Sign in

Dirk-jan

@dirkjanm.io
2K followers 66 following 80 posts

Hacker at outsidersecurity.nl. Researches Entra ID, AD and occasionally Windows security. I write open source security tools and do blogs/talks to educate others on these topics. Blog: dirkjanm.io

PostsRepliesMedia
Dirk-jan @dirkjanm.io · 17/03/2026
It appears that Microsoft removed the discovery of all domains in a tenant through ACS, a technique that I shared at my BH/DC talks last summer (though probably not many people spotted the reference). I found it out during a live demo of course 🙃
082
Dirk-jan @dirkjanm.io · 17/02/2026
Since I was bored on a plane I decided to revisit some of the Windows Hello tradecraft and finally implemented browser based FIDO2 auth using WHFB keys in roadtx. Thanks @fabian.bader.cloud and @nathanmcnulty.com for the inspiration!
061
Dirk-jan @dirkjanm.io · 06/02/2026
Next week at WWHF Mile High I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀
095
Dirk-jan @dirkjanm.io · 27/10/2025
Seems Microsoft is doing some app and permission cleanups and tenant restrictions lately. RIP Microsoft Planner FOCI client.
050
Dirk-jan @dirkjanm.io · 25/07/2025
For those like me who prefer to stay in the terminal and want to call REST APIs like the Microsoft Graph without complicated commands or copy/pasting tokens: roadtx now has a graphrequest command to perform simple requests against these APIs and parse the JSON.
2181
Dirk-jan @dirkjanm.io · 30/05/2025
Since we now can use Entra ID connect sync with a service principal, I thought I'd look into the new security measures. On hosts without a TPM, we can dump the cert+key. On hosts with TPM (second picture) we can use the key to create an auth assertion for roadtx to req tokens.
1152
Dirk-jan @dirkjanm.io · 16/05/2025
I'll be returning to #BHUSA @blackhatevents.bsky.social this summer for a brand talk about moving laterally from AD to Entra ID. I don't think I've ever been this excited about a talk, with lots of cool stuff to share 🎢 😄.
Advanced Active Directory to Entra ID Lateral Movement Techniques
Dirk-jan Mollema  |  Security Researcher, Outsider Security
Format: 40-Minute Briefings
Tracks: Cloud Security, Enterprise Security

Is there a security boundary between Active Directory and Entra ID in a hybrid environment? The answer to this question, while still somewhat unclear, has changed over the past few years as there has been more hardening of how much "the cloud" trusts data from on-premises. The reason for this is that many threat actors, including APTs, have been making use of known lateral movement techniques to compromise the cloud.

In this talk, we will take a deep dive together into Entra ID and hybrid trust internals. We will introduce several new lateral movement techniques that allow us to bypass authentication, MFA and stealthily exfiltrate data using on-premises AD as a starting point, even in environments where the classical techniques didn't work. All these techniques are new, not really vulnerabilities, but part of the design. Several of them have been remediated with recent hardening efforts by Microsoft. Very few of them leave useful logs behind when abused. As you would expect, none of these "features" are documented.

Join me for a wild ride into Entra ID internals, undocumented authentication flows and tenant compromise from on-premises AD.
1151
Dirk-jan @dirkjanm.io · 27/03/2025
Automatic browser SSO with a PRT on a victim device over an Outflank C2 implant 🥰 using ROADtools and some hackery from Max Grim.
0163
Dirk-jan @dirkjanm.io · 09/03/2025
Small detour on the way to Insomni'hack! @1ns0mn1h4ck.bsky.social
A picture of snowy swiss mountains with a blue sky
190
Dirk-jan @dirkjanm.io · 20/02/2025
It appears Microsoft quietly mitigated most of the risk of the "Intune company portal" device compliance CA bypass by restricting the scope of Azure AD graph tokens issued to this app, making them almost useless for most abuse scenarios. Thx @domchell.bsky.social for the heads up.
0299
Dirk-jan @dirkjanm.io · 18/02/2025
Normally you can't auth to Entra ID connected webapps with bearer tokens. But if Teams can open SharePoint/OneDrive with an access token, I guess so can we. roadtx now supports opening SharePoint with access tokens in the embedded browser 😀
1198
Dirk-jan @dirkjanm.io · 22/01/2025
Since redirect URLs are tricky, roadtx now includes redirect URLs for many first-party apps and uses them automatically. Demo below shows the interactiveauth module being used for the complaint device CA bypass with the "interactiveauth" module and the "companyportal" client ID alias.
1136
Dirk-jan @dirkjanm.io · 21/01/2025
After some time off to recharge outside, now back to work (and research) this week!
2603
Dirk-jan @dirkjanm.io · 07/01/2025
Off to a good start in the new year (Part 2). I was awarded the Microsoft MVP status a few days ago for my community contributions in the Microsoft security space. Super grateful for everyone who helped along the way to get me there! ❤️
4400
Dirk-jan @dirkjanm.io · 02/01/2025
Off to a good start in the new year! (Part 1). Thanks @msftsecresponse.bsky.social for the cool swag!
0210
Dirk-jan @dirkjanm.io · 14/11/2024
Bit of work on the go! It's not Starbucks, hope our cult leader @xpnsec.com approves anyway.
461