Phillip Jones

27.2K posts

Phillip Jones banner
Phillip Jones

Phillip Jones

@P2Vme

Solution Architect @ Coretek | 4 boys | Bestest Wife | Cybersecurity, Microsoft, Cloud, AI, VMware, EUC, Citrix ¦ Griller, Medieval Combat, Hiking, RPGs

"Off-Prem" Katılım Ekim 2009
2.5K Takip Edilen1.9K Takipçiler
Phillip Jones retweetledi
IT Unprofessional
IT Unprofessional@it_unprofession·
My friend invited me to his "casual game night." I thought that meant snacks and maybe Uno. He dimmed the lights, pulled out a whiteboard, and said, "We'll start with Catan, obviously." Obviously. Within 20 minutes, three grown adults were accusing each other of "sheep hoarding" with the intensity of a custody battle. One guy slammed his hand on the table and yelled, "You broke our wheat alliance, Trevor." I don't even know Trevor. I'm just trying to figure out why there's a resource called "ore" and why I'm emotionally invested in it. At one point, someone looked me dead in the eye and asked if I wanted to trade wood. I haven't recovered. We finished at midnight and my friend said, "Next time we'll do something light, like Twilight Imperium." I Googled it. That's not a board game. That's a part-time job with lore.
English
341
1.5K
28.1K
1.5M
Phillip Jones retweetledi
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
15
7
123
3.2K
Phillip Jones retweetledi
Steven Lim
Steven Lim@0x534c·
🔑 KQL Detection for MDI Password Protection Insight Microsoft Defender for Identity (MDI) introduced the Password Protection Portal in March, giving defenders deep visibility into the password hygiene of their Entra ID/Active Directory environments. This new capability is a powerful way to shrink your identity attack surface by highlighting weak, compromised, or high‑risk passwords across your tenant. To complement the portal, I’m sharing a custom KQL detection that provides your SOC with near‑real‑time visibility into leaked credentials. With this detection in place, defenders can rapidly respond to exposed accounts, revoke access, and further harden identity security. KQL Code: github.com/SlimKQL/Detect… #Cybersecurity #DefenderXDR #PasswordProtection
Steven Lim tweet media
English
1
22
102
8.2K
Phillip Jones retweetledi
Joe Desimone
Joe Desimone@dez_·
We open sourced the tool used to detect the Axios supply chain compromise! I built it Friday after a red eye home from RSAC. Also, wrote up the full story, including the hectic moments after that first critical alert github.com/elastic/supply…
English
33
250
1.3K
135.8K
Phillip Jones retweetledi
vx-underground
vx-underground@vxunderground·
There is a project on GitHub called Axios. Axios is extremely popular. It is used by millions upon millions of applications. Axios is a programming library that helps your JavaScript code make HTTP/S requests (communicate with websites). In simple terms, if you're a programmer doing something with JavaScript, and want to do stuff that communicates with a website in literally any capacity, people heavily recommend using Axios due to its simplicity. Using Axios you don't have to reinvent the wheel and do a bunch of work. All you need to do is import Axios into your code and you're off to the races. Someone (currently unknown) compromised Axios (currently unknown how) to deliver malware to people. When someone updates or installs Axios, Axios itself contains malware. What the malware does is (currently) unknown, but it is being reversed engineered by probably every malware analyst on the planet at this moment. In a few hours more details will emerge. Information is being exchanged in real time on social media and private communication platforms as I write this. Due to the size and popularity of Axios, it is unknown how many are impacted, it could be millions, it could be thousands, or if we're lucky, only hundreds of people or organizations will be impacted. If this is absolute worst case scenario, millions of organizations across the planet have been infected with malware which (currently) we do not understand. However, the likelihood of this is low. It appears Axios being compromised was detected quickly, potentially within minutes (or hours) of it being compromised to deliver malware. Additionally, the likelihood of every single Axios user updating Axios as soon as it was compromised to deliver malware is astronomically low. It is basically zero. The impact from Axios being compromised is devastating, the fallout from this will be a massive headache. This is unironically a malware nuclear missile and will likely be studied in the future.
English
107
837
7.8K
585.7K
Phillip Jones retweetledi
spencer
spencer@techspence·
Things I didn’t know when I started in IT that I know now: - You shouldn’t use the same password for all local admin accounts - You shouldn’t use your Domain Admin account for all administrative duties - 99% of vulnerabilities won’t hurt you. Your time is better spent identifying and fixing the 1% that could - You shouldn’t yolo lone ranger patch vulnerabilities without working with the rest of the team You learn so much (many times the hard way) working in IT, but it’s invaluable experience for those wanting to work in cybersecurity roles later.
English
6
11
89
6.6K
Phillip Jones retweetledi
Nathan McNulty
Nathan McNulty@NathanMcNulty·
Merged some good XDRInternals updates :) Connect-XdrBySoftwarePasskey does exactly what it says, super easy to automate AI access to the portal 🤖 Get-XdrIdentityUserTimeline lets you extract the whole 180 days of user timeline data if you need it github.com/MSCloudInterna…
Nathan McNulty tweet media
English
2
8
70
5.5K
Phillip Jones retweetledi
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
42
86
1.5K
44.7K
Phillip Jones retweetledi
EZ
EZ@IAMERICAbooted·
It took me years to learn error codes, Oauth flows, OIDC, SAML, Legacy Protocols, Device States, nuances of conflicting policies, group conflictions, federations and what to expect when youre the Resource Provider, and so much more. This is not simple stuff and I would be cautious of anyone who says it is. This tool will help tremendously. There is no replacement for putting in the time, hands on keyboard, AND reading the documentation, even in the world of AI. The problem with AI is missing context. Let me provide you an analogy: The last grade I completed before college (present for the entire school year) was 7th. In college, I had a very high GPA. In college, many students used slides to study for exams. I read textbooks, twice and rarely went to class. The difference was the enriched context I got from reading the textbooks. In the AI world, the context you get is similar to slides in college. The documentation is similar to reading the textbooks in college. We are creating a synthesized, abstract, context-limiting world and our minds are being shaped by it. Those who will survive the AI era in their respective professions will be those who read and dig deeper for understanding, those who collaborate well, those who gain and exercise skills in being "liked", and those who push the boundaries of traditions.
Daniel Bradley@DanielatOCN

