LIVE · cybersecurity feed
Live wire
security

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. One log that really bears looking at is the log of successful and failed logins. the call for that is:

zeroday.news ·

A recent report highlights a persistent oversight in cloud security practices, specifically regarding the monitoring of login attempts within Microsoft Entra ID (formerly Azure Active Directory). The report emphasizes that organizations migrating to cloud environments often neglect to maintain the same level of vigilance over their cloud logs, particularly successful and failed login attempts, that they previously applied to on-premises systems. This oversight creates a significant blind spot for detecting malicious activity.

The core issue revolves around the underutilization of readily available logging data within Entra ID. While cloud platforms provide extensive telemetry, the report suggests that many administrators are not actively reviewing these logs. This contrasts sharply with traditional on-premises security postures, where daily log analysis of authentication events was a common and critical practice.

For Entra ID, the relevant data pertains to authentication events, which record both successful and unsuccessful login attempts. These logs are crucial for identifying various types of attacks, including password spraying. Password spraying is a common attack technique where an attacker attempts a small number of common passwords against a large number of user accounts, rather than repeatedly trying many passwords against a single account. This method often bypasses account lockout policies designed to thwart brute-force attacks.

The report implicitly advocates for the regular use of PowerShell cmdlets to extract and analyze Entra ID login data. PowerShell provides a powerful interface for interacting with Microsoft cloud services, enabling administrators to programmatically query and filter vast amounts of log information. By scripting these queries, organizations can automate the process of identifying suspicious login patterns.

Typical mitigation guidance for this class of issue involves establishing a robust log management and analysis strategy. This includes defining what constitutes suspicious activity, setting up alerts for specific thresholds (e.g., an unusual number of failed logins from a single IP address, or successful logins from unexpected geographic locations), and regularly reviewing aggregated log data. Implementing multi-factor authentication (MFA) is also a critical defense, as it significantly reduces the effectiveness of password-based attacks like password spraying, even if credentials are compromised.

The broader context of this finding points to a common challenge in the transition to cloud computing: the shift in operational responsibilities and the need for updated security skill sets. While cloud providers offer secure infrastructure, the security of data and access within that infrastructure remains a shared responsibility. Organizations must adapt their security operations to leverage cloud-native tools and telemetry effectively, ensuring that the visibility gained from extensive cloud logging is actively translated into actionable security intelligence.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... This is that method. Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We&#;x26;#;39;ll u

phishing

Russian snoops add OAuth abuse to targeted phishing campaigns

Don't click on that State Department meeting invite

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.