Viktor Hedberg 🛡💻

1.5K posts

Viktor Hedberg 🛡💻 banner
Viktor Hedberg 🛡💻

Viktor Hedberg 🛡💻

@headburgh

I do security stuff @Truesec • MVP • Father • My tweets are my own • He/him

Sweden เข้าร่วม Haziran 2016
617 กำลังติดตาม1.1K ผู้ติดตาม
Viktor Hedberg 🛡💻 รีทวีตแล้ว
ExpertsLiveSE
ExpertsLiveSE@ExpertsLiveSE·
🔧 Jobbar du med Microsoft‑teknik? Då är Experts Live Sweden 2026 konferensen du inte vill missa. Registrera dig: expertslive.se Communitydrivet. Ideellt. Fullt fokus på Microsoft‑stacken. #Microsoft #ELSE26 #ExpertsLive
ExpertsLiveSE tweet media
Svenska
1
2
1
305
Viktor Hedberg 🛡💻
Viktor Hedberg 🛡💻@headburgh·
@NITESHRAJPOOT @PyroTek3 MS Creates a baseline policy if you have P1 licenses on a tenant level. But in short, any user that can "benefit" from the feature needs to have a license assigned.
English
0
0
1
9
Schrodinger
Schrodinger@NITESHRAJPOOT·
@PyroTek3 Do u need per user Entra ID p1/pe licence to implement this CAP ór only 1 licence for org is enough to implement this policy 🤔
English
1
0
0
147
Viktor Hedberg 🛡💻
Viktor Hedberg 🛡💻@headburgh·
@AdamTheRock1 @horizon_secured Beg to differ, don't try to do it all at once. Get the structure in place in parallell to the existing env, and migrate into the tiering structure. Done it that way for 50+ companies worldwide the last couple of years.
English
1
0
4
46
Horizon Secured
Horizon Secured@horizon_secured·
🔒 Secure Bits 💡 Do you want to protect your critical assets from vulnerabilities in user infrastructure and the threats that exploit them? Achieve this with the 𝗧𝗶𝗲𝗿𝗶𝗻𝗴 𝗠𝗼𝗱𝗲𝗹. Categorize your Windows Infrastructure into Tiers based on asset criticality. 𝗧𝗶𝗲𝗿 𝟬: The most critical assets, affecting the entire Windows Infrastructure. 𝗧𝗶𝗲𝗿 𝟭: Application infrastructure, affecting client infrastructure. 𝗧𝗶𝗲𝗿 𝟮: User infrastructure, the first point of contact with threats. 👉Follow the Tiering Model thoroughly and implement Access Restrictions. 💡For example, a Tier 0 admin (𝗗𝗼𝗺𝗮𝗶𝗻 𝗮𝗱𝗺𝗶𝗻) should not be able connect to servers or devices in Tier 1 and Tier 2. This effectively protects your environment and contains attacks within specified Tiers. #SecureBits #ActiveDirectory #WindowsSecurity #Windows #Microsoft #CyberSecurity #HorizonSecured @BlueTeamDave
Horizon Secured tweet media
English
2
10
76
4K
Viktor Hedberg 🛡💻 รีทวีตแล้ว
Steven Lim
Steven Lim@0x534c·
Azure Bastion CVE-2025-49752 👀 CVSS Score: 10/10 Affected: All Azure Bastion deployments prior to the security update released on November 20, 2025 zeropath.com/blog/azure-bas…
English
2
54
168
34.1K
Viktor Hedberg 🛡💻
Viktor Hedberg 🛡💻@headburgh·
@UK_Daniel_Card Why bother hacking stuff and spending $ on some 0-day or whatever, when admin/admin, cisco/cisco or whatever gives you what you need? 😅
English
1
0
12
691
Viktor Hedberg 🛡💻 รีทวีตแล้ว
mRr3b00t
mRr3b00t@UK_Daniel_Card·
Key things seen in ransomware incidents: 1) VPN does not require MFA 2) Standard User VPN access gives access to management interfaces 3) LDAP access leads to domain admin via: Passwords in description fields, kerberoasting and other common escalation points (but seriously the above is major) 4) the backup servers are primary corp domain joined 5) the vcenter servers are primary corp domain joined this gives the threat actor the ability to: > destroy your backups > destroy your virtual infrastructure > delete/encrypt your data > exfiltrate the data
