Forum Discussion

Jason Wilson's avatar
Jason Wilson
Former Employee
Apr 18, 2018

New Blog: Azure Advanced Threat Protection - CredSSP Exploit Analysis

After announcing the release of Azure Advanced Threat Protection (Azure ATP) last month, we are excited to provide details on how Azure ATP has been updated to better protect customers against a new exploit by including the identity theft technique used in the Credential Security Support Provider (CredSSP) Protocol exploit as a flavor of the Pass-The-Ticket detection.

 

In the blog, the Azure ATP team provides network behavior analysis of the CredSSP exploitation of this vulnerability and the techniques it uses to propagate in the network. They also highlight how you can use Azure ATP to detect and investigate a variety of advanced cyberattacks.

 

You can read the blog post here

2 Replies

Resources