As a reminder, here is my article
AS2Go | How one certificate template misconfiguration (ESC1) can lead to complete Active Directory (AD) forest compromise – Herr HoZi
#ADSecurity: My opinion, try to avoid using #hybrid#AAD Join. One reason is that Active Directory (#AD) and on-premises Exchange are big targets with many vulnerabilities. https://t.co/lDpKvYEaCd
#MDI: Honeytoken tagging can be a fantastic way to leverage Microsoft Defender for Identities insights into authentication to further help you defend your enterprise.
Learn the different methods of placing and creating enticing honeytokens. https://t.co/CH2anv7Vqs
#Reportly: Take some time to play with Sapir Federovsky cool tool.
Reportly will help blue teams during a cloud incident. The researcher has just to enter the suspicious user and get detailed report with:
- Information about the user
- Actions taken by…https://t.co/gSmlaY2THq
#ADSecurity: #PurpleKnight is free, but the results are priceless. Take some time to run the assessment in your environment.
#TeamSemperis https://t.co/1jUR6YdAYp
#ADSecurity: In our Active Directory Security Assessments (#ADSA) we often find insecure User Rights Assignments. A successful abuse by an attacker allows, among other things, by using publicly available tools to extract logon cred…https://t.co/Xz3GYaFmG9 https://t.co/RBZiv4ieTv
#AD: Learn how Semperis helps Business Recovery from cyber Attacks and keep critical operations in track. Guido Grillenmeier wrote a great blog.
#cyber#adfr#ransomeware https://t.co/c7PVo8eQoF
#ForestDruid: Closes the paths attackers use to target Tier 0 assets. Learn more about Forest Druid from my colleague @RHStam#teamsemperis#tier0 https://t.co/WSgkW7XlQh