Build AI Apps with Azure, Copilot, and Generative AI — Microsoft Certified
Learn EDR Internals: Research & Development From The Masters
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Learn to conduct digital forensics and incident response (DFIR) investigations of malicious scripts within Microsoft Intune environments through this conference presentation. Explore a real-world 2023 case study involving unauthorized access to an Azure tenant by the Scattered Spider threat group, examining how attackers leveraged cloud-based device and application management systems for malicious purposes. Master forensic analysis techniques for recreating attacks and understanding their impact, including baseline configuration establishment, specialized forensic tool deployment, and systematic methodologies for detecting and analyzing cloud-based threats. Discover how to leverage the Microsoft Graph API for investigation purposes, track user actions across cloud environments, analyze modification timestamps for timeline reconstruction, and decode PowerShell script contents using tools like CyberChef. Gain insights into the evolving landscape of enterprise security challenges posed by cloud-based solutions and develop practical skills for investigating incidents in Microsoft Intune and broader Azure environments.
Syllabus
Investigating a Malicious Script in Microsoft Intune
Taught by
SANS Digital Forensics and Incident Response