The Microsoft Threat Intelligence Podcast
Trailer
Recent Episodes
From Identity Compromise to AI Defense: Inside Modern Incident Response
This week we are taking you back to Black Hat USA 2026 and exploring two sides of the security landscape. First, Microsoft incident response experts Adrian Hill and Terry Mee break down identity-based attacks, from compromised credentials and MFA bypasses to containment, logging, access controls, and the growing risks surrounding AI agents. Then, members of Microsoft’s Defender Purple Team discuss how they recreate full attack chains, including emerging AI-driven techniques, to identify detection gaps, strengthen defenses, and use AI to accelerate security research while keeping human expertise in the loop.
Why Threat Actors Love Your RMM
In this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Grant, Principal Threat Intelligence Incident Commander at Huntress. They explore how cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) tools, why trusted remote-access software has become an attractive alternative to traditional malware, and how AI is improving phishing and social engineering. Spike also breaks down a real-world attack that deployed multiple RMM tools to maintain access, shares stories from his years of interacting directly with threat actors and offers practical guidance for detecting suspicious RMM activity before it leads to ransomware or data theft.
JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack
In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding their growing AI infrastructure.
Shifts We Are Seeing Across Social Engineering, Post-Disruption Impact Report
In this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They discuss the rise of QR code phishing, Microsoft Teams scams, SMS-based attacks, and why attackers continue to follow wherever people communicate. Crane also shares practical security recommendations for organizations and explains how Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform led to a dramatic decline in malicious activity while reshaping the broader phishing landscape.
A Farewell from Sherrod: New Season Coming Soon
As we close out season three of the podcast, Sherrod offers her farewell message as she takes on a new threat intelligence leadership role outside of Microsoft. Our executive producer also joins to briefly share our plans for season four, with new faces and voices joining future episodes.


