@SwiftOnSecurity I am increasingly of the opinion that InfoSec is best described as "and..." It's IT and security. It's networking and security. It's business process and security. It's product development and security. It's finance and security. It's people and security.
@SwiftOnSecurity Ah, but the real question: does anyone in the change process have the situational awareness to know when that blast radius is pulled out of one’s butt versus rationally estimated? “Yeah, this GPO applied to the root OU will only affect 2-3 systems, this is fine…”
A tripwire that kills the session and revokes privs is a strong defense, for any anomalous volume of high-impact action (device wipes, account disables or deletes, password resets, file deletes, etc).
Check all your device management platforms. Today it’s intune, tomorrow ???
Taken from the Stryker Handala / Intune Detection Pack v2
"Check PIM role settings for Global Administrator, Intune Administrator, and Cloud Device Administrator. If you see only the "Require Azure MFA" checkbox and no Authentication Context configured, you have the same gap that enabled the Stryker wipe. Configure Authentication Context with FIDO2 or certificate-based auth today.
Enable Intune Multi-Admin Approval for wipe, retire, and delete actions. Tenant Administration > Multi Admin Approval. Under 10 minutes. No additional licensing required.
Deploy Rule 13 (bulk wipe threshold alert). Five wipes in 15 minutes from a single identity fires the alert. Wire it to a Logic App that calls revokeSignInSessions on the triggering account via Microsoft Graph.
"
link to Detection Pack v2 blog and direct download.
Please share so others can lock down their InTune environments please
https://t.co/nLhS49kxut
In early 2026, "Held in the Dark: Finding Light and Hope While Supporting Your Adolescent Through an Eating Disorder" will release. We hope our story can give hope to other families that feel alone and afraid, as we were then. #mentalhealth
Beginning about a decade ago, my family muddled our way through an adolescent addicted to an eating disorder. The whole while we thought we were alone in this struggle and had no idea how to support our daughter through it. #MentalHealthAwareness 🧵
Through the course of this year my wife and my daughter wrote the book we wish existed when we were in the thick of things. This is a very personal book, from the perspective of both the parent and the adolescent, with real talk about the struggles for both.
7:45AM: Flash Flood Warning now in effect for western Llano and northwestern Gillespie. Significant rain has fallen and flooding is expected to develop shortly, particularly over Llano county. #TurnAroundDontDrown
6:00 AM: The heaviest rain continues in northern Llano and Burnet Counties this morning. This system is slowly moving southeast into the Hill Country and southern Edwards Plateau. Do not drive into flooded roads or around barricades. #txwx
Hey @AmericanAir your new policy of making me get off my connecting flight and wait in line to reboard the very same airplane is the stupedest customer service experience I can imagine.
Join my wife and her co-authors for a special livestream celebration to mark the release of their collaborative book "Rising Above" Monday, February 24, 2025, at 7:30 pm ET https://t.co/k88i6hIC4m #mentalhealth