Doug Bienstock(@doughsec) 's Twitter Profileg
Doug Bienstock

@doughsec

IR Leader @Mandiant. Hacking things and responding to things being hacked. Opinions my own

ID:966781971425910784

calendar_today22-02-2018 21:09:18

488 Tweets

2,5K Followers

115 Following

Doug Bienstock(@doughsec) 's Twitter Profile Photo

Audit log query graph API for Microsoft 365 rolling out in May. Has anyone found the actual documentation for the new API? Asking for a friend πŸ’€

account_circle
PIVOTcon(@pivot_con) 's Twitter Profile Photo

'Microsoft Signed my Malware'

Doug Bienstock (Jared Wilson), Mandiant
Jared Wilson (@doughsec) , Mandiant
Barry Vengerik (@BarryV), Mandiant 14/15

'Microsoft Signed my Malware' Doug Bienstock (@JWilsonSecurity), Mandiant Jared Wilson (@doughsec) , Mandiant Barry Vengerik (@BarryV), Mandiant 14/15
account_circle
Doug Bienstock(@doughsec) 's Twitter Profile Photo

🚨 NetScaler vulnerability CVE-2023-4966 is being actively exploited. It can lead to VDI session hijacking, including MFA bypass. There are no logs on the appliance to monitor for exploitation. Upgrade now and investigate your environment!

mandiant.com/resources/blog…

account_circle
Doug Bienstock(@doughsec) 's Twitter Profile Photo

Today we launched a πŸ”Ž scanning tool for orgs to search their Citrix netscalers for evidence of CVE-2023-3519 post-exploration. You can run this direct on the ADC or against a forensic image. With public POCs out there expect more exploitation!

mandiant.com/resources/blog…

account_circle
Doug Bienstock(@doughsec) 's Twitter Profile Photo

The alternate title was 'What's attestation signing? It's about certs, it's about trust babe'
A Microsoft-signed malicious driver we discovered during an IR turned up quite a bit more badness after some hunting by our threat intel team:
mandiant.com/resources/blog…
Mandiant

account_circle
Doug Bienstock(@doughsec) 's Twitter Profile Photo

Testing out Microsoft Entra ID (Azure AD) Authentication Strength Conditional Access.. what am I doing wrong here? All conditions satisfied but policy result fails, love it

Testing out @azuread Authentication Strength Conditional Access.. what am I doing wrong here? All conditions satisfied but policy result fails, love it #Microsoft365
account_circle
Doug Bienstock(@doughsec) 's Twitter Profile Photo

πŸ™€ ADFS Malware hot off the presses attributed to /
Instead of Golden SAML why not embed code to look for a magic value during claims processing that allows you to obtain a Security Token for any user and add in an MFA claim to boot?

account_circle
Roberto Rodriguez πŸ‡΅πŸ‡ͺ(@Cyb3rWard0g) 's Twitter Profile Photo

Dr. Nestori Syynimaa βš™ Rev - Infra & Supply Chain Technician β›ˆπŸ“¦πŸ› οΈ The 'bypassMFA' param sets a federated token claim saying MFA already happened.

ICYDK, there's a setting to ensure that AAD MFA is always performed & rejects MFA if performed by identity provider

federatedIdpMfaBehavior -> rejectMfaByFederatedIdp

docs: docs.microsoft.com/en-us/windows-…

@DrAzureAD @ManuelBerrueta The 'bypassMFA' param sets a federated token claim saying MFA already happened. ICYDK, there's a setting to ensure that AAD MFA is always performed & rejects MFA if performed by identity provider federatedIdpMfaBehavior -> rejectMfaByFederatedIdp docs: docs.microsoft.com/en-us/windows-…
account_circle
Doug Bienstock(@doughsec) 's Twitter Profile Photo

πŸŽ‰ This is a huge feature all orgs should be using. All of my recent M365 IRs (BEC, UNC and APT) have started with the TA registering the first MFA for a dormant 😴 account.

account_circle
Merill Fernando(@merill) 's Twitter Profile Photo

Platform single sign on is coming to macOS!

What does this mean? Users can now sign into a mac with their AD/Azure AD credentials just like Windows users.

Users will then get single sign on to ALL THE APPS with a PRT token just like on Windows.

See techcommunity.microsoft.com/t5/microsoft-e…

Platform single sign on is coming to macOS! What does this mean? Users can now sign into a mac with their AD/Azure AD credentials just like Windows users. Users will then get single sign on to ALL THE APPS with a PRT token just like on Windows. See techcommunity.microsoft.com/t5/microsoft-e…
account_circle