Devin McLean

1.9K posts

Devin McLean banner
Devin McLean

Devin McLean

@devinmclean

SOC & cyber infrastructure manager. I hunt the badness alongside my team. Father of 3. I like video games. Engineer at heart.

Katılım Mart 2009
1.8K Takip Edilen425 Takipçiler
Akshay 🚀
Akshay 🚀@akshay_pachaar·
Traditional RAG vs. Agentic RAG, clearly explained (with visuals):
English
51
275
3.1K
679.6K
Devin McLean retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
The ADSyncCertDump tool is now part of the adconnectdump tools and can be used to extract SP credentials from Entra ID connect hosts. I will cover that during my BH/DC talks today and Friday! Tool is heavily based on Shwmae by @_EthicalChaos_
Dirk-jan@_dirkjan

Since we now can use Entra ID connect sync with a service principal, I thought I'd look into the new security measures. On hosts without a TPM, we can dump the cert+key. On hosts with TPM (second picture) we can use the key to create an auth assertion for roadtx to req tokens.

English
2
99
269
19.7K
Devin McLean retweetledi
nc 🌐🕸️🐱
nc 🌐🕸️🐱@thoughtfault·
opsec like bedrock
nc 🌐🕸️🐱 tweet media
English
113
373
5.9K
365.1K
Devin McLean retweetledi
Nathan McNulty
Nathan McNulty@NathanMcNulty·
This is interesting - a compilation of the well known GUIDs Microsoft uses in cloud This list includes Ids for a bunch of permissions, applications, licensing SKUs, and more We can query Graph API app roles, licensing SKUs, etc., but this is pretty nice github.com/MicrosoftDocs/…
Nathan McNulty tweet media
English
2
59
246
17.8K
Devin McLean retweetledi
Brian Baskin
Brian Baskin@bbaskin·
CTF players be like
Brian Baskin tweet media
English
27
343
2.9K
194.5K
Devin McLean retweetledi
Learn Something
Learn Something@cooltechtipz·
Where has this been all my life?
Learn Something tweet media
English
2.4K
15.8K
153.3K
28.2M
Devin McLean retweetledi
George Kurtz
George Kurtz@George_Kurtz·
As CrowdStrike continues to work with customers and partners to resolve this incident, our team has written a technical overview of today’s events. We will continue to update our findings as the investigation progresses. crowdstrike.com/blog/technical…
English
1.1K
861
3.2K
984.6K
Devin McLean retweetledi
Happy Captain
Happy Captain@EODHappyCaptain·
Candor is an under utilized organizational value. The ability to have hard conversations and be honest and frank across all levels of leadership should be rewarded.
English
16
7
175
5.9K
Devin McLean retweetledi
Digital_Monet
Digital_Monet@aRtAGGI·
Enterprise defenders have grappled with the rise of ORB networks & how to talk about this growing trend among China Nexus threat actors. We dropped a blog on Universal ORB Anatomy, an enterprise framework empowering defenders against this threat class cloud.google.com/blog/topics/th…
English
0
21
58
10K
Devin McLean retweetledi
Nathan McNulty
Nathan McNulty@NathanMcNulty·
Thanks to @stianstrysse for the push to look at this :) # Find all SAML apps with a cert expiring in the next 30 days Get-MgServicePrincipal -Filter "PreferredSingleSignOnMode eq 'saml'" | Where-Object { $_.KeyCredentials.EndDateTime -lt (Get-Date).AddDays(30) }
English
5
21
119
15.6K
Devin McLean retweetledi
Merill Fernando
Merill Fernando@merill·
👏 Folks! Provisioning security groups from Entra ID to on-prem AD just went GA! 🤩 With this, you can move to a cloud-first approach to managing groups in Entra ID while allowing on-prem apps to continue working. Even better, you can use ID Governance to govern access to on-prem apps and make use of access reviews, lifecycle workflows and more! This feature is available in Entra Cloud Sync which can run side by side with Entra Connect Sync! Learn more → learn.microsoft.com/en-gb/entra/id… Bookmark this + like and repost to share with your network. Thanks!
Merill Fernando tweet media
Dhanyah Krish@DhanyahkMSFT

Use Entra ID Governance to govern your AD based (Kerberos) on-premises apps by using cloud security groups that are provisioned to AD with Microsoft Entra Cloud Sync. This capability is now GA! #Cloudsync learn.microsoft.com/entra/identity…

English
6
58
188
23.5K