Attacks That Make Password Useless in Databases
Details
Adversary-in-the-middle phishing, infostealer malware, device-code phishing, and malicious OAuth consent can turn a compromised identity into a path toward SQL environments and data resources. Attendees will learn how identity compromise affects database access, what suspicious activity may appear in identity and SQL audit logs, and why a password reset alone may not terminate an intrusion. The session will also address phishing-resistant authentication, session revocation, Conditional Access, least-privilege database permissions, OAuth grant reviews, and coordinated monitoring to protect sensitive data from unauthorized access.
