Thomas Naunheim 3/20/2023

Abuse and Detection of M365D Live Response for privilege escalation on Control Plane (Tier0) assets

Read Original

This technical article details how Microsoft 365 Defender's Live Response feature, used for remote investigation and forensic evidence collection, can be abused for privilege escalation on critical Control Plane (Tier0) assets. It explains the feature's components, programmatic access via the MDE API, and provides guidance for security teams on detecting such malicious activity.

Abuse and Detection of M365D Live Response for privilege escalation on Control Plane (Tier0) assets

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week