ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What Are You Doing Right Now

    Water Closet
    time waster
    285
    88.9k
    41.8m
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dbeatoD
      dbeato
      last edited by

      Dealing with this...
      https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

      wrx7mW momurdaM zachary715Z 3 Replies Last reply Reply Quote 2
      • wrx7mW
        wrx7m @dbeato
        last edited by

        @dbeato said in What Are You Doing Right Now:

        Dealing with this...
        https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

        Oh no! How did you find out about the breach? Also, that is an interesting tool.

        dbeatoD 1 Reply Last reply Reply Quote 0
        • momurdaM
          momurda @dbeato
          last edited by

          I see scripts like that and realize how bad i am at scripting.
          That is really nice

          1 Reply Last reply Reply Quote 3
          • scottalanmillerS
            scottalanmiller
            last edited by

            Feeling tired, ready for the day to be over.

            1 Reply Last reply Reply Quote 0
            • dbeatoD
              dbeato @wrx7m
              last edited by

              @wrx7m said in What Are You Doing Right Now:

              @dbeato said in What Are You Doing Right Now:

              Dealing with this...
              https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

              Oh no! How did you find out about the breach? Also, that is an interesting tool.

              a customer called and stated he was getting emails from clients that were from him. We noticed it was sent from the Office 365 account and they had a delete rule for all the incoming and sent email.

              wrx7mW 1 Reply Last reply Reply Quote 1
              • wrx7mW
                wrx7m @dbeato
                last edited by

                @dbeato said in What Are You Doing Right Now:

                @wrx7m said in What Are You Doing Right Now:

                @dbeato said in What Are You Doing Right Now:

                Dealing with this...
                https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                Oh no! How did you find out about the breach? Also, that is an interesting tool.

                a customer called and stated he was getting emails from clients that were from him. We noticed it was sent from the Office 365 account and they had a delete rule for all the incoming and sent email.

                Yikes!

                1 Reply Last reply Reply Quote 0
                • zachary715Z
                  zachary715 @dbeato
                  last edited by

                  @dbeato said in What Are You Doing Right Now:

                  Dealing with this...
                  https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                  Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                  dbeatoD 1 Reply Last reply Reply Quote 1
                  • dbeatoD
                    dbeato @zachary715
                    last edited by

                    @zachary715 said in What Are You Doing Right Now:

                    @dbeato said in What Are You Doing Right Now:

                    Dealing with this...
                    https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                    Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                    Did you enable MFA after that on the accounts?

                    zachary715Z 1 Reply Last reply Reply Quote 0
                    • zachary715Z
                      zachary715 @dbeato
                      last edited by

                      @dbeato said in What Are You Doing Right Now:

                      @zachary715 said in What Are You Doing Right Now:

                      @dbeato said in What Are You Doing Right Now:

                      Dealing with this...
                      https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                      Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                      Did you enable MFA after that on the accounts?

                      We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

                      dbeatoD 1 Reply Last reply Reply Quote 1
                      • dbeatoD
                        dbeato @zachary715
                        last edited by

                        @zachary715 said in What Are You Doing Right Now:

                        @dbeato said in What Are You Doing Right Now:

                        @zachary715 said in What Are You Doing Right Now:

                        @dbeato said in What Are You Doing Right Now:

                        Dealing with this...
                        https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                        Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                        Did you enable MFA after that on the accounts?

                        We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

                        Oh okay, this account is fully Office 365.

                        zachary715Z 1 Reply Last reply Reply Quote 0
                        • zachary715Z
                          zachary715 @dbeato
                          last edited by

                          @dbeato said in What Are You Doing Right Now:

                          @zachary715 said in What Are You Doing Right Now:

                          @dbeato said in What Are You Doing Right Now:

                          @zachary715 said in What Are You Doing Right Now:

                          @dbeato said in What Are You Doing Right Now:

                          Dealing with this...
                          https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                          Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                          Did you enable MFA after that on the accounts?

                          We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

                          Oh okay, this account is fully Office 365.

                          Yeah we ended up creating some new rules as a result and learned a whole lot about all the different Office 365 relevant portals to capture logs, etc that we weren't fully aware of prior. It's really quite scattered at the moment and the ability to setup alerting is pretty weak, especially on the Azure side. Now we're having to manually check the "Users Flagged for Risk" and "Risky Sign Ins" weekly to help identify any fishy (phishy?) business.

                          1 Reply Last reply Reply Quote 2
                          • EddieJenningsE
                            EddieJennings
                            last edited by

                            Updating my FreePBX VM at the colo.

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @EddieJennings
                              last edited by

                              @eddiejennings said in What Are You Doing Right Now:

                              Updating my FreePBX VM at the colo.

                              We did that tonight. SO many updates.

                              EddieJenningsE 1 Reply Last reply Reply Quote 0
                              • EddieJenningsE
                                EddieJennings @scottalanmiller
                                last edited by

                                @scottalanmiller said in What Are You Doing Right Now:

                                @eddiejennings said in What Are You Doing Right Now:

                                Updating my FreePBX VM at the colo.

                                We did that tonight. SO many updates.

                                New install for me. Got ZeroTier installed on it, so I don't have to go through a fedora VM in VirtManager to get to the web interface 🙂

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  Loads of FreePBX updates.

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller
                                    last edited by

                                    Loads of NodeBB updates!

                                    1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller
                                      last edited by

                                      Getting ready for MangoLassi to update as we are slow after a very busy day.

                                      1 Reply Last reply Reply Quote 1
                                      • scottalanmillerS
                                        scottalanmiller
                                        last edited by

                                        First three NodeBB test sites are good.

                                        1 Reply Last reply Reply Quote 1
                                        • dbeatoD
                                          dbeato
                                          last edited by

                                          Working on Emails and Updates

                                          1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller
                                            last edited by

                                            Backup taken. Okay, starting in a moment...

                                            dbeatoD 1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 2951
                                            • 2952
                                            • 2953
                                            • 2954
                                            • 2955
                                            • 4443
                                            • 4444
                                            • 2953 / 4444
                                            • First post
                                              Last post