Skip to content

Commit 5b2216f

Browse files
authored
Merge pull request #932 from nterl0k/nterl0k-t1110-mfasweep-events
Nterl0k - T1110 mfasweep events
2 parents d9a5448 + 2109cb0 commit 5b2216f

File tree

2 files changed

+17
-0
lines changed

2 files changed

+17
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:ac689b65ab72fc6bad434ebebba4f42c2c2a846c915225829d2914010f9d9ad0
3+
size 12480
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Steven Dick
2+
id: 27ba7e07-280e-4890-9b31-f2060d86f4c6
3+
date: '2024-12-19'
4+
description: 'Sample of MFA Sweep events used to enumerate Azure/Entra/o365 MFA weaknesses.'
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/azure_mfasweep_events/azure_mfasweep_events.log
8+
sourcetypes:
9+
- o365:management:activity
10+
references:
11+
- https://attack.mitre.org/techniques/T1110
12+
- https://www.blackhillsinfosec.com/exploiting-mfa-inconsistencies-on-microsoft-services/
13+
- https://sra.io/blog/msspray-wait-how-many-endpoints-dont-have-mfa/
14+
- https://github.com/dafthack/MFASweep/tree/master

0 commit comments

Comments
 (0)