Madeleine Massee

Madeleine Massee

Security Analyst, Varonis

Madeleine Massee is a Security Analyst on the Incident Response and Security Architecture teams where every day they help organizations detect and respond to cyber threats. Having worked in the financial sector and being a US Navy Veteran, Madeleine works to help organizations proactively reduce their risk posture and aids in protecting mission critical systems and safgaurding sensitive data. Madeleine graduated from Columbia University and majored in Computer Science.

Here’s an outline of how the attack works:

  • We trick a user into entering creds into our fake O365 login page (made with evilginx)
  • We make Microsoft send a passcode to the user’s phone
  • User enters their passcode on OUR fake page
  • We hijack the user’s session token
  • Gain access to SharePoint Online environment
  • Exfiltrate data from O365
  • Pivot to on-prem and steal CEO’s emails (because why not?)
Our Clients