Detection Opportunities

Detection Opportunities

Detection Opportunities is a podcast for security professionals who care about building resilient detection and response systems. Each episode explores real-world attacks, breaks down how signals become insights, and dives into the engineering mindset behind effective threat detection, investigation, and defense. Grounded in frontline experience across SIEM development, security operations, incident response, and threat hunting, this show brings a practical, systems-level lens to modern security engineering.

Episodes

April 28, 2025 35 mins

Visit my ⁠sponsor⁠ to view the current average annual salary for a Cybersecurity degree and learn how to get started.


I had the pleasure of hosting Dylan Williams and we explored how AI can be applied in cybersecurity, focusing on threat detection. We also examined how his project, D.I.A.N.A., turns threat intelligence reports into actual detections.


Connect with Dylan

Dylan's Resource on Applying LLMs & GenAI to Cybersecurity

Dyla...

Mark as Played

Visit my sponsor to view the current average annual salary for a Cybersecurity degree and learn how to get started.



⁠Purav's LinkedIn⁠

⁠Deciphering UAL

Exchange Admin Audit Logging

Office365 Management Activity API

Connect-IPPSSession



_____________

TIMESTAMPS:

00:00 Intro

00:36 Get-RoleGroup Operation

01:37 Enumeration is not logged??

05:53 SNHU

07:22 Using the Security Compliance Center EOPCmdlet

08:54 Abusing Purview Compliance & E-Discov...

Mark as Played

Learn how to decipher the Microsoft Unified Audit Log (UAL) from a Digital Forensics & Incident Response (DFIR) perspective with Purav Desai, an experienced M365/Azure Incident Responder. In today's episode, we explore the Add-RoleGroupMember operation in Exchange Online.



Purav's LinkedIn

Deciphering UAL

Microsoft Application IDs

Permission Alert Policy



_____________

TIMESTAMPS:

00:00 Intro

00:48 Add-RoleGroupMember Overview

03:22 The R...

Mark as Played

Learn how to decipher the Microsoft Unified Audit Log (UAL) from a Digital Forensics & Incident Response (DFIR) perspective with Purav Desai, an experienced M365/Azure Incident Responder.


⁠Purav's LinkedIn⁠

⁠Deciphering UAL⁠

⁠Learn about auditing solutions in Microsoft Purview⁠



_____________

TIMESTAMPS

00:00 Intro

00:20 Deciphering New-RoleGroup

09:06 Key Fields

10:11 Deciphering with Exchange Online PowerShell

13:42 Detection Opportunit...

Mark as Played

Learn how to decipher the Microsoft Unified Audit Log (UAL) from a Digital Forensics & Incident Response (DFIR) perspective with Purav Desai, an experienced M365/Azure Incident Responder.


Purav's LinkedIn

Deciphering UAL

Learn about auditing solutions in Microsoft Purview



_____________

TIMESTAMPS

00:00 Intro

00:49 Microsoft 365 Auditing

04:43 The Deciphering UAL Project

07:55 Accessing Purview Audit

17:41 Outro


_____________

⚡️⁠JOIN 6,000+...

Mark as Played

This episode covers an attack scenario very similar to the one that led to the breach of US Bank Capital One.  @0xd4y  goes over the attack scenario using CloudGoat by Rhino Security Labs, and I detect his activities using AWS CloudTrail Lake.



_____________

🧬 VIDEO RESOURCES

🔹 Segev's YouTube Channel:  @0xd4y 

🔹 Segev's walkthrough

🔹 Former AWS engineer convicted over hack that cost Capital One $270m

🔹 CloudGoat

🔹 Instance Metadata

...

Mark as Played

GCP Service Accounts are interesting cloud identities. Let's review how they contributed to a Cryptocurrency Mining Attack in this Case.




_____________

🧬 EPISODE RESOURCES

🔹How A Compromised AWS Lambda Function Led to a Phishing Attack

🔹GCP Lateral Movement & PrivEsc

🔹GCP Service Accounts

🔹 DEFCON 30 Cloud Village - Weather Proofing GCP Defaults

🔹GCP IAM basic and predefined roles reference


_____________

⏰ TIMESTAMPS

00:00 How GCP S...

Mark as Played

In this video, I’ll be going over detection opportunities at various stages of cloud security attacks.


Compromised Cloud Compute Credentials: Case Studies From the Wild


_____________

TIMESTAMPS

00:00 Intro

00:40 The Attack Case

02:12 The Attack Graph

02:44 The Attack Flow

03:06 Detection Opportunity 1: Enumeration/Reconnaissance/Discovery - Cloud Infrastructure Discovery

05:27 Detection Opportunity 2: Persistence - Create Cloud Account

08:...

Mark as Played

Popular Podcasts

    Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

    Amy Robach & T.J. Holmes present: Aubrey O’Day, Covering the Diddy Trial

    Introducing… Aubrey O’Day Diddy’s former protege, television personality, platinum selling music artist, Danity Kane alum Aubrey O’Day joins veteran journalists Amy Robach and TJ Holmes to provide a unique perspective on the trial that has captivated the attention of the nation. Join them throughout the trial as they discuss, debate, and dissect every detail, every aspect of the proceedings. Aubrey will offer her opinions and expertise, as only she is qualified to do given her first-hand knowledge. From her days on Making the Band, as she emerged as the breakout star, the truth of the situation would be the opposite of the glitz and glamour. Listen throughout every minute of the trial, for this exclusive coverage. Amy Robach and TJ Holmes present Aubrey O’Day, Covering the Diddy Trial, an iHeartRadio podcast.

    Stuff You Should Know

    If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

    Crime Junkie

    Does hearing about a true crime case always leave you scouring the internet for the truth behind the story? Dive into your next mystery with Crime Junkie. Every Monday, join your host Ashley Flowers as she unravels all the details of infamous and underreported true crime cases with her best friend Brit Prawat. From cold cases to missing persons and heroes in our community who seek justice, Crime Junkie is your destination for theories and stories you won’t hear anywhere else. Whether you're a seasoned true crime enthusiast or new to the genre, you'll find yourself on the edge of your seat awaiting a new episode every Monday. If you can never get enough true crime... Congratulations, you’ve found your people. Follow to join a community of Crime Junkies! Crime Junkie is presented by audiochuck Media Company.

    The Clay Travis and Buck Sexton Show

    The Clay Travis and Buck Sexton Show. Clay Travis and Buck Sexton tackle the biggest stories in news, politics and current events with intelligence and humor. From the border crisis, to the madness of cancel culture and far-left missteps, Clay and Buck guide listeners through the latest headlines and hot topics with fun and entertaining conversations and opinions.

Advertise With Us
Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.