Christian Biehler's Avatar

Christian Biehler

@cssec

InfoSec Professional - Microsoft 365 & MS Windows Security guy - Speaker, Pentester, Training, Dad.

34
Followers
230
Following
15
Posts
08.12.2023
Joined
Posts Following

Latest posts by Christian Biehler @cssec

Preview
LOLBIN / LOLBAS โ€“ WinGet execute PowerShell script LOLBIN WinGet.exe can be exploited to download and execute remote and fileless PowerShell scripts.

www.zerosalarium.com/2024/12/LOLB...
Using WinGet as LOLBIN ...

26.01.2025 04:50 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
VS Code Extension Impersonating Zoom Targets Google Chrome Cookies Uncover a deceptive VS Code extension, masquerading as Zoom, that pilfers your Google Chrome cookies. Join us as we expose the techniques behind this alarming supply chain campaign.

Schadsoftware als VSCode-Extension - ๐Ÿค”
hunt.io/blog/malicio...

23.01.2025 06:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Microsoft 365 - Gerรคte-Compliance-Bypass - Angriffe auf Microsoft 365 รผber Gerรคtecompliance-Bypass sind ab jetzt der Standard. Intune-Portal sei dank, kรถnnen Angreifer CA umgehen!

Heared about TokenSmith to Bypass Azure CA compliance Checks?
Using join/registered-Device as Indicator seems not to be affected - [german] www.bi-sec.de/2024/12/28/m... - Update from january 11.

11.01.2025 15:34 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - f-bader/TokenTacticsV2: A fork of the great TokenTactics with support for CAE and token endpoint v2 A fork of the great TokenTactics with support for CAE and token endpoint v2 - f-bader/TokenTacticsV2

#TokenTactics V2 now has support for auth code flow, if you know what I mean. Other features in v0.2.5 are Invoke-RefreshToDeviceRegistrationToken and backwards compatibility for the v1 endpoint for those special cases. #Entra

04.01.2025 17:48 ๐Ÿ‘ 8 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

The link to the slides is missing a S in the HTTP part

i.blackhat.com/EU-24/Presen...

04.01.2025 19:21 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

I love that Apple is trying to do privacy-related services, but this just appeared at the bottom of my Settings screen over the holiday break when I wasnโ€™t paying attention. It sends data about my private photos to Apple.

29.12.2024 02:46 ๐Ÿ‘ 345 ๐Ÿ” 163 ๐Ÿ’ฌ 39 ๐Ÿ“Œ 26
Preview
Microsoft 365 - Gerรคte-Compliance-Bypass - < bi-sec > Angriffe auf Microsoft 365 รผber Gerรคtecompliance-Bypass sind ab jetzt der Standard. Intune-Portal sei dank, kรถnnen Angreifer CA umgehen!

Bypassing Device-Compliance in Microsoft 365 with the new Tool TokenSmith abusing Intune Portal App - [german] www.bi-sec.de/2024/12/28/m...

28.12.2024 15:06 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - aollivierre/ConditionalAccess: This repository contains a comprehensive set of Conditional Access (CA) policies and PowerShell management tools for Microsoft Entra ID (formerly Azure AD), des... This repository contains a comprehensive set of Conditional Access (CA) policies and PowerShell management tools for Microsoft Entra ID (formerly Azure AD), designed to enhance your organization&#3...

Looks promissing for Conditional Acceess ideas .. github.com/aollivierre/...

28.12.2024 05:54 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
A look into authentication: Passwordless and Passkeys A journey into the world of authentication, from passwords, hashes, credentials, protocols, MFA, through to passwordless

Anyone can explain how the passkey can be shared across devices if theyโ€˜re stored in TPM where they canโ€˜t be extracted?

geekwolf.cloud/2024/12/17/A...

28.12.2024 05:50 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Cybersecurity firm's Chrome extension hijacked to steal user data At least five Chrome extensions were compromised in a coordinated attack where a threat actorย injected code that steals sensitive information from users.

