Sign in

DylanInfosec🛡️

@attackthesoc.com
567 followers 810 following 268 posts

Dad ⚭ Husband 🏛️ Incident Response, M365 Forensics | Defender XDR & Azure Security | DEaTH ⏳ 🏋🏻‍♂️IronCult 🏕️ForestHermit attackthesoc.com | InDefenseofDefenders.org

PostsRepliesMedia
DylanInfosec🛡️ @attackthesoc.com · 30/09/2026
Not because it’s good or right or better than what the person would’ve said but because, imho, folks are so discombobulated that they don’t know what they know anymore. The new default seems to be, “the llm understands my (new) responsibilities better than me, so it must know this too.”
001
DylanInfosec🛡️ @attackthesoc.com · 30/09/2026
AI got AI devs acting like infosec interns, infosec folks like dev interns, devs like pms, and so on.. everyone just kinda shifted roles and are expected to just do it. Responsibilities for many have changed with no guidance or direction. Conversations between people has devolved to output copypasta
100
DylanInfosec🛡️ @attackthesoc.com · 23/03/2025
Have 4 articles I've been working on here and there for a while now, yet I complete the one I started yesterday... go figure. Idea popped into my head so wrote it out in one go. attackthesoc.com/posts/detect... - Using KQL to Detect Gaps in your Conditional Access Strategy
attackthesoc.com
Using KQL to Detect Gaps in your Conditional Access Strategy
Conditional Access Policies serve as the frontline defenders of your Azure resources, but evolving business requirements can introduce unintended gaps. This article explores how to transform your high...
070
Reposted by DylanInfosec🛡️
Jenny Croft @jenniferlcroft.bsky.social · 09/03/2025
Becky Burke of Book Island (a picture book publisher in the UK founded by my fellow Tokarczuk translator Greet Pauwelijn) was "detained" by ICE at the Canadian border on 2/28. Her father asked that her story be shared in case someone can help her. He writes:
18549333533
DylanInfosec🛡️ @attackthesoc.com · 20/02/2025
ForEach-Object (+ -Parallel when possible)
030
DylanInfosec🛡️ @attackthesoc.com · 19/02/2025
Grabs the list of emails form the 'email' column, and queries graph for the user Object Id and puts them in a separate file. *Note: even if you don't use this script, always preserve the original list sent to you.
000
DylanInfosec🛡️ @attackthesoc.com · 19/02/2025
If you work with Application owners you know how fun initializing groups for new SSO apps is. Bulk group member upload makes it easy but app owners tend to only ever provide a big list of emails. Bulk requires UPN or OID so here's a script I always turn to github.com/AttacktheSOC...
github.com
Azure-SecOps/Graph/Users/Get-UserObjectIds.ps1 at main · AttacktheSOC/Azure-SecOps
Collection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc) - AttacktheSOC/Azure-SecOps
130
DylanInfosec🛡️ @attackthesoc.com · 19/02/2025
On Device Code phishing: Some folks were confused about this so wanted to share here. A generated device code is not tied to a single user. If a shared mailbox or mailbox with other accounts with view rights is hit with a spearphish, investigate all accounts.
020
Reposted by DylanInfosec🛡️
Jeffrey Vagle @jvagle.me · 15/02/2025
CISA is one of the most important agencies you may not have heard of, partly due to its relative youth, and partly due to the fact that when it does its job—which it has done admirably—it generally does not make headlines. And now Trump is gutting it.
1146
DylanInfosec🛡️ @attackthesoc.com · 14/02/2025
As @ericazelic.bsky.social mentioned all the energy around Device Code abuse is long overdue. To get more info about how it’s done, these articles are relevant 2020 & 2022 respectively @drazuread.bsky.social aadinternals.com/post/phishing/ @inversecos www.inversecos.com/2022/12/how-...
aadinternals.com
Introducing a new phishing technique for compromising Office 365 accounts
The ongoing global phishing campaings againts Microsoft 365 have used various phishing techniques. Currently attackers are utilising forged login sites and OAuth app consents. In this blog, I’ll intr...
