New script in the block: Get-LogonCount.ps1.
Count AD account(s) logons from all domain controllers (RWDC + RODC), for users and/or computers, all or specific accounts. Optional switch to also show LastLogon date in the entire domain.
https://t.co/6LxQszj3Mb
Mistakes happen. As a team, the important thing is to recognize it’s never an individuals’s fault — it’s the process, the culture, or the infra.
In this case, there was a manual deploy step that should have been better automated. Our team has made a few improvements to the automation for next time, a couple more on the way.
🔦Speaker Intro: @Yossi_Sassi
Security researcher & seasoned hacker bringing real-world insights to the stage.
🎤 Hacking & Defense Tips that A.I will Not Teach You
/Practical lessons beyond the hype/
#BSidesBUD2026#CyberSecurity
In addition to looking for SPNs on sid500, looking for it in services, scheduled tasks, appPools etc., quickest way to know it's being used as svc/batch is this checking for logonCount - sid500 w/tens of thousands - noo good. Can use this script: https://t.co/6LxQszj3Mb
@techspence True. In addition to looking for SPNs on sid500, looking for it in services, scheduled tasks, appPools etc., quickest way to know it's being used as svc/batch is this checking for logonCount - sid500 w/tens of thousands - noo good. Can uss this script: https://t.co/6LxQszj3Mb
Feels great to share knowledge, insights & New open-source tool(s) @ Nordics' veteran community-driven CyberSec Conference @hackcon 26'! Securely navigating #AI & #AISecurity with #PowerShell.
Takk for the opportunity, as always!
Slides & tools -> https://t.co/xzV7PxtYda
Private commit thread with ReadWriteExecute? sounds bad. Just shared new detection script - inspect a process, flag privately committed RWX regions; show hex+ASCII; Pop balloon tip notification on suspicious thread. default flag MZ (4d 5a), can modify oc.
https://t.co/TOOMJb0jo7
Happy to share our latest #BlueTeam tool: 𝐏𝐨𝐰𝐞𝐫𝐆𝐮𝐚𝐫𝐝 𝐂𝐥𝐨𝐮𝐝 🛡️! a layer independent of EDR, "invisible" monitoring for EntraID-joined devices moving PowerShell transcripts to Azure w/Telemetry, detection logic, webhook alerts to Teams & more!
https://t.co/TdDYPBo2iq
As a Security / 98% AI YOLO Maximalist with Guardrails guy, I'm asking you to please listen to this.
Here are some of the top security issues with https://t.co/yCq4RmE7lB that you all should be avoiding.
Don't avoid the project. It's great. But please be safe with it!
Stop guessing if a user clicked a link!
UrlThreatScanner automates the "User Browse Trace" workflow -
Dumps local browser history (NirSoft engine)
Checks URLs against active malware feeds
Reports hits in seconds
Open Source & ready for IR: https://t.co/aYKkBR016i
#InfoSec#DFIR
📷 New PowerShell Tool for the CrowdStrike Community
I’m excited to introduce a PowerShell script I developed at #10root Cyber Security that enables #CrowdStrike Identity Protection users to export all policy rules for faster audits
https://t.co/tWmI2Y5r5g