XPGoD

1.1K posts

XPGoD

XPGoD

@XPGoD

About the only IT Guy you know that actually can do it.

Behind you 参加日 Ocak 2009
184 フォロー中62 フォロワー
Lina
Lina@d0rkph0enix·
Spent my Saturday with a few hundred of my fellow security pals, learning, soldering stuff and things, CTFing, broadcasting analog Hackers, the usual. Another @_BSidesKC in the books!
English
1
1
69
1.7K
XPGoD
XPGoD@XPGoD·
@M_haggis Although you weren’t as chatty as Mauricio Valezco or Bhavin Patel, it was wonderful meeting you all years ago. The content will always be fantastic, and I wish you a wonderful period of relaxation before we hear from you again.
English
0
0
1
67
The Haag™
The Haag™@M_haggis·
After 5.5 years, today is my last day at Splunk. It's been the best run of my career. Shipped a ton of security content, wrote blogs, built tools, and got to help defenders all over the world operationalize the work fast. Huge thanks to the threat research crew. Sharpest, most generous people I've ever worked with. You made me better every day. Taking some time now to breathe, think, and see what's on the horizon.
GIF
English
6
3
109
4.5K
EZ
EZ@IAMERICAbooted·
Haha nice!! The Activity Logs in production environments have all sorts or neat stuff in there to uncover first party services fun facts. I know thats a heavy topic of your research. That, and the UAL for SharePoint. They have undocumented crawlers in there . One that annoys the most is app@sharepoint. It creates so much noise lololol
English
1
0
4
712
XPGoD
XPGoD@XPGoD·
@AFP I thought they were supposed to captured 33 people
English
0
0
1
2.8K
AFP News Agency
AFP News Agency@AFP·
Twenty-two people are to stand trial in France from Monday on charges of murder and other serious crimes centred on a Masonic lodge accused of running hit squads u.afp.com/SbNE
AFP News Agency tweet media
English
353
3.6K
11.1K
4.7M
XPGoD
XPGoD@XPGoD·
@IAMERICAbooted Yeah and it’s mostly in my view those CSPM vendors. I did a hefty PoC on around 7 and just the registration of those were super sketchy. This is akin to “yeah the app needs administrator to work” when the real answer is they don’t quite know what the perms are really.
English
1
0
1
266
EZ
EZ@IAMERICAbooted·
Do you know why Entra App Registrations are such a topic for security? Because there's no good way to secure the secret or cert+key, yet so many vendors require them, internal apps using the M365 APIs require them, and they end up exposed everywhere. Moreover, to this day, I've yet to meet one org that understands the dangers associated with the APIs.
English
6
9
70
4.6K
Lina
Lina@d0rkph0enix·
@XPGoD OH GOD, IT’S SO GOOD
English
1
0
7
196
Lina
Lina@d0rkph0enix·
Ok, fam. I need your mayhem. 😂 I am in Minneapolis for work. The work, tomorrow, is a Segmentation Panel for a Customer Event; I am on said panel. I'm having dinner with another member of the panel, and we have agreed that we are both tired of using the house analogy
English
9
2
51
4.9K
XPGoD
XPGoD@XPGoD·
@kindnessuae @segoslavia Be careful. Tanium and other toys and tools will just utterly kill ingestion if you get charged by it. Or silence those that should be doing what they need to
English
0
0
0
44
Jawad Al Hashmi
Jawad Al Hashmi@kindnessuae·
@segoslavia Script Block Logging fills that gap. Event ID 4104 captures deobfuscated commands that Sysmon simply cannot see.
English
1
0
0
70
Ṣẹ́gunfúnmi😎
Ṣẹ́gunfúnmi😎@segoslavia·
Technical question for SOC Analysts: How do you track and review Powershell logs/history when investigating an incident? Note that Sysmon doesn't collect all logs for Powershell.
English
3
4
24
1.8K
EZ
EZ@IAMERICAbooted·
Happy almost Monday to all you poor blokes who have 10k Agents enabled in your tenant registry and have no idea what they're doing in your environment :p
GIF
English
3
0
18
769
XPGoD
XPGoD@XPGoD·
When I left I was still some kind of Break the Glass Lite bullshit. Thankfully they didn’t call me when the Okta/Entra cert expired on a Sunday…. Their sheer luck was a user who had an active session that saved that ass. Thank god I am not there. They have no idea what Lifecycles, Management, or Requirements are at the basic level
English
0
0
3
104
EZ
EZ@IAMERICAbooted·
