Tech Brandon (@techbrandon) 's Twitter Profile
Tech Brandon

@techbrandon

Father. Engineer. Learner. Lurker. AD, Entra/Azure & enterprise security specialist. Senior Security Consultant @trustedsec. Fellow Human Being.

ID: 362887462

calendar_today27-08-2011 04:27:50

2,2K Tweet

1,1K Followers

371 Following

Tech Brandon (@techbrandon) 's Twitter Profile Photo

Interesting topic I've been asked about a few times. My take? It's more trouble than it's worth for most orgs and I'm concerned about privesc from app admin and cloud app admin.

Tech Brandon (@techbrandon) 's Twitter Profile Photo

Viewing Entra Connect config info such as PHS now requires GA. 👎 PowerShell and Graph API are similarly affected. LMK if you find a way to collect this info with read-only access.

Viewing Entra Connect config info such as PHS now requires GA. 👎 PowerShell and Graph API are similarly affected. LMK if you find a way to collect this info with read-only access.
Tech Brandon (@techbrandon) 's Twitter Profile Photo

I'm hanging with the Red Siege crew in 30m. Come say hi as I ramble about Conditional Access exploitation and defense. redsiege.com/wedoff

St. Baldrick's Foundation (@stbaldricks) 's Twitter Profile Photo

Give moms - especially those fighting beside their child with cancer - the greatest gift this Mother’s Day: a cure. Become a monthly donor or make a one-time gift today: ow.ly/IKmI50VMkIi For every mom, this cure is for you. ❤️

Give moms - especially those fighting beside their child with cancer - the greatest gift this Mother’s Day: a cure. Become a monthly donor or make a one-time gift today: ow.ly/IKmI50VMkIi

For every mom, this cure is for you. ❤️
Tech Brandon (@techbrandon) 's Twitter Profile Photo

If you aren't already following Nathan, you're totally missing out. Probably half of my twitter engagement is connected to him in some way. I could not recommend anyone more.

TrustedSec (@trustedsec) 's Twitter Profile Photo

We just held our first conference at our global HQ and we can't wait to do it again 😃 SmileyCon was a huge success. Thanks to everyone who attended and helped make it a reality!

spencer (@techspence) 's Twitter Profile Photo

Delegated permissions in Active Directory: silent but deadly 💩💨🤢 For example: Some random user with “FullControl” of the Domain Controllers OU Nessus didn’t find it… The IT team didn’t know it was there… It wasn’t discovered on past pentests… 🧵I found it almost

Delegated permissions in Active Directory: silent but deadly 💩💨🤢  

For example: Some random user with “FullControl” of the Domain Controllers OU  

Nessus didn’t find it… 
The IT team didn’t know it was there… 
It wasn’t discovered on past pentests…  

🧵I found it almost
Red Siege Information Security (@redsiege) 's Twitter Profile Photo

24 Hour Reminder! The Wednesday Offensive is tomorrow at 130pm ET! Join the Conversation 🔗 redsiege.com/wedoff #hacking #infosec #cybersecurity

24 Hour Reminder! The Wednesday Offensive is tomorrow at 130pm ET! Join the Conversation 🔗 redsiege.com/wedoff   

#hacking #infosec #cybersecurity
notEricaZelic (@iamericabooted) 's Twitter Profile Photo

Do you know how many Graph API permissions Microsoft documents as low risk as of the last time I read the docs? Less than 5. Think about that.

nyxgeek (@nyxgeek) 's Twitter Profile Photo

Justin Elze Deja vu! Password sprays ftw, AGAIN! Wow, if only there was SOME WAY to make it harder for the baddies to identify valid users in Azure. Too bad it couldn't possibly be an EXTREMELY simple fix, like disabling verbose error codes. 🙄

<a href="/HackingLZ/">Justin Elze</a> Deja vu! Password sprays ftw, AGAIN!

Wow, if only there was SOME WAY to make it harder for the baddies to identify valid users in Azure.

Too bad it couldn't possibly be an EXTREMELY simple fix, like disabling verbose error codes. 🙄
rootsecdev (@rootsecdev) 's Twitter Profile Photo

If you are coming to BlackHat this year and are looking for a blend of offensive tradecraft with a mix of threat hunting training, this is hands down one of the best classes for that. #TrustedSec ADVERSARY TACTICS AND THREAT HUNTING blackhat.com/us-25/training…

Nathan McNulty (@nathanmcnulty) 's Twitter Profile Photo

It looks like Okta finally added support for Entra External Authentication Method (EAM)! 🎉 help.okta.com/oie/en-us/cont… This allows Okta Verify to meet Conditional Access "Require MFA" requirements, no more custom controls! So let's do a thread on how to set this :)

It looks like Okta finally added support for Entra External Authentication Method (EAM)! 🎉

help.okta.com/oie/en-us/cont…

This allows Okta Verify to meet Conditional Access "Require MFA" requirements, no more custom controls!

So let's do a thread on how to set this :)