Sign in

EricaZelic

@ericazelic.bsky.social
1.9K followers 1.1K following 192 posts

Security Engineer / IAM Security. Defending against people like me.

PostsRepliesMedia
EricaZelic @ericazelic.bsky.social · 02/04/2025
Logged on to social media, saw a sick person celebrating people's mistakes and demonstrating their toxicity in the workplace, happy their coworker might be having a hard time. Logging off social media. I don't need to be reminded there are hateful souls in the world today. Try Love, Less Hate.
1160
EricaZelic @ericazelic.bsky.social · 02/04/2025
Working with people like you is toxic. You are the type of person who can't work in a team, completely fake, celebrate people's mistakes, deeply insecure, and rotten at your core. The reason they left likely has zero to do with you. You should quit. Everyone will be happier.
010
EricaZelic @ericazelic.bsky.social · 01/04/2025
This time I tried something new: I'm burnt out and defeated. I'm not used to these feeling coming from offsec. So I took a couple days off, instead of quitting.
0100
EricaZelic @ericazelic.bsky.social · 01/04/2025
thanks!
000
EricaZelic @ericazelic.bsky.social · 26/03/2025
What is the equivalent of windows event view in iOS?
130
EricaZelic @ericazelic.bsky.social · 23/03/2025
People are more reactive than normal due to the political state of the world. This will pass. Hang in there 💙
020
EricaZelic @ericazelic.bsky.social · 23/03/2025
😞
030
EricaZelic @ericazelic.bsky.social · 22/03/2025
Many people are much uglier on the inside than they are on the outside.
040
EricaZelic @ericazelic.bsky.social · 22/03/2025
If nothing else, the last 2 months have allowed American's to see each others' true colors. Ignorance is bliss.
150
Reposted by EricaZelic
jpiterak.bsky.social @jpiterak.bsky.social · 22/03/2025
This is great.👇
0145
EricaZelic @ericazelic.bsky.social · 22/03/2025
Talking doesn't help and it wastes a lot of high dollar salary.
000
EricaZelic @ericazelic.bsky.social · 22/03/2025
I'm not going to vendor calls anymore. I'll send my questions in writing from now on.
100
EricaZelic @ericazelic.bsky.social · 21/03/2025
We'll see how many of us poor people he stole from want to fight his wars.
040
EricaZelic @ericazelic.bsky.social · 20/03/2025
As a public figure, what matters the most is whether or not people like you. Elmo has been given a lesson. It's up to him what he does with it. He can continue a state of denial or he can learn. The choice is his.
020
Reposted by EricaZelic
Covie @covie93.bsky.social · 20/03/2025
Imagine calling yourself the master race and have to resort to erasing the achievements of minorities to make yourself feel better.
923345058545
EricaZelic @ericazelic.bsky.social · 20/03/2025
Once upon a time, long long ago, people used to go over to each others' houses and just sit and talk.
130
EricaZelic @ericazelic.bsky.social · 20/03/2025
I totally forgot about the russian reverse-rdp thing, thanks!
010
EricaZelic @ericazelic.bsky.social · 19/03/2025
Nice!! Thanks Nathan!
110
EricaZelic @ericazelic.bsky.social · 19/03/2025
This is why I prefer email. Put it in writing.
020
EricaZelic @ericazelic.bsky.social · 19/03/2025
I think saying I was pissed would be an understatement
110
EricaZelic @ericazelic.bsky.social · 19/03/2025
Aside from compliance concerns being skirted around, and that, let's just say my BS monitor was maxed out and I got a little mad. His goal was to fill up the call with technobabble that didn't apply to us knowing that most of the people on the call wouldn't understand that's what he was doing.
220
EricaZelic @ericazelic.bsky.social · 19/03/2025
The vendor talked at me instead of to me and played a sales game. Instead of addressing concerns, gambled on stating "it depends on the skill or your admins" not realizing I'm considered an expert.
110
EricaZelic @ericazelic.bsky.social · 19/03/2025
Has anyone ever had a bad call with a vendor? I had one today. It was my first bad call with a vendor.
470
EricaZelic @ericazelic.bsky.social · 19/03/2025
Tell me who does that? 😜
100
EricaZelic @ericazelic.bsky.social · 18/03/2025
Offsec was way more fun
010
EricaZelic @ericazelic.bsky.social · 18/03/2025
Wow
010
EricaZelic @ericazelic.bsky.social · 18/03/2025
www-bleepingcomputer-com.cdn.ampproject.org/v/s/www.blee...
www-bleepingcomputer-com.cdn.ampproject.org
New Windows zero-day exploited by 11 state hacking groups since 2017
At least 11 state-backed hacking groups from North Korea, Iran, Russia, and China have been exploiting a new Windows vulnerability in data theft and cyber espionage zero-day attacks since 2017.
141
EricaZelic @ericazelic.bsky.social · 18/03/2025
Omg Intune. I swear, managing M365 requires 10 PhD equivalencies.
0201
EricaZelic @ericazelic.bsky.social · 16/03/2025
