From Noise to Signal: Fixing SIEM with Unified Security Telemetry and Identity
Introduction
In the summer of 2023, the Storm-0558 cyberespionage group accessed email accounts belonging to US government agencies. The attackers used a stolen Microsoft signing key to forge authentication tokens. They did not need to guess passwords or run a conventional phishing campaign.
That left many account-compromise controls with little