At least five Chrome extensions were compromised in a coordinated attack where a threat actorย injected code that steals sensitive information from users.

27.12.2024 10:39 ๐Ÿ‘ 10 ๐Ÿ” 5 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Preview
Microsoft 365 Security: Understanding Built-in Detection Mechanisms and Investigating Log Events As the landscape of cybersecurity threats evolves, protecting sensitive information stored within enterprise platforms like Microsoft 365โ€ฆ

Nice starting Point:
medium.com/@cyberengage...

25.12.2024 06:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Microsoft now allows connecting to Multi-tenant apps using Managed Identities Learn how to connect to other tenants using Managed Identity federation on your app registration in Microsoft Entra.

Another huge security improvementโšกMicrosoft now allows you to federate your app registrations with a Managed Identity, perfect for securely accessing resources in other tenants with multi-tenant apps! > ourcloudnetwork.com/microsoft-no...

23.12.2024 08:15 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Got the Same things happening december 12 in one customer tenant - great List by @merill.net - what would we do without those stuff โค๏ธ

14.12.2024 09:26 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - ricardojoserf/NativeBypassCredGuard: Bypass Credential Guard by patching WDigest.dll using only NTAPI functions Bypass Credential Guard by patching WDigest.dll using only NTAPI functions - ricardojoserf/NativeBypassCredGuard

github.com/ricardojoser...
Interesting Solution to get credentials on Windows.

10.12.2024 03:52 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Support tip: Windows device configuration policies migrating to unified settings platform in Intune | Microsoft Community Hub New unified settings for device configuration policies in Microsoft Intune!

โ€ผ๏ธImportant noticeโ€ผ๏ธ

Administrative templates will no longer be available in Intune. Settings in this template can be configured via settings catalog only. Expected with Intune's December (2412) release.

techcommunity.microsoft.com/blog/intunec...

#Intune #Microsoft

29.11.2024 07:10 ๐Ÿ‘ 7 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - roadwy/DefenderYara: Extracted Yara rules from Windows Defender mpavbase and mpasbase Extracted Yara rules from Windows Defender mpavbase and mpasbase - roadwy/DefenderYara

Yara rules from MS Defender .. interesting project - github.com/roadwy/Defen...

26.11.2024 05:23 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Conditional Access protections for Generative AI - Microsoft Entra ID Protecting Gen AI services like Microsoft Copilot for Security and Microsoft 365 Copilot with Conditional Access

Working with AI and Microsoft?

You can build CA policies to protect usage of AI by enforcing Phishing-resistant MFA or other things.

learn.microsoft.com/en-us/entra/...

21.11.2024 05:01 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Digital Defense - The ultimate personal security checklist to secure your digital life The ultimate personal security checklist to secure your digital life

First seen โ€ฆ for all โ€žhey โ€ฆ youโ€˜re in security .. how do I protect myโ€ฆโ€œ questions.

digital-defense.io

21.11.2024 04:53 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Unlock Proactive Defense: Microsoft Security Exposure Management Now Generally Available | Microsoft Community Hub As the digital landscape grows increasingly interconnected, defenders face a critical challenge: the data and insights from various security tools are often...

Busy with too many vulnerabilites?
Microsofts answer to XMCyber is there: techcommunity.microsoft.com/blog/microso...
Surprisingly included in most licences without additional cost - worth a look.

21.11.2024 04:35 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

How shall we do detection engineering with that? TimeGenerated and CreateDateTime more than 1 Hour apart
It was our test tenant during ohne of our public trainings... but I could not explain
#microsoft #m365 #security

20.11.2024 05:37 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Windows security book introduction Windows security book introduction

Just came across the updated #Windows 11 Security Book - learn.microsoft.com/en-us/window...
Still good graphical overview of security features.

20.11.2024 04:56 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0