Talk With an Expert

Investigating a Malicious Script in Microsoft Intune

Investigating a Malicious Script in Microsoft Intune (PDF, 2.63MB)Last updated: 24 Jul, 2025
Presented by:
Dennis Labossiere
Dennis Labossiere

The proliferation of cloud-based solutions has significantly transformed the landscape of enterprise security, with Microsoft Intune emerging as a pivotal tool for device and application management. This Digital Forensics and Incident Response (DFIR) case study delves into the forensic investigation of a malicious script within Microsoft Intune, highlighting procedural insights and analytical techniques. The incident, which occurred in 2023, involved unauthorized access to a client’s Azure tenant by Scattered Spider. This presentation discusses the forensic analysis conducted to recreate the attack and understand its impact. This presentation describes baseline configurations, forensic tools, and methodologies deployed to detect and analyze the attack. Key technical aspects discussed include leveraging the Graph API, tracking user actions, modification timestamps, and decoding PowerShell script contents with CyberChef.

SANS DFIR Summit 2025