KQL: Audit of AD Service Account Password Rotation Compliance
This KQL query identifies all Active Directory service accounts with the PasswordNeverExpires attribute enabled. It evaluates whether these accounts comply with your organization's password rotation…
@shenetworks Infrastructure knowledge and communication skills are in very short supply. I'm doing consulting right now, and half my colleagues don't know anything about infra or networking. The other half wouldn't have the ability to talk to their own mother without melting from anxiety.
That was an interesting case about NTLM reflection but yeah, any machine that does not have th patch is vulnerable and it completely bypasses Channel Binding token (ie: we poced the relay from a ADCS server back to its fully HTTP web enroll endpoint and got the cert) pretty fun!
That was an interesting case about NTLM reflection but yeah, any machine that does not have th patch is vulnerable and it completely bypasses Channel Binding token (ie: we poced the relay from a ADCS server back to its fully HTTP web enroll endpoint and got the cert) pretty fun!
This is a great read, and it has some good mitigations listed
There are additional recommendations I would offer that I did not see mentioned, so I'll do my best to expound on this without giving away too much (you need to go read the article) :P
This is a great read, and it has some good mitigations listed
There are additional recommendations I would offer that I did not see mentioned, so I'll do my best to expound on this without giving away too much (you need to go read the article) :P https://t.co/xpDR1xbyGj
Şehidimiz Özkan Özkanlı’nın kardeşiyle birlikte yetim olarak büyüdüğü, öğretmenlerle konuşarak kendisi gibi yetim öğrencilere sözleşmeli maaşından sürekli harçlık gönderdiği ortaya çıktı.
Literally not an excuse:
1. Register a company abroad (US, UK, SG)
•Use Stripe Atlas to start a US LLC (Delaware)
•Or use StartGlobal, Firstbase, or Doola
•Costs ~$300–500 upfront + ~$100/year maintenance
•You’ll need a US bank account (they help with that)
2. Use Razorpay…
Literally not an excuse:
1. Register a company abroad (US, UK, SG)
•Use Stripe Atlas to start a US LLC (Delaware)
•Or use StartGlobal, Firstbase, or Doola
•Costs ~$300–500 upfront + ~$100/year maintenance
•You’ll need a US bank account (they help with that)
2. Use Razorpay…
This script I am working on will be like FBI Watchdog, but for WHOIS changes. It will save previous information and update when a new change is made. It is still early, so nothing but code to show for it.
29K Followers 206 FollowingHacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
2K Followers 1K FollowingICS/OT posts from a GICSP. ISA member working on ISA 62443 Certs. Canadian.
My posts are my own and are not a reflection of my place of work or employer.
10K Followers 6 FollowingBringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://t.co/D5Mco1u8zM
31K Followers 570 FollowingConsultant for InfoSec Innovations | @SANSInstitute Principal Instructor | @IANS_Security Faculty | I like information security. How about you?
5K Followers 2K FollowingRemote desktop protocol expert, OSS contributor and Microsoft MVP. I love designing products with Rust, C# and PowerShell. Proud to be CTO at Devolutions. 🇨🇦
9K Followers 334 FollowingReverse engineer, creator of @x64dbg and 100+ other projects. Love binary analysis and Windows internals. Dreaming about doing open source full time...
333K Followers 2K FollowingIndependent investigative journalist. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter. Mastodon: https://t.co/fTKNavlMwp
2K Followers 748 Followingsecurity, for the internet, at @wiz_io!
opinionated about security.
(he/him) @[email protected], bsky=https://t.co/fxycKAqA6t
8K Followers 151 FollowingFor contact in the security community. NOTE: All the tweets are totally my personal opinions, not about any of my current employer stuff.
875 Followers 71 FollowingAn open-eyed man falling into the well of weird warring state machines. I talk about reverse engineering, vulnerability research and exploit development.