I am happy to announce the newest version of the @m365security ebook! It contains multiple new chapters and significant updates in others.
The content covers both #MicrosoftDefender and #MicrosoftSentinel.
Foreword has been written by @rodtrent
https://t.co/gPfeVZcOjJ
Are you struggling to add the correct data into #MicrosoftSentinel? Check out my latest article on @Practical365, detailing some tips and tricks I use.
This is the first article of a small series, focusing on adding networking data into Sentinel.
@rucam365 I have two 27" 4K myself. It's easier for me to share screens and keep an overview.
As an IT guy working from home, I share my screen multiple times a day
[1/2] 📢 Our next in-person event of 2024, MC2MC Live: The Final Frontier, is taking place on Wednesday, April 17th.
We are thrilled to introduce our event line-up, featuring Jens Du Four, Hanna Engel, @thijslecomte, and @LouisMastelinck
🎟️ https://t.co/FUhud3lxGV
#MC2MC
Just released a new blog talking about a new CA feature which I have been waiting on for a long time. This allows us to better protect our administrator users against token theft and opens up new ways to secure critical applications.
https://t.co/ftnQU1jHXs
#entraid#ca
This weekend, I deep dived into the Microsoft hack to see how it happened and what we learned from it.
I linked it to the @ENowConsulting 's Application Governance, which provides insightful recommendations into some common misconfigurations
https://t.co/HqLIBXimI8
Has anyone else noticed in the Sentinel table AzureActivity that if a role is assigned to a resource using PIM the field here has a massive typo under the Target JSON field? I can't get this out of my head.
Excited to be speaking at @TeamsNation in February with @LouisMastelinck
We will be discussing a new type of Phishing using Microsoft Teams.
What it is, how to protect against it and how to detect it.
Join us in this free awesome event 👇
https://t.co/9FYqbxfb2b
💥App Registrations are highly privileged & often used by #threatactors for privilege escalation attacks in #EntraID
👉 Microsoft MVP @thijslecomte explains how you can protect your organization with the proper permissions in place for attack prevention: https://t.co/zDyNZKR22D
If you like in-depth articles, check out this one below!
It covers, in great detail, how an attack in a cloud environment looks like and how to detect it. Including initial access, persistence, reconnaissance and privilege escalation.
I wrote a blog post about how Entra ID Joined and Hybrid Joined devices can be used to move to #entraid and #cloudsolutions, how to detect it, and what preventive controls you can use.
📜https://t.co/BOn3abMu1c
#microsoftsecurity#hybridbrothers
As the year is coming to an end, I take some time to look back at what has happened.
A lot of new products (outside of E5)
A lot of copilot
And some detection/reliability issues
Looking forward to what 2024 brings!
With the announcement of #MicrosoftDefenderXDR, I wanted to share my thoughts on some of the current pain points in automation with #MicrosoftDefender and #MicrosoftSentinel in this blog 'My wishlist for automation within Microsoft Defender XDR'
https://t.co/Txrb064yDE