Sign in

Lee Holmes

@leeholmes.com
93 followers 103 following 42 posts

Partner Security Architect, Azure Security. PowerShell developer, fanatical hobbyist, and author of the PowerShell Cookbook.

PostsRepliesMedia
Lee Holmes @leeholmes.com · 22/09/2026
Wow, had a fantastic time at Blue Team Con. Every year, the conference finds a way to get better. It's so refreshing to have a conference with talks based on concrete, hard-won lessons for defenders.
110
Lee Holmes @leeholmes.com · 10/09/2026
Holy shit. If you thought SIM swapping was a problem, you wouldn't believe the gaping mess of enacting a Power of Attorney. POA lets family members / care givers get access to somebody's bank accounts etc., and it's ridiculous. A few forged documents / phone calls is all it takes.
010
Lee Holmes @leeholmes.com · 09/09/2026
I really liked the form factor, but the camera was shiiiiiiiiiite
110
Lee Holmes @leeholmes.com · 09/09/2026
Ok, my fragile memory managed to hold onto this. Gonna try it this weekend at Blue Team Con.
001
Lee Holmes @leeholmes.com · 04/08/2026
Ok, finally captured some thoughts about our new book, Threat Driven Software Development here: www.leeholmes.com/threat-drive.... If you are a Blue Teamer working on developing or securing online services - this is your jam and I hope you enjoy it.
leeholmes.com
Threat Driven Software Development
If you’re a Blue Teamer trying to write secure services or secure an organization that does, Threat Driven Software Development is the book you’ve been looking for. This was a deep collaboration betwe...
010
Lee Holmes @leeholmes.com · 04/08/2026
Oooh! At least you know which doggo to have help build your next secure online service then!
000
Lee Holmes @leeholmes.com · 06/06/2026
It's alive! If you're a Blue Teamer trying to write secure services or secure an organization that does, Threat Driven Software Development is the book you've been looking for. www.amazon.com/dp/0135567386
amazon.com
Threat-Driven Software Development: Defending online services from modern threat actors
Threat-Driven Software Development: Defending online services from modern threat actors
062
Lee Holmes @leeholmes.com · 10/04/2026
Arright... I've enjoyed Giordano's and Lou Malnati's when I go to Blue Team Con. I'll make this happen :)
140
Reposted by Lee Holmes
Microsoft Security Response Center @msrc.microsoft.com · 10/04/2026
🗓️ Mark your calendars 🗓️ BlueHat is headed to Singapore, September 17–18. Call for Papers and registration announcements coming soon. 👀
045
Lee Holmes @leeholmes.com · 10/04/2026
100%. Show me the MMA champ that's never had a black eye and I'll show you the charletan.
020
Reposted by Lee Holmes
Barry Dorrans @blowdart.me · 09/04/2026
I still love making bounty payouts though. It's the best bit of my job.
092
Lee Holmes @leeholmes.com · 26/02/2026
Haha, people yell at me when I share tarantula pics without warning :)
010
Lee Holmes @leeholmes.com · 20/02/2026
Artwork is not final yet, but I can't wait! The amount of battle tested content in this book is unbelievable. And by battle tested, I mean it. Name an APT and Microsoft has had to defend against them.
Book cover for "Threat Driven Software Development: Defending online services from modern threat actors." Colors are primarily blue, with a depiction of an attack graph.
120
Lee Holmes @leeholmes.com · 10/02/2026
Sweet! BlueHat Redmond has kicked off its CFP! BlueHat brings together security researchers and responders to exchange ideas and best practices - including vulnerability research, mitigations, emerging threats, techniques, and more. Submit your paper by February 28, 2026: aka.ms/BH26CFP
000
Lee Holmes @leeholmes.com · 30/01/2026
No cover or concrete release date yet (content is fully complete and going through the editorial process), but this is going to be a banger.
020
Lee Holmes @leeholmes.com · 30/01/2026
"Threat Driven Software Development" distills 30 years of lessons learned at Microsoft on how to operationally secure services: management infrastructure, identities, keys, secrets, build systems, networks, risk management - you name it.
120
Lee Holmes @leeholmes.com · 30/01/2026
So freakin' excited. Have a book coming out with Michael Howard (author of Writing Secure Code), Sherrod DeGrippo (Director of Threat Intelligence at Microsoft) and Shawn Hernan (Director of Azure's Security Assurance organization).
140
Lee Holmes @leeholmes.com · 29/01/2026
Don't know if you went down the full ergodox + colemax rabbit hole, but going back to QWERTY from an alternate keyboard layout feels like mars too.
000
Lee Holmes @leeholmes.com · 26/01/2026
People's brains cramp the first time they pick a movie randomly - it's interesting to watch. Give the movie 20 minutes before you bail, and you'll find that you end up watching and enjoying them more often than not.
010
Lee Holmes @leeholmes.com · 21/01/2026
Security is a far better place for his contributions.
040
Lee Holmes @leeholmes.com · 21/01/2026
- The invention of AMSI in Windows, letting applications finally take an active role in their own defense - Appliance-like delivery of some major on-premises projects that hardened these systems far more than operators could, and also protected them from hostile operational environments.
120
Lee Holmes @leeholmes.com · 21/01/2026
- The first scripting language to ever account for security from the get-go - Countless improvements to Code Integrity in Windows to support dynamic runtimes - The only scripting language to actively engage the researcher community in how to adapt to the evolving threat landscape
120
Lee Holmes @leeholmes.com · 21/01/2026
Wow, what an amazing impact @jsnover.com has had on the security industry and everybody that's had the privilege to work with him. Jeffrey's leadership was directly responsible for:
171
Lee Holmes @leeholmes.com · 21/01/2026
Congratulations! If you ever need more fish, I can make that happen :)
020
Lee Holmes @leeholmes.com · 21/01/2026
Like, there should be a meme license that you need to obtain before being granted access to giphy.com.
000
Lee Holmes @leeholmes.com · 21/01/2026
Congrats on the addition to the family :) Before you know it, you'll have a bunch :)
010
Lee Holmes @leeholmes.com · 16/01/2026
Wife: "Whoa, Lewis Hamilton is getting a new race engineer this season" Me: "Who?" Wife: "🏎️🐎 We are checking... 🐎🏎️"
030
Lee Holmes @leeholmes.com · 16/01/2026
Nope, regular ol' APL :) ⎕IO ← 0 iter ←{⍉(≢⍉⍵)↑⍉(≢⍵)↑1⊖1⌽1⊖⊃9.05÷⍨+/+⌿1 0 ¯1∘.⊖1 0 ¯1⌽¨⊂¯1⊖¯1⌽( (≢⍵)+2)↑⍉((≢⍉⍵)+2)↑⍉⍵⍪28+228×?2⍴⍨≢⍵} {}{canvas∘←170↓' +=*░#▒▓'[(⌊(⍵÷10))⌊9]⋄_←⎕DL÷32⋄iter ⍵}⍣≡0⍴⍨1 1×250
110
Lee Holmes @leeholmes.com · 16/01/2026
Those approaches didn't end up working out for Encarta, but congratulations to Wikipedia to being an incredible resource for humanity.
000
Lee Holmes @leeholmes.com · 16/01/2026
They tried for a while with the quality angle - having paid professional editors being the primary content owners. And then they pivoted for a while by allowing community contributions that paid professional editors would then fact and quality check.
100
Lee Holmes @leeholmes.com · 16/01/2026
25 years ago is 2001. I joined Microsoft on the Encarta Encyclopedia team in 2002 and asked as part of my interviews: "So what are you going to do about this Wikipedia thing?"
100
Lee Holmes @leeholmes.com · 15/01/2026
I think it's mostly just "programmer" :) Unlike human languages - after the first programming language, they're mostly all the same.
020
Lee Holmes @leeholmes.com · 15/01/2026
Ever seen a demoscene demo in APL? Now you have. www.leeholmes.com/apl-demoscene/
000
Lee Holmes @leeholmes.com · 15/01/2026
Haha, I've spent so many times looking at it that I can notice the GH version has a bug that makes the fire drift left :) I also did it in APL recently, that was a trip: www.leeholmes.com/apl-demoscene/
leeholmes.com
APL's Demoscene
APL is one of the most curious programming languages you’ll ever run across. For example, take a random problem out of Rosetta Code: “Numbers divisible by their individual digits, but not by the produ...
110
Lee Holmes @leeholmes.com · 10/10/2025
Was in a discussion with somebody once about their horse, and the conversation included the phrase, "and before you know it, you're in it for a million bucks."
000
Lee Holmes @leeholmes.com · 24/09/2025
Tower: "Caution, wake turbulence"
020
Lee Holmes @leeholmes.com · 24/09/2025
Had a huge YouTuber (IShowSpeed, 44M subs) come to a place I was at last night. It was madness. Dozens (200?) of kids and teens swarming, screaming his name, and calling his cliches out to him. He seemed like a nice enough guy, and his security mostly kept the mob from interrupting the rest of us.
IShowSpeed about to approach a crowd of fans
010
Lee Holmes @leeholmes.com · 12/09/2025
On close final to a runway, especially at night, is one of the universe's most beautiful views
110
Lee Holmes @leeholmes.com · 10/09/2025
Have you seen how PowerShell Core now sends de-obfuscated .NET API calls to the AMSI stream?
The following console contetn: [Console]::(-join (294,291,312,293,308,317,312,319,308 | % { [char] ($_ -bxor 337) }))("Hello World")

