# Think Like an Attacker: Microsoft Security Exposure Management with Uros Babic [MVP-MCT] Page: https://stenobird.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214/think-like-an-attacker-microsoft-security-exposure-management-with-uros-babic-mvp-mct Text version: https://stenobird.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214/think-like-an-attacker-microsoft-security-exposure-management-with-uros-babic-mvp-mct.md Podcast: [M365.FM - Modern work, security, and productivity with Microsoft 365](https://stenobird.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214) Published: 2026-07-02T14:00:03+00:00 Episode link: https://www.spreaker.com/episode/think-like-an-attacker-microsoft-security-exposure-management-with-uros-babic-mvp-mct--72786209 Audio file: https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72786209/think_like_an_attacker_microsoft_security_exposure_management_with_uros_babic_mvp_mct_1.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214/episodes/think-like-an-attacker-microsoft-security-exposure-management-with-uros-babic-mvp-mct Duration seconds: 4198 ## Resource Traditional cybersecurity focuses on vulnerabilities, alerts, and dashboards. Attackers don't. They look for opportunities, weak identities, exposed cloud resources, excessive permissions, forgotten endpoints, and misconfigurations they can chain together into a successful attack. In this episode of the M365 FM Podcast, host Mirko Peters takes a unique approach by stepping into the role of the attacker while Microsoft Security MVP and Microsoft Certified Trainer Uros Babic defends a modern Microsoft environment using Microsoft Security Exposure Management, Microsoft Defender XDR, Microsoft Sentinel, Security Copilot, and Zero Trust principles. Instead of discussing security theory, this episode follows a realistic attack scenario from reconnaissance and phishing to privilege escalation, lateral movement, ransomware, and data exfiltration. Along the way, Uros explains how organizations can stop attackers before they reach critical assets by focusing on exposure rather than simply fixing vulnerabilities. The discussion demonstrates why modern security operations are shifting from reactive incident response to proactive risk reduction powered by Microsoft's latest security technologies. THINKING LIKE AN ATTACKER The episode begins with one fundamental mindset shift: attackers don't see security dashboards or compliance reports—they see attack paths. Uros explains why organizations should stop asking "How many vulnerabilities do we have?" and instead ask "Which attack path would an attacker exploit first?" Topics include: Social engineering Phishing attacks Credential theft Privilege escalation Lateral movement Ransomware Data exfiltration Insider threats Supply chain attacks Cloud misconfigurations Understanding how attackers think is becoming one of the most valuable ski… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214/episodes/think-like-an-attacker-microsoft-security-exposure-management-with-uros-babic-mvp-mct/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214/think-like-an-attacker-microsoft-security-exposure-management-with-uros-babic-mvp-mct.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.