sync: auto-sync from GURU-BEAST-ROG at 2026-07-16 10:11:10

Author: Mike Swanson
Machine: GURU-BEAST-ROG
Timestamp: 2026-07-16 10:11:10
This commit is contained in:
Winter Williams
2026-07-16 10:12:05 -07:00
parent 7e1525711a
commit eba471a61a
18 changed files with 65387 additions and 0 deletions

View File

@@ -0,0 +1,102 @@
# Breach Check + Remediation: Orders@valleywideplastering.com
**Date:** 2026-07-16
**Tenant:** Valleywide Plastering (valleywideplastering.com, 5c53ae9f-7071-4248-b834-8685b646450f)
**Subject:** Orders@valleywideplastering.com
**Tool:** ComputerGuru remediation app suite — tiers used: Security Investigator `bfbc12a4` (Graph reads), Investigator-EXO (Exchange reads), User Manager `64fac46b` (session revoke), Tenant Admin `709e6eed` (device deletion)
**Scope:** included remediation (device deletion + session revoke, confirmed by Winter in Discord)
**Requested by:** Winter (Discord @winterguru), thread 1527356833902362654
## Summary
- **Confirmed AiTM token-theft compromise on 2026-07-02 17:20 UTC** — sign-in from datacenter IP 172.245.92.208 (ColoCrossing) to Microsoft Intune Enrollment with "MFA requirement satisfied by claim in the token" (replayed session token; CA MFA passed on the stolen claim).
- **Attacker registered persistence device `DESKTOP-YQL6X9KX`** at 2026-07-02 17:21:00Z (Entra workplace join under this account).
- **Partial remediation already occurred 2026-07-06** (~16:3316:40 UTC): password reset twice + StsRefreshTokenValidFrom bumped via ComputerGuru Tenant Admin; MFA info updated 16:45 UTC.
- **Rogue device was still registered and ENABLED as of 2026-07-16** — deleted this session. Sessions re-revoked.
- Mailbox itself is clean: no rules (incl. hidden), no forwarding, no delegations, no OAuth grants, no outbound abuse.
- **Tenant sweep of attacker IP: only orders@ was touched** — no other VWP users saw sign-ins from 172.245.92.208 (30d window).
## Target details
| Field | Value |
|---|---|
| UPN | Orders@valleywideplastering.com |
| Object ID | 3739c527-f156-49b7-8779-a19033564a0f |
| Account Enabled | true |
| Created | 2023-03-17T21:54:40Z |
| Last Password Change | 2026-07-06T16:39:58Z |
## Per-check findings
### 1. Inbox rules (Graph)
0 rules.
### 2. Mailbox forwarding / settings
No forwarding configured (ForwardingAddress / ForwardingSmtpAddress empty). No auto-reply anomalies.
### 3. Exchange REST (hidden rules, delegates, SendAs, Get-Mailbox)
0 hidden inbox rules. No non-SELF mailbox permissions. No non-SELF SendAs. No mailbox-level forwarding.
### 4. OAuth consents + app role assignments
0 OAuth grants, 0 app role assignments.
### 5. Authentication methods
3 methods, all outside the attack window (benign):
- passwordAuthenticationMethod
- microsoftAuthenticatorAuthenticationMethod — "iPhone 11" (user's phone)
- windowsHelloForBusinessAuthenticationMethod — created 2025-06-24T14:24:00Z (predates incident by a year)
### 6. Sign-ins (30d, interactive)
127 sign-ins. Dominant IP 4.18.160.106 (124 — office egress, Leesburg geo). Error-code mix normal (50072/50076/50079 MFA interrupts, 50140 KMSI).
- 7x 50126 (bad password) on 2026-07-06 16:3522:16 UTC from the office IP = user retrying the OLD password during/after the 7/6 admin reset. Benign.
- **2x from 172.245.92.208 (ColoCrossing datacenter, LA geo) on 2026-07-02 17:20 UTC — Microsoft Authentication Broker → Microsoft Intune Enrollment, Chrome 150, `50199` then `0` (success). "MFA requirement satisfied by claim in the token" = token replay. CA "Require MFA for all users" = success (satisfied by stolen claim); "Block Sign-ins Outside US" notApplied (IP geolocates US).**
