#microsoftincidentresponse

2024-06-11

Imagine you have been the victim of a cybersecurity incident. And you suspect that a large number of accounts, or possibly the entire Active Directory, may have been compromised.

How would you proceed? In such cases, we usually recommend a mass password reset of all user accounts. But are you prepared for this?

Read the article bellow published on our Microsoft Security Experts blog, which I co-authored, to learn in what cases you should do a mass password reset of user accounts and how best to prepare for such a scenario. #microsoftir #microsoftincidentresponse #passwordreset #dart

techcommunity.microsoft.com/t5

2023-07-10

Microsoft IR’s new blog details a BlackByte ransomware incident through the full attack chain, from initial access to impact. We cover tools, techniques, and IOCs identified during our investigation, as well as detections and recommendations to defend against BlackByte ransomware attacks. #CyberSecurity #BlackByteRansomware #microsoftincidentresponse #microsoftIR


Full details shared: microsoft.com/en-us/security/b

2023-03-25

Microsoft Incident Response examines how threat actors trigger Net-NTLMv2 hash leak using CVE-2023-23397 to gain unauthorized access to an organization’s environment #microsoftincidentresponse #microsoftIR: microsoft.com/en-us/security/b

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst