ryan mc

86 posts

ryan mc banner
ryan mc

ryan mc

@detectdotdev

Rhode Island, USA शामिल हुए Temmuz 2022
112 फ़ॉलोइंग234 फ़ॉलोवर्स
ryan mc रीट्वीट किया
Ian Hellen
Ian Hellen@ianhellen·
Long-awaited parallel (threaded) queries arrive in MSTICPy! 🏃‍♀️🏃‍♀️🏃‍♀️ Split big queries into separately executing chunks or across multiple workspaces and clusters.
msticpy@msticpy

MSTICPy 2.6.0 released - Parallel queries for multiple instances of MS Sentinel workspaces and Kusto clusters - Parallel split queries (large time-range queries divided by smaller time periods) - Velociraptor data provider for querying exported data sets github.com/microsoft/msti…

English
0
4
12
1.6K
ryan mc रीट्वीट किया
Fabian Bader
Fabian Bader@fabian_bader·
🚨Small update for TokenTacticsV2 ▫️Two new device platforms ▫️Linux, since it's now supported by Conditional Access ▫️OS/2, because it's not 😁 github.com/f-bader/TokenT…
English
3
24
62
10.1K
ryan mc
ryan mc@detectdotdev·
@svrooij @janbakker_ @DrAzureAD MS indicated that they would release conditional access policies that restrict the issuance of family refresh tokens. I don’t believe that ever came into fruition.
English
0
0
3
20
ryan mc रीट्वीट किया
Clément Notin
Clément Notin@cnotin·
Official confirmation from Microsoft that there is no supported way to rotate nor change DPAPI backup keys! Compromised keys? ➡️ Burn the domain and rebuild a new one 💥
English
7
88
259
70.1K
ryan mc रीट्वीट किया
Katie Nickels
Katie Nickels@likethecoins·
I know a lot of excellent people are looking for jobs right now. We have several openings at @redcanary, including my peer, Senior Director of Detection Engineering, and a Threat Hunter on a team I lead. I hope you'll consider applying or sharing. redcanary.com/job-openings/
Katie Nickels tweet media
English
7
141
308
66.1K
ryan mc रीट्वीट किया
Dirk-jan
Dirk-jan@_dirkjan·
Small update to roadtx, with thanks to @Flangvik for the idea: you can now do the interactive authentication with a "borrowed" ESTSAUTHPERSISTENT cookie from a browser, to get tokens or have an authenticated browser session.
Dirk-jan tweet media
English
7
64
208
36.5K
ryan mc रीट्वीट किया
nyxgeek
nyxgeek@nyxgeek·
New blog is out! OneDrive to Enum Them All trustedsec.com/blog/onedrive-… Major updates: • database storage • logging of previous runs • easily append digits or strings to usernames • stale job detection • skip tried usernames Special thanks to @DrAzureAD and @thetechr0mancer!
English
3
125
262
42.2K
ryan mc रीट्वीट किया
Joosua Santasalo
Joosua Santasalo@SantasaloJoosua·
@DrAzureAD brings some valid points. MemberLevel user can read CA Policies. This has not always been understood, since the GUI and MS Graph requires roles for this, but not Azure AD Graph API. Also means, that if you have gaps in CA, those can be read by normal user
Dr. Nestori Syynimaa@DrAzureAD

@Secureworks' latest Threat Analysis report "Tampering with Conditional Access Policies Using Azure AD Graph API" out now! 1️⃣ Regular users can read Conditional Access Policies (CAPs) 🤔 2️⃣ Administrators can modify CAPs without proper logging 😲 secureworks.com/research/tampe… #IWorkForSecureworks

English
1
4
10
1.5K
ryan mc रीट्वीट किया
Dr. Nestori Syynimaa
Dr. Nestori Syynimaa@DrAzureAD·
@Secureworks' latest Threat Analysis report "Tampering with Conditional Access Policies Using Azure AD Graph API" out now! 1️⃣ Regular users can read Conditional Access Policies (CAPs) 🤔 2️⃣ Administrators can modify CAPs without proper logging 😲 secureworks.com/research/tampe… #IWorkForSecureworks
Dr. Nestori Syynimaa tweet media
English
1
29
76
8K
ryan mc रीट्वीट किया
Matt Hand
Matt Hand@matterpreter·
I've long been interested in how EDRs work under the hood and how we can apply a more evidence-based approach to evasion. I'm happy to announce that I've written a book covering these topics with @nostarch which is now available for preorder 🎉 nostarch.com/book-edr
English
45
331
1.1K
154K
ryan mc रीट्वीट किया
Dr. Nestori Syynimaa
Dr. Nestori Syynimaa@DrAzureAD·
I'll deliver a workshop, "Tokens, everywhere!" at @NorthSec_io, Montreal 🇨🇦 in May! In this hands-on deep-dive, I'll cover #AzureAD #OAuth implementation, different token types, #FOCI, and various attack scenarios. Check out details and get tickets at nsec.io
Dr. Nestori Syynimaa tweet media
English
1
4
20
3.7K