Ryan (@haus3c) 's Twitter Profile
Ryan

@haus3c

Professional Microsoft documentation decoder (MDD).

ID: 4212826813

linkhttps://hausec.com/ calendar_today12-11-2015 13:25:14

1,1K Tweet

6,6K Followers

347 Following

Karl (@kfosaaen) 's Twitter Profile Photo

As a follow up on this thread, we have a new NetSPI blog out today that explains how we were able to get the App Registration certificates for Managed Identities that were attached to Linux Function App containers. netspi.com/blog/technical…

Ryan (@haus3c) 's Twitter Profile Photo

This is quite frustrating. When viewing managed identity sign in logs via portal, the time stamp differs from Log Analytics. Por que? This fucks with some detection logic I have :(. I know one is in UTC time, but specifically the minute & seconds shouldn't be different.

This is quite frustrating. When viewing managed identity sign in logs via portal, the time stamp differs from Log Analytics. Por que? This fucks with some detection logic I have :(. I know one is in UTC time, but specifically the minute & seconds shouldn't be different.
Ryan (@haus3c) 's Twitter Profile Photo

While working at Microsoft, it was somewhat frowned upon to call the baby (Azure logs) ugly. But now I get to call it like it is, so I wrote about trying to make the most out of basically nothing trustoncloud.com/an-attempt-at-…

DebugPrivilege (@debugprivilege) 's Twitter Profile Photo

Very happy to see Shiva P from Microsoft DART blogging about this topic on how to hunt in Graph API logs. Shiva P will also present this topic at OrangeCon so make sure to check it out! He's a great guy and I'm happy for him! techcommunity.microsoft.com/t5/microsoft-s…

Prelude (@preludeorg) 's Twitter Profile Photo

Test-driven development—not just for software engineering. Matt Hand breaks down how applying this logic streamlines how you execute, evaluate, and iterate on your detections to better augment your defensive coverage hubs.la/Q02W9xs80

Test-driven development—not just for software engineering. 

<a href="/matterpreter/">Matt Hand</a> breaks down how applying this logic streamlines how you execute, evaluate, and iterate on your detections to better augment your defensive coverage

hubs.la/Q02W9xs80
Karl (@kfosaaen) 's Twitter Profile Photo

New NetSPI blog out today on "Hijacking Azure Machine Learning Notebooks (via Storage Accounts)". This is very similar to Storage Account attacks that have been done against Function/Logic Apps and Cloud Shell - netspi.com/blog/technical…

Dirk-jan (@_dirkjan) 's Twitter Profile Photo

It's been almost a year since my last blog... So, here is a new one: Extending AD CS attack surface to the cloud with Intune certificates. Also includes ESC1 over Intune (in some cases). dirkjanm.io/extending-ad-c… Oh, and a new tool for SCEP: github.com/dirkjanm/scepr…

Dirk-jan (@_dirkjan) 's Twitter Profile Photo

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…