GIF
English
21
68
379
26.4K
Nathan McNulty
Nathan McNulty@NathanMcNulty·
cyber awareness month is off to a great start
Nathan McNulty tweet media
English
24
12
262
37.8K
Nathan McNulty
Nathan McNulty@NathanMcNulty·
What the... 🐉?
Nathan McNulty tweet media
English
43
22
273
27.5K
Viktor Hedberg 🛡💻
Viktor Hedberg 🛡💻@headburgh·
@rucam365 Also gives you total control of the clean source principle, and chain of trust. Something AVD/VDI/W365 does not.
English
0
0
1
72
Viktor Hedberg 🛡💻
Viktor Hedberg 🛡💻@headburgh·
@rucam365 Forget physical PAWs for each Tier, easiest compromise is to have the laptop as a Hyper-V host and run each PAW as individual VMs on it, including your companion device 😁.
English
1
0
5
764
Ru Campbell
Ru Campbell@rucam365·
Most IT teams, including mature ones, aren’t gonna adopt physical dedicated PAWs and it’s not reasonable to assert they should. What have been your most successful compromises for this?
English
52
30
202
40.2K
Viktor Hedberg 🛡💻
Viktor Hedberg 🛡💻@headburgh·
@reprise_99 Not 5 words, but 200+% of the company were DA. Domain Users and Domain Computers were members of DA. "Everything worked fine, until we got hacked"
English
0
0
2
165
Matt Zorich
Matt Zorich@reprise_99·
Give a cyber security worker nightmares in five words, I’ll start. Domain controller also runs Citrix
English
160
31
497
38.7K
Viktor Hedberg 🛡💻 รีทวีตแล้ว
Jan Bakker
Jan Bakker@janbakker_·
I'm just going to leave this here, as I keep seeing surprised faces when I tell people about Windows Hello multifactor unlock. Yes, you can enforce 2️⃣ factors to unlock your Windows machine! See for yourself. #user-experience" target="_blank" rel="nofollow noopener">learn.microsoft.com/en-us/windows/…
English
11
33
210
29.9K
Viktor Hedberg 🛡💻 รีทวีตแล้ว
Microsoft MVP Communities
🎉 A warm welcome to all the new MVPs! 🎉 You’ve joined a global community of passionate experts, builders, and changemakers who go above and beyond to share knowledge, support others, and drive innovation. Whether you’re leading user groups, writing code, creating content, or empowering your local tech ecosystem—your impact matters. And now, you’re officially part of the MVP family. 🙌 Let’s celebrate YOU. Drop a 👋 and let us know where you're from or what community you're most excited to engage with! #MVPBuzz #MicrosoftMVP
English
5
29
137
6.8K
Viktor Hedberg 🛡💻 รีทวีตแล้ว
Mikael Nystrom
Mikael Nystrom@mikael_nystrom·
Restore and Repair – Don’t Build New After an Incident @Truesec https://www.truesec.comhub/blog/restore-and-repair-dont-build-new-after-an-incident
Mikael Nystrom tweet media
English
1
7
12
1.3K
Microsoft 365
Microsoft 365@Microsoft365·
Send us a 🫵 and we’ll send you a PowerPoint Night topic based on your profile
English
870
53
872
84.2K
Viktor Hedberg 🛡💻 รีทวีตแล้ว
mRr3b00t
mRr3b00t@UK_Daniel_Card·
🤣
mRr3b00t tweet media
QME
50
1.1K
18.4K
635.4K
Viktor Hedberg 🛡💻 รีทวีตแล้ว
vx-underground
vx-underground@vxunderground·
@DOGE Good find. Those licenses cost on average $500,000,000/year. That saved the country potentially hundreds of billions of dollars. Now the government can put that money to good use such as reintroducing lead to paint to keep the photon radioactive waves out of our brains
English
30
72
2.6K
56.1K