🔥🤖 M365 Connector for Claude – Why SecOps Must Care
Monitoring the M365 Connector for Claude is critical because when ResultType=0, it means an Entra Global Admin has granted permissions, enabling Claude to directly access SharePoint, OneDrive, Outlook, and Teams—a governance decision with major security implications that SecOps must track closely. Meanwhile, ResultType=90095 shows end users attempting to use the connector without the admin grant, signaling demand, shadow IT risk, and adoption pressure. By watching both signals, defenders gain visibility into where governance decisions meet user behavior, ensuring connector risks are managed before they escalate.
KQL Code:
https://t.co/NGuwSLgvKF
#Cybersecurity #M365ConnectorClaude #Entra #Governance
Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs
- update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe
- file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll
- network IOCs incl. api[.]skycloudcenter[.]com (-> 61.4.102[.]97), api[.]wiresguard[.]com, 59.110.7[.]32, 124.222.137[.]114
by @rapid7
https://t.co/rrespJ9Ju0
I just solved the strangest tech problem I've ever come across.
My wifi kept dropping packets, confirmed by ping. It would look something like the first image (packets dropping, then it comes back to life). After a while the connection would just stop working completely and drop all packets. If I turned my wifi off and on again, it would resume working normally.
I thought this was a problem with my router, cables or ISP, so I went through the usual troubleshooting processes: checking settings, swapping cables, powercycling, etc. nothing worked.
Eventually I started noticing that it would only happen when I sat in my office. I was taking a video meeting and it kept dropping segments of audio, making it hard to understand the other person.
I unplugged my laptop from my monitor + keyboard because I wanted to try walking into another room. Immediately, the video started working perfectly.
I thought it was because I was a few steps closer to my router - but that didn't really make sense because the router had always worked fine from that location.
I started thinking about what I'd changed in my desk setup recently, the only thing I could think of was when I changed from using a USB-C <-> DP cable for my monitor, to using a HDMI <-> HDMI cable.
I tried plugging my screen back in. Immediately, the packets started dropping. I unplugged it, the dropping stopped.
It turns out my HDMI cable doesn't have enough shielding, so it was jamming my own WiFi signal with radio frequency interference 🤯
I unrolled the HDMI cable that was sitting behind my laptop and draped the main length of the cord down behind my desk, and now my internet works perfectly.
Apparently this is a fairly common issue?!
Cooking some nice Linux Attack Chains. With EDRmetry in minutes, you can prepare your own scenario of a Linux attack path. Install EDR/Runtime Security. Watch your telemetry, get detection events, and collect forensics artifacts from every single stage of attack. Dig deeper. This is how to develop true hands-on #Linux skills in #redteam #blueteam. Let's go!
Time’s ticking makers ⏰~
Only 2 days left! If you miss this, you’ll have to live with the regret… and let’s be real, regret is way worse than running out of filament mid-print. 😱😂
👉 Enter now: https://t.co/X3dP3Ic0K2
Repost for extra entry!
#3DPrinting#polymaker
Another fantastic article from Olaf Hartong exploring the depths of Microsoft XDR's integration of Zeek.
Detection engineering rabbit holes — parsing ASN.1 packets in KQL [https://t.co/E1hugZfaKH]
#detectionengineering#kerberos#xdr
@anton_chuvakin@nas_bench It's also the appeal for ease of risk transferrence. Long-term outcome of that is likely a renewed defense-in-depth approach b/c EDR vendor lawsuit shows client didn't configure it to best practice/environment nuance. The middle piece was the insurance co. denying the claim.
Spending too much on SIEM?
Sentinel's new "Summary Rules" feature can reduce log sizes by 14x, resulting in significant cost savings!
4 Deployment Steps:
1) Identify your largest tables (use the 80/20 rule)
2) Create a summary KQL query to aggregate
3) Convert the table from Analytic to Basic
4) Update your Analytic Rules to use the Summary Table
Documentation: https://t.co/OS44JHZWeK
Microsoft forgot to include the hashes of the RDP files and I wrote a YARA rule to detect them
Hashes
db326d934e386059cc56c4e61695128e
40f957b756096fa6b80f95334ba92034
f58cf55b944f5942f1d120d95140b800
b38e7e8bba44bc5619b2689024ad9fca
e1d7de6979c84a2ccaa2aba993634c48
f7e04aab0707df0dc79f6aea577d76ea
48ed82f14472518251086afc26d886ea
3d7e2ee43faf15c1776aa0277db1c2a5
280ab6fa6087c57b43cd5ac6c257082c
YARA rule
https://t.co/65IWRJOFta
It'll be available in THOR Lite and THOR Cloud Lite in 1h:20m