Here's a video PoC for Azure Entra ID SignIn Log Bypass in action. I had to make it to help MSRC replicate it (lol). You'll see how simple this bypass was.
No worries admins, Microsoft says that it was only a "Moderate" issue.
Elon musk has made this platform a disinformation haven leveraging the monetisation features for people in low income countries.
I would guess that if you spread enough hate here you can make a good living if you live in India / Nigeria etc
It's been almost a year since my last blog... So, here is a new one: Extending AD CS attack surface to the cloud with Intune certificates.
Also includes ESC1 over Intune (in some cases).
dirkjanm.io/extending-ad-cs-…
Oh, and a new tool for SCEP: github.com/dirkjanm/scepreq
Created small tool that joins a device to a Tailscale network and exposes a local SOCKS proxy. It’s built for red team pivots and quick access into (restricted) environments. The underlying tsnet library is currently Go-only, so it's semi-portable for now.
github.com/Yeeb1/SockTail