Loris Ambrozzo

23 posts

Loris Ambrozzo banner
Loris Ambrozzo

Loris Ambrozzo

@LorisAmbrozzo

Security Consultant @baseVISION | Interested in anything related to cloud security and identity topics.

Katılım Ekim 2022
140 Takip Edilen86 Takipçiler
Loris Ambrozzo retweetledi
Janic
Janic@JanicVerboon·
Intune 2603 finally fixes RBAC scope tag pain with Scoped Permissions. I took a deep dive into how it works & which real‑world problems it solves 👇 @verboonjanic/a-deep-dive-into-the-new-intune-scoped-rbac-permissions-3ffb6a9cee74" target="_blank" rel="nofollow noopener">medium.com/@verboonjanic/…
English
2
17
48
6.9K
Loris Ambrozzo
Loris Ambrozzo@LorisAmbrozzo·
Disabling a user account during a security incident removes them from all Microsoft Teams. Private channel membership is not automatically restored. This #KQL query lists all private channels the user was removed from. github.com/lorisAmbrozzo/…
Loris Ambrozzo tweet media
English
0
6
8
913
Loris Ambrozzo
Loris Ambrozzo@LorisAmbrozzo·
While diving into Defender XDR Attack Disruption with @nicolonsky, I noticed that the Enterprise App Microsoft Defender for Identity (formerly Radius Aad Syncer) is responsible for the response actions in Entra ID. The #KQL query lists these actions. github.com/lorisAmbrozzo/…
Loris Ambrozzo tweet media
English
0
2
6
539
Loris Ambrozzo retweetledi
Nicola Suter
Nicola Suter@nicolonsky·
The minimum Sense Agent version required for the #Defender XDR Attack Disruption Contain User action to work is v10.8470. Use the following KQL query to identify endpoints with outdated sense versions: github.com/nicolonsky/ITD…
Nicola Suter tweet media
English
1
11
47
3.7K
Loris Ambrozzo
Loris Ambrozzo@LorisAmbrozzo·
That's a simple one but could be quite useful also in combination with other #detections.💥Since a few days, it's possible to use #KQL to detect when a global admin elevates access to manage all subscriptions and management groups. github.com/lorisAmbrozzo/…
Loris Ambrozzo tweet media
English
0
1
7
274
Loris Ambrozzo
Loris Ambrozzo@LorisAmbrozzo·
#KQL query to identify logon events with the default local administrator on devices to see e.g. if the default local admin can be easily disabled and migrated to a LAPS managed local user account. github.com/lorisAmbrozzo/…
Loris Ambrozzo tweet media
English
0
8
49
3.8K
Loris Ambrozzo retweetledi
Nicola Suter
Nicola Suter@nicolonsky·
Pop quiz, which requirement providers can enforce MFA within Entra ID? #Azure Portal with 'request' & 'App requires MFA' will be next I guess (: #check-the-current-mfa-requirement-provider-for-portals" target="_blank" rel="nofollow noopener">github.com/nicolonsky/ITD…
Nicola Suter tweet media
English
0
8
18
3.3K
Loris Ambrozzo
Loris Ambrozzo@LorisAmbrozzo·
Over the past days, I've had several requests from customers to review and block the access from #Tor exit nodes to all portals. This #KQL Query retrieves all exit nodes from the official Tor project and correlates the IP address with the Sign In logs. github.com/lorisAmbrozzo/…
English
1
16
57
5.2K
Loris Ambrozzo retweetledi
Fabian Bader
Fabian Bader@fabian_bader·
You are not affected by the current #CrowdStrike outage? Great, so you got time. You use #MDE? Then better have a look at the gradual rollout process for Microsoft Defender to avoid this in the future in your environment. cloudbrothers.info/en/gradual-rol…
English
14
99
320
25.7K
Loris Ambrozzo
Loris Ambrozzo@LorisAmbrozzo·
@_dirkjan Was a very cool & interesting session! Thanks for sharing💪🏻!
English
0
0
1
67
Dirk-jan
Dirk-jan@_dirkjan·
The recordings of @a41con are available! If you're interested in credential phishing, device code phishing, applying that to phish for PRTs and Windows Hello keys... Give it a watch! 😁 youtu.be/tNh_sYkmurI
YouTube video
YouTube
English
6
85
264
22.7K
Loris Ambrozzo
Loris Ambrozzo@LorisAmbrozzo·
#KQL Query to list devices which are still using the #KDFv1 algorithm to store the Primary Refresh Token which was addressed in CVE-2021-33781. Unpatched devices using the KDFv1 algorithm will no longer be able to sign in to Entra ID. github.com/lorisAmbrozzo/…
Loris Ambrozzo tweet media
English
1
11
37
7.1K
Nicola Suter
Nicola Suter@nicolonsky·
Happy to see another colleague sharing #KQL queries with the community 🎉
Loris Ambrozzo@LorisAmbrozzo

#KQL Query to list devices which are still using the #KDFv1 algorithm to store the Primary Refresh Token which was addressed in CVE-2021-33781. Unpatched devices using the KDFv1 algorithm will no longer be able to sign in to Entra ID. github.com/lorisAmbrozzo/…

English
2
2
13
1.6K