KiLLERVMs (@killervms) 's Twitter Profile
KiLLERVMs

@killervms

The leading technology hub for training highly skilled cyber talents in Africa.
Founder @codedjeff

ID: 1676381785515606019

linkhttp://linktr.ee/killervms calendar_today05-07-2023 00:06:32

457 Tweet

715 Followers

46 Following

Fabian Bader (@fabian_bader) 's Twitter Profile Photo

NO-BREAK SPACE unicode characters in the display name are not something your average M365 users use. So better look into #Teams chat messages from those users. #SecurityTip #KQL github.com/f-bader/AzSent…

NO-BREAK SPACE unicode characters in the display name are not something your average M365 users use.

So better look into #Teams chat messages from those users.

#SecurityTip #KQL

github.com/f-bader/AzSent…
Tim De Keukelaere (@tim_dk) 's Twitter Profile Photo

❗️❗️❗️Important notification for Endpoint Admins ❗️❗️❗️ Impacts both win32 apps and scripts in Intune. Unfortunate timing combined with a very late notification - surely this could have been handled differently ... #microsoft #intune

❗️❗️❗️Important notification for Endpoint Admins ❗️❗️❗️

Impacts both win32 apps and scripts in Intune.

Unfortunate timing combined with a very late notification - surely this could have been handled differently ...

#microsoft #intune
Fabian Bader (@fabian_bader) 's Twitter Profile Photo

A good reminder that Defender for Identity is NOT Defender for Active Directory or Domain Controllers. It will help you protect your identities at multiple places.

KiLLERVMs (@killervms) 's Twitter Profile Photo

It's the last day of 2024 🎉 We're going to introduce you again to Microsoft 365. How to set up and manage an Intune environment. This playlist has been very helpful for our team, helping us train new members quickly. We hope it serves you... youtube.com/playlist?list=… HNY✨

spencer (@techspence) 's Twitter Profile Photo

I'm not sure who put this site together, but this PingCastle cheat sheet is awesome. If you're a PingCastle fan, definitely something to check out... pentesting.site/cheat-sheets/p… If anyone knows who this site belongs to, let me know so I can give a proper shout out!

Jai Minton (@cyberraiju) 's Twitter Profile Photo

This is really big at the moment and you should absolutely be looking at your M365 logs to identify this activity. speartip.com/fasthttp-used-… We're observing a large number of IPs involved after successful authentication, but a common IP is 113.23.43[.]76 CC:Huntress

Nathan McNulty (@nathanmcnulty) 's Twitter Profile Photo

I came up with a great workaround for not getting TenantAdmin alerts unless you've activated eligible roles in PIM! 🔥 I love Merill Fernando's use of plus addressing on admin accounts so we get alerts sent to our regular accounts, but it only works when roles are active So what do?

I came up with a great workaround for not getting TenantAdmin alerts unless you've activated eligible roles in PIM! 🔥

I love <a href="/merill/">Merill Fernando</a>'s use of plus addressing on admin accounts so we get alerts sent to our regular accounts, but it only works when roles are active

So what do?
KiLLERVMs (@killervms) 's Twitter Profile Photo

ManageEngine is hosting a FREE training with a certificate for their device management solution! This is for anyone interested in learning about IT service management and security. Register here manageengine.com/products/deskt…

Philip Elder (@mpecsinc) 's Twitter Profile Photo

Windows Server Reminder: Always Set the Network Location Awareness Service to Automatic (Delayed). That guarantees the service does not do its poll before the network stack is initialized putting the Windows Firewall into a limp lockdown mode with the Public Profile indicated.

KiLLERVMs (@killervms) 's Twitter Profile Photo

Another Free Microsoft certification for security professionals. introducing SC-401 As usual, it's for fastest fingers only techcommunity.microsoft.com/blog/Microsoft…

IAM!ERICA (@ericazelic) 's Twitter Profile Photo

To people who don't know M365: Entra ID Exchange Online + Protection Defender Suite of tools (there are at least 10 different ones) Teams SharePoint OneDrive Purview (8 more tool suites with different functionalities) Admin Center Apps Admin Center Intune Power Platform It

vx-underground (@vxunderground) 's Twitter Profile Photo

Regarding the BlackBasta leaks: we haven't reviewed them in totality yet. It's quite a bit of messages in JSON format. It also has some Russian slang which makes it difficult to translate accurately. Thankfully there are some native Russian speakers who have made some interesting

Peter van der Woude (@pvanderwoude) 's Twitter Profile Photo

New blog post: Easier managing account management modes for Windows LAPS petervanderwoude.nl/post/easier-ma… #MSIntune #Intune #EMS #MDM #Windows11 #WindowsLAPS #AccountManagement

New blog post: Easier managing account management modes for Windows LAPS
petervanderwoude.nl/post/easier-ma…
#MSIntune #Intune #EMS #MDM #Windows11 #WindowsLAPS #AccountManagement
notEricaZelic (@iamericabooted) 's Twitter Profile Photo

Please ask all your admins to watch! Microsoft will be rolling out the policy as Microsoft Managed soon. This is not like AITM. It doesn't not matter if users have phishing resistant auth. Federation does not matter. This provides long term persistent access without MFA.

Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

In the past, you had to: phish a user, drop malware, escalate privileges, pivot to servers, evade EDR, dump creds, move laterally, exfiltrate quietly, clean up, leave a backdoor. Today, you just: phish a user, steal an OAuth token, access everything from anywhere. Cloud

KiLLERVMs (@killervms) 's Twitter Profile Photo

We've been doing a deep dive into threat modeling recently. You should check this out if you're starting out in threat modeling. youtube.com/playlist?list=…

Philip Elder (@mpecsinc) 's Twitter Profile Photo

Remote Desktop Services RemoteApps RSS: The Seamless and Secure User Experience RDS has a RSS Feed built-in (pic 1). That feed is virtually device agnostic meaning _any_ device with a RDS App can hook into them. The RSS feed gets updated automatically at midnight every day. All

Remote Desktop Services RemoteApps RSS: The Seamless and Secure User Experience

RDS has a RSS Feed built-in (pic 1). That feed is virtually device agnostic meaning _any_ device with a RDS App can hook into them.

The RSS feed gets updated automatically at midnight every day. All
spencer (@techspence) 's Twitter Profile Photo

Delegated permissions in Active Directory: silent but deadly 💩💨🤢 For example: Some random user with “FullControl” of the Domain Controllers OU Nessus didn’t find it… The IT team didn’t know it was there… It wasn’t discovered on past pentests… 🧵I found it almost

Delegated permissions in Active Directory: silent but deadly 💩💨🤢  

For example: Some random user with “FullControl” of the Domain Controllers OU  

Nessus didn’t find it… 
The IT team didn’t know it was there… 
It wasn’t discovered on past pentests…  

🧵I found it almost