In case you missed it, Microsoft just released their new AI-powered self-service support agent in Microsoft Entra 🫧 ourcloudnetwork.com/microsoft-rele… 🩵 It's fairly simple and works. It combines your data from Microsoft Graph (sign-in logs etc) with knowledge powered by Microsoft Learn, to give you answers and help you troubleshoot. I tested the experience in my article above! #Entra #Agents #AI

English
2
15
118
11.2K
Phillip Jones retweetledi
Merill Fernando
Merill Fernando@merill·
👋 We just sent out issue #139 of Entra.News Featuring Daniel Bradley, Nathan McNulty, Jan Bakker, Scott Breen, Sam Erde, James Robinson, Per-Torben Sørensen, Irwin Strachan, Eric Woodruff, Thomas Naunheim, Dennis Johansson, Oliver Müller 1/2
Merill Fernando tweet media
Dansk
1
7
50
3.4K
Phillip Jones retweetledi
Dark Web Informer
Dark Web Informer@DarkWebInformer·
💥 MITRE ATT&CK Explorer was updated with the following: Added Relationship cross-linking in modals, Data Sources tab (empty currently), ATT&CK Navigator-style heatmap, Global cross-section search, Comparison mode, and Platform filter on techniques This will be available for everyone for free, later this month. Currently Elite only: darkwebinformer.com/mitre-att-ck-e…
Dark Web Informer tweet media
English
2
37
188
13.3K
Phillip Jones retweetledi
Kostas
Kostas@Kostastsale·
Sometimes the call comes a little too late and you gotta do what you gotta do 😂
English
4
21
137
11.5K
Phillip Jones retweetledi
nolen
nolen@itseieio·
made a hook that adds a bouncing dvd logo to claude code whenever it's thinking
English
308
1.1K
17.1K
933K
Phillip Jones retweetledi
dev
dev@zivdotcat·
pov: your vibecoder friend demoing what he built using his $200 claude code max plan
English
48
191
3.2K
395.2K
Phillip Jones
Phillip Jones@P2Vme·
@techspence Yes, more than ever. security is foundational imo, it should be ubiquitous, now to what level is a different question and harder to define.
English
0
0
0
4
spencer
spencer@techspence·
True or false, cybersecurity skills are necessary for IT admins?
English
138
9
312
26.7K
Phillip Jones retweetledi
Matt Levy | Microsoft Security MVP
Struggling to understand the impact of the upcoming passkey rollout in Microsoft Entra tenants (MC1221452)? ME TOO. So I had this flow diagram created.
Matt Levy | Microsoft Security MVP tweet media
English
0
17
119
18.4K
spencer
spencer@techspence·
Sure Pentest one a year, but also, don’t wait until your next pentest to: Run Locksmith Run ADeleginator Run PingCastle/PurpleKnight Check shares, sharepoint, wikis for creds
English
7
24
210
12.1K