ISC StormCast for Friday, October 2nd 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 October 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, October 2, 2020 edition of the Sandcent Storm Center's Stormcast. |
| 0:08.3 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.7 | Of course, we are all aware that companies are moving servers into the cloud at a record rate. And with that security relevant services, |
| 0:24.9 | like for example, Active Directory often end up in the cloud as well. Of course, Microsoft is |
| 0:32.0 | ready for that with Azure AD. And today we have a quick diary from Daniel about how to actually deal with AAD logs. |
| 0:45.4 | Now yes, you can haul them back into your on-premise secure infrastructure, but well, |
| 0:52.1 | that probably moved into the cloud as well. And Microsoft, again, |
| 0:56.3 | has a solution for you here to directly import your Asia AD or AAD logs into a log analytics |
| 1:06.5 | space within Asia. Daniel is explaining how to find some interesting events in this case and what to look for |
| 1:16.1 | here, because after all, well, no active directory is exposed to the internet and with that |
| 1:22.1 | of course monitoring it becomes even more important. |
| 1:26.5 | And now of course if you for example come up with a suspicious IT address or such by reviewing |
| 1:32.7 | these logs, you better act on it fast and also review these logs regularly. |
| 1:38.9 | And that's really what a second diary by Daniel is about. |
| 1:44.0 | And that's the lifetime of indicators |
| 1:47.3 | of compromise, which, as he points out, often then become indicators of outdated intelligence. |
| 1:54.8 | Quite often organizations love to purchase and apply in the case of compromise, like IP addresses and malware has a very |
| 2:05.1 | short lifetime. And while it's easy to apply and search for these in a case of compromise, |
| 2:12.9 | the value of that search may be somewhat limited. And yes, it may be worth the time to actually look |
| 2:20.5 | for some of the more complex techniques, tactics, and procedures that are not as quickly |
| 2:27.8 | and simply matched to log files. And Apple pulled the latest Mojave Security Update 2025 and also removed Safari 14 from its |
| 2:43.0 | download site. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

