ThreatCast

Inside Microsoft GHOST with Matt Zorich – Exploring Threat Hunting

Threatscape Season 1 Episode 11

Send us a text

In this episode of ThreatCast , Ru and Matt dive deep into the world of Microsoft GHOST, a specialised team focused on cybersecurity hunting within Microsoft. Matt explains the role of the DoD (Detection and Response Team), their work on incident response for customers dealing with ransomware and nation-state attacks, and how Microsoft telemetry plays a crucial role in detecting and mitigating threats.

They also discuss current trends in the cybersecurity landscape, including token theft, adversary-in-the-middle attacks, and the importance of mandatory MFA (Multi-Factor Authentication) for securing Azure and Intune admin portals. Matt shares his insights on how these measures, along with KQL, are helping Microsoft and its customers stay ahead of evolving threats.

ThreatCast podcast is produced by Threatscape.

Our mission is to provide a secure and certain future for our clients. Keeping them protected so that they can go about their business is how we know we’re delivering on our promise.

Contact us

Email Address : info@threatscape.com


Thanks for listening & keep podcasting!

People on this episode