Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile
Eric Woodruff | MVP | CIDPRO

@ericonidentity

Security researcher @SemperisTech. Microsoft Security MVP, Entra nerd. Part-time hiker, full-time dad and partner. Opinions expressed are from my cat.

ID: 905958958254448641

linkhttp://ericonidentity.com calendar_today08-09-2017 01:00:22

1,1K Tweet

1,1K Takipçi

703 Takip Edilen

Clate (@clatent) 's Twitter Profile Photo

Created an interactive web version of EntraFIDOFinder now too as well as updated the module. Made a quick blog post it, let me know your thoughts. clatent.com/2024/10/entraf… #PowerShell #MicrosoftEntra #Security

Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile Photo

I propose that CyberRisk Alliance would better serve their speakers if they didn’t give out speaker contact information to vendors. It takes a lot of time to prepare for big conferences… and the payment is “sorry we missed you” spam from vendors 🙄

Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile Photo

Redmond bound for Microsoft BlueHat, co-presenting with Cam “The Two Sides of UnOAuthorized” 😎 It will be my sixth trip out to the PNW - one of my favorite parts of the country to visit, so I’m excited for many reasons!

Redmond bound for <a href="/MSFTBlueHat/">Microsoft BlueHat</a>, co-presenting with <a href="/SecretlyHidden1/">Cam</a> “The Two Sides of UnOAuthorized” 😎

It will be my sixth trip out to the PNW - one of my favorite parts of the country to visit, so I’m excited for many reasons!
Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile Photo

En route to #HIPConf24, where I’ll be presenting on #UnOauthorized, as well as joining a panel with Thomas Naunheim, Gil Kirkpatrick, Guido Grillenmeier and Sean Deuby on workload identities, and having some good hallway conversations. Looking forward to seeing folks! #Entra #infosec

En route to #HIPConf24, where I’ll be presenting on #UnOauthorized, as well as joining a panel with <a href="/Thomas_Live/">Thomas Naunheim</a>, <a href="/gkirkpatrick/">Gil Kirkpatrick</a>, <a href="/GGrillen/">Guido Grillenmeier</a> and <a href="/shorinsean/">Sean Deuby</a> on workload identities, and having some good hallway conversations. Looking forward to seeing folks!

#Entra #infosec
Cyber Saiyan | RomHack Conference, Training, Camp (@cybersaiyanit) 's Twitter Profile Photo

Curious about the sessions you missed at #RomHack2024 this year? Here you go: Eric Woodruff | MVP | CIDPRO - UnOAuthorized: The discovered path to privilege elevation Find a schedule that works for you and start watching 👉 youtube.com/watch?v=JQOVPA…

Andrea Pierini (@decoder_it) 's Twitter Profile Photo

M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/Krb…

M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx
A  Kerberos relay &amp; forwarder for MiTM attacks! 
&gt;Relays Kerberos AP-REQ tickets 
&gt;Manages multiple SMB consoles 
&gt;Works on Win&amp; Linux with .NET 8.0
&gt;...
GitHub: github.com/decoder-it/Krb…
Trimarc (@trimarcsecurity) 's Twitter Profile Photo

Wednesday, December 11th, Trimarc Active Directory Security Assessment Service Lead Jake Hildreth joins the Antisyphon Training crew for a free one-hour #infosec training session on: 🔒 Finding and Fixing AD CS Issues with Locksmith Jake will cover the essentials of Public Key

Wednesday, December 11th, Trimarc Active Directory Security Assessment Service Lead Jake Hildreth joins the <a href="/Antisy_Training/">Antisyphon Training</a> crew for a free one-hour #infosec training session on:

🔒 Finding and Fixing AD CS Issues with Locksmith

Jake will cover the essentials of Public Key
Dr. Nestori Syynimaa (@drazuread) 's Twitter Profile Photo

New #AADInternals version is finally out now: ▪ Moved endpoint related stuff to new module: AADInternals-Endpoints ▪ Added blue team stuff: Get app consent info, find backdoors, convert SID<>Entra ID Object ID, find abusable dynamic groups ▪ Added red team stuff: Get ESTSAUTH

New #AADInternals version is finally out now:
▪ Moved endpoint related stuff to new module: AADInternals-Endpoints
▪ Added blue team stuff: Get app consent info, find backdoors, convert SID&lt;&gt;Entra ID Object ID, find abusable dynamic groups
▪ Added red team stuff: Get ESTSAUTH
%TEMP% (@temp43487580) 's Twitter Profile Photo

I finished my talk at BHEU! The attack methods and techniques shared in the talk are not a great deal, but I hope this serves as an opportunity to draw attention to the importance of security measures for Intune. Here is the tool released for the talk. github.com/secureworks/py…

SpecterOps (@specterops) 's Twitter Profile Photo

Check out this new blog post from Andy Robbins discussing the fundamental components & mechanics that enable the emergence of critical Attack Paths in Microsoft's increasingly popular Intune product. ⬇️ ghst.ly/3Cd5cwH

Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile Photo

If you consume multi-tenant apps in #EntraID, and they’ve been granted consent to do things in your tenant, you can spy on the auth choices your vendor makes - secrets or certs - in the logs available in your #Entra tenant. #infosec #azure #m365 ericonidentity.com/2025/01/13/spy…

Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile Photo

If you work in, around, near, adjacent, or so on, to #identity, including #infosec and #Entra, you should fill out the #IDPro skills survey. It takes five minutes and really helps in understanding the industry landscape. surveymonkey.com/r/L9QB6T2