ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What Are You Doing Right Now

    Water Closet
    time waster
    285
    88.9k
    41.3m
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dbeatoD
      dbeato @wrx7m
      last edited by

      @wrx7m said in What Are You Doing Right Now:

      @dbeato said in What Are You Doing Right Now:

      Dealing with this...
      https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

      Oh no! How did you find out about the breach? Also, that is an interesting tool.

      a customer called and stated he was getting emails from clients that were from him. We noticed it was sent from the Office 365 account and they had a delete rule for all the incoming and sent email.

      wrx7mW 1 Reply Last reply Reply Quote 1
      • wrx7mW
        wrx7m @dbeato
        last edited by

        @dbeato said in What Are You Doing Right Now:

        @wrx7m said in What Are You Doing Right Now:

        @dbeato said in What Are You Doing Right Now:

        Dealing with this...
        https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

        Oh no! How did you find out about the breach? Also, that is an interesting tool.

        a customer called and stated he was getting emails from clients that were from him. We noticed it was sent from the Office 365 account and they had a delete rule for all the incoming and sent email.

        Yikes!

        1 Reply Last reply Reply Quote 0
        • zachary715Z
          zachary715 @dbeato
          last edited by

          @dbeato said in What Are You Doing Right Now:

          Dealing with this...
          https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

          Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

          dbeatoD 1 Reply Last reply Reply Quote 1
          • dbeatoD
            dbeato @zachary715
            last edited by

            @zachary715 said in What Are You Doing Right Now:

            @dbeato said in What Are You Doing Right Now:

            Dealing with this...
            https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

            Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

            Did you enable MFA after that on the accounts?

            zachary715Z 1 Reply Last reply Reply Quote 0
            • zachary715Z
              zachary715 @dbeato
              last edited by

              @dbeato said in What Are You Doing Right Now:

              @zachary715 said in What Are You Doing Right Now:

              @dbeato said in What Are You Doing Right Now:

              Dealing with this...
              https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

              Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

              Did you enable MFA after that on the accounts?

              We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

              dbeatoD 1 Reply Last reply Reply Quote 1
              • dbeatoD
                dbeato @zachary715
                last edited by

                @zachary715 said in What Are You Doing Right Now:

                @dbeato said in What Are You Doing Right Now:

                @zachary715 said in What Are You Doing Right Now:

                @dbeato said in What Are You Doing Right Now:

                Dealing with this...
                https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                Did you enable MFA after that on the accounts?

                We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

                Oh okay, this account is fully Office 365.

                zachary715Z 1 Reply Last reply Reply Quote 0
                • zachary715Z
                  zachary715 @dbeato
                  last edited by

                  @dbeato said in What Are You Doing Right Now:

                  @zachary715 said in What Are You Doing Right Now:

                  @dbeato said in What Are You Doing Right Now:

                  @zachary715 said in What Are You Doing Right Now:

                  @dbeato said in What Are You Doing Right Now:

                  Dealing with this...
                  https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                  Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                  Did you enable MFA after that on the accounts?

                  We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

                  Oh okay, this account is fully Office 365.

                  Yeah we ended up creating some new rules as a result and learned a whole lot about all the different Office 365 relevant portals to capture logs, etc that we weren't fully aware of prior. It's really quite scattered at the moment and the ability to setup alerting is pretty weak, especially on the Azure side. Now we're having to manually check the "Users Flagged for Risk" and "Risky Sign Ins" weekly to help identify any fishy (phishy?) business.

                  1 Reply Last reply Reply Quote 2
                  • EddieJenningsE
                    EddieJennings
                    last edited by

                    Updating my FreePBX VM at the colo.

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @EddieJennings
                      last edited by

                      @eddiejennings said in What Are You Doing Right Now:

                      Updating my FreePBX VM at the colo.

                      We did that tonight. SO many updates.

                      EddieJenningsE 1 Reply Last reply Reply Quote 0
                      • EddieJenningsE
                        EddieJennings @scottalanmiller
                        last edited by

                        @scottalanmiller said in What Are You Doing Right Now:

                        @eddiejennings said in What Are You Doing Right Now:

                        Updating my FreePBX VM at the colo.

                        We did that tonight. SO many updates.

                        New install for me. Got ZeroTier installed on it, so I don't have to go through a fedora VM in VirtManager to get to the web interface 🙂

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller
                          last edited by

                          Loads of FreePBX updates.

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller
                            last edited by

                            Loads of NodeBB updates!

                            1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller
                              last edited by

                              Getting ready for MangoLassi to update as we are slow after a very busy day.

                              1 Reply Last reply Reply Quote 1
                              • scottalanmillerS
                                scottalanmiller
                                last edited by

                                First three NodeBB test sites are good.

                                1 Reply Last reply Reply Quote 1
                                • dbeatoD
                                  dbeato
                                  last edited by

                                  Working on Emails and Updates

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller
                                    last edited by

                                    Backup taken. Okay, starting in a moment...

                                    dbeatoD 1 Reply Last reply Reply Quote 1
                                    • dbeatoD
                                      dbeato @scottalanmiller
                                      last edited by

                                      @scottalanmiller said in What Are You Doing Right Now:

                                      Backup taken. Okay, starting in a moment...

                                      Good luck 🙂

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @dbeato
                                        last edited by

                                        @dbeato said in What Are You Doing Right Now:

                                        @scottalanmiller said in What Are You Doing Right Now:

                                        Backup taken. Okay, starting in a moment...

                                        Good luck 🙂

                                        Thanks.

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          Here we go....

                                          1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller
                                            last edited by

                                            And we are back!

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2951
                                            • 2952
                                            • 2953
                                            • 2954
                                            • 2955
                                            • 4443
                                            • 4444
                                            • 2953 / 4444
                                            • First post
                                              Last post