ForumsGeneral

What we changed after reading the Storm-0558 post-incident reporting

Discussion 13 Mar 2026 836 views
Tom Whitfield Sample Security leadership across 14 countries of retail estate. · member since Mar 2026

For anyone who has not read it: in July 2023 Microsoft disclosed that a threat actor tracked as Storm-0558 forged authentication tokens using a stolen signing key to access Exchange Online mail for a number of organisations, including government bodies. The subsequent public review of the incident was unusually critical of the vendor's practices.

What I took from it as a customer was not about that vendor specifically. It was that our own detection assumed the identity provider was trustworthy. If tokens can be forged upstream, the authentication logs look perfectly normal.

3 replies

Priya Raghunathan Sample Detection engineering lead. Writes the rules, tunes the noise. · 5 months ago

This is the part that changed our detection thinking too. We added detections that do not depend on the authentication event being suspicious: impossible travel on the mailbox rather than the login, anomalous mail rule creation, unusual client strings, bulk access patterns.

If the front door log cannot be trusted, watch what happens after the door.

Isabelle Moreau Sample Consultant Independent consultant. Runs vendor bake-offs for a living. · 5 months ago

We also started retaining mailbox audit logs for longer than the default, because the investigation window for something like this is far longer than the retention most tenants ship with. That is a cheap change with a real payoff.

Tom Whitfield Sample Security leadership across 14 countries of retail estate. · 5 months ago

Longer retention is on our list now. The uncomfortable general lesson is that a cloud service's own logs are the only evidence you have, and you are trusting the same party for both the service and the evidence about the service.

Sign in or join to reply.