🚨 Agent 365 – Local AI Agent Installation Detection
For organizations licensed with Microsoft Agent 365 or E7, here’s a DefenderXDR custom detection designed to flag local AI Agent installations on Microsoft Defender endpoints.
This detection surfaces installs of tools such as:
- Claude Code / Claude Desktop
- GitHub Copilot CLI
- ChatGPT Desktop
- and other emerging AI agents
Any installation event matching these patterns will be flagged and trigger alerts, giving defenders visibility into shadow AI adoption before it becomes a risk.
https://t.co/tKFTWTnrXx
#Cybersecurity #AIAgent #DefenderXDR
🆕 NightmareEclipse Bitlocker Bypass 0-Day Detection
GreatXML is a Windows zero‑day that bypasses BitLocker by abusing the Windows Recovery Environment (WinRE) and Defender Offline Scan workflow, allowing an attacker to gain an unrestricted shell and access encrypted drives without credentials.
Here's a GreatKQL to compliment the detection 🤭
https://t.co/DfFnZMnZqb
#Cybersecurity #NightmareEclipse #GreatXML #GreatKQL
NRPT rules are highly underrated and might be a better fit than Windows Firewall dynamic keywords (FQDN filtering)
Today I got to investigate why a bunch of Microsoft portals were broken, and the root cause was blocking *.cn with Windows Firewall!
A short 🧵 on my mistake :)
Do you know what your agents are doing? Worried about what kind of websites they might be looking at?
Now you can apply the same web content filtering policies to them as you do to your users! 😅
https://t.co/SZKP2AE5QJ
420 PM CT: Today’s excessive rain outlook has a Level 2 of 4 “Slight Risk” across a large part of Texas.
Important: most folks will not flood. This is a very isolated flooding setup, not a “everyone gets flooded” setup.
The concern is that storms may train over the same small areas tonight into Saturday morning. Where that happens, rainfall totals could quickly pile up and cause significant flash flooding, especially in parts of Central and North Texas.
This sounds simple, but I swear it’s just not done nearly as much as it should be….
Suzie in accounting’s computer has no business communicating with sql1 using the ITAdmin account over WinRM.
The built-in windows firewall is a great start for restricting this.
Free minus your time. Why not?
This 👇 is why I feel bad for the folks running these LLMs on Windows.
There are certain tasks where they run into so many issues and waste tokens doing other stuff instead of actual work.
No wonder Microsoft announced bringing CoreUtils to Windows
https://t.co/uktAjqtWOq
It still feels like a hack though...
Whelp, it seems GitHub Copilot went from one extreme to the next
It was obvious and understandable something had to change as the premium request model was unsustainably generous, but the new token based model ends up being way more expensive than Codex, Claude, or https://t.co/t0jownCQ8W
5:45 PM CT: It’s a stormy dinner hour across North Texas, East Texas, and Southeast Texas.
Plenty of pop-up storms are slowly drifting southwest, with the strongest storms producing heavy rain, strong wind gusts, nasty lightning, and localized street flooding. Lots of severe storm warnings for these storms producing microburst winds over 60 MPH.
Not everyone gets rain, but storms that do develop can be rowdy. Head indoors when thunder is nearby.
Radar: https://t.co/ZZQhbx5wWG