Tom Degreef

2.3K posts

Tom Degreef

Tom Degreef

@TomDegreef

CoFounder @AppControlAI | Making application allowlisting simple & scalable | Helping orgs stop malware at the source instead of chasing signatures | Zero-trust

België Katılım Nisan 2012
134 Takip Edilen847 Takipçiler
Sabitlenmiş Tweet
Tom Degreef
Tom Degreef@TomDegreef·
Pentesters agree: Application allowlisting is THE most critical defense against compromise. Our ACfB/WDAC training gives you the practical skills to deploy application control for business with confidence—blocking threats before they execute. academy.viamonstra.com/courses/master… Make sure to checkout AppControl.AI as well to see what tooling we offer to beter manage and control your application allowlisting implementation. #Cybersecurity #WDAC #AppControl #ZeroTrust #ThreatPrevention #AppControlforBusiness #ACFB
English
0
4
8
775
Tom Degreef retweetledi
AppControl.ai
AppControl.ai@Appcontrolai·
Tl;Dr Nightmare Eclipse brand new Legacy hive 0-day, reliably stopped by a comprehensive Application Control implementation. Don't get in the crosshairs between this security researcher and Microsoft's vulnerability disclosure handling. Implement Application Control for business (With AppControl.ai's assistance), now. linkedin.com/pulse/security…
English
0
1
1
48
Tom Degreef retweetledi
AppControl.ai
AppControl.ai@Appcontrolai·
So, you have your allowlisting under control and only allow what is needed? Awesome. Casey released Scan-LolbinPrimitives.ps1 as a reconnaissance tool to bypass your rules by identifying what you've allowed that is subject to 'proxy execution'.
English
0
2
2
776
Tom Degreef retweetledi
AppControl.ai
AppControl.ai@Appcontrolai·
The most efficient strategy to get there is to build your trustlist by application instead of the typical web of rules to cover everything. Appcontrol.ai helps you get there with a vastly reduced worload. Schedule a demo or chat by filling in the account request form.
Kim Oppalfens (MVP) ✖️@TheWMIGuy

A proper Allowlisting implementation (analyzing exe, dll and scripts) stops pretty much every threat on Windows endpoints that uses code execution on the device and that is gold to your security posture. Every DfE threat report stopped.

English
0
2
1
253
Tom Degreef
Tom Degreef@TomDegreef·
@mmsmoa Happy and proud to be part of the gang again! As usual, looking forward to seeing you all again.
English
0
0
1
24
Tom Degreef retweetledi
MMS Minnesota
MMS Minnesota@mmsmoa·
Why should you attend MMS Midway Edition? It's THE Endpoint Management event of the year, where industry-leading speakers and MVPs from around the globe connect with Microsoft PMs and developers for deep-dive technical sessions which you won't find anywhere else. And there are plenty of opportunities to network, swap stories, and maybe make some lifelong IT friends. Register Today: mmsmoa.com/mms2026midway October 25-28, 2026 #MMSMidway #MMSMOA #SanDiego #ITpros #MSIntune
MMS Minnesota tweet media
English
1
3
6
303
Tom Degreef retweetledi
Rudy Ooms
Rudy Ooms@Mister_MDM·
Microsoft just announced system-level network configuration support for Intune Endpoint Privilege Management. That means standard users can change things like IP address, gateway, and DNS settings without being a local admin. That part is already interesting. But while looking at the latest EPM agent bits, I noticed something else besides it. Time Sync!!! Inside EpmElevate.exe, it looks like Microsoft is also going to add something to sync and change the time zone? I wrote down what I found in the client-side pieces, what Microsoft has now announced, and how it's going to work patchmypc.com/blog/intune-ep… #Intune #MSIntune #PatchMyPC
Rudy Ooms tweet media
English
3
40
200
24.5K
Tom Degreef retweetledi
Nathan McNulty
Nathan McNulty@NathanMcNulty·
Another day, another bad set of CIS recommendations Here are the items you do not want to do in this list: 5.1.5.6 - Ensure maximum certificate lifetime for applications does not exceed 180 days ⚠️ This will silently break cert renewal for all of your SAML based SSO apps...
Nathan McNulty tweet media
English
14
64
350
45.7K
Tom Degreef retweetledi
Martin Bengtsson
Martin Bengtsson@mwbengtsson·
📢 Remote Help is now included in M365 E3/E5 Small but useful script update: added -TenantId to my Remote Help RBAC script. If you're a consultant running it as a guest in a customer tenant, pass their domain - Graph handles auth against the right tenant. → github.com/imabdk/Intune-… #MSIntune #PowerShell
Martin Bengtsson tweet media
English
0
22
97
7.1K
Tom Degreef
Tom Degreef@TomDegreef·
Rogue Planet: a zero-day that abuses Windows Defender to execute as SYSTEM. Organisations running application allowlisting were protected before the exploit had a name. You can win the race and still lose the exploit. Read our analysis here : linkedin.com/posts/yet-anot…
English
0
0
3
215
Tom Degreef
Tom Degreef@TomDegreef·
The hard part of App Control for Business isn't the technology. It's managing it at the application level, not the file level. With AppControl.ai tooling and guidance, a 25,000-seat customer reached 80% enforcement in 6 months. Their story: appcontrol.ai/post/how-a-25-…
English
0
5
15
872