Load site modules...
lade...
random avatar

markmorow - Network

Posts Subscribe

Something I look forward to reading each year is the 6 colors enterprise report card. Give it a read,...

https://infosec.exchange/@markmo...

Something I look forward to reading each year is the 6 colors enterprise report card. Give it a read, sixcolors.com/post/2025/04/app and if you want to see ALL the comments, sixcolors.com/post/2025/04/app. The podcast this week also talked about it. podcast.macadmins.org/2025/04/. Lots of good insights here.

2.5.2025 15:10Something I look forward to reading each year is the 6 colors enterprise report card. Give it a read,...
https://infosec.exchange/@markmo...

Excellent episode. If you’re not looking at your apps you should be.https://mastodon.social/@richcampbell/114308128023702996

https://infosec.exchange/@markmo...

Excellent episode. If you’re not looking at your apps you should be.
mastodon.social/@richcampbell/

9.4.2025 14:21Excellent episode. If you’re not looking at your apps you should be.https://mastodon.social/@richcampbell/114308128023702996
https://infosec.exchange/@markmo...

Every year I read this in full. Super insightful. https://theinternet.social/@tbridge/114304661596486878

https://infosec.exchange/@markmo...

Every year I read this in full. Super insightful. theinternet.social/@tbridge/11

9.4.2025 00:48Every year I read this in full. Super insightful. https://theinternet.social/@tbridge/114304661596486878
https://infosec.exchange/@markmo...

If there are any folks coming to the #microsoft MVP Summit in March, I’ll be co-presenting a new session with a few give aways. Check...

https://infosec.exchange/@markmo...

If there are any folks coming to the MVP Summit in March, I’ll be co-presenting a new session with a few give aways. Check your schedules!

12.2.2025 01:25If there are any folks coming to the #microsoft MVP Summit in March, I’ll be co-presenting a new session with a few give aways. Check...
https://infosec.exchange/@markmo...

https://infosec.exchange/@markmo...

5.2.2025 04:56
https://infosec.exchange/@markmo...

We included a discount code for listeners of RunAs Radio as well. #infosec https://mastodon.social/@richcampbell/113912001895877987

https://infosec.exchange/@markmo...

We included a discount code for listeners of RunAs Radio as well. mastodon.social/@richcampbell/

29.1.2025 14:27We included a discount code for listeners of RunAs Radio as well. #infosec https://mastodon.social/@richcampbell/113912001895877987
https://infosec.exchange/@markmo...

The 2005 White Sox SABR book is nearly done! I’ll share more info soon but I helped update the Ken “The Hawk” Harrelson biography as...

https://infosec.exchange/@markmo...

The 2005 White Sox SABR book is nearly done! I’ll share more info soon but I helped update the Ken “The Hawk” Harrelson biography as part of this research project. That update is already posted sabr.org/bioproj/person/ken-ha.

25.1.2025 23:57The 2005 White Sox SABR book is nearly done! I’ll share more info soon but I helped update the Ken “The Hawk” Harrelson biography as...
https://infosec.exchange/@markmo...

Reminder, if you are using Windows Server 2016, you have 2 years left of support...

https://infosec.exchange/@markmo...

Reminder, if you are using Windows Server 2016, you have 2 years left of support learn.microsoft.com/en-us/life. Now is an excellent time to check inventory and build your plan. You can go directly to Server 2022 or 2025. learn.microsoft.com/en-us/wind.

13.1.2025 16:25Reminder, if you are using Windows Server 2016, you have 2 years left of support...
https://infosec.exchange/@markmo...

Thought this was a really great podcast about how you can leverage AI as a defender....

https://infosec.exchange/@markmo...

Thought this was a really great podcast about how you can leverage AI as a defender. sans.org/podcasts/blueprint/ho. I've also been listening to the OWASP podcast youtube.com/playlist?list=PL88. Good stuff.

1.1.2025 18:22Thought this was a really great podcast about how you can leverage AI as a defender....
https://infosec.exchange/@markmo...

I also recommend this session. https://mastodon.social/@macadminsconf/113748588683832725

https://infosec.exchange/@markmo...

I also recommend this session. mastodon.social/@macadminsconf

31.12.2024 18:02I also recommend this session. https://mastodon.social/@macadminsconf/113748588683832725
https://infosec.exchange/@markmo...

The Objective By The Sea talks are up https://www.youtube.com/playlist?list=PLliknDIoYszuWU8jz_QzSrzlpRot4Vrn5. These are some of the most...

https://infosec.exchange/@markmo...

The Objective By The Sea talks are up youtube.com/playlist?list=PLli. These are some of the most technical sessions I've watched. Great stuff

31.12.2024 01:37The Objective By The Sea talks are up https://www.youtube.com/playlist?list=PLliknDIoYszuWU8jz_QzSrzlpRot4Vrn5. These are some of the most...
https://infosec.exchange/@markmo...

This was a really good session. This is an area I don’t think people are paying enough attention to....

https://infosec.exchange/@markmo...

This was a really good session. This is an area I don’t think people are paying enough attention to. mastodon.social/@macadminsconf

26.12.2024 14:30This was a really good session. This is an area I don’t think people are paying enough attention to....
https://infosec.exchange/@markmo...

