chrisonsecurity
@ChrisOnSecurity
New blog post: Windows 11 security - a first look You have heard about the TPM requirement. In this post, I talk about the background and give a high-level overview on hardening capabilities in #Windows11. #WindowsInsider @windowsinsider #Microsoft chrisonsecurity.net/2021/07/15/win…
#PingCastle 3.0 released !!! pingcastle.com/download/ Active Directory & AzureAD security health check in seconds >200k AD audited, management readable, no install, no admin, no data sent "to a cloud" Example of report: pingcastle.com/PingCastleFile… github: github.com/vletoux/pingca…
I use(d) Twitter for two things: 1. as some sort of RSS feed for tech news 2. to stay in touch with the infosec community For the latter I can say that I really love the energy over at Mastodon, so naturally I also joined: infosec.exchange/@ChrisOnSecuri… See you there!
For any #Microsoft365Security analysts out there, we've published addons.mozilla.org/addon/zipit/ to password-protect your #Malware downloads through the #LiveResponse sessions 🪲 A standard feature one could have said... #infected #zip
The definitive reference of changes between Win10 and Win11! Huge thanks to @bunsofwrath12 for taking on this documentation effort for the #DFIR community >> Windows 10 vs. Windows 11, What Has Changed? giac.org/research-paper… + a repo of raw artifacts: github.com/AndrewRathbun/…
Aug. 2022 update of ~80 Defender for Endpoint features by OS. Updates: • Available in Excel (biggest request) • New vulnerability management capabilities • Improvements to macOS, Linux, iOS, and Android features • Loads more Feedback welcomed! campbell.scot/mde-comparison…
I'm excited about this one 🎉 Hunt in Microsoft 365 Defender without KQL! Our new query builder is now in public preview techcommunity.microsoft.com/t5/microsoft-3… thanks @Taliash1
techcommunity.microsoft.com
Hunt in Microsoft 365 Defender without KQL! | Microsoft Community Hub
To reduce the learning curve for hunting and enable all analysts to hunt easily, we are excited to announce that a Guided hunting experience in Microsoft 365...
Sysmon 14.0 has been just released by @Sysinternals . Sporting a new feature that will now allow it to start having prevention features. The new Event ID is 27 and is called FileBlockExecutable. I've written a short blog with some more details. medium.com/@olafhartong/s… #sysmon
How to get started with Microsoft Defender Threat Intelligence (MDTI) 👉bit.ly/3zDh85k MDT premium license is needed for all features but without a license, you can login to the portal and access for free Defender TI offering
The #BloodHoundEnterprise is proud to announce the release of #BloodHound 4.2: The Azure Refactor! This is a HUGE release. Get all the details in this blog post: posts.specterops.io/1cff734938bd
Have you checked out all the new learning resources for the entire Microsoft 365 Defender suite of product in our new learning portal? docs.microsoft.com/en-us/learn/m3…
Hey all #passwordless friends! Excited to share that Multiple Passwordless Phone sign-in accounts on one iOS device is now in public preview! Check out below for more details. docs.microsoft.com/en-us/azure/ac…
„How do I know if I have WIP enabled on my devices?“ I think if you implemented WIP you remember the pain. techcommunity.microsoft.com/t5/intune-cust…
#LAPS built-in in to #Windows11 #Insider and support for #AzureAD, #PasswordHistory and much more. #MEM #EndpointManagement bit.ly/3yiRKSZ
I’m over the moon to help launch Microsoft Entra, our new family of Identity and Access solutions that includes Azure AD, Entra Permissions Management (previously CloudKnox), Entra Verified ID and a new simplified admin portal experience microsoft.com/security/blog/…
Unser Security Experte @ChrisOnSecurity erklärt, wie anfällig Azure AD für MFA-Spamming ist und wie Unternehmen MFA trotzdem in sichereren Konfigurationen verwenden können. eu1.hubs.ly/y0-1mH0 #security #azuread #ActiveDirectory #mfa #ITsecurity #zerotrust
Did you know you can populate Administrative Units in Azure AD based on a user's on-premises OU? You can now key off of the onPremisesDistinguisedName property of a user to add them to an AU:
Happy to share we've decreased false positives for impossible travel alerts by up to 75% across Defender for Cloud Apps and M365 Defender techcommunity.microsoft.com/t5/microsoft-3…
United States Trends
- 1. #RiyadhSeason 13.5K posts
- 2. Mason 37.7K posts
- 3. Syracuse 8,123 posts
- 4. Lincoln Riley 1,453 posts
- 5. Oregon 27K posts
- 6. #AEWFullGear 6,739 posts
- 7. Arch Manning 2,973 posts
- 8. #AEWTailgateBrawl 1,384 posts
- 9. #TheRingIV 3,956 posts
- 10. Joe Jackson 1,158 posts
- 11. Stoops 1,672 posts
- 12. Kansas State 3,029 posts
- 13. #GoBlue 2,499 posts
- 14. Arkansas 9,789 posts
- 15. Vandy 3,353 posts
- 16. Jonathan Smith N/A
- 17. Jeremiyah Love 3,772 posts
- 18. Fran Brown N/A
- 19. Sadiq 8,112 posts
- 20. Harden 31.2K posts
Something went wrong.
Something went wrong.