Build a stronger security strategy with proactive and reactive incident response: Cyberattack Series
ID: b208206f-44ed-5c7c-8f8d-b5223fb597a2
STIX ID: report--b208206f-44ed-5c7c-8f8d-b5223fb597a2
Feed Name: Microsoft Security
This Microsoft Incident Response case study describes a mid-2024 compromise assessment that escalated when Storm-2077, a Chinese state-sponsored threat actor, used stolen session tokens and token-replay to access multiple accounts, create a global administrator account, disable legitimate admins, and exfiltrate email data; because the assessment was already active, the team rapidly transitioned to reactive response, contained the actor, remediated access, and highlights lessons and recommendations for combining proactive compromise assessments with reactive incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
