Hello token friends, do you use the content of the access token as part of your application. Then be aware that Microsoft will switch to encrypted access token and this might break stuff.
Switch to id token. #EntraID
https://devblogs.microsoft.com/identity/access-tokens-and-id-tokens/
21.01.2025 18:30 β π 16 π 11 π¬ 2 π 1
Do you know the Azure IP Ranges site by @derdanu.bsky.social ?
It's a great tool to filter IP ranges by service and even download them in different formats.
https://azureipranges.azurewebsites.net/
04.12.2024 18:24 β π 19 π 5 π¬ 2 π 0
Had not see this before. What could go wrong if you allow any user to create mailboxes with nearly arbitrary name ?!
Seen via @jangeisbauer.bsky.social, thanks for sharing!
References
- www.linkedin.com/posts/jangei...
- www.cyberis.com/article/micr...
- jeffreyt.nl/2024/taking-...
05.12.2024 10:48 β π 1 π 0 π¬ 0 π 0
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx
A Kerberos relay & forwarder for MiTM attacks!
>Relays Kerberos AP-REQ tickets
>Manages multiple SMB consoles
>Works on Win& Linux with .NET 8.0
>...
GitHub: github.com/decoder-it/K...
25.11.2024 17:31 β π 63 π 43 π¬ 3 π 0
Principal Windows Security Researcher @HuntressLabs | Windows Internals & Telemetry Research
System Administrator | Ex-MSFT | Microsoft MVP in Windows and Devices | Interested in Security, Debugging, and Windows Internals. Tweets are my own.
Penetration Testing, Red Teaming, Incident Response, Managed Detection, Digital Forensics, Security Training, Managed Bug Bounty, Cyber Training Range
Red Teaming. Security Research. Continuous Penetration Testing. Threat Intelligence.
Trying to find a path in the fog.
Principal Program Manager, Microsoft. Azure Stack HCI/Windows Server/Hybrid Cloud. He/Him. Posts are mine and don't represent my company. πΊπΈ π΅π¦
By the power of truth, I, while living, have conquered the universe - /OS(C(P|E)|EE)/ -- Red teamer @codewhitesec.bsky.social | @dhn@infosec.exchange | @dhn_ on X
Pwn2Own 20{22,23,24,24.5}, i look for 0-Days but i find N-Days & i chase oranges π
https://summoning.team/
CEO, CISO, Trainer, Hacker, and Speaker.
AI + hacking + sec leadership.
ex:BuddoBot-Ubisoft-Bugcrowd-Fortify-HP-Redspin-Citrix.
Liking colors, π©Έbeing my favorite but also a bit into π§’ with the occasional βοΈ | head of red team at @codewhitesec - @niph_ on X
Targeted Ops @TrustedSec. Hacker of things, writer of bad code. This is our world now... the world of the electron and the switch, the beauty of the baud.
https://linktr.ee/two06
Senior Security Consultant @ Mandiant (part of Google Cloud). Messages attributable to me β not current or former employers. Honneur de vous rendre compte.
Private account! Red teamer @codewhitesec. @frycos@infosec.exchange @frycos@X