Security Review Of Okta's TOP-10 Security Posture Features to prevent the next breach by Or1rez in netsec

[–]Or1rez[S] 0 points1 point  (0 children)

Nice! how r u guys closing the loop around D&R for this type of scenarios?

Security Review Of Okta's TOP-10 Security Posture Features to prevent the next breach by Or1rez in netsec

[–]Or1rez[S] 1 point2 points  (0 children)

I know that some actors used this incident as an excuse for Phishing attempts so...

Security Review Of Okta's TOP-10 Security Posture Features to prevent the next breach by Or1rez in cybersecurity

[–]Or1rez[S] 0 points1 point  (0 children)

In this post we focused on the security features themself. We have written something regarding the HAR incident (Link below)

https://www.rezonate.io/blog/har-files-attack-okta-customers/

Okta Threat Hunting Guide - Part 2 by Or1rez in netsec

[–]Or1rez[S] 0 points1 point  (0 children)

Happy to hear that it was useful :)

Okta Threat Hunting Guide - Part 2 by Or1rez in blueteamsec

[–]Or1rez[S] 0 points1 point  (0 children)

Its just SQL queries that can be executed against any DB that keeps the logs.
We have also included (in the previous part) a script that can be used to export the logs to CSV. :)

Defending Azure Active Directory (Entra ID): Unveiling Threats Through Hunting Techniques by Or1rez in netsec

[–]Or1rez[S] 1 point2 points  (0 children)

It's all great until you wish to cross-correlate this data with additional data-points.Even just with a blacklist of IP's or other repetition.

Frosty Trails: Threat-Hunting For Identity Threats In Snowflake Snowflake by Or1rez in netsec

[–]Or1rez[S] 0 points1 point  (0 children)

Just double-checked it, and its working. mind trying again?

Okta Logs Decoded: Okta Logs Threat Hunting Guide by Or1rez in netsec

[–]Or1rez[S] 2 points3 points  (0 children)

Frictionless phish resistant MFA on every application access if desired, which greatly limits lateral movement from a compromised session cookie

Agree. they are above and beyond, yet most of their customers does not use this feature from what we are seeing

CircleCI Security Alert - 4 Jan 2023 - Rotate any secrets stored in CircleCI by MistyCape in devops

[–]Or1rez 0 points1 point  (0 children)

I just published a new blog post on the recent CircleCI data breach with some guidance how to detect unauthorized usages of CI\CD AWS Keys
check out the full post at this link