InfoSec | PowerShell Novice | Craft Beer | Gamer | Prefers 4 out of 5 Great Lakes

Joined March 2018
33 Photos and videos
5 Sep 2024
SigninLogs - what is the difference between AuthenticationDetails[0].authentication method and Authentication Details[1]authenticationMethod? [1] is not always present in the logs. Question - which is more accurate to use to determine auth methods used over time? #KQL
88
Morgan retweeted
25 Jul 2024
๐Ÿ’ฅ Exciting update and launch competition! ๐Ÿ“ข Folks, I'm happy to announce another important milestone for @PwnedLabs - the launch of the ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ ๐—ฎ๐—ป๐—ฑ ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐˜€๐—ฒ ๐—•๐—ผ๐—ผ๐˜๐—ฐ๐—ฎ๐—บ๐—ฝ - and our first certification! ๐—ง๐—ผ ๐˜„๐—ถ๐—ป ๐—ฎ ๐˜ƒ๐—ผ๐˜‚๐—ฐ๐—ต๐—ฒ๐—ฟ, ๐—ท๐˜‚๐˜€๐˜ ๐—น๐—ถ๐—ธ๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—ฟ๐—ฒ๐˜๐˜„๐—ฒ๐—ฒ๐˜ ๐˜๐—ต๐—ถ๐˜€ ๐—ฝ๐—ผ๐˜€๐˜. 5 vouchers are available and will be drawn randomly. This comprehensive 4-week bootcamp and its structured learning path provide students with foundational concepts, essential security tools and techniques, and instruction in attacking and defending Azure and Microsoft 365 environments. Students who successfully complete the 4-week bootcamp and structured learning path can then attempt the exam lab to try and earn the ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ฅ๐—ฒ๐—ฑ ๐—ง๐—ฒ๐—ฎ๐—บ ๐—ฃ๐—ฟ๐—ผ๐—ณ๐—ฒ๐˜€๐˜€๐—ถ๐—ผ๐—ป๐—ฎ๐—น (๐— ๐—–๐—ฅ๐—ง๐—ฃ) certification. This has been one of the main things that our community has been asking for. What can you expect to learn? -> bootcamps.pwnedlabs.io/mcrtpโ€ฆ

8
76
105
11,288
9 Jan 2024
Looking for any reference/guidance on what the โ€œRiskEventTypesโ€ values are - when querying against AADSignInEventsBeta in Defender Adv Hunting. Example: RiskEventType 100. Looking to determine what this value is. #KQL
1
98
11 Jan 2024
Still havenโ€™t had any luck finding any documentation listing what this matches toโ€ฆmay need to switch gears and start manually lining these up to the actual sign in logs to determine. To be continuedโ€ฆ
36
7 Nov 2022
โ€œSecurity isnโ€™t very technicalโ€ - the number of ppl within the IT Dept that believe this is concerning.
1
6 Jul 2022
Despite being on the security team - somehow I spend more time in AD/Group Policy than the systems teamโ€ฆ Starting to feel like I never really left the Systems side despite switching roles a while ago.
1
2 May 2022
Devices onboarded for Defender and Security Administrator = fast track to owning them. Applies in general to Security Administrator and or custom roles with adv live response with unsigned scripts. Especially important to pay attention to if DCs are onboarded.
13 Apr 2022
Information overload - vuln scans are great if the info is actionable. Scans from multiple sources for the sake of additional info and to compare against is just wasteful. Shiny object syndrome kicking hard these days with all these vendors promising the latest greatest.
12 Apr 2022
The daily blue screen feeling of working in #infosec
1
3
17 Mar 2022
A bit of lightweight reading during lunch. But for real, a month in and already wondering what have I gotten myself intoโ€ฆ #InfoSec #CISSP
1
1
17 Mar 2022
Demoโ€™d to my coworkers an escalation path to Domain Admin and showcase why logging/alert alone isnโ€™t sufficient. Reactions were mixed but overall we learned as a teamโ€ฆ(but seriously it was a cool path to exploit)
27 Jan 2022
Taking a break and hitting up the slopes for some classic Midwest skiing. Better than being in the office!
26 Jan 2022
Show your AD environment some love, clean up those highly permission groups and users.
2 Jun 2021
For the past 3 years Iโ€™ve worked in security until recently. I felt that a change was needed opted for a sys admin role elsewhere. Didnโ€™t realize how much I really enjoyed InfoSec until now that Iโ€™m on the other side of the glass looking inโ€ฆ
1
26 May 2021
Few weeks into a new job and just recently learned what hours im supposed to workโ€ฆ Is that a sign? I feel like thatโ€™s a sign.
26 Feb 2021
Another day where an object was used elsewhere (not documented) and caused an issue when changed. Yesterday it was a service account, today a group. Positive note, itโ€™s been identified and properly remediated but still. Create purpose built objects from the start.
11 Feb 2021
Itโ€™s a work can wait and hit up the slopes instead kind of day...
2 Feb 2021
Offering your team a 4x10 with conditions on Friday to: check in, answer emails, and be available - isnโ€™t really much of an offer. But thanks for letting me know I can always work longer days and extra hours if I want to.
16 Nov 2020
People over the 3x week pause announcement be like:
14 Nov 2020
InfoSec is one conversation I'll never get bored of. Its always a great time when you can connect, share, and discuss ideas with others.