of Bloodhound Enterprise and Its Capabilities in Active Directory
Bloodhound Enterprise, developed by SpectorOps, is a tool designed to connect to Active Directory systems and identify attack paths by identifying misconfigurations and risky permissions. The tool provides insights into potential vulnerabilities by demonstrating how adversaries can exploit pre-existing configurations and privileges within the system.
Discussion on the Russian SVR Attack and Initial Access Methods
The podcast elaborates on a large-scale attack by Russia's SVR intelligence agency on EntraID tenants, emphasizing the vulnerability stemming from weak passwords and easy-to-guess credentials. The interview with Andy Robbins reveals how the attackers gained initial access through a test tenant and proceeded to compromise an app registration within the tenant.
Importance of Permissions Auditing and Configuration Management
The conversation highlights the criticality of permissions auditing in Azure environments to mitigate risks associated with foreign applications gaining elevated privileges. Emphasis is placed on reducing superfluous permissions granted to applications and the necessity of periodic audits to evaluate and adjust access levels.
Challenges and Limitations in Permissions Auditing Tools
The podcast delves into the challenges faced by Azure admins in effectively auditing permissions, citing limitations in the GUI interface of the Azure portal. It points out the complexities in understanding and controlling permissions, emphasizing the need for streamlined auditing processes and improved visibility into permissions cross-tenant boundaries.
The need to properly secure Entra ID tenants has been made pretty obvious this year thanks to a large-scale attack on them by Russia’s SVR intelligence agency. In this interview Andy Robbins from SpecterOps, the maker of Bloodhound Enterprise, talks through how he thinks those attacks actually went down, about how if you’re an o365 customer you’re using Entra ID whether you like it or not, and about how you can lock down your Entra ID tenant.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode