This WiCyS webinar will dive into UNC3944, also famously known as Scattered Spider has earned a reputation for aggressive social engineering, SIM swapping and identity based intrusions and their web footprints stretches deep into cloud environments. They have been known to exploit Azure AD, Microsoft 365 and other identity platforms to escalate privileges, maintain persistence and laterally move up without detection.
In this session, Varsha will unravel the tactics, techniques and procedures (TTPs) UNC3944 uses to compromise and abuse cloud platforms. Either as a beginner or mid-career professional interested in threat hunting, we'll talk through how to prepare a threat hunt methodology and hunt for their activity by correlating Azure AD sign-in data, M365 Unified Audit Logs, OAuth app grants and endpoint telemetry based off of open source threat intelligence data.
--
WiCyS is proud to provide members the opportunity to earn CPE/CEU credits for attending WiCyS Webinars live.
To earn CPE/CEU credits with the following providers, you must meet the minimum requirements:
- GIAC/(ISC)2: attend for a minimum of 45 minutes or the entirety of the webinar
- CompTIA: attend for a minimum of 60 minutes or the entirety of the webinar (webinar topic must relate to the certificate being renewed)
Attendees who meet the requirements can log into BrightTALK to print out their attendance certificates to submit for CPE/CEU credits.