sync: auto-sync from GURU-BEAST-ROG at 2026-07-16 10:11:10

Author: Mike Swanson
Machine: GURU-BEAST-ROG
Timestamp: 2026-07-16 10:11:10
This commit is contained in:
Winter Williams
2026-07-16 10:12:05 -07:00
parent 7e1525711a
commit eba471a61a
18 changed files with 65387 additions and 0 deletions

View File

@@ -0,0 +1,102 @@
# Breach Check + Remediation: Orders@valleywideplastering.com
**Date:** 2026-07-16
**Tenant:** Valleywide Plastering (valleywideplastering.com, 5c53ae9f-7071-4248-b834-8685b646450f)
**Subject:** Orders@valleywideplastering.com
**Tool:** ComputerGuru remediation app suite — tiers used: Security Investigator `bfbc12a4` (Graph reads), Investigator-EXO (Exchange reads), User Manager `64fac46b` (session revoke), Tenant Admin `709e6eed` (device deletion)
**Scope:** included remediation (device deletion + session revoke, confirmed by Winter in Discord)
**Requested by:** Winter (Discord @winterguru), thread 1527356833902362654
## Summary
- **Confirmed AiTM token-theft compromise on 2026-07-02 17:20 UTC** — sign-in from datacenter IP 172.245.92.208 (ColoCrossing) to Microsoft Intune Enrollment with "MFA requirement satisfied by claim in the token" (replayed session token; CA MFA passed on the stolen claim).
- **Attacker registered persistence device `DESKTOP-YQL6X9KX`** at 2026-07-02 17:21:00Z (Entra workplace join under this account).
- **Partial remediation already occurred 2026-07-06** (~16:3316:40 UTC): password reset twice + StsRefreshTokenValidFrom bumped via ComputerGuru Tenant Admin; MFA info updated 16:45 UTC.
- **Rogue device was still registered and ENABLED as of 2026-07-16** — deleted this session. Sessions re-revoked.
- Mailbox itself is clean: no rules (incl. hidden), no forwarding, no delegations, no OAuth grants, no outbound abuse.
- **Tenant sweep of attacker IP: only orders@ was touched** — no other VWP users saw sign-ins from 172.245.92.208 (30d window).
## Target details
| Field | Value |
|---|---|
| UPN | Orders@valleywideplastering.com |
| Object ID | 3739c527-f156-49b7-8779-a19033564a0f |
| Account Enabled | true |
| Created | 2023-03-17T21:54:40Z |
| Last Password Change | 2026-07-06T16:39:58Z |
## Per-check findings
### 1. Inbox rules (Graph)
0 rules.
### 2. Mailbox forwarding / settings
No forwarding configured (ForwardingAddress / ForwardingSmtpAddress empty). No auto-reply anomalies.
### 3. Exchange REST (hidden rules, delegates, SendAs, Get-Mailbox)
0 hidden inbox rules. No non-SELF mailbox permissions. No non-SELF SendAs. No mailbox-level forwarding.
### 4. OAuth consents + app role assignments
0 OAuth grants, 0 app role assignments.
### 5. Authentication methods
3 methods, all outside the attack window (benign):
- passwordAuthenticationMethod
- microsoftAuthenticatorAuthenticationMethod — "iPhone 11" (user's phone)
- windowsHelloForBusinessAuthenticationMethod — created 2025-06-24T14:24:00Z (predates incident by a year)
### 6. Sign-ins (30d, interactive)
127 sign-ins. Dominant IP 4.18.160.106 (124 — office egress, Leesburg geo). Error-code mix normal (50072/50076/50079 MFA interrupts, 50140 KMSI).
- 7x 50126 (bad password) on 2026-07-06 16:3522:16 UTC from the office IP = user retrying the OLD password during/after the 7/6 admin reset. Benign.
- **2x from 172.245.92.208 (ColoCrossing datacenter, LA geo) on 2026-07-02 17:20 UTC — Microsoft Authentication Broker → Microsoft Intune Enrollment, Chrome 150, `50199` then `0` (success). "MFA requirement satisfied by claim in the token" = token replay. CA "Require MFA for all users" = success (satisfied by stolen claim); "Block Sign-ins Outside US" notApplied (IP geolocates US).**
- The "non-US" flag in the script summary was a false positive: a 500142 redemption-continuation event from the office IP with no geo populated.
