Google Webinar | Spider in the Web: UNC3944 in your Cloud Identity Fabric

Google Webinar | Spider in the Web: UNC3944 in your Cloud Identity Fabric

🎙 Varsha (Google) 👥 3K 📅 February 18, 2026 ⏱ 60 min 👁 32 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

threat huntingUNC3944Scattered SpiderAzure ADM365AWSTTPs

Summary

This WiCyS webinar, presented by Varsha from Google’s Mandiant incident response team, focuses on threat hunting for the threat actor UNC3944 (Scattered Spider). The presentation begins with an overview of the threat actor’s tactics, techniques, and procedures (TTPs), including social engineering, SIM swapping, and identity-based attacks. The core of the webinar is a practical guide to threat hunting, emphasizing proactive detection over reactive incident response. Varsha outlines a methodology based on the MITRE ATT&CK framework, covering initial access, privilege escalation, persistence, and lateral movement. She demonstrates specific hunts using M365 and AWS as examples, showing both GUI-based and query-based approaches. Key hunts include detecting privileged account password resets, MFA device changes, and suspicious logins. She also covers privilege escalation detection via credential dumping tools and persistence mechanisms like new cloud accounts and VMs. The webinar concludes with a Q&A session, providing practical advice for threat hunters.

146 words

Critical Evaluation

Value of the Information & Strength of the Argument

The webinar provides valuable, actionable insights for threat hunting, particularly for cloud environments. Varsha’s argumentation is solid, grounded in her experience with Mandiant and real-world engagements. She effectively explains the importance of proactive threat hunting and provides concrete examples of queries and techniques. The presentation is well-structured, following the attack lifecycle, and offers practical tips such as IP enrichment using tools like VirusTotal and Spur. However, the argumentation is largely anecdotal, lacking formal citations or references to specific research or reports, which slightly weakens its scientific rigor.

Scientific Rigor, Source Quality, Title Accuracy

The webinar demonstrates a good level of scientific rigor in its methodology, but the sources are not formally cited. The presenter references MITRE ATT&CK and mentions open-source threat intelligence, but no specific URLs or publications are provided. The title accurately reflects the content, focusing on UNC3944 and cloud identity threats. The webinar is presented by a professional from Google’s Mandiant team, which adds credibility. However, the lack of explicit citations and reliance on personal experience may limit its verifiability. The description includes a link to BrightTALK for more webinars, but no direct references to the mentioned tools or reports.

201 words

Title / Content Match

The title accurately reflects the content, focusing on the threat actor UNC3944 and cloud identity threats.

Quality & Reliability

7/10

The webinar is presented by an incident response consultant from Google's Mandiant team, providing practical threat hunting methodology based on real-world experience. However, it lacks formal citations and is largely anecdotal, with no peer-reviewed sources.

Key Moments

Cited Sources

Concurring Sources

  • CISA Alert on Scattered Spider — Provides official information on UNC3944 TTPs and IOCs, aligning with the webinar's content.

Contribution & Novelties

The webinar offers a practical, hands-on approach to threat hunting for a specific and active threat actor (UNC3944). It provides concrete query examples for M365 and AWS, which are directly applicable for security professionals. The emphasis on proactive hunting rather than reactive incident response is a valuable perspective. The presenter shares real-world insights from her experience at Mandiant, adding practical depth.

Pour aller plus loin :

  • MITRE ATT&CK — The framework referenced for understanding attack lifecycles and TTPs.
  • Scattered Spider (UNC3944) - CISA Alert — Official advisory providing IOCs and TTPs.
  • Microsoft 365 Advanced Hunting — Documentation for the query language used in M365 hunts.
  • AWS CloudTrail — Documentation for AWS logging and event history.

115 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly higher scores in information quantity and quality, reflecting the webinar's practical content. The technical level is moderate, suitable for a broad audience, while reliability is good due to the presenter's expertise.

Reliability 7/10

💬 No comments were provided for analysis.