Analyze the anatomy of advanced attacks 12/5/2018 9:08 PM BRK2001 Analyze the anatomy of advanced attacks Benny Lakunishok Product Manager © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
1 Collect Analyze & Learn 2 ATA Center Detect 3 Alert & Investigate 4 12/5/2018 9:08 PM 1 Collect Port Mirroring or Sensor on DC L7 Deep Packet Inspection (DPI) Hybrid data sources 2 Analyze & Learn Self-learning and profiling technology Patented IP resolution mechanism ATA Center Detect 3 Abnormal behavior and suspicious activities Real-breach oriented research Microsoft Intelligence Alert & Investigate 4 ATA Gateway Intuitive Attack timeline Detailed investigation with dedicated entity profile PROXY VPN AD HR APPS ADFS SIEM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
12/5/2018 9:08 PM Our story begins © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Mamazon Industry: Commerce and Cloud computing 12/5/2018 9:08 PM Mamazon Industry: Commerce and Cloud computing Publicly traded (450B $) Founded: 1994 HQ: Albuquerque, NM, USA Employee #: ~350,000 © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Black Circle Industry: Business Intelligence Privately held 12/5/2018 9:08 PM Black Circle Industry: Business Intelligence Privately held Founded: 2010 HQ: Tel Aviv, Israel Employee #: ~100 © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Moogle Industry: Software Publicly traded (650B $) Founded: 1999 12/5/2018 9:08 PM Moogle Industry: Software Publicly traded (650B $) Founded: 1999 HQ: Orlando, FL, USA Employee #: ~50,000 © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
The Target https://www.linkedin.com/in/ruth-borat-3bab06146/ 12/5/2018 9:08 PM The Target Ruth Borat Senior Vice President and CFO, Moogle https://www.linkedin.com/in/ruth-borat-3bab06146/ © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
12/5/2018 9:08 PM Demo © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Attack story step 1 JohnD-Laptop JohnD SAMR Recon 12/5/2018 9:08 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Attack story step 2 JohnD-Laptop JohnD RuthB 12/5/2018 9:08 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Attack story step 3 Failure JohnD-Laptop Success RuthB EdnaF 12/5/2018 9:08 PM Attack story step 3 Failure JohnD-Laptop Success EdnaF RuthB © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
12/5/2018 9:08 PM Preview To get access to the preview please contact ATAEVAL@Microsoft.com © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Attack story step 4 EdnaF EdnaF-PC Helpdesk RuthB-Laptop 12/5/2018 9:08 PM Attack story step 4 EdnaF EdnaF-PC Helpdesk RuthB-Laptop © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Attack story step 5 EdnaF-PC HelpDesk AXFR Query 12/5/2018 9:08 PM Attack story step 5 EdnaF-PC HelpDesk AXFR Query TopSecretFinanceServer © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Attack story step 6 RuthB-Laptop Helpdesk EdnaF-PC 12/5/2018 9:08 PM Attack story step 6 Helpdesk RuthB-Laptop EdnaF-PC TopSecretFinanceServer RuthB © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Takeaways Attackers life is easy ATA makes the defenders life easier 12/5/2018 9:08 PM Takeaways Attackers life is easy ATA makes the defenders life easier Proactive defense Azure ATP limited preview: http://aka.ms/azureatp © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Q&A If you have questions please proceed to the Q&A MICROPHONE. 12/5/2018 9:08 PM Q&A If you have questions please proceed to the Q&A MICROPHONE. © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.