#30959 [Huntress Detection] CRITICAL - ISOLATED - Incident on [email protected] (Five Valleys Land Trust)
Resolved
Created Dec 23, 2024, 8:24 PM
Resolved Oct 15, 2025, 12:07 AM
Huntress (internal)
Dec 23, 2024, 8:24 PM
Artichoke Support - Peet (internal)
Dec 23, 2024, 9:10 PM
Looks like Ramey approved an MFA prompt while being phished. Checking logging to see if any data was accessed. Peet
customer-reply (internal)
Dec 23, 2024, 9:19 PM
Thanks Peet keep me posted. I've been thinking lately before this how we may be overdue for a security training. Get [Outlook for Android](https://aka.ms/AAb9ysg) --------------------------------------------------------------- From: Artichoke Support - Peet <[email protected]> Sent: Monday, December 23, 2024 2:10:00 PM To: Boston Wakeham <[email protected]> Subject: [Huntress Detection] CRITICAL - ISOLATED - Incident on [email protected] (Five Valleys Land Trust) (message id: 89899901)
Artichoke Support - Peet (internal)
Dec 23, 2024, 10:11 PM
I can talk to you more about that ... but for the moment. There were no changes post phish, and she should be back in. I'll keep an eye out. Peet
Artichoke Support - Peet (internal)
Dec 23, 2024, 10:12 PM
The following remediation plan was approved by [email protected]: Manual Remediations: Cloud: Kill the current session for [email protected] Cloud: Please audit any suspicious application registrations and Enterprise applications added or consented to for [email protected] Cloud: Rotate the credentials for [email protected]. Cloud: Audit activity for user [email protected]. Cloud: Enable and enforce MFA for [email protected], if otherwise not enabled. Cloud: Enable complex conditional access policies for [email protected].
Ticket Automation (internal)
Oct 15, 2025, 12:07 AM
Automation AutoResolve-Waiting for Customer ran on this ticket. Actions: Change Status to Resolved
| Started | Ended | Hours | Notes |
|---|---|---|---|
| No time entries | |||