Attack scenarios
In this section, we will explore some of the common attack scenarios that have been increasing in recent years and how Microsoft’s XDR and SIEM solutions can detect and remediate them.
An identity-based supply chain attack in the cloud
What’s the definition of a supply chain attack? It is an attack that targets a trusted third-party vendor who provides critical supply chain services or software. In recent years, there has been a significant increase in security vulnerabilities related to cloud identities within the context of supply chain attacks (such as Solarigate).
Let’s suppose an adversary can get access to a service provider environment by compromising the user entity. In this case, there are doors open to all client environments where the service provider provides services. To mitigate this, there are plenty of security measures that you could use on both the MSP/MSSP and client sides. However, many environments lack these safeguards...