The price of tuna has increased 700% since the 80s. Invest in tuna 😋 🐟
130
EricaZelic @ericazelic.bsky.social · 16/03/2025
Be sure to look at all the mail records and don't search just based on a designation of Failure. Sometimes, you will see a Failure with a Delivered with the same timestamp and the recipient did in fact receive the email.
030
EricaZelic @ericazelic.bsky.social · 16/03/2025
Some nuances to look out for: Depending on tenant settings (some orgs are very complex), you may need to check both *@yourdomain.yourtopleveldomain and *@yourdomainmoera.onmicrosoft.yourtopleveldomain. This depends on your DNS records and mail gateways. Another gotcha is the UTC time. Be careful.
140
EricaZelic @ericazelic.bsky.social · 16/03/2025
You can also run Exchange Message Trace reports from either Exchange Online Admin Center or Security Admin Center. There is a selection the Message Trace that allows you to search for failed/bounced messages or all messages in the past 1 day. You can update the search time to look back further.
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
The first thing you can check is the NDR report in Exchange Online Admin Cetner: admin.exchange.microsoft.com --> Reports --> Mail Flow --> Non-delivery details report.
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
As many people are aware, there have been ongoing issues with Exchange the past few weeks. The latest *incident* (not advisory) is about NDRs. We have been seeing tons of NDRs but do not match the NDR codes in the Incident. /1
160
EricaZelic @ericazelic.bsky.social · 16/03/2025
Interesting.
140
EricaZelic @ericazelic.bsky.social · 16/03/2025
Today I learned the difference between TPMv2 and fTPM. It seems like a lot of devices are using firmware versions of TPM although the specification version lists 2.0 with a subversion.
160
EricaZelic @ericazelic.bsky.social · 16/03/2025
nvm, I found the answer. It will use software based key storage if TPM version 1
130
EricaZelic @ericazelic.bsky.social · 16/03/2025
for clarity, I'm talking about this part: learn.microsoft.com/en-us/entra/...
120
EricaZelic @ericazelic.bsky.social · 16/03/2025
And if it's bound using TPM, would it be required to have TPM version 2 to ensure the certificate is bound to the device?
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
If it's just mapping based on the device hostname, what's to stop someone from impersonating that hostname on a rogue device?
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
Since the device certificate and the user certificate are separate, would this mean I would be able to steal the device certificate and use it on another device? Or is the device certificate mapped to a UPN or specific criteria of the device registered?
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
Compare this **Object ID** using the Microsoft Graph API to query for the details using [GET /servicePrincipals/{objectid}](/graph/api/serviceprincipal-get) and confirm that the servicePrincipalNames property is `urn:p2p_cert`. /4
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
To ensure this is the correct application, you can find the **Object ID** of the P2P Server application in the **Microsoft Entra admin center** > **Applications** > **Enterprise Applications**. Remove the default filter applied do you can see all applications. /3
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
any Microsoft Entra joined or Microsoft Entra hybrid joined Windows devices in your tenant. This application creates a tenant wide certificate issued by Microsoft Entra's certificate authority and is used to issue RDP device and user certificates for RDP connectivity. /2
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
SO @nathanmcnulty.com another question based on the MS github description: The P2P Server application is application registered by Microsoft Entra ID to enable Remote Desktop Protocol (RDP) connections to /1
110
EricaZelic @ericazelic.bsky.social · 16/03/2025
Thanks Nathan!!
010
EricaZelic @ericazelic.bsky.social · 16/03/2025
Dear SharePoint developers. If your SharePoint Online application is more than one year old, your delegated API permissions may no longer follow least privilege. Microsoft now has the sites.selected API permission which is akin to SP on-prem ACS permissions. learn.microsoft.com/en-us/sharep...
learn.microsoft.com
Understanding Resource Specific Consent for Microsoft Graph and SharePoint Online
Understanding Resource Specific Consent for Microsoft Graph and SharePoint Online.
030
EricaZelic @ericazelic.bsky.social · 16/03/2025
Thank you!!
010
EricaZelic @ericazelic.bsky.social · 16/03/2025
also, this blog is awesome! thanks for sharing this!
010
EricaZelic @ericazelic.bsky.social · 16/03/2025
Thanks!!!
110