Sign in

DylanInfosec🛡️

@attackthesoc.com
566 followers 810 following 268 posts

Dad ⚭ Husband 🏛️ Incident Response, M365 Forensics | Defender XDR & Azure Security | DEaTH ⏳ 🏋🏻‍♂️IronCult 🏕️ForestHermit attackthesoc.com | InDefenseofDefenders.org

PostsRepliesMedia
DylanInfosec🛡️ @attackthesoc.com · 19h
AI got AI devs acting like infosec interns, infosec folks like dev interns, devs like pms, and so on.. everyone just kinda shifted roles and are expected to just do it. Responsibilities for many have changed with no guidance or direction. Conversations between people has devolved to output copypasta
100
DylanInfosec🛡️ @attackthesoc.com · 23/03/2025
Have 4 articles I've been working on here and there for a while now, yet I complete the one I started yesterday... go figure. Idea popped into my head so wrote it out in one go. attackthesoc.com/posts/detect... - Using KQL to Detect Gaps in your Conditional Access Strategy
attackthesoc.com
Using KQL to Detect Gaps in your Conditional Access Strategy
Conditional Access Policies serve as the frontline defenders of your Azure resources, but evolving business requirements can introduce unintended gaps. This article explores how to transform your high...
070
Reposted by DylanInfosec🛡️
Jenny Croft @jenniferlcroft.bsky.social · 09/03/2025
Becky Burke of Book Island (a picture book publisher in the UK founded by my fellow Tokarczuk translator Greet Pauwelijn) was "detained" by ICE at the Canadian border on 2/28. Her father asked that her story be shared in case someone can help her. He writes:
18549333533
DylanInfosec🛡️ @attackthesoc.com · 19/02/2025
If you work with Application owners you know how fun initializing groups for new SSO apps is. Bulk group member upload makes it easy but app owners tend to only ever provide a big list of emails. Bulk requires UPN or OID so here's a script I always turn to github.com/AttacktheSOC...
github.com
Azure-SecOps/Graph/Users/Get-UserObjectIds.ps1 at main · AttacktheSOC/Azure-SecOps
Collection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc) - AttacktheSOC/Azure-SecOps
130
DylanInfosec🛡️ @attackthesoc.com · 19/02/2025
On Device Code phishing: Some folks were confused about this so wanted to share here. A generated device code is not tied to a single user. If a shared mailbox or mailbox with other accounts with view rights is hit with a spearphish, investigate all accounts.
020
Reposted by DylanInfosec🛡️
Jeffrey Vagle @jvagle.me · 15/02/2025
CISA is one of the most important agencies you may not have heard of, partly due to its relative youth, and partly due to the fact that when it does its job—which it has done admirably—it generally does not make headlines. And now Trump is gutting it.
1146
DylanInfosec🛡️ @attackthesoc.com · 14/02/2025
As @ericazelic.bsky.social mentioned all the energy around Device Code abuse is long overdue. To get more info about how it’s done, these articles are relevant 2020 & 2022 respectively @drazuread.bsky.social aadinternals.com/post/phishing/ @inversecos www.inversecos.com/2022/12/how-...
aadinternals.com
Introducing a new phishing technique for compromising Office 365 accounts
The ongoing global phishing campaings againts Microsoft 365 have used various phishing techniques. Currently attackers are utilising forged login sites and OAuth app consents. In this blog, I’ll intr...
0143
DylanInfosec🛡️ @attackthesoc.com · 14/02/2025
Had this saved in the WIP folder forever KQL for anti-forensics activities github.com/AttacktheSOC... So much can be added to this. Think 3rd party tools to aid anti-forensics, browser forensics... too much to name OMG, look at this😶updates to come! github.com/MikeHorn-git...
github.com
193
DylanInfosec🛡️ @attackthesoc.com · 14/02/2025
Was asked by a colleague for some help with a Remediation Script and remembered this little number: reg2ps.azurewebsites.net from @roger_zander Thank you! Bookmark it If using it for Intune, modify the Check Script output. Replace any $false with a 1. and $true with 0
reg2ps.azurewebsites.net
Registry to PowerShell converter
Convert PowerShell scripts into Windows executables.
010
Reposted by DylanInfosec🛡️
Jouni Mikkola @jounimikkola.bsky.social · 09/02/2025
Just posted a new entry to my blog! Trying to hunt for couple of anomalies using MDE. A lot of problems arised, as usually. #threathunting #mde #defender threathunt.blog/registry-hun...
threathunt.blog
Look into couple of suspicous registry activities
Look into couple of suspicous registry activities
011
DylanInfosec🛡️ @attackthesoc.com · 28/01/2025
Looking at some of the Aggregated Reporting of the different tables for the past few days (23-28) for a single device. #XDR #Defender
a timechart showing the trend of aggregated reporting events between Jan 23rd-28th for the 4 different supported tables. (No DeviceLogonEvents are shown)
120
DylanInfosec🛡️ @attackthesoc.com · 26/01/2025
Took a trip inside to get a break from the bleak winter weather
100
Reposted by DylanInfosec🛡️
Alex Verboon @vacyber.bsky.social · 26/01/2025
Defender Resource Hub Update - Winter 2025 defenderresourcehub.info #Security #Learn #StayUptodate #Defenders #MicrosoftSecurity
132
DylanInfosec🛡️ @attackthesoc.com · 24/01/2025
Very cool course by the folks at Kopidion LLC on how to look at things from the adversary's perspective. Thank you for the training!
Certificate of completion from Kopidion LLC on their course "Adversarial Thinking: The Art of Dangerous Ideas"
020
Reposted by DylanInfosec🛡️
Runa Sandvik @runasand.bsky.social · 24/01/2025
I wrote a very timely introduction to digital security for journalists for @gijn.org last fall. This guidance may also apply to activists, lawyers, and anyone else doing at-risk work these days. gijn.org/resource/int...
gijn.org
Introduction to Investigative Journalism: Digital Security
Digital security may seem a little daunting at first, but increased security will help investigative journalists build trust with — and protect — current and future sources.
26237
DylanInfosec🛡️ @attackthesoc.com · 23/01/2025
Well... that was an experience, I thought I prepared for everything, just not Teams failing. Dug out an old laptop. Very big thanks to @cyb3rmik3.bsky.social for inviting me on and to anyone able to stick around and listen, thank you for your patience. I hope you were able to learn something new.
150
DylanInfosec🛡️ @attackthesoc.com · 23/01/2025
Very excited to do my first my talk ever tomorrow. Me and public speaking aren’t close friends. Nervous as hell lol but ready and excited
470
Reposted by DylanInfosec🛡️
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 22/01/2025
📢 Don't miss @attackthesoc.com tomorrow talking about deception with MDE! The Greek Microsoft Security Community is thrilled to host its 3rd meetup tomorrow, featuring an exciting discussion with Dylan. ℹ️ More info on how to join ⤵️ www.meetup.com/greek-micros...
meetup.com
Greek Microsoft Security Community - 3rd Meetup with Dylan Tenebruso, Thu, Jan 23, 2025, 7:00 PM | Meetup
🇬🇷 Σας καλούμε στο πρώτο meetup για το 2025 και το τρίτο κατά σειρά της Ελληνικής Microsoft Security Κοινότητας που θα πραγματοποιηθεί online με θέμα "Artifice: Leveragin
132
DylanInfosec🛡️ @attackthesoc.com · 22/12/2024
I’m honored and excited to have the opportunity to speak about the powerful deception rules feature in the MDE platform with the Greek Microsoft Security Community. Join us as we explore how to leverage this feature to enhance your detection strategy. Thank you, @cyb3rmik3.bsky.social !
260
DylanInfosec🛡️ @attackthesoc.com · 22/12/2024
How's everyone's Winter Arc going? What's that flashback scene going to look like?
000
DylanInfosec🛡️ @attackthesoc.com · 21/12/2024
Been playing more with the rpi and arduino. This time using OpenCV for facial detection and sending the id to rpi to the arduino display. Next, seeing if the kids want to help hook up some servos, craft a viable hand and get a waving robot hand. Articulation after that
a picture of myself on a computer screen with a green square around my face. The box is facial recognition identifier. My name at the top of the box and a confidence score of 48% at the bottomAn arduino is plugged into a raspberry pi via USB. The Arduino also has connections to a breadboard that also has an LCD screen and 8x8 LED matrix plugged in. The LCD shows the text "Hi, Dylan! Hope you're doin".
The LED matrix shows a sideways sad/angry face
020
DylanInfosec🛡️ @attackthesoc.com · 15/12/2024
Final product: 1) Sideways smiley face (clear skies) : ) 2) Cold ass nights 3) kids thinking they’re funny asking for a real raspberry 🥧
an LCD screen that display the current temperature "Temp 25. 🤌" on the top line and the current datetime on the bottom line.

