Rime   ๐Ÿ‡จ๐Ÿ‡ฆ   ๐Ÿณ๏ธโ€๐ŸŒˆ's Avatar

Rime ๐Ÿ‡จ๐Ÿ‡ฆ ๐Ÿณ๏ธโ€๐ŸŒˆ

@rime1313.bsky.social

Cybersecurity consultant, Microsoft Security Expert๐Ÿ‡จ๐Ÿ‡ฆ

241 Followers  |  815 Following  |  40 Posts  |  Joined: 10.11.2024  |  1.7314

Latest posts by rime1313.bsky.social on Bluesky

Thank you! will give it try but will also recommend signing scripts

21.05.2025 02:23 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thank you!
But wouldn't the execution itself be subject to the restriction? Meaning the command to set it as unrestricted will not even be evaluated because it is in effect restricted or am I wrong?

21.05.2025 00:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

How would you handle using Intune remediation scripts in an env where there's a GPO that sets the powershell execution policy to Restricted. Is there a way to only allow IME?
Any thoughts @nathanmcnulty.com

19.05.2025 19:09 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Yes please ๐Ÿ™‚

07.05.2025 11:09 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

You're right and I will use "one incident is more expensive"!
My biggest concern is that the allow personal devices is implicit and for everyone regardless of what they access
Going to propose a deeper review based on criticality
Thanks again! I knew I needed your opinion๐Ÿ™‚

13.02.2025 18:56 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Agreed, but how would you handle a customer with thousands of users that travel constantly, are not issued a corp device and rely on M365 and custom apps to work?
I am still trying to convince them to do MAM

13.02.2025 11:41 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

This was a fun question, and I think it might be helpful for others to show how I researched it

To start, I already knew this wasn't exposed in data exported by diagnostic settings or anything we could query with KQL, but that would have been a good first place to check :)

01.01.2025 23:49 โ€” ๐Ÿ‘ 9    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

I use the ZSA Voyager, have been for over a year and I cannot go back. It is worth it to go through the learning curve of proper typing. And to taje the time to configure shortcuts and layers, especially to replace the mouse
I do not use a mouse anymore it it has help greatly with shoulder pain.

17.12.2024 09:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Hmm this is a good lead to follow! need to go check thanks again ๐Ÿ˜Š

13.12.2024 01:57 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

So I checked the folder and for the issue servers there's nothing special. Comparing to the only server there are Jason files missing related to the policies
I have an open ticket with support.I am at loss here hopefully they'll be able to help๐Ÿ˜Š

12.12.2024 23:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image Post image Post image


Check out my Azure workbook, "Storage Account Security Posture" on GitHub github.com/laythchebbi/...
It provides an overview of security configurations for storage accounts in your Azure environment.
#azure #security #workbook #microsoft #storageaccount

12.12.2024 11:34 โ€” ๐Ÿ‘ 13    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Could you please repost the link it is giving a 404

12.12.2024 11:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thank you for the tip will check the folder and report back

12.12.2024 02:35 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Yes all is correctly created group targeted MDE ClientAnalyser not showing any issue servers are 2016 (and thank you)

11.12.2024 21:06 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@nathanmcnulty.com
Please I some #MDE help, servers are onboard and show in defender portal as managed by MDE AV policies set via Intune are not being pushed no error or conflict just nothing and its not a comm issue btw MDE and Intune any ideas?

11.12.2024 18:24 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

"He who has the 'why' to live can bear almost any 'how' *

08.12.2024 05:11 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@shiroishi.bsky.social do you do commissions?

03.12.2024 21:05 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
nathanmcnulty/Intune/auto-update-eac-apps.ps1 at master ยท nathanmcnulty/nathanmcnulty Contribute to nathanmcnulty/nathanmcnulty development by creating an account on GitHub.

I realize hardly anyone is using Enterprise App Catalog yet, and this may eventually be built in... but it was bugging me that apps don't automatically update to the latest version available :-/

So I created an automation to do just that! ๐Ÿค“

github.com/nathanmcn...

03.12.2024 08:04 โ€” ๐Ÿ‘ 17    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
mattias.engineer Book release ๐ŸŽ‰ Book Release: Terraform Authoring and Operations Professional Study Guide (AWS edition) 2 October 2024ยท212 wordsยท1 min Book Terraform Aws

Shameless self-promotion of my blog ๐Ÿšจ

I write about #Terraform, #Boundary, #Vault, #Azure, #AWS, and other things and technologies I find interesting!

Highly recommended by me (๐Ÿ”Ÿ out of ๐Ÿ”Ÿ) and at least one other person who clicked the "Buy me a coffee button". Thanks Eric! ๐Ÿ™

mattias.engineer

10.11.2024 15:50 โ€” ๐Ÿ‘ 9    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The Answer is your question Andrew your are a community person ๐Ÿ™

02.12.2024 12:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Azure Infiltrated: How Attackers Exploit Misconfigured Environments to Breach Data and Cause Damage Introduction Cloud computing has become increasingly popular among enterprises, corporations, and individuals, providing an easy way to deploy projects without the need for infrastructure maintenance,...

Ever wondered how attackers exploit misconfigured Azure environments? I've created a step-by-step lab to show exactly how breaches happen and how to prevent them!
Read now ๐Ÿ‘‰ laythchebbi.com/index.php/20...
#azure #cloudcecurity #microsoft #cyberchreats #cyberSecurity #datasecurity #infosec

28.11.2024 20:27 โ€” ๐Ÿ‘ 7    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Finding out that #NeveGallus in #DragonAge #TheVeilguard was voiced by non other than Jessica Clark!
There. I rest my case.
#TeamNeve

24.11.2024 21:14 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Just finished #DragonAge #TheVeilguard what am emotional journey. My withdrawal is going to be tough. Thank you @briannebattye.bsky.social for writing such a great storyline and making me fall in love with #NeveGallus

24.11.2024 18:43 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I do not like the new #Teams chat experience one bit! It is messed up! I dislike how all messages in the thread are aligned left!

24.11.2024 16:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

And I think we have a winner!

24.11.2024 12:49 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I think I like Streak!

24.11.2024 02:26 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

Here's the new good boy looking for a fitting name #Caturday

23.11.2024 23:05 โ€” ๐Ÿ‘ 169    ๐Ÿ” 5    ๐Ÿ’ฌ 23    ๐Ÿ“Œ 0
Preview
Privilege escalation using Azure Service principal Introduction In Microsoft Azure, the management of access and permissions is critical for maintaining a secure environment. Azure Service Principals serve as non-human identities that allow applicatio...

In this blog post i breaks down how attackers can exploit and abuse service principals and what you can do to defend against it.
Check it out here:
laythchebbi.com/index.php/20...
#AzureSecurity #PrivilegeEscalation #OffensiveSecurity #CloudSecurity #Cybersecurity

21.11.2024 10:35 โ€” ๐Ÿ‘ 24    ๐Ÿ” 9    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The link does not work if you could cleck please

21.11.2024 10:48 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Genuine question: Bluesky being open source and all how do they monitize the platform? How do they pay for hosting de maintenance etc?

20.11.2024 12:25 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

@rime1313 is following 19 prominent accounts