Midnight Blizzard attack on Microsoft corporate environment: a detailed analysis, detections and recommendations
wiz.io | blog | #threat-detection | #microsoft | #oauth | #incident-analysis | #password-spraying | #apt29
Summary
Analysis of Midnight Blizzard's (APT29) breach of Microsoft: a password-sprayed legacy test tenant plus abused OAuth apps led to corporate mailbox access; with detections and hardening advice.
- Published
- Collected
Skip to content