The red is an LED matrix with a sideways smiley emoji displayed 
   : )
000
DylanInfosec🛡️ @attackthesoc.com · 15/12/2024
We took over the table to learn a bit about programming today. Raspberry Pi hits the OpenWeatherAPI to get the weather forecast and feeds it to the micro LCD, top line reads datetime Bottom line summarizes the weather. Max7219 displays a emoji face resultant of the weather
a messy table littered with electrical components, wires, breadboards, a mega2560 microcontroller, raspberry pi 3B v2, and a laptop with stickers because 1337
250
DylanInfosec🛡️ @attackthesoc.com · 13/12/2024
Bought my daughter a Procreate license an hour ago… she’s so damn awesome. So proud and excited to see what she makes next . No books or tutorials, just craftin some stuff up
110
Reposted by DylanInfosec🛡️
Rudy Ooms | MVP @call4cloud.nl · 07/12/2024
And just like that, all our #windows devices suddenly got dual enrollment aka LinkedEnrollment. This groundbreaking step toward Declarative Device Management enrollment was triggered by Device Inventory. This new feature also makes use of the MMP-C infra alongside EPM #msintune #intune
1171
DylanInfosec🛡️ @attackthesoc.com · 08/12/2024
Sometimes to get back to my NJ Italian-American roots I call sausage, sawseege. Mozzarella, motz or motzahrell. Vaffanculo, fongool
media.tenor.com
a man in a tuxedo is standing in a room with the word prego written on the bottom of his face .
Alt: a man in a tuxedo is standing in a room and raises his hand with the Italian hand gesture🤌 with the word prego written on the bottom
110
DylanInfosec🛡️ @attackthesoc.com · 08/12/2024
tired as hell.. think i wrote the last few paragraphs cross-eyed... gonna watch Harakiri again and pass out before opening credits
media.tenor.com
a black and white photo of a man kneeling on a white mat
Alt: a black and white photo of a man kneeling on a white mat before a blade, a mope bucket sits behind him. This is taken from the move Harakiri
010
DylanInfosec🛡️ @attackthesoc.com · 08/12/2024
Finally, another blog post.. this one is a bit different focusing on cleaning up the SOC instead of adding things to it. Optimizing what you already have for more efficiency. attackthesoc.com/posts/ms-xdr...
attackthesoc.com
Optimizing the SOC
Explore ways of optimizing alerts to reduce false positives, leveraging built-in tools to streamline operations, and implementing features that boost productivity for a more efficient and effective SO...
140
DylanInfosec🛡️ @attackthesoc.com · 07/12/2024
This is the 8th drone sighting notification I received in the last hour from just one little area of Jersey neighbors.ring.com/n/V99QgXYFoV
neighbors.ring.com
Ring Neighbors
100
DylanInfosec🛡️ @attackthesoc.com · 06/12/2024
My wife is terrible with surprises so I got some gifts early lmfao Also a pic of the axe, multi-effects processor and amp… was eyeing the katana unless y’all got some recommendations for a noob? Put some new patches together on the Zoom, sounds aight still learning the ropes
A collection of Mike Stetina’s Metal Guitar series. This pic includes Rhythm Guitar vol 1,2 and Lead Guitar vol 2 (1 is on the way)A picture a guitar (Stratocaster), multi effects processor (zoom gx1 four) and a Frontman 10g amp
140
DylanInfosec🛡️ @attackthesoc.com · 06/12/2024
Yo Jersey, you good with that drone issue??
000
DylanInfosec🛡️ @attackthesoc.com · 06/12/2024
Are you using Deception tech in your detection stack? (i.e. honeypots, canary tokens, lures, etc.) If not, what's stopping you?
media.tenor.com
a dog laying on the floor next to a laundry basket in a living room
Alt: A cat gets trapped under a laundry basket after someone off screen yanks some twine holding the trap up
041
DylanInfosec🛡️ @attackthesoc.com · 05/12/2024
Hot chocolate for the kids to end the snow day right … whipped cream when it cools a bit
Four festive cups filled with hot chocolate, a crushed candy cane lay in ruin at the top of the photo
040
DylanInfosec🛡️ @attackthesoc.com · 05/12/2024
First snow day of the year. Noice. As a WFH, it's awesome to walk off a call to grab coffee or something and see the little ones all day. Would not trade this for anything
040
DylanInfosec🛡️ @attackthesoc.com · 05/12/2024
Anyone else in the Microsoft TechCommunity portal not able to open their inbox? Also get an internal server error every once in a while on random pages. Tried from Chrome on Desktop and mobile, Safari on mobile
000
DylanInfosec🛡️ @attackthesoc.com · 04/12/2024
lol, this one is on you @campbell.scot And it’s only 7 streams because I ended getting the album
A picture of my “Spotify year 2024 wrapped” top song. The song is Warriors by I, played 7 times and apparently part of the top 0.1% listener’s worldwide
110
DylanInfosec🛡️ @attackthesoc.com · 04/12/2024
Cool, haven't seen this but the MS docs were updated back in March so I might be late to the party. You can create a custom export an incident in Defender to a pdf. Nothing crazy but if you need to provide the quick details on an incident for reporting or w/e its got the info that would be needed
120
DylanInfosec🛡️ @attackthesoc.com · 04/12/2024
Farmer Walks with this setup is janky but gets the job done after a couple laps around the dungeon… does wonders for grip strength with vertical grip
000
DylanInfosec🛡️ @attackthesoc.com · 03/12/2024
Finally found time to start practicing guitar 🎸 again and been working on the Tenacious D cover of Wicked Games… I might actually feel confident enough to post a video of it lmao, it’ll be the first (hopefully of many)
240
DylanInfosec🛡️ @attackthesoc.com · 03/12/2024
That damn "-All" flag always catching me slipping in Graph PS..
