Sean Metcalf

22.9K posts

Sean Metcalf banner
Sean Metcalf

Sean Metcalf

@PyroTek3

Identity Security Architect @ TrustedSec. Microsoft Certified Master #ActiveDirectory & former Microsoft MVP. Co-Host @ Enterprise Security Weekly. He/Him. #BLM

4°08'15.0N 162°03'42.0E Katılım Ağustos 2014
687 Takip Edilen36.9K Takipçiler
Sabitlenmiş Tweet
Sean Metcalf
Sean Metcalf@PyroTek3·
To my black family, friends, and people seeing this: I love you You matter I'm here for you #BlackLivesMatter
English
4
5
138
0
Sean Metcalf retweetledi
Blue Team Village
Blue Team Village@BlueTeamVillage·
We've been busy planning and organising for #DEFCON 34 so we're going to unwind with y'all next week on Friday evening. Check out the details in our poster below.
Blue Team Village tweet media
English
1
13
27
2.1K
Sean Metcalf retweetledi
Josh Cook | Microsoft MVP
Josh Cook | Microsoft MVP@FlowAltDelete·
Microsoft just gave admins a domain blocklist for Copilot web grounding. Up to 1,000 websites can now be excluded from Microsoft 365 Copilot and Copilot Chat responses. It is tenant-wide. It is PowerShell-managed. It is opt-in. Important catch: excluded domains could still appear through news results. Useful governance control. Not a complete web firewall. Read more here: learn.microsoft.com/en-us/copilot/…
English
5
38
167
11.8K
Sean Metcalf retweetledi
Tech Brandon
Tech Brandon@TechBrandon·
For the love of God make this default behavior... Did AD teach us nothing?!?!
Daniel Bradley@DanielatOCN

Microsoft just added the ability to 𝐝𝐢𝐬𝐚𝐛𝐥𝐞 𝐠𝐫𝐨𝐮𝐩 𝐧𝐞𝐬𝐭𝐢𝐧𝐠 for groups in Microsoft Entra > ourcloudnetwork.com/how-to-disable… It's very new, can only be set during group creation and I cannot see any documentation on Microsoft Learn about this yet outside of the Graph API permission reference, but it was caught by my MsDocsTracker! Very useful for groups that protect sensitive applications or resources where you want every member to be added directly. Check out my article linked above to enable the disableNesting property for groups! #Entra #News #Microsoft

English
1
1
25
5.1K
Sean Metcalf retweetledi
Dave Kennedy
Dave Kennedy@HackingDave·
I’ll be on CNBC later today at 4:15PM and CNN later in the evening !
English
17
6
116
7.5K
Sean Metcalf retweetledi
Rob Fuller
Rob Fuller@mubix·
Friendly @defcon reminder: Meta-style glasses w/ recording capabilities are prohibited at DEF CON. No exception for recording glasses with prescription lenses. Be sure to pack non-violating eyewear if you need them. Please see our Photo policies for more: defcon.org/html/links/dc-…
English
15
66
278
31.5K
Sean Metcalf retweetledi
Dave Kennedy
Dave Kennedy@HackingDave·
Dave Kennedy@HackingDave

You thought NightBeacon was cool? That's only half of the picture of what we've been working on at #BinaryDefense. We've been in the skunkworks for over two years doing something even more game changing and frankly it's incredible. Patents are in. We're releasing at BlackHat. Seriously game changing and changes everything. Everyone is concerned about models attacking you. We've figured out a way to shut that down completely. No marketing fluff, fake promises, or vaporware. It works, and it works extremely well. We've been testing this for over a year and a half, and we've operationalized it to high effect. NightBeacon was only the beginning. Welcome to the era of NightBeacon and what will be known as Stealth. Stay tuned.

