Defender AV's ASR rules really are fantastic, great way to break attacker tools while still allowing your apps to work
I need to update my blog, but the core is there - KQL queries to help build your allow lists and get it done
https://t.co/Di1lfwkrWD
Some lessons learned 🧵
I've collated 2400+ Microsoft architecture icons and published them for easy access at https://t.co/C1Zv6sIkzn 💙
For every icon, you can:
• Download the scalable SVG file
• Download the PNG of your desired size
• Embed the icon directly into your website or markdown
• Choose a light, dark or transparent background
You can can even compare different icons together and favourite multiple icons for bulk download!
#Microsoft
Hey Microsoft Defender admins! Do you use Disable Local Admin Merge?
If not, you really should, and I just published an article to help you use Intune to collect all of the adhoc exclusions in your environment :)
Helpful for IR and security teams as well
https://t.co/pVbcCWdlM1
Entra App Proxy continues to be one of the biggest hidden gems of Entra P1
For over a decade, we've been able to stop exposing risky apps to the Internet by routing through agents with outbound connections to Azure
I don't care what vendor you use, just get it off the Internet
If you do anything with Defender Antivirus / MDE, you should definitely read this to understand what is coming :)
This will solve a bunch of problems ranging from policy conflicts (GPO vs Intune), local policy changes by admins or attackers, and more
Me explaining the Active Directory tiering model to a group of sys admins after finding them using their domain admin accounts to troubleshoot end user laptop issues
Microsoft 365 security isn’t just about enabling the right protections - it’s also about disabling the wrong defaults.
Here are 25 settings admins should disable or review👇
https://t.co/qmWgg4iPCj
#Microsoft365#Security#AdminDroid
Whether this is true or not, it’s no longer funny.
First, these attacks on Nigerian institutions only confirm what I told my colleagues in the banking industry three years ago: the only reason many security engineers here sleep well is because serious threat actor groups haven’t focused on us yet.
The moment they do, a lot of people will lose their jobs, and it will be because institutions chose politics, nepotism, and rushed product launches over doing security properly.
Secondly, who exactly are Nullsec Nigeria?
If you’re one of these actors treating real applications like CTF playgrounds or exploiting them for profit on the dark web instead of responsibly disclosing, or better yet, leaving them alone, and you think you’ll get away with it because accountability is messed up in this country or because you’re hiding behind VPNs, proxychains, or whatever tools you trust, think again.
The second Nigerian law enforcement decides to collaborate with foreign intelligence agencies, all that perceived anonymity disappears. And when that happens, it won’t be a game anymore.
Prison is not something you play with.
A word is enough, even for a fool.