thomas

Blue Team Basics: Active Directory Security Assessments

Want to annoy script kiddie hackers who rely on pressing buttons in Mimikatz? Then give this blog post about AD and Windows security basics! We’ll be going over some key techniques for safeguarding your network against common attack vectors, such as privileged account exposures, Pass-the-Ticket (PTT) attacks, and SID injection. We’ll also provide some powerful…

Read More

AppLocker in Intune or: How I Learned to Love the (ChatGPT) Bot and Start Worrying

I’ve been playing around with OpenAI’s ChatGPT bot and… this is going to be a really short blog post (just like my career).  It actually **welp** did a pretty damn good job… Not perfect but scarily close. Impressive, right? But not perfect. To start off with, the solution the bot suggested isn’t AppLocker but rather App Protection….

Read More

Security Identifiers (SIDs) and how to understand them [Part 2]

Welcome to Part 2 of a planned four-part series!   Part 1: Security Identifiers (SIDs) and Object Permissions in Windows Part 2: Security Identifiers (SIDs) and how to understand them (you’re reading this it now!) Part 3: Converting Azure Object IDs in Azure into Security Identifiers (SIDs) Part 4: Security Identifiers (SIDs) and User Rights Management In Part 1 we…

Read More

Security Identifiers (SIDs) and Object Permissions in Windows [Part 1]

Welcome to Part 1 of a planned four-part series! Part 1: Security Identifiers (SIDs) and Object Permissions in Windows (you’re reading this it now!) Part 2: Security Identifiers (SIDs) and how to understand them Part 3: Converting Azure Object IDs in Azure into Security Identifiers (SIDs)  Part 4: Security Identifiers (SIDs) and User Rights Management  So on to Part…

Read More

Automating CIS Benchmarks: Using the CIS-CAT Tool for Hardening and Compliance

This post is pretty heavy on the on-premise/hybrid/Windows Server/Active Directory side of things; so if you’re new to that then I recommend you read: Group Policy Administrative Templates (ADMX): What are they? How are they used? And what if I need to update them? Ingesting Policy Templates (ADMX) into Intune And/Or if you’re new to…

Read More