Jose Reyes

325 posts

Jose Reyes

Jose Reyes

@lfredoreyes

Katılım Eylül 2017
1.4K Takip Edilen32 Takipçiler
Jose Reyes
Jose Reyes@lfredoreyes·
@RealEmirHan this is the first episode from this show I actually sat and watched after the super bowl, I didn't really get it before. Still my favorite episode.
English
0
0
1
1.4K
Emir Han
Emir Han@RealEmirHan·
The Office writers were told to open the Super Bowl episode so wild no one changes the channel. They almost went with “Jim loses Pam in a poker game.” Instead: the legendary fire drill chaos. Filming took 1.5 days. Real cast panic made it even crazier. Two trained identical cats, a $12K stuffed double backup. No animals harmed, takes were tightly controlled. It was the most-watched episode of the series
Emir Han@RealEmirHan

Most iconic moment in TV history? I’ll start:

English
89
1.1K
28.3K
3.4M
Jose Reyes
Jose Reyes@lfredoreyes·
@IAMERICAbooted @merill It bugs me that if I disable or delete a compromised app registration/secret the malicious session remains until it expires. A lot can happen in that time. Considering workload identity premium for at least some mitigation around secret usage for critical apps with app perms.
English
0
0
2
42
EZ
EZ@IAMERICAbooted·
Tomorrow is an exciting day! @merill and I are going to talk about APIs! I'm betting Merill has some great stories and I will put the fear of nation states in your heart :p
English
7
4
43
606
Jose Reyes
Jose Reyes@lfredoreyes·
@Coach_Yac in the pregame radio for this game that the niners were leading league in takeways up to that point. I remember thinking... wow we can probably be really good this year.
English
0
0
3
249
Jose Reyes
Jose Reyes@lfredoreyes·
@arpeyton @IAMERICAbooted like deploying add ins in M365 admin console. for some reason even though the docs say an Exchange Admin can do I've only been able to do so with GA. Specifically when deploying custom add ins.
English
0
0
1
16
Anthony Peyton
Anthony Peyton@arpeyton·
@IAMERICAbooted MS: don’t use GA Also MS: to perform this completely normal admin task you need user admin, SharePoint admin, teams admin, application admin, and Intune admin.
English
2
0
4
129
EZ
EZ@IAMERICAbooted·
Whoever came up with tiering for M365 roles (yes, I know many who did), dont understand how to abuse the roles they missed for privilege escalation to Global Admin. If your trying to contain and prevent damage to the company, there are a lot more roles with privesc paths to Global Admin. Hint: that's why Microsoft calls them privileged roles. Additionally, theres SharePoint Admin. If you could only fathom what you would find and what you can do with that role.... The problem is, many people working in security dont have the experience as security engineers in the cloud. Thats why they dont know.
English
5
2
38
2.6K
Jose Reyes
Jose Reyes@lfredoreyes·
@Coach_Yac My mental health was not ready for this today but I watched it again for the millionth time. The loss hurts, but man that feeling when you get so close and there is hope still alive is such a thrill. Even the last play I recall feeling like "we can do this"
English
0
0
3
337
Jose Reyes
Jose Reyes@lfredoreyes·
@OurSf49ers 3x 1pm home games early in the season is going to be hot as heck out there for us in the sun. usually they give us a week or two on the road then a prime time game.
English
0
0
1
1.1K
OurSF49ers
OurSF49ers@OurSf49ers·
The #49ers official 2026 Schedule Leaked: What do you think their record will be 🤔
OurSF49ers tweet media
English
159
206
1.5K
134.8K
Jose Reyes
Jose Reyes@lfredoreyes·
@NathanMcNulty Thank goodness for tab complete, imagine typing that out in bash... invoke-mgsupercalifragilisticexpialidocious
English
0
0
1
10
Nathan McNulty
Nathan McNulty@NathanMcNulty·
I love getting gaslit by Azure all the time... Automation accounts and Function apps only support PowerShell 7.4, even though 7.5 was released 1.5 years ago and 7.6 was released a few months ago "Please consider updating it soon." 😒 No Azure, you consider updating it soon...
Nathan McNulty tweet media
English
10
7
87
6.3K
Jose Reyes
Jose Reyes@lfredoreyes·
@NathanMcNulty Yep, I do the same. I’ve always preferred using the rest API URIs directly rather than learning get-mggrapsuperlongcommand.
English
1
0
1
20
Nathan McNulty
Nathan McNulty@NathanMcNulty·
@lfredoreyes Runtimes are amazing, and try to pull in only Microsoft.Authentication, then only use Connect-MgGraph and Invoke-MgGraphRequest :) It's definitely a pain, but keeps the memory low and the code more auditable.
English
1
0
0
169
Jose Reyes
Jose Reyes@lfredoreyes·
@Drect R A Rugged Man on Uncommon Valor Capadonna on Winter Warz
English
0
0
0
119
Drect Williams
Drect Williams@Drect·
We named some of the HARDEST VERSES in rap history: Bun B - Murder Kim - Quiet Storm Andre - Elevators Nas/AZ - Life’s a B*tch Banks/Biggie - Victory Nicki - Monster Eminem - The Way I Am Ross - Devil in a New Dress Wayne - Cannon 50 - Many Men Remy - Ante Up What did we miss?
