BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-cymru-2024//speaker//VRL9LY
BEGIN:VTIMEZONE
TZID:Europe/London
BEGIN:DAYLIGHT
DTSTART:20230428T000000
TZNAME:BST
TZOFFSETFROM:+0100
TZOFFSETTO:+0100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20231029T020000
RDATE:20241027T020000
TZNAME:GMT
TZOFFSETFROM:+0100
TZOFFSETTO:+0000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20240331T020000
RDATE:20250330T020000
TZNAME:BST
TZOFFSETFROM:+0000
TZOFFSETTO:+0100
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Ohhhh365 - How to (Quite) Reliably Hack into Microsoft 365\, And W
 hat to Do Afterwards - Sunny Chau
DTSTART;TZID=Europe/London:20240427T153500
DTEND;TZID=Europe/London:20240427T160500
DTSTAMP:20260911T190853Z
UID:pretalx-bsides-cymru-2024-MC3RN9@pretalx.com
DESCRIPTION:An employee's M365 account has become a pivotal asset\, guardi
 ng business-critical data such as internal emails and SharePoint data. In 
 this talk\, we dive into modern tradecraft used by JUMPSEC to compromise M
 365 in our adversary simulation engagements\, some of which were recently 
 used by an advanced threat group to successfully breach Microsoft. The tal
 k will outline our methodologies in obtaining unauthorised access\, follow
 ed by strategies for post-compromise actions.
LOCATION:Main Room (Ballroom) - Track 1
URL:https://pretalx.com/bsides-cymru-2024/talk/MC3RN9/
END:VEVENT
END:VCALENDAR
