Netsurion logo Netsurion logo
  • Our Solution
    Back
     Image
    OUR SOLUTION
    • Capabilities
      Predict, prevent, detect, and respond
    • How It Works
      People, platform, and process
    • Use Cases
      By threat, environment, or industry
    • Talk to a Cybersecurity Advisor
      See how we deliver managed threat protection
  • WHY NETSURION
    Back
     Image
    WHY NETSURION
    • Key Business Benefits
      Powerful yet practical cybersecurity
    • Industry Leadership
      Perennial recognition for innovation
    • Customer Success
      Driven to be your trusted partner
  • Partners
    Back
    Partner Program Overview Image
    PARTNER PROGRAM OVERVIEW
    • Partner Program Benefits
      Our solutions are built for service providers
    • Become a Partner
      Grow your cybersecurity practice
  • Insights
    Back
     Image
    VIEW ALL INSIGHTS
    • Articles
      Read the latest from our blog
    • SOC Catch of the Day
      Real stories of threats we reel in daily
    • Cybersecurity Q&A Videos
      Answering your toughest cybersecurity queries
    • Webcasts & Events
      Join us in-person or online to learn more
  • Company
    Back
     Image
    MEET NETSURION
    • Leadership
      Meet our management team
    • News
      Press releases and news stories
    • Careers
      Check out our current openings
    • Contact Us
      Talks to sales or support
  • MyNetsurion
  • Support
  • Partner Portal
  • Contact Us
SOC Catch of the Day

We review billions of logs daily to keep you safe from advanced threats.

HomeInsights Catch of the Day Nosy Admin Snoops Managing Partners Email

Nosy Admin Snoops Managing Partners Email

The Network: A law firm headquartered in the U.S. East Coast with a dozen offices worldwide.

The Expectation: Email is the “killer” app for attorneys. Confidentiality of electronic communications is essential and to be expected. Law firm uses on-premises Microsoft Exchange as the hub of email communications. This is considered to be safe and controlled.

The Catch: Netsurion’s EventTracker detected a privileged user (admin on the Exchange box) abusing his privileges to view a Managing Partner’s email communications.

The Find: Microsoft Exchange users can share items like calendars and delegate access. Senior staff do this regularly so that their calendar can be maintained and coordinated. However, while an admin has complete power and can view everything, it doesn’t mean that s/he should.

The Fix: Institute monitoring since such behavior cannot be prevented. High priority alerts are defined to capture this type of situation. Make sure to filter out legitimate access such as calendar delegation to minimize false positives.

The Lesson: Compliance and privacy are impacted by snooping employees who exceed their “need to know” role and responsibility. Security awareness training and Role-Based-Access-Control can educate and limit rogue employees. Comprehensive 24/7/365 monitoring by the Netsurion SOC quickly detects and helps respond to harmful employee access.

Related Catches
  • Dubious Document Destroyed at Law Firm
  • Phony Performance Warning Foiled
  • Vulnerable VoIP
Latest Catches
  • Trojan Hunted at a Medical Center
  • Ransomware Detected & Blocked in Business Services Firm
  • MITRE ATT&CK Guides MSP on Cobalt Strike Threat Mitigation

This site uses cookies to store information on your computer. Some are essential to make our site work; others help us improve the user experience. By using the site, you consent to the placement of these cookies. Read our Privacy Statement to learn more.

I Accept

Contact Us

  • 1 (877) 333-1433
  • Customer Support
  • partners@netsurion.com
  • sales@netsurion.com

Partners

  • Partner Program Overview
  • Partner Program Benefits
  • Become a Partner
  • Partner Portal Login

Quick Links

  • Why Netsurion
  • Blog
  • Careers
  • Our Solution
SOC 2
  • Terms of Use
  • |
  • Privacy Notice
  • |
  • Soc 2 Type 2 Compliant
  • |
  • Contact Us
  • |
  • Sitemap
  • |

Copyright © 2023 Netsurion. All rights reserved.