"CISA Launches Free Tool to Detect Hacking in Microsoft Cloud Services"

1 min read
Source: BleepingComputer
"CISA Launches Free Tool to Detect Hacking in Microsoft Cloud Services"
Photo: BleepingComputer
TL;DR Summary

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has released an open-source incident response tool called 'Untitled Goose Tool' that helps detect signs of malicious activity in Microsoft cloud environments. The Python-based utility can dump telemetry information from Azure Active Directory, Microsoft Azure, and Microsoft 365 environments. With the help of CISA's cross-platform Microsoft cloud interrogation and analysis tool, security experts and network admins can export and review AAD sign-in and audit logs, M365 unified audit log (UAL), Azure activity logs, Microsoft Defender for IoT alerts, and Microsoft Defender for Endpoint data for suspicious activity.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

77%

41195 words

Want the full story? Read the original article

Read on BleepingComputer