0143
DylanInfosec🛡️ @attackthesoc.com · 14/02/2025
Full disclosure: Needs a lot of work. An over-reliance on filename and cmdline. Performance ugh. Also asked GPT to clean it up and consolidate it as it was a mess @wietzebeukema.nl ArgFuscator really comes to mind on this one 🤔Could look at the InitiatingProcess + the InitiatingAccount
010
DylanInfosec🛡️ @attackthesoc.com · 14/02/2025
Had this saved in the WIP folder forever KQL for anti-forensics activities github.com/AttacktheSOC... So much can be added to this. Think 3rd party tools to aid anti-forensics, browser forensics... too much to name OMG, look at this😶updates to come! github.com/MikeHorn-git...
github.com
193
DylanInfosec🛡️ @attackthesoc.com · 14/02/2025
Was asked by a colleague for some help with a Remediation Script and remembered this little number: reg2ps.azurewebsites.net from @roger_zander Thank you! Bookmark it If using it for Intune, modify the Check Script output. Replace any $false with a 1. and $true with 0
reg2ps.azurewebsites.net
Registry to PowerShell converter
Convert PowerShell scripts into Windows executables.
010
Reposted by DylanInfosec🛡️
Jouni Mikkola @jounimikkola.bsky.social · 09/02/2025
Just posted a new entry to my blog! Trying to hunt for couple of anomalies using MDE. A lot of problems arised, as usually. #threathunting #mde #defender threathunt.blog/registry-hun...
threathunt.blog
Look into couple of suspicous registry activities
Look into couple of suspicous registry activities
011
DylanInfosec🛡️ @attackthesoc.com · 28/01/2025
the simple query
let FileEvents = DeviceFileEvents
| where DeviceId == @"<device-id>"
| where ActionType endswith "AggregatedReport"
| summarize count() by bin(TimeGenerated, 1h)
| extend EventType = "FileEvents";
let ProocessEvents = DeviceProcessEvents
| where DeviceId == @"<device-id>"
| where ActionType endswith "AggregatedReport"
| summarize count() by bin(TimeGenerated, 1h)
| extend EventType = "ProocessEvents";
let NetworkEvents = DeviceNetworkEvents
| where DeviceId == @"<device-id>"
| where ActionType endswith "AggregatedReport"
| summarize count() by bin(TimeGenerated, 1h)
| extend EventType = "NetworkEvents";
let LogonEvents = DeviceLogonEvents
| where DeviceId == @"<device-id>"
| where ActionType endswith "AggregatedReport"
| summarize count() by bin(TimeGenerated, 1h)
| extend EventType = "LogonEvents";
union FileEvents, ProocessEvents, NetworkEvents, LogonEvents
| render timechart by EventType
000
DylanInfosec🛡️ @attackthesoc.com · 28/01/2025
Looking at some of the Aggregated Reporting of the different tables for the past few days (23-28) for a single device. #XDR #Defender
a timechart showing the trend of aggregated reporting events between Jan 23rd-28th for the 4 different supported tables. (No DeviceLogonEvents are shown)
120
DylanInfosec🛡️ @attackthesoc.com · 26/01/2025
000
DylanInfosec🛡️ @attackthesoc.com · 26/01/2025
100
DylanInfosec🛡️ @attackthesoc.com · 26/01/2025
Took a trip inside to get a break from the bleak winter weather
100
Reposted by DylanInfosec🛡️
Alex Verboon @vacyber.bsky.social · 26/01/2025
Defender Resource Hub Update - Winter 2025 defenderresourcehub.info #Security #Learn #StayUptodate #Defenders #MicrosoftSecurity
132
DylanInfosec🛡️ @attackthesoc.com · 24/01/2025
Very cool course by the folks at Kopidion LLC on how to look at things from the adversary's perspective. Thank you for the training!
Certificate of completion from Kopidion LLC on their course "Adversarial Thinking: The Art of Dangerous Ideas"
020
Reposted by DylanInfosec🛡️
Runa Sandvik @runasand.bsky.social · 24/01/2025
I wrote a very timely introduction to digital security for journalists for @gijn.org last fall. This guidance may also apply to activists, lawyers, and anyone else doing at-risk work these days. gijn.org/resource/int...
gijn.org
Introduction to Investigative Journalism: Digital Security
Digital security may seem a little daunting at first, but increased security will help investigative journalists build trust with — and protect — current and future sources.
