Petra Security
banner
petrasecurity.bsky.social
Petra Security
@petrasecurity.bsky.social
Detect and respond to M365 account compromises in real time. Stop BEC and Token Theft in their tracks. https://www.petrasecurity.com/
6/6: Seen any weird API behavior yourself? Drop your Qs below 👇 We're diving into Exchange/SharePoint/Teams logs next and would love to know what you're curious about!
December 10, 2024 at 9:32 PM
5/6: Want to sleuth through the data yourself? Check out our deep dive into Microsoft's API latency patterns here:

petrasecurity.substack.com/p/o365-mgmt-...
Spelunking in the Microsoft API, Part I: Entra ID Latency
One of the most important and least understood factors for building ML systems using Entra ID Login Events
petrasecurity.substack.com
December 10, 2024 at 9:32 PM
4/6: The biggest surprise? Failed login attempts from suspicious IPs consistently show up later than other events. We found distinct delay patterns tied to potential brute force attacks.
December 10, 2024 at 9:32 PM
3/6: While 90% of events show up within 6.5 mins, the tail end is wild: 0.5% of events take 4+ HOURS to appear, and some took nearly a week!
December 10, 2024 at 9:32 PM
2/6: Most security teams assume Microsoft events appear in minutes. But our analysis of 72 hours of data across 2,300+ users revealed a shocking pattern in the API's worst-case performance...
December 10, 2024 at 9:32 PM