Microsoft is releasing Out-of-band (OOB) updates to address a known issue which might cause sign in failures or other Kerberos authentication issues. https://t.co/3til5aSjFR
OOB patch to fix affected DCs is scheduled. ETA before end of week.
Patch will fix underlying bug and disable the reg key floating around the internet.
Releasing a new tool: Orpheus! Bypasses most Kerberoast Detections (including my own). Blog post and video is up at @TrustedSec! Even used @HackingDave's old alias in the demo. https://t.co/qhP8r28s4K #infosec#security#kerberoast
I am very excited to have a blog published by @MicrosoftDART and @MsftSecIntel that I was one of the major contributors to. I would love for you to have a read! The use of cloud token theft is on the rise; learn how to prevent, detect and respond - https://t.co/hB0GdPOxBW
Hey all, I just published an article on using Azure AD's Access Packages to enable end user device enrollment in Microsoft Intune
https://t.co/PBTwDCWAN9
If you have Azure AD P2 licensing and haven't seen Access Packages, welcome to your new obsession :)
TIL that as the CO river dries up, AZ is leasing its largest underground aquifer to the Saudis, who are growing water-intensive alfalfa, which is then shipped back to S.A. to feed cattle. Market rate for the lease is $5 million/yr. Saudis pay $86K.
https://t.co/8sDDYCqNO0
Here are the main ways that vulnerable #OpenSSL instances *might* manifest in-the-wild (we will update this diagram to be more precise once the CVE details have been published). Credit to @ncsc_nl for the appropriately Halloween-themed logo.
Based on what we have seen during Active Directory security assessments, if you have Active Directory Certificate Services (ADCS) in your environment, you want to download and run Locksmith to scan for ADCS security issues.
Locksmith provides remediation as well!
🎊 I am pleased to present VMPlex Workstation - A modern, tabbed UI for Hyper-V. The code is open source and the first release is available for download on GitHub. Kudos to @0xf005ba11 for creating this! https://t.co/eZ41d7v6Di
Huge thanks to @SantasaloJoosua for creating the awesome 𝗖𝗔 𝗢𝗽𝘁𝗶𝗰𝘀 for analyzing gaps in #Azure Active Directory conditional access policies. Thanks for working through my uncommon scenario with me! #MVP! #IAM#InfoSec#BlueTeam#AzureAD#GCCHIGH
https://t.co/SzUv34Nqfl
🎉 I'd like to share something that I'm legit really excited about: https://t.co/kj5vhVIcS4
Pivit is our tool that we've been using for git signing using hardware-attested private keys generated in Yubikey's PIV applet (we send the CSR to a CA that verifies attestation).
PTAL!
One of the first things I did at Panther was configure SSO and hardware MFA.
Read about how our team has up-leveled with FIDO2 and Okta:
https://t.co/FH7hSLysEf
1/ Perhaps a lesser known "feature" of Microsoft Authenticator, but the diagnostic data can be very helpful in investigating a compromised #Azure account where MFA is enabled but the user claims not to have confirmed the MFA Consent Prompt. 🧵