Block High Risk AI Agents in Microsoft 365!
So many AI Agents are available to use in your Microsoft tenant without you even knowing.
More and more agents are becoming available, and this trend will continue.
The first thing you should do is block the high-risk AI agents from accessing your organization's resources.
Read more: https://t.co/6ixle7ED96
#Microsoft365 #EntraID #Cybersecurity
Search 15M+ Microsoft 365 tenants by org name or domain and discover all known domains in the same tenant: https://t.co/QxzqVo4sbf. Legacy methods like Autodiscover/GetFederationInfo no longer work (https://t.co/qoKZCMIIU6).
🚨I HAVE LEAKED EVERY SINGLE PASSWORD EVER (4 to 32 chars long)!
That is 347 novemdecillion passwords, the largest password leak ever!
ALL of your passwords are in here, GUARANTEED!
This is a client-side app, so what you search for is all local, never sent anywhere.
TeamViewer - @whynotsecurity
TL;DR: TeamViewer stored user passwords encrypted with AES-128-CBC with they key of 0602000000a400005253413100040000 and iv of 0100010067244F436E6762F25EA8D704 in the Windows registry.
https://t.co/0Cbwvu4ZgA
Threat hunters rejoice! This is HUUUGE news 👏
Microsoft just introduced linkable identifiers in Microsoft Entra ID logs.
The bad guys 🥷 are going to hate this so much 😂
Learn more at https://t.co/1pGm1CzjNm
Share the good news 👍
By making minor changes to command-line arguments, it is possible to bypass EDR/AV detections.
My research, comprising ~70 Windows executables, found that all of them were vulnerable to this, to varying degrees.
Here’s what I found and why it matters 👉 https://t.co/VpMttDZI9K
🚨 Detect C2 Beacons!
New Microsoft Defender for Endpoint telemetry provides new opportunities for threat detection!
🔗
https://t.co/L5TM7BWIc6
#ThreatHunting#DetectionEngineering#MDE
New Active Directory Mindmap v2025.03! 🚀
📖 Readable version: https://t.co/gQd6WsLnzG
🔧 Now fully generated from markdown files—way easier to update and maintain!
💡 Got improvements? PRs welcome! 👉 https://t.co/o52PAmek7b
Bypass AMSI in 2025, my newest blog post is published 🥳! A review on what changed over the last years and what's still efficient today.
https://t.co/hSqMxeJx2K
Microsoft Defender for Endpoint uses advanced machine learning models to block malicious command lines and protect against a wide variety of threats, including ransomware and living off the land binary (LOLBin) attacks. Defender for Endpoint uses the CommandLineBerta, a model that evaluates suspicious command lines to determine the probability that they are malicious. If they are classified as malicious, they are blocked. https://t.co/0uWvNdYmGw
Instead of relying on RemCom, what if we had a python client to interact with the latest, Microsoft signed PSExec? In this post @Defte_ details how he and the team did exactly this, including a tool, some PSExec internals and detection opportunities!
https://t.co/StXoZS9gEw
🚀 Today I'm launching ArgFuscator: an open-source platform documenting command-line obfuscation tricks AND letting you generate your own
🔥 68 executables supported out of the box - use right away, make tweaks, or create your own
👉 Now available at https://t.co/eZbpI08AzP
Tired of using ts::multirdp, because Mimikatz is a nogo nowadays and get's flagged anyway most of the time? 🧐
Well, here is a standalone patching implementation with Win11 support:
https://t.co/lCb8HlQm9c
Easy to port to a BOF/Coff🤠🔥
#pentest#redteam
APEX now has it's own home on github:
https://t.co/7mOBZOEujT
Newest addition is the interaction with Key Vaults including auto discovery and credential extraction.
Use Windows Server for FREE for up to 3 years!
Did you know you can use Windows Server for three years without purchasing a license?
Windows evaluation editions are trial versions of Windows operating systems provided by Microsoft.
These editions allow users, especially IT professionals, to test and evaluate the features and capabilities of different Windows versions before making a purchase decision.
Start with the initial 180-day evaluation and extend it 6 times. This gives you a total of 1,080 days to test, explore, and learn!
Learn how to extend your Windows Server evaluation period:
https://t.co/0ZWoYKGXHz
Remember that once the evaluation period expires, the server will begin to shut down every hour as a reminder to obtain a proper license.
#Microsoft #WindowsServer #ITPro #SysAdmin
Another approach to disable EDRs (with anti-tampering). Credit goes to @sixtyvividtails for the idea🧙♂️
PendingFileRenameOperations and an NTFS junction, we can ask Windows to delete EDR binaries on reboot (with Admin privs)
A link to a complete GitHub PoC follows in replies
We've open-sourced GReAT’s plugin for the IDA Pro decompiler - an indispensable set of tools for analyzing malware, shellcodes, etc. Grab our secret ingredient for reverse engineering and check out the GIFs demonstrating its usage - https://t.co/W4uWIPXsMN