QHT
2
7
53
7.3K
Sean Metcalf retweetledi
All day Astronomy
All day Astronomy@forallcurious·
NASA has released one of the most detailed visualizations ever created of Earth’s ocean currents. Using data from satellites and advanced ocean models, the map reveals massive rivers of moving water, swirling eddies hundreds of miles wide, and the powerful Gulf Stream carrying warm water from the Gulf of Mexico across the Atlantic.
English
648
6.3K
24.3K
1.3M
Sean Metcalf retweetledi
mRr3b00t
mRr3b00t@UK_Daniel_Card·
How to be safer online..... > disable device code auth! > block legacy auth! > ensure risky sign ins require MFA (or just block them!) (and then go as far as you can/need/want to with regards to hardening auth... that part is really contextual) you have to understand threat, asset and risk, then apply controls....
mRr3b00t tweet media
English
11
14
123
8.2K
Sean Metcalf retweetledi
Jason Lang
Jason Lang@curi0usJack·
Last call guys... Red teamers are going to LOVE this class. 😈
TrustedSec@TrustedSec

Get a sneak peek at what's waiting for you at @BlackHatEvents 👀 August 1-4 with our "Supply-Chain to Runtime: Attacking & Defending the Modern DevOps Stack" training. Last week to register at the current price—enroll now! #supply-chain-to-runtime-attacking-amp-defending-the-modern-devops-stack-50985" target="_blank" rel="nofollow noopener">blackhat.com/us-26/training… @curi0usJack @__spitzer__

English
3
15
29
11K
Sean Metcalf retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
CertiGhost (CVE-2026-54121) deserves much more attention than it is getting right now, from my point of view. In a common/default AD CS setup, a low-privileged domain user can create a rogue machine account, trick the CA into issuing a certificate with the identity of a Domain Controller, authenticate as that DC via PKINIT, gain replication access and basically compromise the whole domain. So if you run on-prem Active Directory with AD CS and your CA is still unpatched, an ordinary domain user may currently have a path to the highest privileges in your domain. Patch it, obviously, or apply the temporary mitigation. But if you patched only recently, the harder and from my point of view more important question is: did someone already exploit it? A patch closes the hole. It does not unfuck a domain that was already compromised. I put a list of things I would check in the first reply. Overview: linkedin.com/posts/martinso… Technical details: gist.github.com/H0j3n/a5ef2609… PoC: github.com/aniqfakhrul/CV… Microsoft advisory: msrc.microsoft.com/update-guide/e… Temporary mitigation: x.com/aniqfakhrul/st…
Florian Roth ⚡️ tweet media
nix@aniqfakhrul

@sahruldotid @h0j3n You can modify registry with certutil. 1. certutil -setreg policy\EditFlags -EDITF_ENABLECHASECLIENTDC 2. Restart-Service CertSvc -Force This should disable the chase

English
9
133
525
80.4K
Sean Metcalf retweetledi
Fabian Bader
Fabian Bader@fabian_bader·
If you want to hunt for signs of Certighost (CVE-2026-54121) by @h0j3n and @aniqfakhrul in your #XDR environment try this query. 1. Exclude DCs 2. Identify ADCS servers 3. Check for LDAP or SMB connectivity to any non DC from ADCS BP for SMB possible! gist.github.com/f-bader/8c447a…
English
2
48
137
9.7K
Sean Metcalf retweetledi
Fabian Bader
Fabian Bader@fabian_bader·
The success secret behind Maester is not only the amazing UI but the people that contribute their domain knowledge and make this not just another checkbox report but many checks are backed by actual implementations in the wild
Merill Fernando@merill

Putting the final touches on the upcoming 🔥 Maester 2.2 release and look at this! A new Contributors page dedicated to the awesome community of folks that make Maester what it is today. Check it out and click through to the detail page of each author. maester.dev/contributors BTW @fabian_bader had a neat idea. Soon we'll be handing out exclusive badges/credentials to folks who contribute Maester tests.

English
2
9
37
4.9K
Sean Metcalf retweetledi
An0maly
An0maly@LegendaryEnergy·
Dr. Suess over a rap beat is fire. This guy crushed this performance 🔥
English
654
6.5K
39.8K
2.3M
Sean Metcalf retweetledi
Mike's Weather Page
Mike's Weather Page@tropicalupdate·
Florida FDOT for the win. Love these signs. They always make me smile. Which is your favorite?
Mike's Weather Page tweet media
English
137
267
2.1K
111.7K
Sean Metcalf retweetledi
The Hacker News
The Hacker News@TheHackersNews·
‼️ Bing Images Turned a 1-Pixel SVG Into a SYSTEM Shell on Microsoft’s Servers. A crafted SVG sent through Bing’s public image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s Windows servers and root on its Linux servers. No login, session, or click required. Read how the image reached a shell: thehackernews.com/2026/07/bing-i…
The Hacker News tweet media
English
0
44
179
38.7K