
Joosua Santasalo-Cloud Security MVP - MSRC MVR
@santasalojoosua
DadOf2,Security researcher@Secureworks, Azure MVP,MSRC Top100 MVR23,Node.js Certified (JSNSD),Azure Security enthusiast,blogs @(securecloud.blog)
ID: 989813731973586949
https://securecloud.blog 27-04-2018 10:29:18
3,3K Tweet
2,2K Takipçi
736 Takip Edilen

Is it possible to conduct AiTM phishing attacks with Azure Functions to phish Entra ID sign-in cookies? Spoiler: Yes it is. And we can bypass injected canary tokens and automate the replay😶🌫️nicolasuter.medium.com/aitm-phishing-… Kudos to Wesley Jan Bakker Fabian Bader Joosua Santasalo


Merill Fernando's project has become SO GOOD that it should be your go-to resource when investigating Microsoft Graph application permissions 👇


My former colleague Dr. Nestori Syynimaa knows this scenario pretty well :) This attack scenario is "old but gold" ( Golden SAML 🙂) Just to confirm you should not see Incoming token type of SAML 2.0 for non-federated users...




New chapter of #MicrosoftEntra Attack & Defense ☁️🔐 playbook: Sami Lamppu and I have worked on #AiTM attack scenarios, detection and mitigation capabilities. This includes #KQL queries for advanced hunting in #MicrosoftDefender and #MicrosoftSentinel. github.com/Cloud-Architek…


Thanks to our friends at Microsoft Press we now have a sample chapter available for free from our KQL book - if you want to get a feel for the content. We also have a discount code KUSTO for you, which gets you 30% off your purchase. aka.ms/kQLMSPress/Sto…



Got this cool badge from MSRC: Microsoft Most Valuable Security Researcher (MVR) for 2024! Thanks again to Security Response for recognizing security researchers! credly.com/badges/15217f8…






Celebrating 4 years of the "#MicrosoftEntra Attack & Defense Playbook" community project! Last week, Sami Lamppu and I took the opportunity to record a video about the journey of this project, from research to writing process. #MVPBuzz youtube.com/watch?v=fBD1ft…


I was blessed to conduct some fantastic research at Secureworks for 2024, in partnership with the amazing folks Security Response ,who kindly provided this awesome swag for MVR's2024. The Stanley Quencher&the rest of the swag no doubt increase RIZZ &aura by at least 10X,no cap🎇

