Jerrad ⚾™ (@j_dahl9) 's Twitter Profile
Jerrad ⚾™

@j_dahl9

• Believer 🙌🏻 • Husband🤵🏻‍♂️ • Sports Fanatic ⚾ • Crazy Cat Lover 🐈 • Psalm 23 ✞ • Minnesota sports for life

ID: 147637667

calendar_today24-05-2010 17:12:38

3,3K Tweet

358 Followers

559 Following

Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

I have made my first ever Microsoft community post, and I want to thank Prajwal Desai for being such an incredible mentor and friend. Thank you for all you do for the Microsoft community, and I am so happy to be a part of your community and team. #community #microsoft #team

Josh Stroschein | The Cyber Yeti (@jstrosch) 's Twitter Profile Photo

🎙️ Latest episode of the podcast is now live! Pavel Yosifovich Pavel Yosifovich is here to talk Windows and how his authoring Windows Internals was a fluke... open.spotify.com/episode/2ylz9J…

Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

Nine Lives, Zero Trust is live. 🚀 I write about cloud security & the stuff that keeps defenders up at night. Three cats taught me nothing should be trusted, especially at 3 AM. nineliveszerotrust.com #CloudSecurity #InfoSec #ZeroTrust #DevSecOps

Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

A common Terraform misconception: sensitive redacts output, not state. sensitive=true only redacts output. Secrets still end up in state/plan files. 1.11’s write-only args fix this. Hands-on guide with AWS + Azure examples nineliveszerotrust.com/blog/terraform… #CloudSecurity #DevSecOps

A common Terraform misconception: sensitive redacts output, not state.

sensitive=true only redacts output. Secrets still end up in state/plan files.
1.11’s write-only args fix this. 

Hands-on guide with AWS + Azure examples

nineliveszerotrust.com/blog/terraform…

#CloudSecurity #DevSecOps
Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

No keys to rotate. No secrets to leak. New post: Container supply chain security with GitHub Actions - vuln scanning, SBOM generation, keyless signing, and SLSA provenance. Stack: Trivy, Syft, Cosign + Sigstore. Blog + repo: nineliveszerotrust.com/blog/container… #DevSecOps #infosec

Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

Microsoft’s Sentinel MCP Server went GA. The attack surface is real. Sentinel logs contain attacker-influenced fields like email subjects, command lines, and user agents. When AI processes this data, prompt injection becomes possible. I put together a walkthrough covering

Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

New blog post: Building a serverless edge prompt filter for LLM security Catches injection attacks + PII at the edge before semantic analysis. One layer in defense-in-depth. nineliveszerotrust.com/blog/llm-promp… #AISecurity #AWS

New blog post: Building a serverless edge prompt filter for LLM security

Catches injection attacks + PII at the edge before semantic analysis. One layer in defense-in-depth.

nineliveszerotrust.com/blog/llm-promp…

#AISecurity #AWS
Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

Azure PIM solves just-in-time access for humans. I wanted to bring that same pattern to non-human identities. PIM handles just-in-time access for humans. For non-human identities like AI coding agents, backup automation, and CI/CD pipelines, it breaks down. Service principals

Azure PIM solves just-in-time access for humans. I wanted to bring that same pattern to non-human identities.

PIM handles just-in-time access for humans. For non-human identities like AI coding agents, backup automation, and CI/CD pipelines, it breaks down. Service principals
Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

Microsoft is rolling out two Entra ID changes this spring that take effect automatically. Passkey profiles move to GA in March. Tenants that do not opt in will be auto-migrated starting in April (through late May for Worldwide, late June for GCC/GCC High/DoD). If attestation is

Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

OAuth redirect abuse in Entra ID is worth watching. New post with 4 Sentinel detections, hunting queries, and hardening steps: nineliveszerotrust.com/blog/oauth-red… #EntraID #OAuth #MicrosoftSentinel

Jerrad ⚾™ (@j_dahl9) 's Twitter Profile Photo

I deployed Microsoft Entra Prompt Shield and tested it against real jailbreak payloads on ChatGPT and Gemini. Adversarial prompts blocked at the network layer before reaching the model. nineliveszerotrust.com/blog/prompt-sh… #AISecurity #PromptInjection #ZeroTrust