
Jef Kazimer
573 posts

Jef Kazimer
@JefTek
Principal Product Manager @Microsoft #MicrosoftEmployee #Microsoft #Entra #Identity #EntraID - Tweets are my own














Life decided I haven’t had enough lately, so it decided to give my cat terminal cancer for Christmas. Now I’m just waiting on whether this is carcinoma or lymphoma, both have a terrible prognosis, but carcinoma I’d be looking at days. Two years ago, we lost my mom’s cat right after Christmas, I hate this holiday.





@shane_cyber @NathanMcNulty @TechBrandon You can use my work ID. @Thomas_Live I and some other colleagues built it to allow for exactly this use case glueckkanja.com/en/security/my…







I work DFIR. People ask if their stuff is "private". And it is. Mostly. Private from your coworkers. Not from your endpoint. Not from your servers. Not from your admin. Not from your SIEM. Not from your EDR console. Not from backups. Not from retention. Not from legal hold. Not from the screenshot you sent in the ticket. When you delete evidence, you're usually deleting it from your view. The evidence still exists. In logs. In exports. In snapshots. In cloud audit trails. In caches. In email. In your "temp" folder that's been there since 2021. And in the case notes you forgot we wrote. We're very careful to explain that investigators can't see everything in real time. We have to do it properly. Open a case. Collect images. Pull triage. Validate timelines. Correlate with identity logs. Do the boring parts. Forms. Approvals. Waiting. Very high barrier. Almost impossible to abuse. The key takeaway is simple. Treat your work devices like a witness. If you wouldn't say it with Legal behind you, don't type it. That's privacy. Informed privacy. Enterprise grade informed privacy. Hope you didn't do anything spicy in 2019. #Satire #DFIR #InfoSec #BlueTeam


