Sec ops tool-building wizard, thrives on detections and keyboard clacking. hackerjobs.com

Joined December 2013
207 Photos and videos
Pinned Tweet
26 Jul 2025
Replying to @Nulloop
Do not go gentle into that good night, grandmother.
2
457
Felix Jr. retweeted
It was an honor to be shown the awesome @Intel fab in Oregon this week. Looking forward to a great partnership with @SpaceX & @Tesla!
4,092
9,001
113,857
46,349,714
Why doesn't CoreNFC work with reading WiFi Config payload? Has this always been the case?
1
108
Felix Jr. retweeted
A rule that will accelerate your career: If you bring a problem, bring context. If you bring context, bring options. If you bring options, bring a recommendation. People trust people who help them think. Anyone can spot an issue, few can actually help move things forward.
94
1,126
6,797
172,268
Protect Malicious Apps acces to Mail: -Disable user consent - require admin approval -Audit & remove unused apps regularly, especially those with mail permissions -Enforce Conditional Access -Enable admin consent workflow to review all permission requests -Monitor OAuth grants
🚨#BREAKING: Chinese hackers linked to the group known as Salt Typhoon have breached the email systems of U.S. congressional committee staff, gaining access to internal communications.
1
130
My assumption was an consentfix or a compromised app.
40
Why do HR companies not screen for double employment and DPRK workers? This could be a service people would pay for.
41
30 Dec 2025
Understanding permission context before executing is critical. Always verify that permissions match the intended execution before taking action. Peek Before You Poke, Operator: open.substack.com/pub/detect…

42
Felix Jr. retweeted
You really should consider requiring assignment for all the CLI tools like Graph, Azure, Exchange, etc. You can even license devs/admins and allow access via PIM for Groups or Access Packages I may even have automated setup for that here 😏 github.com/PatriotConsulting…
New ConsentFix attack hijacks Microsoft accounts via Azure CLI - @billtoulas bleepingcomputer.com/news/se… bleepingcomputer.com/news/se…
10
39
238
41,179
11 Dec 2025
Cooking with Visual Editor for @cursor_ai Browser
27
5 Dec 2025
what ever happened to @redteamsblog ?
28
Felix Jr. retweeted
#MDE custom collection is finally in public preview! It's a centrally managed solution to improve visibility and detection opportunities. We're releasing a management tool and rule repository in YAML format to share new rules with the community. medium.com/falconforce/micro…
5
43
168
29,977
Felix Jr. retweeted
Replying to @simonbs
Someone on Reddit found a couple fixes that might be worth trying: reddit.com/r/MacOS/s/l2yE2xz…
1
2
35
1,884
26 Oct 2025
Beautiful bob cat was watching me as I walked my dog.
65
Felix Jr. retweeted
25 Oct 2025
TIL you can get Apple's docs as json
4
6
128
11,688
17 Oct 2025
54
Felix Jr. retweeted
13 Oct 2025
My @BSides_NoVA talk from Saturday was called “10 Ways to Improve Entra ID Security Quickly”. I focused on the areas that tend to be missed in Entra ID. Talk slides are now posted. Download the slides: adsecurity.org/?p=4799
1
33
141
22,365
13 Oct 2025
Just got lvl 8 in Google reviews but honestly it’s a community service being done because there’s not benefit. I travel for food, culture, and experiences.
3
63
12 Oct 2025
I wrote a little something about this on my blog: open.substack.com/pub/detect… I remember doing a bit a research on this back in 2022 after a post @jhencinski made.

Dawg, Microsoft found a Threat Actor that compromised a company and modified the internal payroll system so when paychecks were scheduled to be deposited it went into THEIR accounts, NOT the employees. That's fucking badass wtf I've never seen that before
1
75
12 Oct 2025

Replying to @jhencinski
Why? When you make a payroll change in Workday, like “send 100% of my paycheck to this new account” - Workday will likely send you an email confirmation. The attacker creates a new Inbox-rule so the victim doesn’t see this email.
53