Hacker News new | ask | show | jobs
by ronbenton 84 days ago
Bypassing logging feels relatively unimportant compared to some of the recent EntraID vulns we’ve seen
2 comments

It takes a village of exploits to raise a successful and undetected attack.
Microsoft standpoint is probably: If it's undetected was there really an attack?
I dunno. It seems kinda bad that core auth log - which should be a primary source of truth during, say, a security audit - seems to work on a best-effort basis?