Q3 Attacker Trends: Inside Todays Identity Led Attacks

This previous quarter, attackers turned phone calls and Teams messages into persistent cloud access. Threat groups used stolen identities to download SharePoint data at scale — sometimes within minutes — and password resets didn't stop them. Ransomware Groups changed, but their playbooks stayed the same: valid accounts, remote-support tools, and SMB moving from access to encryption.
Join ReliaQuest Threat Research for a review of the quarter's findings and what they mean for defenders — including how to connect identity changes to the activity that follows and contain identity-led intrusions before data leaves.
What you'll learn:
Why a password reset isn't full containment. The devices, MFA methods, and refresh tokens that survive a reset, and the steps that remove them.
How to connect identity changes to follow-on activity. Correlating a new device or MFA enrollment with the SharePoint enumeration, bulk downloads, or SMB movement that follows.
How to contain identity-led intrusions in five minutes or less. Revoking sessions and tokens, removing attacker-controlled authentication methods, and isolating affected hosts before data leaves.