@XPGoD Omfg lololololol. I'm so sorry you had to live through that
English
1
0
2
388
EZ
EZ@IAMERICAbooted·
At my previous org, I was a Global admin and IdP super admin (and many more admins with the entire security stack). At my last org, what did global admin mean? All of M365 and Power Platform. All of it. Exchange, SharePoint, Teams, Entra, Intune, Purview, Security Center, Apps Admin Center, Admin Center, power Platform Admin, Power BI Admin, everything. Yes everything. That was Global Admin.
English
5
0
20
3.8K
XPGoD
XPGoD@XPGoD·
@imog @0xMatt This is accurate. Even salesforce DKIMs the “sandbox” emails (thank god) as they did not do this for quite a while. So if you’re not setup on that… do it!
English
0
0
0
21
imog
imog@imog·
@0xMatt What is the solution to this scenario? CEO was getting spoofing to our clients, strong DKIM/DMARC/SPF fixed it. But we do have salesforce in there. So not a current problem for us, but if it becomes one I don't have a plan yet.
English
5
0
0
1.7K
Matt Linton
Matt Linton@0xMatt·
Confused that you have strong DKIM/DMARC rules & configured SPF, yet people are still spoofing your CEO's mail in fraud attempts? This may be because you included Salesforce, Mailchimp, or other SaaS in your SPF. Abusers can use free/fraudulent accounts there to spam "as" you.
English
14
33
399
32.8K
XPGoD
XPGoD@XPGoD·
@NickBenderKMBC When I was a kid. You always waited for the St. Patty storm from the Alberta Clipper in UP of Michigan to determine: yes spring is here
English
0
0
1
176
Nick Bender
Nick Bender@NickBenderKMBC·
❄️Snow chances are trending higher from late Sunday afternoon through Sunday night. While the chance of at least 1 inch of snow may seem low (20% to 40%), some weather models are forecasting much higher amounts. There are still many uncertainties, but one thing is certain: northerly winds Sunday evening and night could gust as high as 55 mph—near severe thunderstorm strength. Any snow falling during this time would have significant impacts. March has been known to produce some blockbuster snowstorms and blizzards, and we aren’t there yet, but this is something to pay close attention to.
Nick Bender tweet media
English
6
14
91
12.2K
XPGoD
XPGoD@XPGoD·
@XPlaneOfficial @justinryanio Did he leave? I haven’t seen him in a minute. He has a black topped rarri… I hope nothing bad happened :(
English
0
0
0
12
Justin Ryan ᯅ
Justin Ryan ᯅ@justinryanio·
Here’s a first look at X-Plane 12 on Apple Vision Pro! With visionOS 26.4 and NVIDIA CloudXR 6.0, the simulator streams wirelessly at up to 4K/120fps to your headset. And if you have a physical yoke or throttle, ARKit uses image detection to recognize them and place them inside your virtual cockpit. 🤯 It’ll be available later this spring.
English
123
233
3.9K
719.4K
Nick Vasos
Nick Vasos@NickVasos·
Lees Summit, MO - storm 17 mi away.
English
2
0
14
1.3K
XPGoD
XPGoD@XPGoD·
@ben_williams_wx I think right at sunset you will see a discrete cell in Cass/Jackson
English
0
0
0
89
Ben Williams
Ben Williams@ben_williams_wx·
Watching this sleeper target near KC later today. Good heating/cape, 3000 ML cape at sundown, profiles favor photogenic supercells/tors, the problem may be storm mode, as bulk shear is mostly parallel to the front, but there is a window for discrete storms or a lead sup…
Ben Williams tweet mediaBen Williams tweet mediaBen Williams tweet media
English
4
10
76
5.6K
XPGoD
XPGoD@XPGoD·
@JacobLanierWx @fox4kc Maybe it should conditionally be a separate watch. Not fill the void like nobody looks. The OK watch is 50/40% but KC is 60/40? There is an actual tornado now.. idk maybe the new CIG stuff generated confusion.
English
1
0
0
317
Jacob Lanier
Jacob Lanier@JacobLanierWx·
@XPGoD @fox4kc FWIW the tornado risk around KC stays low in my opinion. The higher tornado probabilities are up in Iowa which is also included in this same watch.
English
1
0
3
508
Jacob Lanier
Jacob Lanier@JacobLanierWx·
⚠️ The entire Kansas City Metro is now in a Tornado Watch until 4 AM Saturday (though it should be canceled before then). Damaging 60mph & a brief tornado remain possible in tonight's storms. @fox4kc #KCwx #MOwx #KSwx
Jacob Lanier tweet media
English
6
3
45
5.3K