Skip to content

Instantly share code, notes, and snippets.

View helloitsliam's full-sized avatar

Liam Cleary helloitsliam

View GitHub Profile
datetime(2023-03-24T10:16:00Z),'PasswordReset','admin@msdx878906.onmicrosoft.com','192.168.1.100','PowerShell/7','Azure Active Directory','User Account','Success','NULL','{ \"AttackMethod\": \"PowerShell Execution\", \"AttackStage\": \"Credential Access\" }','T1110','Credential Access',
datetime(2023-03-25T10:18:00Z),'PhishingEmailSent','admin@msdx878906.onmicrosoft.com','192.168.1.100','PowerShell/7','Microsoft Teams','Other Accounts','Success','NULL','{ \"AttackMethod\": \"Phishing Email\", \"AttackStage\": \"Command and Control\" }','T1566','Command and Control'

Keybase proof

I hereby claim:

  • I am helloitsliam on github.
  • I am helloitsliam (https://keybase.io/helloitsliam) on keybase.
  • I have a public key whose fingerprint is F95D 5883 8A8F 07F5 E690 99A0 D021 157E 3868 B718

To claim this, I am signing this object: