I do security stuff @Truesec • MVP • Father • My tweets are my own • He/him

Joined June 2016
148 Photos and videos
Pinned Tweet
219 domain admins.
Write a scary story in 6 words or less.
2
3
27
Viktor Hedberg 🛡💻 retweeted
🔧 Jobbar du med Microsoft‑teknik? Då är Experts Live Sweden 2026 konferensen du inte vill missa. Registrera dig: expertslive.se Communitydrivet. Ideellt. Fullt fokus på Microsoft‑stacken. #Microsoft #ELSE26 #ExpertsLive
1
3
1
326
Viktor Hedberg 🛡💻 retweeted
Key things seen in ransomware incidents: 1) VPN does not require MFA 2) Standard User VPN access gives access to management interfaces 3) LDAP access leads to domain admin via: Passwords in description fields, kerberoasting and other common escalation points (but seriously the above is major) 4) the backup servers are primary corp domain joined 5) the vcenter servers are primary corp domain joined this gives the threat actor the ability to: > destroy your backups > destroy your virtual infrastructure > delete/encrypt your data > exfiltrate the data

ALT Petya Ransomware GIF

21
68
374
26,489
Viktor Hedberg 🛡💻 retweeted
I'm just going to leave this here, as I keep seeing surprised faces when I tell people about Windows Hello multifactor unlock. Yes, you can enforce 2️⃣ factors to unlock your Windows machine! See for yourself. learn.microsoft.com/en-us/wi…
11
33
208
29,898
Viktor Hedberg 🛡💻 retweeted
🎉 A warm welcome to all the new MVPs! 🎉 You’ve joined a global community of passionate experts, builders, and changemakers who go above and beyond to share knowledge, support others, and drive innovation. Whether you’re leading user groups, writing code, creating content, or empowering your local tech ecosystem—your impact matters. And now, you’re officially part of the MVP family. 🙌 Let’s celebrate YOU. Drop a 👋 and let us know where you're from or what community you're most excited to engage with! #MVPBuzz #MicrosoftMVP
5
29
137
6,782
Viktor Hedberg 🛡💻 retweeted
Restore and Repair – Don’t Build New After an Incident @Truesec https://www.truesec.comhub/blog/restore-and-repair-dont-build-new-after-an-incident
1
7
12
1,318
Viktor Hedberg 🛡💻 retweeted
🤣
49
1,077
18,241
635,547
Viktor Hedberg 🛡💻 retweeted
Replying to @DOGE
Good find. Those licenses cost on average $500,000,000/year. That saved the country potentially hundreds of billions of dollars. Now the government can put that money to good use such as reintroducing lead to paint to keep the photon radioactive waves out of our brains
30
70
2,591
56,112
Viktor Hedberg 🛡💻 retweeted
Enhance your AppManagEvent 2025 visit by attending an exclusive in-person IT-Pro training from top experts like @samilaiho @PaulaCqure @mikael_nystrom @headburgh or @TimothyMangan – before and/or after the event! 🎟️ Bonus: Your training session includes a ticket to the event.
3
4
608
Viktor Hedberg 🛡💻 retweeted
29 Jan 2025
⚡ Check out this new Microsoft Entra blog post 👇 Microsoft Entra PowerShell module now generally available techcommunity.microsoft.com/…

1
18
43
4,962
Viktor Hedberg 🛡💻 retweeted
21 Dec 2024
That's him. He's the one forcing us to change our passwords every 90 days.
8
12
151
8,371
Viktor Hedberg 🛡💻 retweeted
11 Dec 2024
Hey, Entra ID admins. Do you have Passkey (FIDO2) enabled, and does your setting look like this? Early next year, Passkey in Authenticator will be enabled automatically. If that's okay, sit back and relax while your users become phishing-resistant. If not, please act now!
3
20
130
14,772
Wheels up tomorrow morning, prepping for mine and @mikael_nystrom's Masterclass at @NICconf on Wednesday, and our respective sessions on Thursday. #Truesec #NICConf #PreventBreach #MinimizeImpact
1
5
653
Viktor Hedberg 🛡💻 retweeted
Pop quiz, which requirement providers can enforce MFA within Entra ID? #Azure Portal with 'request' & 'App requires MFA' will be next I guess (: github.com/nicolonsky/ITDR/b…
7
18
3,307
Spent the last couple of days in Stockholm speaking at #Teamsdagen. Made new friends and met old ones as well. The event was a huge success, and kudos to the organizers for an awesome event!
176
Viktor Hedberg 🛡💻 retweeted
The financially motivated cybercriminal group that Microsoft tracks as Storm-0501 has been observed exfiltrating data and deploying Embargo ransomware after moving laterally from on-premises to the cloud environment. msft.it/6013m5gnf
3
119
288
55,179
Viktor Hedberg 🛡💻 retweeted
18 Sep 2024
Understanding EVERY Token in Entra ID 🔎 Not all tokens are equal. There are many different types with different uses and benefits. In this blog, I break down each token and what they are used for and which tokens are the most "valuable" for an attacker to obtain. Full blog here👇👇 @XintraOrg xintra.org/blog/tokens-in-en…
17
225
720
88,179