Ohhhh365 - How to (Quite) Reliably Hack into Microsoft 365, And What to Do Afterwards

No ratings

Presented at Bsides Cymru 2024 by

An employee's M365 account has become a pivotal asset, guarding business-critical data such as internal emails and SharePoint data. In this talk, we dive into modern tradecraft used by JUMPSEC to compromise M365 in our adversary simulation engagements, some of which were recently used by an advanced threat group to successfully breach Microsoft. The talk will outline our methodologies in obtaining unauthorised access, followed by strategies for post-compromise actions.