With a debug message showing what is being sent to AMSI:

=== Amsi notification report content ===
<System.Console>.WriteLine(<Hello World>)
=== Amsi notification report success: True ===
030
Lee Holmes @leeholmes.com · 10/09/2025
One of the little pet projects I'm proudest of - extremely simple comment system for static sites: www.leeholmes.com/statique-sim...
leeholmes.com
Statique: Simple Self-Hosted Comments for Static Websites
When hosting a static website or blog, you ultimately have to tackle the question: “What about the comments?
010
Lee Holmes @leeholmes.com · 08/09/2025
I could watch stuff like this all day. The world needs more fixers.
Construction workers ashphalting a road.
000
Lee Holmes @leeholmes.com · 08/09/2025
I also haven't seen anybody poking into the new method invocation logging (vs raw 4304 script text) in Open Source PowerShell from a defensive side of things - github.com/PowerShell/P...
github.com
Add AMSI method invocation logging as experimental feature by PaulHigin · Pull Request #16496 · PowerShell/PowerShell
PR Summary This PR adds a new experimental feature that adds new AMSI logging of .NET method invocations. PR Context This uses a new AMSI notification API to log .NET method invocations. PR Checkli...
020
Lee Holmes @leeholmes.com · 08/09/2025
That looks cool. Are these recorded? It would be cool to see if the Revoke-Obfuscation work (based on PowerShell's AST) is any help. github.com/danielbohann...
github.com
GitHub - danielbohannon/Revoke-Obfuscation: PowerShell Obfuscation Detection Framework
PowerShell Obfuscation Detection Framework. Contribute to danielbohannon/Revoke-Obfuscation development by creating an account on GitHub.
110
Lee Holmes @leeholmes.com · 08/09/2025
Smart way for Chicago to protect the crowds at this weekend's Taste of Chicago festival from the monsters that try to mow them down.
A line of dump trucks, full, nose-to-tail, parked on the side of the street protecting a park.
021