logo

Build a stronger security strategy with proactive and reactive incident response: Cyberattack Series

ID: b208206f-44ed-5c7c-8f8d-b5223fb597a2

STIX ID: report--b208206f-44ed-5c7c-8f8d-b5223fb597a2

Feed Name: Microsoft Security

Threat Score
85/100

Date Published: 2025-02-10

Date Updated: 2026-04-28

Author: Microsoft Incident Response

...
...

This Microsoft Incident Response case study describes a mid-2024 compromise assessment that escalated when Storm-2077, a Chinese state-sponsored threat actor, used stolen session tokens and token-replay to access multiple accounts, create a global administrator account, disable legitimate admins, and exfiltrate email data; because the assessment was already active, the team rapidly transitioned to reactive response, contained the actor, remediated access, and highlights lessons and recommendations for combining proactive compromise assessments with reactive incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.