flâneur — a map of the web's best reading

Entra ID service principals in business email compromise schemes

redcanary.com · 3,658 words · saved by 1 readers

Threat Detection Report: Midyear Update Read our latest analysis of security tends and the rise of identity-based threats. Contact Us How can we help you? The service principals in Microsoft’s Entra ID can be a boon for business email compromise, but they’re also a key log source for detection. Adversaries have started to abuse service principals in Microsoft’s Entra ID identity platform. As was openly discussed in CISA’s investigation of the Microsoft key-signing breach and another breach caused by the threat group called Midnight Blizzard, the use of service principals was a key mechanism for reading emails in victim organization mailboxes. After crafting valid tokens with newly obtained stolen signing keys, adversaries were able to read emails from their victims’ mailboxes using an unidentified application. The Microsoft breach was reportedly discovered from a customer’s detection analytic internally dubbed the “Big Yellow Taxi.” While the exact detection logic from “Big Yellow Ta

Entra ID service principals in business email compromise schemes | Red Canary Skip Navigation Get a Demo Products Managed Detection and Response AI Agents Threat Intelligence Automation Security Data Lake Managed Phishing Response Training & Tabletops What's New Plans Solutions By domain Identity Email Endpoint Cloud By technology Zscaler Microsoft CrowdStrike SentinelOne Palo Alto Networks AWS Google Linux & Kubernetes By Industry Financial Services Healthcare Technology Manufacturing Education Government Resources Blog Guides & Overviews Case Studies Videos Webinars Cybersecurity 101 Events

Explore this link on the map →

saved by

related reading