Our Red Team found multiple ways to get around SharePoint’s “Restricted View” and exfiltrate data. Here's how...
@JackBJohns walks through Red Team methods using OCR and screenshots, Copilot, browser tricks, and HTML scraping to keep and collect data.
No matter the file type (TXT, PPTX, XLSX), there's a way...
📌Read here: https://t.co/09wPBnpvSY
If you’re relying on “Restricted View” to protect sensitive data, it’s time to rethink.
#redteam #cybersecurity #infosec #sharepoint #microsoft365 #datasecurity #restrictedview #copilot
Microsoft Copilot for SharePoint just made recon a whole lot easier. 🚨
One of our Red Teamers came across a massive SharePoint, too much to explore manually. So, with some careful prompting, they asked Copilot to do the heavy lifting...
It opened the door to credentials, internal docs, and more.
All without triggering access logs or alerts.
Copilot is being rolled out across Microsoft 365 environments, often without teams realising Default Agents are already active.
That’s a problem.
Jack, our Head of Red Team, breaks it down in our latest blog post, including what you can do to prevent it from happening in your environment.
📌Read it here: https://t.co/zjSQHE5wUh
#RedTeam #OffSec #AIsecurity #Microsoft365 #SharePoint #MicrosoftCopilot #InfoSec #CloudSecurity
A 32TB SSD for £21?! Bargain, or maybe not. Our @JackBJohns is no stranger to AliExpress, but this purchase was something else. Actually something else - Dodgy disks. My 32TB SSD Adventure
https://t.co/KgpvW6jiXj
Time to be terrified. I've just dropped my Okta Terrify tool which I demonstrated as part of my @BSidesCymru talk last week. You can now backdoor compromised Okta accounts via Windows Okta Verify using attacker controlled passwordless keys. Enjoy - https://t.co/a8Nj6CdZam
A post from our @JackBJohns on why ensuring that Azure Entra ID MFA policies are set correctly. Things to consider: Unexpected patterns of use e.g. logons from Linux or macOS & Make sure you log and can react to out-of-band behaviour. There's loads more...
https://t.co/qwo6bWn01I
BeaconEye: My first defensive tool release for my #DFIR friends. Detects and monitors beacon command output. Should be considered alpha at this stage and appreciate any feedback on undetected beacons.
https://t.co/NacSMsOfY8
1/5 We are hosting a free Bakery-themed Capture The Flag competition Saturday 15th May - Monday 17th May where you can win a Raspberry Pi! Make sure to sign up before 7pm Friday 14th May to ensure you get an account for the CTF. Students from any UK University are free to enter.
Finally caught up with @hackthebox_eu writeups. ~25 new ones are now live at https://t.co/T4spgtseKZ. Lots of fun machines included! But, I need to stay on top of them better in future.