A practical guide for managing sharing with OneDrive

A practical guide for managing sharing with OneDriveWith today’s reality of remote work and online learning, people need the ability to share content—documents, presentations, photos, videos, lesson plans, you name it—to get work done. And because of this, security around internal and external sharing is more important than ever before. While the abi… TECHCOMMUNITY.MICROSOFT.COMAnkita Kirti [https://techcommunity.microsoft.com/t5/microsoft-onedrive-blog/a-practical-guide-for-managing-sharing-wit…

Read More

SASE: Secure Access Service Edge

Interesting article here by Teri Radichel (@2ndSightLab); SASE: Secure Access Service EdgeYou may have seen a new acronym floating around: SASE. I’ve been exploring the capabilities of this new class of security service offering. I talk about my take on security and cloud acronyms in my…Cloud SecurityTeri Radichel [https://medium.com/cloud-security/sase-secure-access-service-edge-1164a5ecaf55]…

Read More

A bunch of FQDNs and IPs to block (Ransomware-related)

Some useful FQDNs and IPs to block at the perimeter (at least): > Publishing my IoCs for WastedGholish (SocGholish loader/WastedLocker ransomware), involved in big incidents. hostnames, example hashes etc: https://t.co/jPPts8eBa7 YARA rule for generic detection: https://t.co/EuBMKc4wyy Most importantly block IP this address: 130.0.233.178 — Kevin Beaumont (@GossiTheDog) October 8, 2020 [https://twitter.com/GossiTheDog/status/1314192814289362944?ref_src=twsrc%5Etfw] In case the tweet disappe…

Read More

AD Security Guidance

> Wow, this was a happy little discovery... Here's a huge list of recommended remediations for #ActiveDirectory [https://twitter.com/hashtag/ActiveDirectory?src=hash&ref_src=twsrc%5Etfw] https://t.co/FE84VsRcmp There's a bunch of other guidance in this section. Looks like it's for the old PFE-led RaaS's, but still valid :P — Nathan McNulty (@NathanMcNulty) October 24, 2020 [https://twitter.com/NathanMcNulty/status/1319793488754425856?ref_src=twsrc%5Etfw] Remediation steps for Active Directory…

Read More

Microsoft Defender ATP: Attack Surface Reduction

> Secret tip. Running Windows Pro? Not a Defender ATP customer. They still work with defender standalone. Pre-configure ASR even if you use a third party solution. If your primary AV fails to get loaded you should be in a decent protected state out of the box. #infosec [https://twitter.com/hashtag/infosec?src=hash&ref_src=twsrc%5Etfw] https://t.co/1K41kDZTf0 — Root (@rootsecdev) October 10, 2020 [https://twitter.com/rootsecdev/status/1314729531639463937?ref_src=twsrc%5Etfw]…

Read More