26237
DylanInfosec🛡️ @attackthesoc.com · 24/01/2025
no way
120
DylanInfosec🛡️ @attackthesoc.com · 23/01/2025
Any and all feedback is welcome. Did sprint through quite a few things I was hoping to dive into but the presentation gods were not pleased with me on this day. Here are the slides for MDE Deception Capabilities: github.com/AttacktheSOC... KQLs: github.com/AttacktheSOC... many more to trickle in
github.com
020
DylanInfosec🛡️ @attackthesoc.com · 23/01/2025
Well... that was an experience, I thought I prepared for everything, just not Teams failing. Dug out an old laptop. Very big thanks to @cyb3rmik3.bsky.social for inviting me on and to anyone able to stick around and listen, thank you for your patience. I hope you were able to learn something new.
150
DylanInfosec🛡️ @attackthesoc.com · 23/01/2025
Thank you, man! Been prepping for it
000
DylanInfosec🛡️ @attackthesoc.com · 23/01/2025
Will do. Always seems to be the issue, have all these things I intend to say and they all try getting out at the same time causing me to freeze up. 🥤 I do get to cheat a little as it's an online talk so that alone calmed the nerves a bit.
110
DylanInfosec🛡️ @attackthesoc.com · 23/01/2025
Thank you, Tim!
010
DylanInfosec🛡️ @attackthesoc.com · 23/01/2025
Thank you! Much appreciated and needed. I never heard of Toorcamp but it looks awesome
110
DylanInfosec🛡️ @attackthesoc.com · 23/01/2025
Very excited to do my first my talk ever tomorrow. Me and public speaking aren’t close friends. Nervous as hell lol but ready and excited
470
Reposted by DylanInfosec🛡️
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 22/01/2025
📢 Don't miss @attackthesoc.com tomorrow talking about deception with MDE! The Greek Microsoft Security Community is thrilled to host its 3rd meetup tomorrow, featuring an exciting discussion with Dylan. ℹ️ More info on how to join ⤵️ www.meetup.com/greek-micros...
meetup.com
Greek Microsoft Security Community - 3rd Meetup with Dylan Tenebruso, Thu, Jan 23, 2025, 7:00 PM | Meetup
🇬🇷 Σας καλούμε στο πρώτο meetup για το 2025 και το τρίτο κατά σειρά της Ελληνικής Microsoft Security Κοινότητας που θα πραγματοποιηθεί online με θέμα "Artifice: Leveragin
132
DylanInfosec🛡️ @attackthesoc.com · 23/12/2024
🤘Happy to have you there man!
010
DylanInfosec🛡️ @attackthesoc.com · 22/12/2024
I’m honored and excited to have the opportunity to speak about the powerful deception rules feature in the MDE platform with the Greek Microsoft Security Community. Join us as we explore how to leverage this feature to enhance your detection strategy. Thank you, @cyb3rmik3.bsky.social !
260
DylanInfosec🛡️ @attackthesoc.com · 22/12/2024
How's everyone's Winter Arc going? What's that flashback scene going to look like?
000
DylanInfosec🛡️ @attackthesoc.com · 21/12/2024
Been playing more with the rpi and arduino. This time using OpenCV for facial detection and sending the id to rpi to the arduino display. Next, seeing if the kids want to help hook up some servos, craft a viable hand and get a waving robot hand. Articulation after that
a picture of myself on a computer screen with a green square around my face. The box is facial recognition identifier. My name at the top of the box and a confidence score of 48% at the bottomAn arduino is plugged into a raspberry pi via USB. The Arduino also has connections to a breadboard that also has an LCD screen and 8x8 LED matrix plugged in. The LCD shows the text "Hi, Dylan! Hope you're doin".
