Steven Nesbitt

Steven Nesbitt

Engineer, Varonis

Steve has worked in the industry for over 15 years with a particular interest in the management of data. After completing a Master’s Degree in Information Management, he went on to work with SharePoint ISV’s before joining Microsoft as an O365 Technical Specialist. Towards the end of his tenure at Microsoft, he began to diversify into both Management of Modern Desktops and Cyber Security and it was this that led him to move on from Microsoft to join Varonis.

Here’s an outline of how the attack works:

  • We trick a user into entering creds into our fake O365 login page (made with evilginx)
  • We make Microsoft send a passcode to the user’s phone
  • User enters their passcode on OUR fake page
  • We hijack the user’s session token
  • Gain access to SharePoint Online environment
  • Exfiltrate data from O365
  • Pivot to on-prem and steal CEO’s emails (because why not?)
Our Clients