Why attackers are living off Microsoft Graph - until a few months there wasn’t any logging of GraphAPI access queries (!), it’s still only in Preview, it isn’t available in US Government tiers (hack the planet) and it costs money. https://learn.microsoft.com/en-us/graph/microsoft-graph-activity-logs-overview
You can literally run around doing a whole bunch of things at an org without touching a VPN, without triggering an MS product alert and without a log.
MS support often say things like ‘you can see the activity in Azure AD audit logs’.. nope.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.