Profile avatar
jimsycurity.adminsdholder.com
I enjoy security, technology, learning, books, & the great outdoors. Trying to be human & kind. Opinions = mine. He/Him/Hän https://github.com/JimSycurity https://www.adminsdholder.com
620 posts 1,006 followers 612 following
Regular Contributor
Active Commenter

Politics is the use of power. Replace "No talking about politics," with "No talking about the use of power," and the enforcement of status quo—and its attendant privileges—from this rule become all too clear. Your discomfort with the reality of injustice does not oblige me to remain silent.

Google’s M-Trends 2025 report is out - data from Mandiant’s incident response engagements. Direct PDF link to avoid the sales pitch wall: https://services.google.com/fh/files/misc/m-trends-2025-en.pdf Thread about my main observations: - Firstly, no mention of generative AI or GenAI again […]

Please join us for Windows Server Summit, and in particular for Securing Active Directory and our AD Certificate Services Enhancements, Innovations, and Security sessions! aka.ms/WindowsServerSummit

Walz: "This is how government is supposed to work. It's not supposed to be one old man in the Oval Office sending out middle of the night tweets that shock markets into free fall. It's not supposed to be a bunch of 20 somethings unelected and firing everyone. It's not supposed to be chaos."

Any data hoarders out there happen to have an ISO of Exchange 2010 RC from 2009? techcommunity.microsoft.com/blog/exchang...

The Take It Down Act sacrifices encrypted messaging and has no safeguards against false reports being used to remove protected- already often censored speech- like sex education, reproductive healthcare resources, or just LGBTQ content online. 🙅‍♀️ www.fightforthefuture.org/actions/stop...

Just pushed a new versions for #AADInternals and AADInternals-Endpoint modules! Some bug fixes plus support for: 1️⃣ Microsoft Authentication Library (MSAL) 2️⃣ Token Protection 3️⃣ Continuous Access Evaluation (CAE)

News: @thekrebscycle.bsky.social, a target of Trump's wrath last week, is resigning from SentinelOne to focus fully on fighting back against against the White House's campaign to punish dissent. www.wsj.com/politics/pol...

Trans Rights are Human Rights.

Most Microsoft tenants do not have Advanced Auditing configured correctly, and orgs only find out after it is too late :( I tried really hard to make this as short and simple as possible. Please be nice to your IR folks and set this up, it's important ;) nathanmcnulty.com/bl...

Dust off your cyber-boots and load up your data blasters — Jeff McJunkin is ridin’ in to speak at Wild West Hackin’ Fest – Deadwood 2025! wildwesthackinfest.com/register-for... #WWHF #Deadwood2025 #TheFutureIs

NEW from me: A whistleblower says DOGE may have taken sensitive labor data...and then someone posted a threatening letter to his door. www.npr.org/2025/04/15/n...

Due to recent events, I decided not to give any talks in the US until further notice. If you know any non-US conferences that has a CFP open, please let me know!

Gizmo had a great hike yesterday.

Had some fun with PDQ deploy/inventory credential decryption and wrote about it here: unsigned-sh0rt.net/posts/pdq_cr... thanks to @dru1d.bsky.social for writing a BOF out of the POC tl;dr get admin on PDQ box, decrypt privileged creds

We are proud to introduce #dAWShund to the world: a framework for putting a leash on naughty AWS permissions. dAWShund helps blue and red teams find resources in #AWS, evaluate their access levels and visualize the relationships between them. falconforce.nl/dawshund-fra... #blueteaming #redteaming

After installing April's updates, Windows 10 and 11 systems now have an empty `C:\Inetpub` directory. This seems... unexpected?

Think NTLM relay is a solved problem? Think again. Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31

This is Ripley. He was nervous about taking the stairs. May have panicked a bit. 12/10

"Age verification" laws are actually "upload your ID or get your face scanned to access every website, ending anonymity and associating your identity with everything you do online" laws and if more people understood that they would not be down for this authoritarian nonsense

YOU GUYS.

A sign of wisdom is choosing not to believe everything you think. A mark of emotional intelligence is choosing not to internalize everything you feel. Thoughts and emotions are possibilities to ponder, not facts to accept. We don’t always invite them in, but we decide whether they deserve to stay.

You OK babe? You barely touched your trauma disassociation

Excited to be at @specterops.bsky.social SO-CON this week!! If you're around, I'll be presenting "Abusing AUs, Confusing the SOC" tomorrow bright & early:

Nice Myst analysis: a graph of the original game's nodes, extracted from the Hypercard source code. glthr.com/myst-graph-1

We're net importers of everything that isn't grain, chicken, or pork. Some threads on US's dependence on food imports: bsky.app/profile/sara... bsky.app/profile/sara...

The former ambassador to Denmark for the United States, Rufus Gifford, posted this video on his Facebook account: Ht: @hpsc24.bsky.social