### 7. Directory audits
15 events (30d):
- 2026-07-02 17:21:01Z — "Add registered users to device" + "Add registered owner to device" via Device Registration Service (**attacker device join**).
- 2026-07-06 16:33 + 16:39 UTC — two password resets + StsRefreshTokenValidFrom updates via ComputerGuru Tenant Admin / User Manager (prior remediation).
- 2026-07-06 16:45 UTC — Azure MFA StrongAuthenticationService "Update user" (MFA info re-registration after reset).
### 8. Risky users / risk detections
riskyUser endpoint returned 403 Forbidden — Security Investigator consent on this tenant is PARTIAL (missing User.Read.All, Sites.Read.All; IdentityRiskyUser likely part of the stale grant). riskDetections returned 0. Sign-in risk fields on the attack events are "hidden" (license/scope).
### 9. Sent items (recent 25)
Normal business traffic (orders to suppliers, internal scheduling). No blast patterns, no unusual externals.
### 10. Deleted items (recent 25)
Normal. No deleted security alerts or MFA notifications.
## Suspicious items
- AiTM token replay from 172.245.92.208 (ColoCrossing hosting) on 2026-07-02 17:20 UTC.
- Attacker-registered Entra device `DESKTOP-YQL6X9KX` (deviceId 850e5a7e-c7bb-4d65-9bc4-740e11a61ebc, objectId 575e7b36-8ec1-46df-b66b-c0228ca93c64), registered 2026-07-02 17:21:00Z, still enabled 14 days later. Never signed in after registration.
## Gaps — checks not completed
- Identity Protection riskyUser: 403 (partial Investigator consent). Fix: re-consent
`https://login.microsoftonline.com/5c53ae9f-7071-4248-b834-8685b646450f/adminconsent?client_id=bfbc12a4-f0dd-4e12-b06d-997e7271e10c`
- Consent audit grade AMBER: investigator (missing User.Read.All, Sites.Read.All), exchange-op (missing Mail.ReadWrite, MailboxSettings.ReadWrite), user-manager (missing Directory.ReadWrite.All). Re-consent links in consent-audit output.
## Next actions
1. [DONE this session] Delete rogue device — see below.
2. [DONE this session] Re-revoke sessions.
3. Re-consent the three AMBER apps on this tenant (any Global Admin, links above) — ACG.
4. Consider phishing-resistant MFA / token-protection CA for this tenant; the "Block Sign-ins Outside US" policy did not stop a US-datacenter AiTM proxy. — ACG, discuss with Mike.
5. User awareness: orders@ operator was almost certainly phished ~Jul 2; worth a heads-up to the client contact.
## Remediation actions
| Time (UTC) | Action | Tier | Result |
|---|---|---|---|
| 2026-07-16 ~17:0x | `DELETE /v1.0/devices/575e7b36-8ec1-46df-b66b-c0228ca93c64` (DESKTOP-YQL6X9KX) | tenant-admin | HTTP 204; verified — only legit device ORDERSTY remains registered to user |
| 2026-07-16 ~17:0x | `POST /v1.0/users/3739c527-f156-49b7-8779-a19033564a0f/revokeSignInSessions` | user-manager | HTTP 200, value=true |
Tenant-wide sign-in sweep for 172.245.92.208 (30d): only the two orders@ events on 2026-07-02. No lateral spread.
