Conditional Access Policies in Microsoft Entra ID are super important because they allow granular control of who can access what and under what conditions.
But those policies need to be properly configured and tested. And I almost always see gaps in coverage of conditional access policies.
I put together a list of conditional access policies that I recommend. Feel free to share/like if you like it or comment if you have questions and comments 👇👇
https://t.co/zwpfBpOwrO
#cybersecurity #tips #conditionalaccess #entraid #cap
So your Microsoft 365 tenant has been compromised by a malicious app!
Here's a step by step guide to block access to the app and remove it from your tenant -Bkmk this!
1️⃣ Go to Microsoft Entra → Enterprise Apps
2️⃣ Select the compromised app
3️⃣ Permissions → Review Permissions
📃 How attackers can add a secondary token-signing certificate to an #EntraID federated authentication configuration for stealthier persistence & privesc 🙈
https://t.co/dugP4BTwlo
Have you heard about the "nextSigningCertificate"? 😉
Re: Midnight Blizzard breach of Microsoft, this bears repeating:
The AppRoleAssignment.ReadWrite.All MS Graph app role BYPASSES the consent process. This is BY DESIGN. This app role is EXTRAORDINARILY dangerous.
Read more in @sahilmalik's blog post: https://t.co/hiDR57QUzR
First, I want to compliment @Microsoft for being forthright with details. Some of the problems I see in this report, I SEE EVERYWHERE due to VULNERABLE DEFAULTS.
Let's start with creating malicious OAuth applications. By default, ANY USER can create app registrations and consent to Graph permissions as well as sharing 3rd party company data. In tenants where this is hardened, ability to create app registrations require Application Administrator or Cloud-Application Administrator and admins must consent to permissions used by the application whether local or from another tenant.
How to disable some parts of EDR’s telemetry on Windows 10? Just ask nicely!
See https://t.co/Vxio1trFh4 for more info about an interesting logic bug we found on Win10 that affects all EDRs 😉
The Art Of Hiding In Windows: techniques used by malicious actors to obscure their activities, making detection and analysis significantly more challenging for security professionals.
Article: https://t.co/qKPQhSufA6
EBook: https://t.co/emftpjjHJ7
#windows#redteam
Some really great sites you should bookmark
https://t.co/3EEngO4DJt (just released)
https://t.co/Wm9fP9YX1d
https://t.co/NCfZfD0feh
https://t.co/u8ZvkcjkU7
https://t.co/eH52vHPH7b
https://t.co/wBpyhvZfhg
Are you responsible for Azure AD in your org?
We just published a new doc (https://t.co/1CZteJJWyl) that lists all the upcoming changes in one place.
PS. This page will be updated quarterly in line with our change announcements in Mar, Jun, Sep, and Dec.
1\ #DFIR: Detecting malicious device code phishing in M365 😈
This technique is HARDER to detect than OAuth abuse:
> No app registration needed
> Bypasses all MFA (token auth)
> No URL redirect
Not much has been written about detection so ..😝👇
https://t.co/1jIRBal0Gk
Here we go, we are finally releasing all the materials of our workshop at @defcon and our talk at @BSidesLV on “CI/CD : The new Eldorado” 🔥🔥🔥
With this content, you will go through… 🧵
https://t.co/V6gJg6IiG9
ADeleg. Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest, along with their potential issues
https://t.co/sbqcK2mPHW
OMI is back! @msftsecresponse published CVE-2022-29149, a new LPE vulnerability in OMI, the Azure agent that was vulnerable to #OMIGOD. Seems like manual update of the silently installed agent is required again in most cases
https://t.co/Ga4hETg6i2
The Illustrated QUIC Connection - Every byte explained and reproduced (QUIC is a secure UDP-based stream protocol that forms basis of HTTP/3) : https://t.co/lrPN7aNsd2
The Illustrated TLS 1.3 Connection - Every byte explained : https://t.co/jD4flPnYcu credits : @xargsnotbombs
Did you know that Dirty Pipe could also be used to escape unprivileged containers and gain root access on a Kubernetes host?
📖 Write-up: https://t.co/DCGmbI14xP
👀 Proof of concept: https://t.co/YORJIr4HfT
A thread on how it's done. 🧵⬇️
Who has privileges to get full permissions or modify RBAC of #Azure subscriptions? Assigned owners in #AzureRBAC & Elevated #AzureAD GA only? Large organizations are mostly using #EnterpriseAgreement (EA) as billing option. Let’s talk about privileged access paths in EA... (1/4)
Oh yeah 🤘 DACL read/write/backup/restore tooling in Impacket Python. Example screenshot with DCSync, but WriteMembers, ResetPassword and FullControl also possible
🔧 PR: https://t.co/nQGZy1dnbR
🧑🍳 The Hacker Recipes: https://t.co/3HRH8p730i
Co-authored by @BlWasp_
[HackTip ⚒] (1/2) Recently during a pentest I've encountered a GitLab instance with Azure-based authentication. Later admin's access token was found in a Python script. Having a compromised low-privileged GitLab account you can grant it 'admin=true' with a single API request.