hawk
CrpUsernameStuffing
hawk | CrpUsernameStuffing | |
---|---|---|
14 | 1 | |
652 | 3 | |
- | - | |
3.9 | 4.3 | |
3 months ago | 9 months ago | |
PowerShell | PowerShell | |
MIT License | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
hawk
- Hawk Repo
-
Message Trace O365
I recommend checking this out btw https://github.com/T0pCyber/hawk
-
Office 365 Outlook rules automatically generating
run HAWK against the mailbox and it should surface something useful.
- Useful Email Compromise resource
- Compromised Email HOW?
-
Crazy Email Hacking
Use https://github.com/T0pCyber/hawk on the mailbox, it will show you everything you need to know. it knows what to look for, and produces a report on all the suss activities. Ive learnt best from letting it do its job then seeing what it found.
-
What do you use for your office 365 security routines and what routines do you perform?
HAWK is a great tool to investigate for suspicious activity. Its no silver bullet, but it does even dump a list of suspect accounts when you run the Tenant Investigation command. Probably with a little bit of work you could script HAWK to run automatically in bulk.
- User got phished. I asked her to think back and try to remember if she'd got an attachment that required login.
- Track down how account was compromised.
-
Office 365 audit log for compromised account
Have you ran the Powershell HAWK Tool ? https://github.com/T0pCyber/hawk
CrpUsernameStuffing
-
Compromised Email HOW?
Additionally, even if the system supports it, OTP methods presently break the ability to return vendor-specific attributes from the matching NPS policy (so your VPN server can't receive information based on AD groups, for example). This makes in-band MFA less viable even where the client supports it. However, Microsoft released a ridiculous workaround instead of fixing it: put the group based attributes in connection request policies instead of network policies - these work, but CRPs can't be based on groups, so they linked to some script on GitHub that you can make a scheduled task, that stuffs every username from a group into a CRP: https://github.com/OneMoreNate/CrpUsernameStuffing Basically, they have made little effort to enable the NPS MFA extensions to work with in-band methods in a sane and viable way.
What are some alternatives?
Business-Email-Compromise-Guide - The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Office 365 environment. Each step is intended to guide the process of identifying, collecting and analysing activity associated with BEC intrusions.
PowerShell - PowerShell functions and scripts (Azure, Active Directory, SCCM, SCSM, Exchange, O365, ...)
o365recon - retrieve information via O365 and AzureAD with a valid cred
monkey365 - Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Microsoft Entra ID security configuration reviews.
office365 - Repo for containing and managing office 365 scripts for my customers, techs and others. If you have any questions please feel free to hit me up.
Export-RecipientPermissions - Document, filter and compare Exchange permissions: Mailbox access rights, mailbox folder permissions, public folder permissions, send as, send on behalf, managed by, moderated by, linked master accounts, forwarders, sender restrictions, resource delegates, group members, management role group members
BadZure - BadZure orchestrates the setup of Azure AD tenants, populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack paths.
gophish - Open-Source Phishing Toolkit
orca - The Microsoft Defender for Office 365 Recommended Configuration Analyzer (ORCA)
SophosCentral - Sophos Central PowerShell module
PSKoans - A simple, fun, and interactive way to learn the PowerShell language through Pester unit testing.