- The "non-US" flag in the script summary was a false positive: a 500142 redemption-continuation event from the office IP with no geo populated.
### 7. Directory audits
15 events (30d):
- 2026-07-02 17:21:01Z — "Add registered users to device" + "Add registered owner to device" via Device Registration Service (**attacker device join**).
- 2026-07-06 16:33 + 16:39 UTC — two password resets + StsRefreshTokenValidFrom updates via ComputerGuru Tenant Admin / User Manager (prior remediation).
- 2026-07-06 16:45 UTC — Azure MFA StrongAuthenticationService "Update user" (MFA info re-registration after reset).
### 8. Risky users / risk detections
riskyUser endpoint returned 403 Forbidden — Security Investigator consent on this tenant is PARTIAL (missing User.Read.All, Sites.Read.All; IdentityRiskyUser likely part of the stale grant). riskDetections returned 0. Sign-in risk fields on the attack events are "hidden" (license/scope).
### 9. Sent items (recent 25)
Normal business traffic (orders to suppliers, internal scheduling). No blast patterns, no unusual externals.
### 10. Deleted items (recent 25)
Normal. No deleted security alerts or MFA notifications.
## Suspicious items
- AiTM token replay from 172.245.92.208 (ColoCrossing hosting) on 2026-07-02 17:20 UTC.
- Attacker-registered Entra device `DESKTOP-YQL6X9KX` (deviceId 850e5a7e-c7bb-4d65-9bc4-740e11a61ebc, objectId 575e7b36-8ec1-46df-b66b-c0228ca93c64), registered 2026-07-02 17:21:00Z, still enabled 14 days later. Never signed in after registration.
## Gaps — checks not completed
- Identity Protection riskyUser: 403 (partial Investigator consent). Fix: re-consent
`https://login.microsoftonline.com/5c53ae9f-7071-4248-b834-8685b646450f/adminconsent?client_id=bfbc12a4-f0dd-4e12-b06d-997e7271e10c`
- Consent audit grade AMBER: investigator (missing User.Read.All, Sites.Read.All), exchange-op (missing Mail.ReadWrite, MailboxSettings.ReadWrite), user-manager (missing Directory.ReadWrite.All). Re-consent links in consent-audit output.
## Next actions
1. [DONE this session] Delete rogue device — see below.
2. [DONE this session] Re-revoke sessions.
3. Re-consent the three AMBER apps on this tenant (any Global Admin, links above) — ACG.
4. Consider phishing-resistant MFA / token-protection CA for this tenant; the "Block Sign-ins Outside US" policy did not stop a US-datacenter AiTM proxy. — ACG, discuss with Mike.
5. User awareness: orders@ operator was almost certainly phished ~Jul 2; worth a heads-up to the client contact.
## Remediation actions
| Time (UTC) | Action | Tier | Result |
|---|---|---|---|
| 2026-07-16 ~17:0x | `DELETE /v1.0/devices/575e7b36-8ec1-46df-b66b-c0228ca93c64` (DESKTOP-YQL6X9KX) | tenant-admin | HTTP 204; verified — only legit device ORDERSTY remains registered to user |
| 2026-07-16 ~17:0x | `POST /v1.0/users/3739c527-f156-49b7-8779-a19033564a0f/revokeSignInSessions` | user-manager | HTTP 200, value=true |
Tenant-wide sign-in sweep for 172.245.92.208 (30d): only the two orders@ events on 2026-07-02. No lateral spread.
## Data artifacts
Raw JSON saved at `/tmp/remediation-tool/5c53ae9f-7071-4248-b834-8685b646450f/user-breach/Orders_valleywideplastering_com/` — files:
- 00_user.json, 01_inbox_rules_graph.json, 02_mailbox_settings.json, 03a_InboxRule_hidden.json, 03b_MailboxPermission.json, 03c_RecipientPermission.json, 03d_Mailbox.json, 04a_oauth_grants.json, 04b_app_role_assignments.json, 05_auth_methods.json, 06_signins.json, 07_dir_audits.json, 08a_risky_user.json, 08b_risk_detections.json, 09_sent.json, 10_deleted.json