www.zerosalarium.com/2024/12/LOLB...
Using WinGet as LOLBIN ...
www.zerosalarium.com/2024/12/LOLB...
Using WinGet as LOLBIN ...
Schadsoftware als VSCode-Extension - ๐ค
hunt.io/blog/malicio...
Heared about TokenSmith to Bypass Azure CA compliance Checks?
Using join/registered-Device as Indicator seems not to be affected - [german] www.bi-sec.de/2024/12/28/m... - Update from january 11.
#TokenTactics V2 now has support for auth code flow, if you know what I mean. Other features in v0.2.5 are Invoke-RefreshToDeviceRegistrationToken and backwards compatibility for the v1 endpoint for those special cases. #Entra
The link to the slides is missing a S in the HTTP part
i.blackhat.com/EU-24/Presen...
I love that Apple is trying to do privacy-related services, but this just appeared at the bottom of my Settings screen over the holiday break when I wasnโt paying attention. It sends data about my private photos to Apple.
Bypassing Device-Compliance in Microsoft 365 with the new Tool TokenSmith abusing Intune Portal App - [german] www.bi-sec.de/2024/12/28/m...
Looks promissing for Conditional Acceess ideas .. github.com/aollivierre/...
Anyone can explain how the passkey can be shared across devices if theyโre stored in TPM where they canโt be extracted?
geekwolf.cloud/2024/12/17/A...
At least five Chrome extensions were compromised in a coordinated attack where a threat actorย injected code that steals sensitive information from users.
Another huge security improvementโกMicrosoft now allows you to federate your app registrations with a Managed Identity, perfect for securely accessing resources in other tenants with multi-tenant apps! > ourcloudnetwork.com/microsoft-no...
Got the Same things happening december 12 in one customer tenant - great List by @merill.net - what would we do without those stuff โค๏ธ
github.com/ricardojoser...
Interesting Solution to get credentials on Windows.
โผ๏ธImportant noticeโผ๏ธ
Administrative templates will no longer be available in Intune. Settings in this template can be configured via settings catalog only. Expected with Intune's December (2412) release.
techcommunity.microsoft.com/blog/intunec...
#Intune #Microsoft
Yara rules from MS Defender .. interesting project - github.com/roadwy/Defen...
Working with AI and Microsoft?
You can build CA policies to protect usage of AI by enforcing Phishing-resistant MFA or other things.
learn.microsoft.com/en-us/entra/...
First seen โฆ for all โhey โฆ youโre in security .. how do I protect myโฆโ questions.
digital-defense.io
Busy with too many vulnerabilites?
Microsofts answer to XMCyber is there: techcommunity.microsoft.com/blog/microso...
Surprisingly included in most licences without additional cost - worth a look.
How shall we do detection engineering with that? TimeGenerated and CreateDateTime more than 1 Hour apart
It was our test tenant during ohne of our public trainings... but I could not explain
#microsoft #m365 #security
Just came across the updated #Windows 11 Security Book - learn.microsoft.com/en-us/window...
Still good graphical overview of security features.