Yassine El's Avatar

Yassine El

@yassine-e

#PowerShell #Security #DevSecOps

49
Followers
177
Following
10
Posts
16.01.2024
Joined
Posts Following

Latest posts by Yassine El @yassine-e

Post image

Get ready, folks. 🌟

You’re about to witness ONE. BIG. BEAUTIFUL. ABSURDLY. EPIC. THREAD. 🧡πŸ”₯

Some say this might be the MOST EPIC and MOST RIDICULOUSLY LONG identity thread ever written

πŸ“— Bookmark this

Honestly… the cover image alone deserves a like + retweet

DO IT πŸ˜‚

19.11.2025 15:20 πŸ‘ 14 πŸ” 7 πŸ’¬ 1 πŸ“Œ 0
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...

17.09.2025 13:20 πŸ‘ 87 πŸ” 37 πŸ’¬ 9 πŸ“Œ 5
Preview
Improving passkey registration experiences Lets see what we can do about minimizing passkey deployment issues with Compliance and App Protection Policy requirements :)

I love passkeys in Microsoft Authenticator, but rolling them out with Compliance and/or App Protection Policies has not been as easy as it should be...

But I have good news - we can create a better experience without introducing significant gaps :)

10.09.2025 02:50 πŸ‘ 13 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Post image

Folks, bookmark this πŸ‘‡

Did you know I curate a list of all the awesome Entra related links all in one place?

Here's a quick peak into this list

06.08.2025 00:38 πŸ‘ 11 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0

The NIH’s 2024 budget of just under $37B generated $95B in economic activity in 2024 alone. 99.4% of new pharmaceuticals approved from 2010-2019 came from NIH-funded research. I’m hard pressed to think of anything that generates as much direct economic benefit as our NIH did before they destroyed it

27.07.2025 22:49 πŸ‘ 2600 πŸ” 952 πŸ’¬ 81 πŸ“Œ 25
Preview
Merill Fernando :verified: :donor: (@merill@infosec.exchange) Attached: 1 image Microsoft just dropped a banger spreadsheet to help you level up your security! πŸš€ It's a FREE Zero Trust assessment tool with a clear roadmap covering SIX key pillars. Let's break it down! πŸ‘‡ πŸ‘₯ Identity πŸ“± Devices πŸ“Š Data 🌐 Network πŸ—οΈ Infrastructure πŸ•΅οΈβ€β™€οΈ Security Operations

This looks like an awesome free tool from Microsoft to help guide an organization through a zero trust assessment, and to help keep track of your progress. #cybersecurity

From: @merill
https://infosec.exchange/@merill/114828836541804825

10.07.2025 12:58 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸ”₯ OBAMA: β€œIMAGINE IF I HAD DONE ANY OF THIS… I say this not on a partisan basis. This has to do with something more precious β€” who are we as a country, and what values do we stand for?” πŸ‡ΊπŸ‡Έ

04.04.2025 23:55 πŸ‘ 30269 πŸ” 9628 πŸ’¬ 802 πŸ“Œ 792
Post image

Threat hunters rejoice! This is HUUUGE news πŸ‘

Microsoft just introduced linkable identifiers in Microsoft Entra ID logs.

The bad guys πŸ₯· are going to hate this so much πŸ˜‚

Learn more at learn.microsoft.com/...

Share the good news πŸ‘

01.04.2025 03:55 πŸ‘ 59 πŸ” 19 πŸ’¬ 4 πŸ“Œ 2
Preview
β€˜It’s a Heist’: Real Federal Auditors Are Horrified by DOGE WIRED talked to actual federal auditors about how government auditing worksβ€”and how DOGE is doing the opposite.

"18F was explicitly designed to serve as an in-house consultancy that would allow federal agencies to leverage private-sector expertise. As part of DOGE’s sweep, however, it has gutted the group, putting a pause on several ongoing projects to make government services more efficient for users."

24.03.2025 04:11 πŸ‘ 575 πŸ” 130 πŸ’¬ 6 πŸ“Œ 7
β€œAnd isn’t being happy the ultimate land annexation?”

Jessica Moschini, Garlic Mincer

β€œAnd isn’t being happy the ultimate land annexation?” Jessica Moschini, Garlic Mincer

Israel Ranked 8th Happiest Country
theonion.com/israel-...

21.03.2025 23:00 πŸ‘ 1517 πŸ” 93 πŸ’¬ 27 πŸ“Œ 4
Preview
DEI Scholarship Program - O'Reilly Media To help members of groups underrepresented in technology develop and sharpen the skills needed to break through barriers within the field, we're offering 500 annual scholarships giving recipients full...

Folks, if you're in IT and don't fit the classic stereotype of white, middle-class guy, you might be eligible for a year's access to the O'Reilly learning platform for free (highly recommended - I use it all the time to dive into tech books). Apply here:

www.oreilly.com/diversity/sc...

19.03.2025 14:11 πŸ‘ 32 πŸ” 23 πŸ’¬ 0 πŸ“Œ 0

As the Gaza body count increases, I wonder how all these supposed 'leftists' & self-styled 'contrarians' who berated me for not applauding Trump for bringing about a 'ceasefire' and 'peace' feel today.

Like fools, I hope.

Because they are indeed fools: they believed Trump.

18.03.2025 19:51 πŸ‘ 3738 πŸ” 509 πŸ’¬ 140 πŸ“Œ 31
Post image

I know the What-If API has been here for a while, but I haven't seen it documented yet.

Anyway, in case it's helpful to anyone, you can do What-If analysis via API ;)

Invoke-MgGraphRequest -Method POST -Uri '/beta/identity/conditionalAccess/analyze' -Body $body

14.03.2025 01:11 πŸ‘ 7 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Level Up Your App Governance With MDA Workshop Series | Microsoft Community Hub Over the past two years, there has been a significant increase in nation-state attacks leveraging OAuth apps. These attacks often serve as entry points for...

Level Up Your App Governance With MDA Workshop Series techcommunity.micros...

#MicrosoftDefender #DefenderforCloud #Security #MicrosoftSecurity #Cybersecurity #DefenderXDR #MicrosoftThreatIntelligence

13.03.2025 17:30 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Screenshot of beta.weather.gov with an announcement info box saying "beta.weather.gov has been deactivated until further notice." The message continues by mentioning "This page has been deactivated...due to the loss of critical federal staff, which leaves the project without the resources required to continue its development or for routine monitoring and maintenance."

Screenshot of beta.weather.gov with an announcement info box saying "beta.weather.gov has been deactivated until further notice." The message continues by mentioning "This page has been deactivated...due to the loss of critical federal staff, which leaves the project without the resources required to continue its development or for routine monitoring and maintenance."

This is what happens when 18F goes away: beta.weather.gov has been deactivated, β€œdue to the loss of critical federal staff, which leaves this project without the resources to continue its development or for routine monitoring and maintenance.”
18f.org/projects/#:~...

13.03.2025 22:19 πŸ‘ 429 πŸ” 114 πŸ’¬ 8 πŸ“Œ 9

SANS Daily StormCast
SANS Blueprint
Risky Biz
Blue Security
Defense in Depth
Microsoft Threat Intelligence
Security Now

12.03.2025 02:49 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Podcasts, LinkedIn and Reddit

11.03.2025 13:30 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

There it is: Speaker of the House says Elon has already started running your Social Security through his AI.

02.03.2025 17:59 πŸ‘ 7495 πŸ” 2886 πŸ’¬ 600 πŸ“Œ 220

Seems like the is with the Akamai CDN

02.03.2025 17:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
We're not done yet | 18F

18F was doing exactly the type of work that DOGE claims to want – yet we were eliminated shortly after midnight. Read our letter to the American people:
18f.org

01.03.2025 23:38 πŸ‘ 18833 πŸ” 6846 πŸ’¬ 697 πŸ“Œ 446

Just checked and it loaded fine

02.03.2025 16:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

The derogatory term β€œrubio” now has three meanings in American slang:

1) A spineless lump of nothing
2) The piece of shit you scrape off the bottom of your shoe
3) A person with no scruples or sense of morality

Example: β€œDon’t be such a fucking rubio β€” just think of what your mother would say.”

01.03.2025 05:10 πŸ‘ 3627 πŸ” 940 πŸ’¬ 234 πŸ“Œ 64

PLEASE RP: Windows Server 2025 Delegated Managed Service Accounts

Delegated Managed Service Accounts (dMSA) are a new type of managed service account introduced in Windows Server 2025. They offer several advantages over traditional service accounts and Group Managed Service Accounts (gMSA).

27.02.2025 18:06 πŸ‘ 4 πŸ” 5 πŸ’¬ 1 πŸ“Œ 0
Post image

The world’s richest man appears to be dismantling the government with an eye toward consolidating power and punishing his political enemies, Charlie Warzel writes. Will it work? theatln.tc/zoCxaorI

08.02.2025 19:35 πŸ‘ 2440 πŸ” 704 πŸ’¬ 110 πŸ“Œ 26
Preview
Top 3 Priorities for Proactive Identity and Access Security in 2025 | Microsoft Community Hub In 2024, we faced some serious security challenges. We dealt with widespread cybersecurity issues like major breaches, outages, and persistent threat...

⚑ Check out this new Microsoft Entra blog post πŸ‘‡

Top 3 Priorities for Proactive Identity and Access Security in 2025

28.01.2025 17:04 πŸ‘ 13 πŸ” 3 πŸ’¬ 1 πŸ“Œ 1