This account assembles and disseminates information related to Active Directory and Windows security.

Joined December 2017
427 Photos and videos
Pinned Tweet
24/7 Active Directory Incident Response Contact: Tel. 49 (0) 6221 7569637 E-mail: incident-response@ernw.de
2
22
114
90,163
DirectoryRanger retweeted
Insights into Entra ID’s (Un)Conditional Access, by @insinuator insinuator.net/2026/05/insig…

6
56
8,040
Entra Agent ID from a Security Perspective blog.compass-security.com/20…

4
8
1,289
Hardening Intune, by @Carlos_Perez Part 1: The Privileged Roles Nobody Talks About trustedsec.com/blog/the-priv… Part 2: The Implementation Guide trustedsec.com/blog/hardenin…
10
37
2,190
DirectoryRanger retweeted
Imagine yourself on the beach in Thailand getting the email you got accepted to @WEareTROOPERS !!!! It was one of my happiest moments 🥰 I can't wait to #Troopers26
4
2
57
7,044
Enumerate Domain Data (EDD): Powerview’s .NET Cousin redsiege.com/blog/2026/06/to…

4
3
1,034
DirectoryRanger retweeted
Apr 23
At the last @DerbyCon, @PyroTek3 asked me up on stage just for fun. I was so terrified I cowered in the back! Now I’m speaking at @WEareTROOPERS! The biggest AD security conference in the world. 🔥🔥🔥 “Pursue excellence. Never give up!” 👊 See you in Heidelberg 🍻
8
7
66
7,541
DirectoryRanger retweeted
Finally had time to add EtwInspector to the PSGallery! Check it out. PSGallery: powershellgallery.com/packag… GitHub: github.com/jonny-jhnson/ETWI…
14
82
8,528
DirectoryRanger retweeted
What Anthropic’s Mythos Means for the Future of Cybersecurity. The new reality rewards systems that can be tested and patched continuously. spectrum.ieee.org/ai-cyberse…
5
4
1,220
DirectoryRanger retweeted
"The Art of Evasion" talk at #x33fcon by @ShitSecure - x33fcon.com/#!s/FabianMosch.…
20
78
5,870
DirectoryRanger retweeted
"#Fingerprinting Modern #C2 #Implants Through Runtime Telemetry" talk at #x33fcon 2026 by @thefLinkk and @dphillips__ - x33fcon.com/#!/s/SebastianFe… #blue, #POC
12
27
3,269
DirectoryRanger retweeted
Jun 13
Releasing Tunnel Vision Toolkit, part of my @x33fcon talk on Microsoft Global Secure Access. Includes BOFs to assist in engagements where you face GSA, plus a rogue client that lets you connect to internal resources from unmanaged devices. github.com/ar0x4/tunnel-visi…
2
37
88
10,080
DirectoryRanger retweeted
To figure out if a user account is stale will require a lot of log sources and will depend on the environment. There are a lot of different signals to consider and will be different if you are hybrid with SSSO, hybrid with PRT SSO, Hybrid with ADFS and a tertiary IdP, not hybrid with Entra SSO, not hybrid with Entra as a resource provider to the primary IdP, not hybrid with IdP chaining, not hybrid and an External Identity, using config manager in hybrid setups, not using config manager in hybrid setups, etc. Some log sources to consider integrating with: 1. AD 2. AAD: non-interactive 3. AAD: interactive 4. Intune: device metrics 5. Intune: account metrics for their associated devices 6. All IdPs. All of them. Most larger organizations have at least 3. 7. HR systems (i.e. Workday) 8. Does the account own any applications in Entra, on-prem, or any IdP where they are the single owner? 9. How are devices onboarded in Intune? Autopilot? Other ways? If the account is not active in all these logs, I would then create an automation with the HR system to validate and approve the disablement, only after doing it manually a number of times. There's a lot of missing details here but the Intune logs are a great source of information that are often overlooked and not widely understood. I wouldn't consider them a source of truth, but I would still want a dashboard of this info in Intune. I would be careful about how to interpret the information because it's going to depend on a lot of factors. The problem with dashboards is the interpretation of them requires a depth of knowledge that most people don't have. Moreover, dashboards don't do anything.
Replying to @xenappblog
How are you figuring out if a user account is stale? No interactive sign in for 90 days does not mean the account is stale.
5
4
39
6,325
DirectoryRanger retweeted
My talk; Mapping the Adversary: Enriched Incident Graphs with BloodHound Data in Kusto from SO-CON 26 is now live on YouTube. youtube.com/watch?v=v4fG9XNh… big thanks to @SpecterOps for having me and keeping BloodHound open source!
8
29
4,707
DirectoryRanger retweeted
''Debugging Windows Isolated User Mode (IUM) Processes - Quarkslabs blog'' #infosec #pentest #redteam #blueteam blog.quarkslab.com/debugging…

7
15
2,966
DirectoryRanger retweeted
MS AD Kerberos update active since April: If there is no explicit msds-SupportedEncryptionTypes Active Directory attribute defined the DefaultDomainSupportedEncTypes will be AES-SHA1 (0x18). This is significantly slower to crack as RC4.
10
63
5,357