@OctopusEnergy Worth mentioning the octopus customer support Conner has been very helpful in resolving this, the issue was from the Tesla side and they fixed it based on the RCA given by Octopus. Very happy! Kudos ๐ค๐ฝ @OctopusEnergy
โฆ@OctopusEnergyโฉ I am so frustrated with this. Unable to onboard my Tesla even after granting the permissions required by the app. I have also sent you email but still no response.
This strange tweet got >25k retweets. The author sounds confident, and he uses lots of hex and jargon. There are red flags though... like what's up with the DEI stuff, and who says "stack trace dump"? Let's take a closer look... ๐งต1/n
You have just finished remediating your last machine impacted by #crowdStrike#bluescreen, but now you have no idea who can access all the BitLocker keys you just exported! ๐๐ข๐ฆ๐ ๐ญ๐จ ๐๐จ๐ญ๐๐ญ๐ ๐ฒ๐จ๐ฎ๐ซ ๐๐ข๐ญ๐๐จ๐๐ค๐๐ซ ๐ค๐๐ฒ๐ฌ!
The full article along with device action reporting options (including getting all devices) > https://t.co/lQZf2b2kah โก
Luckily for you, if you are using Microsoft Intune and storing your BitLocker keys in Entra, you can use this super simple script to queue a key rotation job on each device. When the device next checks in, the key will be rotated!
I have seen various iterations of this type of thing over the last 24 hours, all seem to use custom app registrations, secret keys and certificates. This is a one-off job you should run in the ๐๐๐ฅ๐๐ ๐๐ญ๐๐ ๐๐จ๐ง๐ญ๐๐ฑ๐ญ, please don't necessarily open your org to additional risk! This is something I cover in my book "Microsoft Graph PowerShell for Administrators".
#intune #entra #graph #bsod
My new blog has arrived. A lot of what is in here mimics APT29 (Midnight Blizzard) Tradecraft. Some good nuggets also on using Evilginx development mode for phishlet development if you donโt want to expose a VPS. Enforcing cloud native in Entra ID? I got you covered with a bypass. Stay tuned for part 2.
Weaponization of Token Theft โ A Red Team Perspective
https://t.co/uT9KUyX5z2
Happy to share a new Active Directory audit tool to the cybersecurity community :
AD Miner (aka #Bloodhound on steroids) can help you:
โฉCheck more than 40 attack vectors or weaknesses
โฉUncover most risky control paths
โฉPrioritize and track mitigations efforts
https://t.co/d5j2OWWGSo
AD Miner basically plugs into an already-populated neo4j BH database, runs a series of cypher queries and produces a report where all results are nicely presented with graphs, listing, etc.
Enjoy and feel free to send feedback or to open issues on our github.
Chandrayaan-3 Mission:
'India๐ฎ๐ณ,
I reached my destination
and you too!'
: Chandrayaan-3
Chandrayaan-3 has successfully
soft-landed on the moon ๐!.
Congratulations, India๐ฎ๐ณ!
#Chandrayaan_3#Ch3
I wanted to give the new VS BOF template a go, so I've implemented @tiraniddo's SCMUACBypass into the Elevate Kit. You just need a suitable Kerberos ticket in your cache (from whatever attack chain you like) and it takes care of the LPE for you.