Am feeling very fortunate to be a part of the Alpha class for this. The authors are all top of their game and the huge amount of effort they've put into the content certainly shows. Looking forward to day 2!
- The attack surface of on-prem Exchange paired with the extensive domain privileges held by it is something that has always troubled me. I've come to figuratively consider it as "Tier 0b". There is some solid advice here on how to best manage it:
- I'm a huge fan of using Obsidian for everything from a knowledgebase through to a shopping list. @Bank_Security has done a great job in this post of showing how effective it can be as a CTI tool:
- AITM phishing. PDF links to the Cloudflare protected kit through DoubleCick and Baidu redirects. Common indicators: 24x7bus[.]com eviva13[.]com httpbin[.]org adfs.heart[.]org and sign-in's observed using Surfshark and Proxy-Seller IP's.
- While the technique has been known of for a while, there's a growing trend of BEC using Dynamics 365 Customer Voice as a landing. Example: customervoice[.]microsoft[.]com -> CF worker - > evans-dixon[.]homes or oil-marketings[.]com Sample: app.any.run/tasks/2ebe5f2c…