010
DylanInfosec🛡️ @attackthesoc.com · 03/12/2024
If you're setting up SAML apps in Entra you may want/need to update the SAML certificate expiration notification email address: github.com/AttacktheSOC...
github.com
Azure-SecOps/Graph/Service Principals/Update SAML Certificate Expiration Email Addresses.ps1 at main · AttacktheSOC/Azure-SecOps
Collection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc) - AttacktheSOC/Azure-SecOps
071
DylanInfosec🛡️ @attackthesoc.com · 03/12/2024
Been working through a few Microsoft Learn modules (chasing a number of self-paced certs: AZ-104 > AZ-305 & AZ-500+SC-200 > SC-100) and there's just so much going on. Too easy to miss tools and features that will make your life so much easier.
290
DylanInfosec🛡️ @attackthesoc.com · 02/12/2024
The man, the myth, the legend.. is here
030
DylanInfosec🛡️ @attackthesoc.com · 30/11/2024
We bout to get into this #mushroom puzzle
010
DylanInfosec🛡️ @attackthesoc.com · 29/11/2024
KQL best practices: learn.microsoft.com/en-us/kusto/... MS is always updating their docs, don't forget to check-in every now and then Boost your query performance but don't strain yourself trying to follow guidelines like this to a 'T'. Sometimes you need to do the quick and dirty and that's fine!
learn.microsoft.com
Best practices for Kusto Query Language queries - Kusto
This article describes Query best practices.
4162
DylanInfosec🛡️ @attackthesoc.com · 29/11/2024
Just got home with the fam from cutting down our own tree. Absolutely the best way to get a tree. If there’s a well reviewed place in your area, do it Here’s a pic from last year of the cats enjoying the tree as well.. and yes of course he cried for help once he was done having his fun
A photo of tuxedo cat’s face poking out from behind the branches of a Christmas tree.
040
DylanInfosec🛡️ @attackthesoc.com · 29/11/2024
youtube.com/playlist?lis...
media.tenor.com
two men are standing next to each other with the words get em written on the screen
ALT: two men are standing next to each other with the words get em written on the screen
021
DylanInfosec🛡️ @attackthesoc.com · 27/11/2024
My wife was testing a dairy-free recipe for Pumpkin pie and handed me the test pie and said the words “Here, let me know how it is. This one’s yours, do with it what you will” Folks. I have no shame and the only regret that I do have is on a purely digestive system level
An picture of an empty aluminum pie pan that is dirtied by the scraps of what used to be an entire pumpkin pie
140
DylanInfosec🛡️ @attackthesoc.com · 27/11/2024
Always a good time when you end up blocking yourself from work because tools were config'd properly Tried deploying an Arc extension Failed.. Ok, ah extensions.allowlist. Done. Failed.. Hmm, permissions perhaps? Temp eligibility. PIM accepted Denied.. Looks closer. Carve out a custom policy Success.
media.tenor.com
a cartoon man with a mustache is making a funny face while standing in front of trees .
Alt: a cartoon man with a mustache is making a funny face while standing in front of trees. His face goes from angry, to confused, then upset and finally, happy.
040
DylanInfosec🛡️ @attackthesoc.com · 27/11/2024
Oofa! Was completely wrong. Thanks to @fabian.bader.cloud for pointing out that it can be found in the UAL (as seen here: learn.microsoft.com/en-us/purvie...) which can be turned on by following (this: learn.microsoft.com/en-us/defend...) You can see if it was done via GUI or API, commands and all
learn.microsoft.com
Audit log activities
Use the unified audit log to view user and administrator activity in your Microsoft 365 organization.
220