Dirk-jan @dirkjanm.io · 17/03/2026It appears that Microsoft removed the discovery of all domains in a tenant through ACS, a technique that I shared at my BH/DC talks last summer (though probably not many people spotted the reference). I found it out during a live demo of course 🙃 082
Dirk-jan @dirkjanm.io · 17/02/2026Since I was bored on a plane I decided to revisit some of the Windows Hello tradecraft and finally implemented browser based FIDO2 auth using WHFB keys in roadtx. Thanks @fabian.bader.cloud and @nathanmcnulty.com for the inspiration! 061
Dirk-jan @dirkjanm.io · 06/02/2026Next week at WWHF Mile High I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀 095
Dirk-jan @dirkjanm.io · 27/10/2025Seems Microsoft is doing some app and permission cleanups and tenant restrictions lately. RIP Microsoft Planner FOCI client. 050
Dirk-jan @dirkjanm.io · 25/07/2025For those like me who prefer to stay in the terminal and want to call REST APIs like the Microsoft Graph without complicated commands or copy/pasting tokens: roadtx now has a graphrequest command to perform simple requests against these APIs and parse the JSON. 2181
Dirk-jan @dirkjanm.io · 30/05/2025Since we now can use Entra ID connect sync with a service principal, I thought I'd look into the new security measures. On hosts without a TPM, we can dump the cert+key. On hosts with TPM (second picture) we can use the key to create an auth assertion for roadtx to req tokens. 1152
Dirk-jan @dirkjanm.io · 16/05/2025I'll be returning to #BHUSA @blackhatevents.bsky.social this summer for a brand talk about moving laterally from AD to Entra ID. I don't think I've ever been this excited about a talk, with lots of cool stuff to share 🎢 😄. 1151
Dirk-jan @dirkjanm.io · 27/03/2025Automatic browser SSO with a PRT on a victim device over an Outflank C2 implant 🥰 using ROADtools and some hackery from Max Grim. 0163
Dirk-jan @dirkjanm.io · 09/03/2025Small detour on the way to Insomni'hack! @1ns0mn1h4ck.bsky.social 190
Dirk-jan @dirkjanm.io · 20/02/2025It appears Microsoft quietly mitigated most of the risk of the "Intune company portal" device compliance CA bypass by restricting the scope of Azure AD graph tokens issued to this app, making them almost useless for most abuse scenarios. Thx @domchell.bsky.social for the heads up. 0299
Dirk-jan @dirkjanm.io · 18/02/2025Normally you can't auth to Entra ID connected webapps with bearer tokens. But if Teams can open SharePoint/OneDrive with an access token, I guess so can we. roadtx now supports opening SharePoint with access tokens in the embedded browser 😀 1198
Dirk-jan @dirkjanm.io · 22/01/2025Since redirect URLs are tricky, roadtx now includes redirect URLs for many first-party apps and uses them automatically. Demo below shows the interactiveauth module being used for the complaint device CA bypass with the "interactiveauth" module and the "companyportal" client ID alias. 1136
Dirk-jan @dirkjanm.io · 21/01/2025After some time off to recharge outside, now back to work (and research) this week! 2603
Dirk-jan @dirkjanm.io · 07/01/2025Off to a good start in the new year (Part 2). I was awarded the Microsoft MVP status a few days ago for my community contributions in the Microsoft security space. Super grateful for everyone who helped along the way to get me there! ❤️ 4400
Dirk-jan @dirkjanm.io · 02/01/2025Off to a good start in the new year! (Part 1). Thanks @msftsecresponse.bsky.social for the cool swag! 0210
Dirk-jan @dirkjanm.io · 14/11/2024Bit of work on the go! It's not Starbucks, hope our cult leader @xpnsec.com approves anyway. 461