## Data artifacts
Raw JSON saved at `/tmp/remediation-tool/5c53ae9f-7071-4248-b834-8685b646450f/user-breach/Orders_valleywideplastering_com/` — files:
- 00_user.json, 01_inbox_rules_graph.json, 02_mailbox_settings.json, 03a_InboxRule_hidden.json, 03b_MailboxPermission.json, 03c_RecipientPermission.json, 03d_Mailbox.json, 04a_oauth_grants.json, 04b_app_role_assignments.json, 05_auth_methods.json, 06_signins.json, 07_dir_audits.json, 08a_risky_user.json, 08b_risk_detections.json, 09_sent.json, 10_deleted.json

View File

@@ -0,0 +1,75 @@
# VWP — Orders@ Breach Check + Remediation, Syncro #32557 + Billing
## User
- **Executed by:** ClaudeTools Discord Bot (GURU-BEAST-ROG)
- **Requested by:** Winter Williams (@winterguru, via Discord) - tech
- **Role:** automation (acting on the requester's behalf)
## Session Summary
Winter requested a security check on Orders@valleywideplastering.com via Discord (#tech-department, thread 1527356833902362654). Ran the remediation-tool workflow: consent audit (grade AMBER — three apps with partial grants), then full user-breach-check via Security Investigator + Investigator-EXO tiers.
Found a confirmed AiTM token-theft compromise from 2026-07-02 17:20 UTC: interactive sign-in from datacenter IP 172.245.92.208 (ColoCrossing) to Microsoft Intune Enrollment via Authentication Broker, with "MFA requirement satisfied by claim in the token" (replayed stolen session token — CA MFA passed on the stolen claim). 40 seconds later the attacker registered Entra device DESKTOP-YQL6X9KX to the account (persistence). The "Block Sign-ins Outside US" CA policy did not fire because the proxy IP geolocates to Los Angeles. Directory audits showed a prior partial remediation on 2026-07-06 (~16:33-16:40 UTC): two password resets + StsRefreshTokenValidFrom bumps via ComputerGuru Tenant Admin, MFA info updated 16:45. The mailbox itself was clean: 0 inbox rules (incl. hidden), no forwarding, no non-SELF delegations/SendAs, 0 OAuth grants, sent/deleted items normal. Auth methods all predate the incident (Authenticator iPhone 11; WHfB from 2025-06-24).
The rogue device DESKTOP-YQL6X9KX was still registered and ENABLED 14 days later. With Winter's explicit YES: deleted the device via tenant-admin tier (HTTP 204, verified only legit device ORDERSTY remains) and re-revoked all sessions via user-manager tier (HTTP 200). Tenant-wide sign-in sweep for 172.245.92.208 (30d): only orders@ was touched — no lateral spread. Full report written to clients/valleywide/reports/2026-07-16-orders-breach-check.md.
Created Syncro ticket #32557 for Valley Wide Plastering Inc (customer 31694734) via /syncro with Winter's API key (attribution), status Resolved, priority 1 High, assigned Winter (1737), Initial Issue comment customer-emailed at Winter's direction (Do Not Email = no). Billed 0.5 hrs Labor - Remote Business (product 1190473, $150/hr): VWP is prepaid — block went 16.25 → 15.75 hrs, invoice #68050 total $0.00 with note "Block hours remaining: 15.75.", ticket marked Invoiced. Bot alerts posted to #bot-alerts for both writes.
## Key Decisions
- Used investigator/investigator-exo tiers for all reads; escalated to tenant-admin only for the device DELETE and user-manager for the session revoke (minimum privilege).
- Deleted (not just disabled) the rogue device after Winter's explicit YES — it had never signed in since registration and had no legitimate claim.
- Re-revoked sessions after device deletion even though a 7/6 revoke existed (belt-and-suspenders — device registration postdated nothing, but revoke is free).
- Judged the script's "non-US: 1" flag a false positive (a 500142 event from the office IP with no geo populated); the real finding was the US-datacenter IP that geo checks cannot catch.
- Judged the 7x 50126 failures on 7/6 benign: office-IP retries of the old password during the admin reset window.
- Initial Issue comment posted with do_not_email: false at Winter's explicit instruction (customer gets notified).
- Billed with the delivery-channel product (1190473 remote) per prepaid rules — NOT 9269129; verified block decrement post-invoice.
## Problems Encountered
- riskyUser endpoint returned 403 — Security Investigator consent on this tenant is PARTIAL (missing User.Read.All, Sites.Read.All). Documented re-consent URL in the report; not blocking.
