The US government’s Cybersecurity and Infrastructure Security Agency (CISA) has released the Untitled Goose Tool, a software developed in conjunction with Sandia National Labs, to help network administrators spot potentially malicious activity in the Microsoft Azure cloud, Microsoft 365 services, and Azure Active Directory (AAD). The tool offers novel authentication and data gathering methods for network defenders to use as they interrogate and analyze their Microsoft cloud services. This release comes alongside the Pre-Ransomware Notification Initiative, which delivers early warnings to organizations about attacks, possibly in enough time to stop the attacks before the miscreants can encrypt or steal data.