@scriptingosx Can you update this typo?...

https://infosec.exchange/@markmo...

@scriptingosx Can you update this typo? gist.github.com/scriptingosx/b

17.12.2024 17:24@scriptingosx Can you update this typo?...
https://infosec.exchange/@markmo...

If you have Apple devices in your environment (you do) and #EntraID, give the #macadmin podcast a listen...

https://infosec.exchange/@markmo...

If you have Apple devices in your environment (you do) and , give the podcast a listen podcast.macadmins.org/2024/12/ @_michaelepping and I discuss how you can improve your end user experience and security. Thanks to @tbridge & Marcus for having us.

17.12.2024 15:00If you have Apple devices in your environment (you do) and #EntraID, give the #macadmin podcast a listen...
https://infosec.exchange/@markmo...

Sharing this post from earlier this week about NTLM. https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/. You...

https://infosec.exchange/@markmo...

Sharing this post from earlier this week about NTLM. msrc.microsoft.com/blog/2024/1. You should NOT wait until you start moving to Server 2025 to start on this. The LDAP Channel Binding audit alert was back ported to all the way to Server 2019. Enable this, see what WILL break and start fixing!

11.12.2024 16:18Sharing this post from earlier this week about NTLM. https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/. You...
https://infosec.exchange/@markmo...

Submitted a few sessions for TechMentor Redmond. https://techmentorevents.com/pages/call-for-papers.aspx CFP closes in a few hours.

https://infosec.exchange/@markmo...

Submitted a few sessions for TechMentor Redmond. techmentorevents.com/pages/cal CFP closes in a few hours.

9.12.2024 00:25Submitted a few sessions for TechMentor Redmond. https://techmentorevents.com/pages/call-for-papers.aspx CFP closes in a few hours.
https://infosec.exchange/@markmo...

Really great @nostarch bundle https://www.humblebundle.com/books/hacking-2024-no-starch-books & a ton of MSFT certifications including...

https://infosec.exchange/@markmo...

Really great @nostarch bundle humblebundle.com/books/hacking & a ton of MSFT certifications including my SC-900 prep guide. humblebundle.com/books/microso

3.12.2024 00:44Really great @nostarch bundle https://www.humblebundle.com/books/hacking-2024-no-starch-books & a ton of MSFT certifications including...
https://infosec.exchange/@markmo...

If you’re not at CyberWarCon and can’t attend this session you can give this post a read....

https://infosec.exchange/@markmo...

If you’re not at CyberWarCon and can’t attend this session you can give this post a read. microsoft.com/en-us/security/b. You can also listen to the MSFT Threat Intel podcast latest episode discussing this threat actor. thecyberwire.com/podcasts/micr

22.11.2024 16:23If you’re not at CyberWarCon and can’t attend this session you can give this post a read....
https://infosec.exchange/@markmo...

@scriptingosx can you add myself and @_michaelepping to your macadmins fediverse csv please?

https://infosec.exchange/@markmo...

@scriptingosx can you add myself and @_michaelepping to your macadmins fediverse csv please?

16.11.2024 14:26@scriptingosx can you add myself and @_michaelepping to your macadmins fediverse csv please?
https://infosec.exchange/@markmo...

One of the topics that came up at BlueHat last week was around apps. Lots of good information was covered that will be posted at...

https://infosec.exchange/@markmo...

One of the topics that came up at BlueHat last week was around apps. Lots of good information was covered that will be posted at microsoft.com/bluehat/. Until then here are some resources for you to check out.

First, if you aren't familiar with oAuth application consent, we did a few sessions on this topic a few years ago. You can watch the one @baileybercik and I did youtube.com/watch?v=oqb3n7UUgpk. Start by checking what your current application permissions are. @_michaelepping has a great script you can find as part of Identity Tools (github.com/AzureAD/MSIdentityT) and if you want a video walk through of it, @merill has you covered youtube.com/watch?v=vO0m5yE3dZA.

Second, the Entra ID Security Operations guide has a whole section just on applications. learn.microsoft.com/en-us/entr. There are Sentinel templates or Sigma rules for these recommendations.

Next, there are Risk Events for apps aka workload identities. Take a look to see if you've had any of these events fire in your environment. learn.microsoft.com/en-us/entr and make sure you are not missing these events in your export to your SIEM. learn.microsoft.com/en-us/entr.

Finally, there are 2 ready made IR playbooks(application consent-learn.microsoft.com/en-us/secu, & compromised app-learn.microsoft.com/en-us/secu) if you found something in your previous investigations or you want to be prepared for when you will, give these a read.

Big kudos to the team for putting on a great event. Don't miss it next year!

8.11.2024 16:10One of the topics that came up at BlueHat last week was around apps. Lots of good information was covered that will be posted at...
https://infosec.exchange/@markmo...
Subscribe
To add news/posts to your profile here, you must add a link to a RSS-Feed to your webfinger. One example how you can do this is to join Fediverse City.
         
Webfan Website Badge
Nutzungsbedingungen   Datenschutzerklärung  Impressum
Webfan | @Web pages | Fediverse Members

⬆️

⬇️