- Consent audit AMBER: investigator, exchange-op, user-manager all have stale partial grants. Re-consent links in the report's Gaps section.
## Configuration Changes
- Created: `clients/valleywide/reports/2026-07-16-orders-breach-check.md` (full breach report)
- Created: this session log
- M365 tenant (5c53ae9f-7071-4248-b834-8685b646450f): deleted Entra device object 575e7b36-8ec1-46df-b66b-c0228ca93c64 (DESKTOP-YQL6X9KX, deviceId 850e5a7e-c7bb-4d65-9bc4-740e11a61ebc); revoked sign-in sessions for user 3739c527-f156-49b7-8779-a19033564a0f
## Credentials & Secrets
- None created or discovered. Vault paths used (app certs auto-resolved by get-token.sh): msp-tools/computerguru-security-investigator.sops.yaml, msp-tools/computerguru-exchange-operator.sops.yaml (via investigator-exo), msp-tools/computerguru-user-manager.sops.yaml, msp-tools/computerguru-tenant-admin.sops.yaml; msp-tools/syncro-winter (Syncro attribution).
## Infrastructure & Servers
- Tenant: valleywideplastering.com = 5c53ae9f-7071-4248-b834-8685b646450f
- Target user: Orders@valleywideplastering.com = 3739c527-f156-49b7-8779-a19033564a0f
- Attacker IP: 172.245.92.208 (ColoCrossing datacenter, geolocates Los Angeles)
- Office egress IP: 4.18.160.106 (geolocates Leesburg; 124/127 sign-ins)
- Legit device: ORDERSTY (registered 2025-04-08); rogue device: DESKTOP-YQL6X9KX (registered 2026-07-02 17:21:00Z, deleted 2026-07-16)
- Syncro customer: Valley Wide Plastering Inc (VWP) = 31694734, prepaid block
## Commands & Outputs
- `bash scripts/consent-audit.sh valleywideplastering.com` → GRADE: AMBER (investigator, exchange-op, user-manager partial)
- `bash scripts/user-breach-check.sh valleywideplastering.com Orders@valleywideplastering.com` → artifacts at /tmp/remediation-tool/5c53ae9f-7071-4248-b834-8685b646450f/user-breach/Orders_valleywideplastering_com/
- `DELETE /v1.0/devices/575e7b36-8ec1-46df-b66b-c0228ca93c64` (tenant-admin) → HTTP 204
- `POST /v1.0/users/3739c527-f156-49b7-8779-a19033564a0f/revokeSignInSessions` (user-manager) → HTTP 200 value=true
- `GET /auditLogs/signIns?$filter=ipAddress eq '172.245.92.208'` → only the two orders@ events on 2026-07-02
- Syncro: POST /tickets → id 113912233 (#32557); comment 424044507 (Initial Issue), comment 424044987 (Resolution); line item 43297806 (0.5h @ $150); POST /invoices → 1651071811 (#68050, $0.00); PUT invoice note; PUT status Invoiced
## Pending / Incomplete Tasks
- Re-consent the three AMBER apps on the VWP tenant (any Global Admin; URLs in the report Gaps section) — enables Identity Protection risk reads.
- Discuss phishing-resistant MFA / token-protection CA for VWP with Mike — geo-block CA did not stop the US-datacenter AiTM proxy.
- Client user awareness: orders@ operator was likely phished ~Jul 2.
## Reference Information
- Report: clients/valleywide/reports/2026-07-16-orders-breach-check.md
- Syncro ticket: #32557 → https://computerguru.syncromsp.com/tickets/113912233
- Syncro invoice: #68050 (id 1651071811), $0.00, applied 0.5 prepay hrs; block 16.25 → 15.75
- Discord thread: 1527356833902362654 (#tech-department)
- Bot alerts: message_ids 1527360784940798073 (ticket create), 1527361632278286386 (billing)
- Raw artifacts: /tmp/remediation-tool/5c53ae9f-7071-4248-b834-8685b646450f/user-breach/Orders_valleywideplastering_com/
- Prior related log: clients/valleywide/reports/2026-06-29-offboarding-teresa-carpio.md