back

by ronbenton·4mo ago·view on hn ↗
Bypassing logging feels relatively unimportant compared to some of the recent EntraID vulns we’ve seen
2 comments
It takes a village of exploits to raise a successful and undetected attack.
Microsoft standpoint is probably: If it's undetected was there really an attack?
I dunno. It seems kinda bad that core auth log - which should be a primary source of truth during, say, a security audit - seems to work on a best-effort basis?