Threat report

www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack

https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/
Published on
www.microsoft.com
Sources in this catalogue
2

ATT&CK techniques those detections carry

  • T1136.003Cloud Account
  • T1098.003Additional Cloud Roles
  • T1003.002Security Account Manager
  • T1098.002Additional Email Delegate Permissions
  • T1114.002Remote Email Collection
  • T1528Steal Application Access Token
  • T1566Phishing
  • T1566.002Spearphishing Link
Open the original

12 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Entra ID End-User Consent to Application with High-Risk Delegated ScopesMedium
O365 Privileged Graph API Permission AssignedMedium
O365 OAuth App Mailbox Access via EWSMedium
O365 Multiple Service Principals Created by UserInformational
O365 Multiple Service Principals Created by SPInformational
O365 Multiple Mailboxes Accessed via APIMedium
O365 FullAccessAsApp Permission AssignedMedium
O365 Admin Consent Bypassed by Service PrincipalMedium
Azure AD Privileged Graph API Permission AssignedMedium
Azure AD Multiple Service Principals Created by UserInformational
Azure AD Multiple Service Principals Created by SPInformational
Azure AD FullAccessAsApp Permission AssignedMedium

Showing 12 of 12

Filter in the catalogue

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice