Loris Ambrozzo's Avatar

Loris Ambrozzo

@lorisambrozzo

Security Consultant @baseVISION Interested in anything related to cloud security and identity topics

76
Followers
186
Following
6
Posts
11.11.2024
Joined
Posts Following

Latest posts by Loris Ambrozzo @lorisambrozzo

Check out my blog post "Mastering (Orphan) API Connections in Microsoft Sentinel Playbooks" in which I demonstrate how to manage the API connections of your Microsoft Sentinel Playbooks and identify orphaned ones.

blog.ambrozzo.ch/posts/master...

#microsoftsentinel #LogicApps #IaC

29.12.2025 08:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Disabling a user account during a security incident removes them from all Microsoft Teams. Private channel membership is not automatically restored. This #KQL query lists all private channels the user was removed from.

github.com/lorisAmbrozz...

07.11.2025 10:06 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

While diving into Defender XDR Attack Disruption with x.com/nicolonsky, I noticed that the Enterprise App Microsoft Defender for Identity (formerly Radius Aad Syncer) is responsible for the response actions in Entra ID. The #KQL query lists these actions.

github.com/lorisAmbrozz...

17.04.2025 10:53 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

That's a simple one but could be quite useful also in combination with other #detections. πŸ’₯Since a few days, it's possible to use #KQL to detect when a global admin elevates access to manage all subscriptions and management groups.

github.com/lorisAmbrozz...

07.02.2025 06:45 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I was wondering the same thing this morning 😁 in one customer environment it is also available and in another tenant, there is still no MDCA available. Let's hope soon 🀞

11.12.2024 19:09 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Insight into the Azure instance metadata service from an attacker and defender perspective Insight into the Azure instance metadata service with analysis on a Windows server and detection in Microsoft Defender XDR

Check out my first blog post about "Insight on Azure Instance Metadata Service from an attacker and defender perspective" πŸ›‘οΈβš”οΈ!

lorisambrozzo.medium.com/insight-into...

#MicrosoftAzure #IMDS #MicrosoftSentinel #MicrosoftDefenderXDR

11.12.2024 06:45 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1