Call For Paper - Workshops

Ethan Bowen

Ethan Bowen is a Security Solutions Architect at NVISO, where he helps organizations solve complex SOC challenges. He brings more than 10 years of blue team experience across consulting, financial services, federal government, and technology sectors, with a focus on detection engineering, incident response, threat hunting, and Microsoft security technologies.

Before joining NVISO, Ethan worked at Deutsche Bank, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Microsoft, Pacific Northwest National Laboratory, and the U.S. Department of Defense.

Ethan holds a Bachelor of Science in Cybersecurity from Penn State University. He also holds multiple industry certifications, including GREM, GCFA, CISSP, and multiple Microsoft certifications. Outside of work, Ethan enjoys running and playing board games.


Session

09-11
09:00
240min
Defending Microsoft Entra ID: Common Attacks, Tokens, and Response Planning
Ethan Bowen

Microsoft Entra ID is a major target for attackers and a core part of modern incident response. SOC analysts must understand cloud identity from initial access, persistence, privilege abuse, and lateral movement. Understanding Active Directory alone is not enough.

This 4-hour session gives defenders a practical understanding of how Entra ID works and how it is abused. It covers identity types, hybrid authentication, OAuth and OIDC, application objects and service principals, token types, Conditional Access, and key attack paths including device code phishing, attacker-in-the-middle, and refresh token replay. It also discusses Entra sign-in logs, the Graph API and its logs, sign-in session tracking, and practical KQL-based hunting.

Attendees will run KQL queries to identify suspicious activity and execute 'attacks' in a lab environment.

Uni Campus Seminarhaus 3