Autonomous IT, Live! Inside the Breach — Identity Hijack Response Exercise, E04
Autonomous IT17 Jul 2025

Autonomous IT, Live! Inside the Breach — Identity Hijack Response Exercise, E04

In this special live episode of Autonomous IT, Live! we walk through a high-stakes incident response drill that mimics a disturbingly realistic threat scenario: an attacker gains access to your internal tools — not by breaking in, but by logging in.

Here's the setup: a user unknowingly reuses compromised credentials with the company’s SSO provider. An attacker logs in, flies under the radar, and impersonates internal IT support using Slack, email, and calendar invites. Their goal? Convince employees to install a fake remote access tool—all while avoiding anyone likely to report suspicious behavior.

Join Landon Miles, Tom Bowyer, and Ryan Braunstein as they:

  • 🔍 Investigate a suspicious login and Slack impersonation
  • 🔐 Contain and remediate the breach using real-world tactics and tools
  • 📉 Discuss phishing-resistant MFA, endpoint visibility, Slack impersonation risks, and more
  • 🧠 Share tips on improving security awareness, incident playbooks, and interdepartmental collaboration
  • 💬 Answer live audience questions about malware analysis, EDR response, and building detection rules

Whether you’re a security veteran or just starting out in IT, this episode offers an unfiltered look at how to respond when credentials are compromised and attackers act like insiders.

📎 Bonus: We also include a downloadable Incident Response Checklist to help your team run your own tabletop exercise.

🛡️ Because in today’s world, attackers don’t need to break in—they just need to log in.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(228)

Patch [FIX] Tuesday – [973 CVEs and a New Patch Tuesday Record], Ep. 36

Patch [FIX] Tuesday – [973 CVEs and a New Patch Tuesday Record], Ep. 36

Labor Day is over and Microsoft made up for the day off. Landon Miles and Serena DiPenti sort September's Patch Tuesday down to the six bugs that matter, starting with the only one Microsoft confirms ...

8 Sep 23min

Autonomous IT, Live! Turn to Face the StrAInge, Patch Speed vs AI Attacks, E08

Autonomous IT, Live! Turn to Face the StrAInge, Patch Speed vs AI Attacks, E08

In April, Jason Kikta and Dmitri Alperovitch landed on a structural conclusion: AI had collapsed patch-to-exploit time to under an hour, 1-10-60 was no longer fast enough, and the only answer was prev...

25 Aug 42min

Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35

Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35

August 2026 delivers the second-largest Patch Tuesday on record with nearly 400 CVEs, and Landon Miles, Jason Kikta, and Serena DiPenti sort out which ones actually matter. They start with the only ac...

11 Aug 22min

Secure IT – PKI, Certificates, and What Breaks When Trust Fails, E22

Secure IT – PKI, Certificates, and What Breaks When Trust Fails, E22

Public Key Infrastructure (PKI) underpins nearly every secure interaction in modern IT, but it's also one of the most misunderstood and overlooked foundations of security.In this episode of Secure IT,...

22 Jul 17min

Patch [FIX] Tuesday – [The 570-CVE Month], Ep. 34

Patch [FIX] Tuesday – [The 570-CVE Month], Ep. 34

570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin. Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPe...

14 Jul 29min

 Executive IT – What IT hiring actually looks like when AI does the work, E07

Executive IT – What IT hiring actually looks like when AI does the work, E07

Eighteen months after the Hands-On IT podcast tackled the state of IT careers, Chelsea Rickey, SVP of Human Resources at Automox, comes back to the conversation to assess what held up, what changed, a...

1 Jul 15min

Product Talk – CISA's BOD 26-04 Directive Explained, E26

Product Talk – CISA's BOD 26-04 Directive Explained, E26

CISA's BOD 26-04 replaces severity-based patching with an exploit-evidence model and remediation clocks as short as three days, fleet-wide, no exceptions. Peter Pflaster and Jason Kikta unpack the fou...

11 Jun 27min

Patch [FIX] Tuesday – [Nothing Weaponized, Everything Exposed], E33

Patch [FIX] Tuesday – [Nothing Weaponized, Everything Exposed], E33

June 2026 has no headliner. Instead of one critical bug, the release spreads thin across the kernel, the network stack, a code editor, an AI assistant, a bootloader, and a nine-year-old Linux root bug...

9 Jun 23min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
bt-dokumentar-2
stopp-verden
popradet
fotballpodden-2
nokon-ma-ga
det-store-bildet
dine-penger-pengeradet
rss-espen-lee-usensurert
hanna-de-heldige
rss-gukild-johaug
unitedno
rss-ness
aftenbla-bla
e24-podden
frokostshowet-pa-p5
rss-penger-polser-og-politikk