XPGoD
1.1K posts

XPGoD
@XPGoD
About the only IT Guy you know that actually can do it.
Behind you Katılım Ocak 2009
184 Takip Edilen62 Takipçiler

Spent my Saturday with a few hundred of my fellow security pals, learning, soldering stuff and things, CTFing, broadcasting analog Hackers, the usual. Another @_BSidesKC in the books!
English

After 5.5 years, today is my last day at Splunk.
It's been the best run of my career. Shipped a ton of security content, wrote blogs, built tools, and got to help defenders all over the world operationalize the work fast.
Huge thanks to the threat research crew. Sharpest, most generous people I've ever worked with. You made me better every day.
Taking some time now to breathe, think, and see what's on the horizon.
GIF
English

Haha nice!!
The Activity Logs in production environments have all sorts or neat stuff in there to uncover first party services fun facts. I know thats a heavy topic of your research. That, and the UAL for SharePoint. They have undocumented crawlers in there . One that annoys the most is app@sharepoint. It creates so much noise lololol
English

Twenty-two people are to stand trial in France from Monday on charges of murder and other serious crimes centred on a Masonic lodge accused of running hit squads
u.afp.com/SbNE

English

@IAMERICAbooted Yeah and it’s mostly in my view those CSPM vendors. I did a hefty PoC on around 7 and just the registration of those were super sketchy. This is akin to “yeah the app needs administrator to work” when the real answer is they don’t quite know what the perms are really.
English

Do you know why Entra App Registrations are such a topic for security?
Because there's no good way to secure the secret or cert+key, yet so many vendors require them, internal apps using the M365 APIs require them, and they end up exposed everywhere. Moreover, to this day, I've yet to meet one org that understands the dangers associated with the APIs.
English

@kindnessuae @segoslavia Be careful. Tanium and other toys and tools will just utterly kill ingestion if you get charged by it. Or silence those that should be doing what they need to
English

@segoslavia Script Block Logging fills that gap. Event ID 4104 captures deobfuscated commands that Sysmon simply cannot see.
English

When I left I was still some kind of Break the Glass Lite bullshit. Thankfully they didn’t call me when the Okta/Entra cert expired on a Sunday…. Their sheer luck was a user who had an active session that saved that ass. Thank god I am not there. They have no idea what Lifecycles, Management, or Requirements are at the basic level
English

At my previous org, I was a Global admin and IdP super admin (and many more admins with the entire security stack).
At my last org, what did global admin mean? All of M365 and Power Platform. All of it. Exchange, SharePoint, Teams, Entra, Intune, Purview, Security Center, Apps Admin Center, Admin Center, power Platform Admin, Power BI Admin, everything. Yes everything. That was Global Admin.
English

@NickBenderKMBC When I was a kid. You always waited for the St. Patty storm from the Alberta Clipper in UP of Michigan to determine: yes spring is here
English

❄️Snow chances are trending higher from late Sunday afternoon through Sunday night. While the chance of at least 1 inch of snow may seem low (20% to 40%), some weather models are forecasting much higher amounts. There are still many uncertainties, but one thing is certain: northerly winds Sunday evening and night could gust as high as 55 mph—near severe thunderstorm strength. Any snow falling during this time would have significant impacts. March has been known to produce some blockbuster snowstorms and blizzards, and we aren’t there yet, but this is something to pay close attention to.

English

@XPlaneOfficial @justinryanio Did he leave? I haven’t seen him in a minute. He has a black topped rarri… I hope nothing bad happened :(
English

@XPGoD @justinryanio Thank you! (Although Randy is not here :D)
English

Here’s a first look at X-Plane 12 on Apple Vision Pro!
With visionOS 26.4 and NVIDIA CloudXR 6.0, the simulator streams wirelessly at up to 4K/120fps to your headset.
And if you have a physical yoke or throttle, ARKit uses image detection to recognize them and place them inside your virtual cockpit. 🤯 It’ll be available later this spring.
English

@ben_williams_wx I think right at sunset you will see a discrete cell in Cass/Jackson
English

@JacobLanierWx @fox4kc Maybe it should conditionally be a separate watch. Not fill the void like nobody looks. The OK watch is 50/40% but KC is 60/40? There is an actual tornado now.. idk maybe the new CIG stuff generated confusion.
English











