Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile
Daniel Chronlund | Security MVP

@danielchronlund

Microsoft Security MVP, Microsoft 365 security expert, blogger, and consultant at Truesec.

ID: 1063861819947843584

linkhttp://danielchronlund.com calendar_today17-11-2018 18:29:58

690 Tweet

2,2K Followers

295 Following

Kyle Alspach (@kylealspach) 's Twitter Profile Photo

New - I attempted to boil down the key things businesses should be looking at when it comes to stopping identity-based attacks: protocol.com/manuals/securi… w/ commentary from Vasu Jakkal Todd McKinnon Rachel Tobac Mark McClain Dr. Nestori Syynimaa David Weston (DWIZZZLE) & many more

Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

I've updated my #AzureAD stale accounts report tool in DCToolbox to take non-interactive sign-ins into consideration. Also, you can now filter the report by adding -OnlyGuests or -OnlyMembers. Install/update DCToolbox with 'Install-Module -Name DCToolbox -Force' to get started!

I've updated my #AzureAD stale accounts report tool in DCToolbox to take non-interactive sign-ins into consideration. Also, you can now filter the report by adding -OnlyGuests or -OnlyMembers.

Install/update DCToolbox with 'Install-Module -Name DCToolbox -Force' to get started!
Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

Exactly one year ago today, I wrote this blog post about removing telecom based #MFA factors from #AzureAD. With rising numbers of MFA targeted attacks, we all need to look at implementing phishing resistent MFA methods like #FIDO2 instead. danielchronlund.com/2021/10/07/azu…

Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

Use #MicrosoftSentinel #UEBA and #DefenderForCloudApps to hunt for recent tenant cloud app activity originating from, by Microsoft, known bad IP addresses (botnets, anonymization services...). Check out the latest hunting queries in #DCSecurityOperations: danielchronlund.com/2022/10/03/sen…

Use #MicrosoftSentinel #UEBA and #DefenderForCloudApps to hunt for recent tenant cloud app activity originating from, by Microsoft, known bad IP addresses (botnets, anonymization services...). Check out the latest hunting queries in #DCSecurityOperations: danielchronlund.com/2022/10/03/sen…
Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

I'm happy to announce that my #MicrosoftSentinel #MicrosoftDefender 'Attack Surface Reduction Dashboard' is now included in Sentinel. You'll find it in your Sentinel workspace today under Workbooks > Templates!

I'm happy to announce that my #MicrosoftSentinel #MicrosoftDefender 'Attack Surface Reduction Dashboard' is now included in Sentinel. You'll find it in your Sentinel workspace today under Workbooks > Templates!
Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

I've just updated my #MicrosoftSentinel repo with some new #threathunting queries for #MicrosoftDefender (and some improvements to existing queries), based on the recent incident deep dives posted by Microsoft Detection and Response Team (DART). danielchronlund.com/2022/10/03/sen…

Fabian Bader (@fabian_bader) 's Twitter Profile Photo

📢 My latest blog on Sentinel 🛡️ Integrate your #Microsoft Defender for Identity health alerts into #Sentinel incidents and use custom alert mapping to make you live easier. #MDI #MDO #M365D #Security cloudbrothers.info/en/integrate-m…

Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

A somewhat different blog post for me where I share some thoughts on #Microsoft #cloudsecurity in 2023. danielchronlund.com/2023/01/25/a-s…

Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

My latest blog post is a proof of concept of how poorly protected #AzureAD app permissions can be used in a data exfiltration #cybersecurity attack. I’ve added a new tool to my DCToolbox PowerShell module called Invoke-DCM365DataExfiltration. Interested? danielchronlund.com/2023/02/09/mic…

Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

I'm currently investigating the potential threat of #Microsoft365 wiper #malware. Simulate an attack with 'Invoke-DCM365DataWiper' today, and take precautions in your #AzureAD tenant! danielchronlund.com/2023/02/14/the…

Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

I've added a simple tool to #DCToolbox to quickly request a refresh token from #AzureAD using the OAuth 2.0 device code flow. For me, the clipboard integration is the killer feature! Install/update with 'Install-Module -Name DCToolbox -Force'

I've added a simple tool to #DCToolbox to quickly request a refresh token from #AzureAD using the OAuth 2.0 device code flow. For me, the clipboard integration is the killer feature! Install/update with 'Install-Module -Name DCToolbox -Force'
Daniel Chronlund | Security MVP (@danielchronlund) 's Twitter Profile Photo

#AzureAD PIM makes it possible to configure activation and expiration settings on a per-role basis. Read my latest blog post for some cool PowerShell role automation based on role impact :) danielchronlund.com/2023/06/21/aut…

#AzureAD PIM makes it possible to configure activation and expiration settings on a per-role basis. Read my latest blog post for some cool PowerShell role automation based on role impact :)

danielchronlund.com/2023/06/21/aut…