Philip K

260 posts

Philip K

Philip K

@KronheimK

IT Specialist #Windows10 #ConfigMgr #Intune #EMS #SCCM

Germany Katılım Aralık 2015
279 Takip Edilen90 Takipçiler
Philip K retweetledi
Bert-Jan 🛡️
Bert-Jan 🛡️@BertJanCyber·
In the last months, I have collected some awesome new #KQL sources, and this 🧵lists them. Are you using Defender For Endpoint, Sentinel, Intune or do you want to learn KQL then have a look! #MDE #Sentinel #Intune #Detection #ThreatHunting
English
7
67
196
18.1K
Philip K retweetledi
Jonathan Bourke
Jonathan Bourke@jonathanbourke·
This @Microsoft #EntraID tweet blew up, so here is some #KQL to go along with it... I removed Per-user MFA from all but one user (you got to have a control!); checking the impact of that change: Colours are hard to make out, but only one user impacted post-change! #Result
Jonathan Bourke tweet media
Jonathan Bourke@jonathanbourke

Quick @Microsoft #EntraID tip: Getting excessive MFA prompts? Use the "Authentication Prompts Analysis" workbook under Entra ID > Identity > Monitoring & Health > Workbooks and look for "Authentication prompts by policy"

English
0
10
28
3.6K
Philip K retweetledi
Ru Campbell
Ru Campbell@rucam365·
Just released my latest analysis of Defender for Endpoint features by OS. Targeted at folks deploying MDE to understand what can be used and where; what capabilities you might have missed; or potential customers evaluating options. Blog + download: campbell.scot/mde-comparison…
Ru Campbell tweet media
English
19
153
507
77.3K
Philip K retweetledi
Stephan Berger
Stephan Berger@malmoeb·
1/ Defender prevented the execution of the malware 'Casdet' on an endpoint. Especially with AV alerts, besides the detection, I am always interested in the birth time of the detected file. Was the file detected when it was written to the disk, or since when is it present? 🧵
Stephan Berger tweet media
English
9
54
262
0
Philip K retweetledi
Jonny Johnson
Jonny Johnson@JonnyJohnson_·
I've always thought that in order for Defenders to be truly effective, it is vital they know where the telemetry they are leveraging is coming from. Today I am releasing a project called TelemetrySource that is meant to support that cause. Blog: posts.specterops.io/uncovering-win…
English
7
173
341
0
Philip K retweetledi
ConfigMgrDogs
ConfigMgrDogs@ConfigMgrDogs·
Security Settings Management in Microsoft Defender for Endpoint is now generally available: Security Settings Management in Microsoft Defender for Endpoint is now generally available (3 min.) Preventing data breaches and… bit.ly/3FFJUVV #MDATP #Security #MEM
ConfigMgrDogs tweet media
English
0
14
36
0
Philip K retweetledi
Ru Campbell
Ru Campbell@rucam365·
Thread of some Defender for Endpoint/Defender Antivirus config + deployment tips that are often overlooked. 1. Modern AVs like to update frequently and intelligence updates are done with deltas. Unless you have exceptionally poor internet, set updates to hourly and before scans.
Ru Campbell tweet media
English
19
141
535
0
Philip K retweetledi
Philip K retweetledi
ariaupdated
ariaupdated@ariaupdated·
#ProTip If you check the following paths on the device & don't see the #WindowsUpdate policy you've "set"- you haven't set it. GP: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate CSP: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\current\device\Update
ariaupdated tweet media
English
1
40
91
0