The LED matrix shows a sideways sad/angry face
020
DylanInfosec🛡️ @attackthesoc.com · 16/12/2024
This makes sense
010
DylanInfosec🛡️ @attackthesoc.com · 15/12/2024
They're all good. Is that the 15 R3? This is the 17 R4. This thing is more of a beast than I needed which has come in handy for bigger lab environments. reaching ~11 years old in a month or two and though it's falling apart it still runs strong and lives up to todays demands
110
DylanInfosec🛡️ @attackthesoc.com · 15/12/2024
Final product: 1) Sideways smiley face (clear skies) : ) 2) Cold ass nights 3) kids thinking they’re funny asking for a real raspberry 🥧
an LCD screen that display the current temperature "Temp 25. 🤌" on the top line and the current datetime on the bottom line.

The red is an LED matrix with a sideways smiley emoji displayed 
   : )
000
DylanInfosec🛡️ @attackthesoc.com · 15/12/2024
Relearning all of it as we went. Had completely forgotten there was a time I went to school for Computer Engineering with a plan to focus on Swarm Tech/Intelligence. Might make it a side hobby lol
000
DylanInfosec🛡️ @attackthesoc.com · 15/12/2024
We took over the table to learn a bit about programming today. Raspberry Pi hits the OpenWeatherAPI to get the weather forecast and feeds it to the micro LCD, top line reads datetime Bottom line summarizes the weather. Max7219 displays a emoji face resultant of the weather
a messy table littered with electrical components, wires, breadboards, a mega2560 microcontroller, raspberry pi 3B v2, and a laptop with stickers because 1337
250
DylanInfosec🛡️ @attackthesoc.com · 13/12/2024
Ahhh man… the gifs didn’t gif, what the hell.
000
DylanInfosec🛡️ @attackthesoc.com · 13/12/2024
Bought my daughter a Procreate license an hour ago… she’s so damn awesome. So proud and excited to see what she makes next . No books or tutorials, just craftin some stuff up
110
DylanInfosec🛡️ @attackthesoc.com · 10/12/2024
Every once in a while I’ll throw that movie on just for the opening scene. Excited to see what they do with this next one.
000
DylanInfosec🛡️ @attackthesoc.com · 08/12/2024
lol damn, now I want too
010
Reposted by DylanInfosec🛡️
Rudy Ooms | MVP @call4cloud.nl · 07/12/2024
And just like that, all our #windows devices suddenly got dual enrollment aka LinkedEnrollment. This groundbreaking step toward Declarative Device Management enrollment was triggered by Device Inventory. This new feature also makes use of the MMP-C infra alongside EPM #msintune #intune
1171
DylanInfosec🛡️ @attackthesoc.com · 08/12/2024
Sometimes to get back to my NJ Italian-American roots I call sausage, sawseege. Mozzarella, motz or motzahrell. Vaffanculo, fongool
media.tenor.com
a man in a tuxedo is standing in a room with the word prego written on the bottom of his face .
Alt: a man in a tuxedo is standing in a room and raises his hand with the Italian hand gesture🤌 with the word prego written on the bottom
110
DylanInfosec🛡️ @attackthesoc.com · 08/12/2024
Really glad you found it useful. Of course if you any questions or guidance, ask away. There’s a starter pack here including just about everyone in that post and more: go.bsky.app/FEimG9X
010
DylanInfosec🛡️ @attackthesoc.com · 08/12/2024
tired as hell.. think i wrote the last few paragraphs cross-eyed... gonna watch Harakiri again and pass out before opening credits
media.tenor.com
a black and white photo of a man kneeling on a white mat
Alt: a black and white photo of a man kneeling on a white mat before a blade, a mope bucket sits behind him. This is taken from the move Harakiri
010
DylanInfosec🛡️ @attackthesoc.com · 08/12/2024
Finally, another blog post.. this one is a bit different focusing on cleaning up the SOC instead of adding things to it. Optimizing what you already have for more efficiency. attackthesoc.com/posts/ms-xdr...
attackthesoc.com
Optimizing the SOC
Explore ways of optimizing alerts to reduce false positives, leveraging built-in tools to streamline operations, and implementing features that boost productivity for a more efficient and effective SO...
140
DylanInfosec🛡️ @attackthesoc.com · 07/12/2024
I think you nailed it
010