Anders Kristiansen

721 posts

Anders Kristiansen banner
Anders Kristiansen

Anders Kristiansen

@pelsner

Master Information Security.

Oslo เข้าร่วม Mart 2010
242 กำลังติดตาม126 ผู้ติดตาม
Magic: The Gathering
Magic: The Gathering@wizards_magic·
With every calm word and calculated strike, Leonardo shows what it means to be a leader. #MTGxTMNT
English
12
9
116
21.3K
Anders Kristiansen รีทวีตแล้ว
Matified
Matified@matifiedcustoms·
🤩!!Foil Playmat Giveaway!!🤩 We would like to giveaway an official Magic the Gathering Dominaria United stained glass playmat that was customized and foiled out by me. All you have to do is: Follow us Repost Like the Post I'll pick a random winner Sunday 1/25, Good luck to everyone!
Matified tweet media
English
170
1.2K
1.9K
106.1K
Anders Kristiansen รีทวีตแล้ว
Dirk-jan
Dirk-jan@_dirkjan·
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English
140
900
3.2K
471.6K
Anders Kristiansen รีทวีตแล้ว
Tom Warren
Tom Warren@tomwarren·
Microsoft is starting to move antivirus providers out of the Windows kernel. Security vendors are about to test new Windows changes in a private preview that's designed to prevent another CrowdStrike incident. Full details and interview 👇 theverge.com/news/692637/mi…
English
7
37
255
26.6K
Ru Campbell
Ru Campbell@rucam365·
@pelsner Not sure I follow - or maybe my first tweet needs explained. It's "just" a script to grab CA policies then make sure a group is listed in the exclusions (if not, add it).
English
1
0
0
38
Ru Campbell
Ru Campbell@rucam365·
What’s one thing about Defender, Entra, or Purview you wish you'd learned sooner? Operational or technical. I'll go first: Have a scheduled job to auto add emergency access (break glass) accounts to all Conditional Access policies. No comment re why this makes my list...
English
7
6
104
12.8K
Dirk-jan
Dirk-jan@_dirkjan·
Pretty proud of this one, took a lot of work. And no, this device does not exist 😎
Dirk-jan tweet media
English
15
27
222
39.7K
Anders Kristiansen รีทวีตแล้ว
Karl
Karl@kfosaaen·
Assuming I'm reading this one correctly, this one is a pretty big deal. Continuing my take on it in a thread, but read the blog from @xybytes here: xybytes.com/azure/Abusing-…
English
1
29
79
9K
Anders Kristiansen รีทวีตแล้ว
Gunnar Haslinger
Gunnar Haslinger@GHaslinger·
Attention IT Pros! The Microsoft UEFI CA, which SecureBoot relies on, will expire on Monday October 19, 2026, after 15 years of validity. Mark this date in your calendar. Devices require a Firmware/DB update; otherwise, stop booting. 🔒#WindowsSecurity support.microsoft.com/en-us/topic/kb…
Gunnar Haslinger tweet media
English
13
206
516
83.8K
Ru Campbell
Ru Campbell@rucam365·
Do you exclude at least one global admin account from all Conditional Access? I'm in the nope camp. Generally have two accounts with different Conditional Access requirements; likelihood of both failing is slim. Risk of that is preferable to single factor GA. What do you think?
Ru Campbell tweet media
English
56
10
97
32.6K
Karim El-Melhaoui
Karim El-Melhaoui@karimscloud·
You can manage secrets and env vars on a GitHub repository without having the admin role for the repo🤯 Not knowing this, I've worked around the limitation by creating a central function to de-privilege users nicruo.com/posts/2024/03/…
English
2
0
5
449
Anders Kristiansen รีทวีตแล้ว
Brett Adcock
Brett Adcock@adcock_brett·
OpenAI + Figure conversations with humans, on end-to-end neural networks: → OpenAI is providing visual reasoning & language understanding → Figure's neural networks are delivering fast, low level, dexterous robot actions (thread below)
English
402
1.4K
6.3K
1.9M
Anders Kristiansen รีทวีตแล้ว
Andy Robbins
Andy Robbins@_wald0·
Since we're talking about MS Graph... Did you know that the combination of... ● Organization.ReadWrite.All ● Policy.ReadWrite.AuthenticationMethod ...enables escalation to Global Admin? Details here: posts.specterops.io/passwordless-p… Enforce 👏 M 👏 F 👏 A 👏for Global 👏 Admins 👏
English
3
73
249
28.4K
Andy Robbins
Andy Robbins@_wald0·
Starting now: join me and @StephenHinck in the #BloodHound Slack. Ask us anything about the recent Microsoft breach, especially the technical details of the attack path. Not in the BloodHound Slack yet? Join here: ghst.ly/BHSlack
English
1
2
11
2.6K