English
918
554
6.7K
291.5K
Jose Reyes
Jose Reyes@lfredoreyes·
@merill The connect sync to cloud sync is interesting. Last I looked at it there wasn’t full parity, especially for hybrid scenarios. I have wondered if both can run in parallel while handling different things. I need to dig back into this.
English
0
0
1
62
Jose Reyes
Jose Reyes@lfredoreyes·
@gogogogetem @Philly19553993 @NCBubblehead @ModestTeacher Decks mostly come in the same order. Most are shuffled the same (machine or rifled). people play the same games leading to similar groupings of cards prior to shuffling. 52! but given the patterns in our games and methods it’s possible the same order has been dealt IMO.
English
1
0
0
35
go
go@gogogogetem·
@Philly19553993 @NCBubblehead @ModestTeacher Yeah but you gotta think how many times a deck has been shuffled considering casinos and commonly played house games. I'm sure the same order has happened before
English
2
0
1
289
Barstool Gambling
Barstool Gambling@stoolgambling·
What is the only NFL logo that faces to the left?
English
149
40
3.6K
1.2M
Merill Fernando
Merill Fernando@merill·
Entra Hardening Tip #4 - Block legacy authentication Problem: Legacy auth (SMTP/IMAP/ROPC) doesn’t support MFA, making it a prime target for password attacks and an easy entry point for attackers using stolen creds. Legacy authentication also provides attackers with a consistent method to reenter a system using compromised credentials without triggering security alerts or requiring reauthentication. @ellishlomo shared some insights on how attackers are still targeting tenants that allow legacy protocols (see below). Fix: - Assignments - All users - Target resources > All resources - Conditions - Client apps, set Configure to Yes. - Check only the boxes Exchange ActiveSync clients and Other clients. - Access controls - Block access
Merill Fernando tweet media
English
2
16
146
7.2K
Jose Reyes
Jose Reyes@lfredoreyes·
@merill does this have to be a rule that explicitly includes the action or does an overarching MFA rule if accessing any resource suffice?
English
1
0
0
234
Merill Fernando
Merill Fernando@merill·
Entra Hardening Tip #2: Require MFA for device join & device registration using 'User Action' If you don’t enforce a Conditional Access policy for “Register or join devices”, you’re leaving a gap. Attackers can take advantage of this and register new devices without MFA. Once they’re in, they can: 🚩 Stay persistent 🚩 Bypass controls that rely on trusted devices From there, it opens the door to: 🚩 Data exfiltration 🚩Dropping malicious apps 🚩 Moving laterally across your environment 🚩Recon of your device configuration and compliance policies The fix: Create a CA policy → Include: All users → Target: User Action = Register or join devices → Grant access: Require authentication strength - MFA
Merill Fernando tweet media
English
4
43
217
13.9K
Jose Reyes
Jose Reyes@lfredoreyes·
@mozzeph Is detecting for this just looking for logs with "Add service principal credentials" operation? Looks like managed identities have a few events with that operation and also adding new SSO certificates trigger that log as well.
English
2
0
0
174
Martin H. | MVP
Martin H. | MVP@mozzeph·
I updated my blog about Entra ID App Registrations vs Service Principals. It was only a couple of months ago that I learned that with Graph API, it's possible to add credentials directly to service principals and that they never show up in Entra Portal except in audit log. #update-19042026" target="_blank" rel="nofollow noopener">heusser.pro/p/whats-the-di…
English
5
5
84
4.6K
Jose Reyes
Jose Reyes@lfredoreyes·
@IAMERICAbooted does requiring admin consent make a difference here or since these are not application level perms the admin consent isn't usually required?
English
1
0
1
95
EZ
EZ@IAMERICAbooted·
Part 1 of why your delegated API permissions are not the control you think they are: Entra App Registration owners can add delegated permissions to the application manifest and create additional secrets. This allows attackers to move laterally by sending a consent to unknowing users. They WILL consent most of the time because non-technical users have no idea whats happening. Moreover, the phish can be easily masked as other things going on. For example: MyCoolApp has 10 owners who have already consented to the app permissions. Attacker pops one owner. They can now read all other owners and consenters files and move laterally by phishing consents and token harvesting. Delegated API permissions for internal apps added in a manifest by an app owner do not require admin consent from GA, Privileged Role Admin, Cloud Apps Admin, or App Admin. They are added immediately.
English
3
4
36
3.1K