Slide deck of my @WEareTROOPERS talk "Dumping NTHashes from Azure AD" available at https://t.co/J9iCAkwrP4
TL;DR:
🔹Deploying Azure AD Domain Services (AADDS) makes Azure AD connect to sync legacy credentials (NTHashes) to Azure AD
🔹Credentials are stored in Azure AD in hidden user object attributes only accessible by "Azure AD Domain Services Sync" application
🔹Credentials are encrypted/decrypted using certificates stored in AADDS DC:s certificate store
🔹Dumping NTHashes requires compromising AADDS DC
Here is my follow up on the escalation from DA to EA with the demo on how to install Enterprise CA without Enterprise Admins and get to EA: https://t.co/RdhdqKsX2W #PKI#adcs#specterops
The Name Resolution Policy Table (NRPT) is a very effective way to specify DNS servers per domain/TLD - on the DNS client!
Blocking TLDs like .zip is just one use case.
I'm glad to announce a new version of AD CS "SID Policy Module" that addresses limitations in KB5014754. New version includes support of SAN URI strong mapping enforcement policy and other improvements: https://t.co/777M0r7CMj #pki#ADCS#CryptoAPI
#Microsoft introduces preview of new SAN URI for strong certificate mapping with offline templates. Would love to get your thoughts on this @Crypt32. :) https://t.co/fbR7nSVmlo
📢 The first public edition of my "Offensive Azure AD and Hybrid AD" training is now scheduled and available for booking. June 5th to 7th in The Hague, The Netherlands. Tickets and more information at https://t.co/9vDTucJo4X.
With more than two months to go of 2022 I can say with certainty that this is THE tip of the year: Shortcuts to Microsoft admin and user portals + deep shortcuts to Azure AD sections. https://t.co/h5b77hxzph
#MSXFAQ Free/Busy mit OAUTH https://t.co/n21IUqlvkL - Troubleshooting von Free/Busy-Fehlern zwischen #Outlook, #ExchangeOnline und #Exchange OnPremises mit #Fidder, IIS Request Tracing u.a. Ist das noch Level 400? Hilft aber beim Verstehen der Zusammenhänge.
Check out this post on the Microsoft Tech Community : Basic Authentication Deprecation in Exchange Online – May 2022 Update - Microsoft Tech Community https://t.co/RkEEXSRz1H #MSExchange#MSFTExchange#security
Yes, it seems you can connect to #Azure in #WinPE using Device Code Flow (User Auth), grab your Tokens and Headers, and get to custom Windows Images on #Azure Storage
#OSDCloud will support imaging from #Azure soon, very soon @mike_marable@gwblok#MMSMOA#OSD
.@Office365 Sensitivity labels (or is that Microsoft Purview labels?) have a new advanced setting (in preview) to control #SharePoint site sharing permissions. Another example of why container management via labels is goodness.
https://t.co/QqEMf9XZWD
#Microsoft365#Office365
🚨 Do NOT blindly copy-paste KQL from the internet: Malicious Kusto query allows attacker to collect access tokens and use them to query information as victims..
And yes, this is by-design 🤦♂️