Sign in

Nathan McNulty

@nathanmcnulty.com
5.7K followers 431 following 3.5K posts

Loves Jesus, loves others | Husband, father of 4, security solutions architect, love to learn and teach | Microsoft MVP | @TribeOfHackers | 🐘infosec.exchange@nathanmcnulty

PostsRepliesMedia
Nathan McNulty @nathanmcnulty.com · 11/08/2026
Huge improvements to nodoc! I redesigned orchestration so Sol now drives continual improvement of the playbooks :) Putting the process through evals, codex-spark now drives CDP/npm scripts and static analysis, luna handles review and next steps, and sol manages and approves 🔥
110
Nathan McNulty @nathanmcnulty.com · 09/08/2026
They always hide the good stuff in the notes :) I've always liked Enterprise State Roaming, but many places never enabled it. Now the feature has been superseded by Windows settings backup and restore which will be enabled by default starting with the upcoming 26H2 release 🥳
191
Nathan McNulty @nathanmcnulty.com · 08/08/2026
Did you know Entra has recommendations for configuration settings and can even send email alerts on expiring app/service principal credentials? Ideally, I recommend using Maester which has far broader coverage, but this is a nice built-in feature :) entra.microsoft.com/...
081
Nathan McNulty @nathanmcnulty.com · 18/07/2026
It makes me laugh every time I see something like this, lol Like, there is some criminal out there that thought, hmm, I'm gonna sign up for a free Azure trial, set up an Azure Monitor group, and abuse it to send out malicious email 🧠 This is why we can't have nice things :p
120
Nathan McNulty @nathanmcnulty.com · 16/07/2026
Conditional Access in the portal has been flaky for me most of the day, and then randomly this showed up in a few tenants 😎 This is a really nice view, makes it so much easier to find the right policies and notice where you are missing control 🥳
070
Nathan McNulty @nathanmcnulty.com · 16/07/2026
Whelp, it seems they are going to keep me around for another year, now in two categories :p A huge thanks to everyone here who shares and asks great questions - I wouldn't be in this program if it weren't for you :) Looking forward to sharing even more this year!
2220
Nathan McNulty @nathanmcnulty.com · 27/06/2026
WHAT?!?
292
Nathan McNulty @nathanmcnulty.com · 18/06/2026
Periodic reminder that even Microsoft recommends disabling Device code flow The primary two areas I see this used are Teams phones / Conference room type equipment and administrative CLI tools, and you should still block by default and exclude as needed learn.microsoft.com/...
151
Nathan McNulty @nathanmcnulty.com · 17/06/2026
Apparently M365 Developer tenants only enforce 1 factor for SSPR for admins... 🫠 Almost had a heart attack and opened a ticket with MSRC, lol I've checked several retail tenants now, and they are all properly enforcing 2 factors 😅
130
Nathan McNulty @nathanmcnulty.com · 10/06/2026
Do you know what your agents are doing? Worried about what kind of websites they might be looking at? Now you can apply the same web content filtering policies to them as you do to your users! 😅 learn.microsoft.com/...
050
Nathan McNulty @nathanmcnulty.com · 07/06/2026
😭
130
Nathan McNulty @nathanmcnulty.com · 01/06/2026
Whelp, it seems GitHub Copilot went from one extreme to the next It was obvious and understandable something had to change as the premium request model was unsustainably generous, but the new token based model ends up being way more expensive than Codex, Claude, or openrouter.ai
020
Nathan McNulty @nathanmcnulty.com · 28/05/2026
No big deal, just Purview admin portal shipping telemetry to Google...
062
Nathan McNulty @nathanmcnulty.com · 22/05/2026
Holy crap they did it! They backported support for AppContainers from 7.7 to 7.6 🥳 For those who many not be familiar with AppContainers - it's sandboxing. We can sandbox PowerShell. I repeat, we can freaking sandbox PowerShell, natively! github.com/PowerShel...
160
Nathan McNulty @nathanmcnulty.com · 16/05/2026
Can anyone tell me what the point is in reporting malicious domains in Defender XDR if it's not even getting looked at within 24 hours? Even free services already identified this as bad... Daniel Card pointed this one out, seemed pretty easy but I guess not 🤷‍♂️
091
Nathan McNulty @nathanmcnulty.com · 16/05/2026
I cannot wait to use this phrase on a call "That was useful in a painful way" 🤣
040
Nathan McNulty @nathanmcnulty.com · 14/05/2026
I may need an intervention... I'm pretty sure I just said "user-based service accounts are better than service principals, actually"... and in the given context, it was 100% true Service Principals have some really dumb limitations that make user accounts a better fit 🥴
160
Nathan McNulty @nathanmcnulty.com · 14/05/2026
I love getting gaslit by Azure all the time... Automation accounts and Function apps only support PowerShell 7.4, even though 7.5 was released 1.5 years ago and 7.6 was released a few months ago "Please consider updating it soon." 😒 No Azure, you consider updating it soon...
240
Nathan McNulty @nathanmcnulty.com · 05/05/2026
For all the shady stuff I've done so far, it's funny a simple request to use the Bearer token from the integrated browser against the CLI is what got me in trouble :p
150
Nathan McNulty @nathanmcnulty.com · 30/04/2026
Did you know there are at least 6 ways to store data about users in Entra? 😅 Outside of normal user object attributes, directory extensions tend to be one of the best fits for most things, except for sensitive data - use custom security attributes ;) learn.microsoft.com/...
0100
Nathan McNulty @nathanmcnulty.com · 30/04/2026
You can allow xAI models in M365 Copilot, and this note is... 🫠🤣
171
Nathan McNulty @nathanmcnulty.com · 29/04/2026
Wait... agents get to have Linux desktops in Cloud PC but users don't?
240
Nathan McNulty @nathanmcnulty.com · 15/04/2026
Shiny brain
151
Nathan McNulty @nathanmcnulty.com · 15/04/2026
This is pretty cool. You can build consent URLs for Logic Apps for use in phishing, and it looks like Microsoft has added warnings to this consent dialog :) It's been a long time since I used the URL like this - anyone know when this change happened?
010
Nathan McNulty @nathanmcnulty.com · 07/04/2026
Do you exclude MFA on joined/registered devices? If so, do you require MFA for device join/registration? I see this often because these controls aren't considered at the same time, and that's how we get this gap: Attacker steals user/pass -> register device -> no MFA required
130
Nathan McNulty @nathanmcnulty.com · 03/04/2026
WhoAmI - Dynamics edition 😂
020
Nathan McNulty @nathanmcnulty.com · 30/03/2026
OMG, XDRInternals dumping MDE device timeline straight into Azure Data Explorer 🤯
020
Nathan McNulty @nathanmcnulty.com · 29/03/2026
Soon ™️
191
Nathan McNulty @nathanmcnulty.com · 29/03/2026
Brand new feature being developed in 2026 using secrets for authentication 👎
181
Nathan McNulty @nathanmcnulty.com · 27/03/2026
Support for TAP and Phone Sign In are done! It was surprisingly harder than expected to get the phone sign-in flow to work properly :p Working on cross-platform browser auth now, and hopefully will be able to add it to XDRInternals this weekend
060
Nathan McNulty @nathanmcnulty.com · 25/03/2026
"Because everyone else lowered the bar, we decided to join them" is so on-brand...
0145
Nathan McNulty @nathanmcnulty.com · 19/03/2026
*chuckles* I'm in danger
000
Nathan McNulty @nathanmcnulty.com · 18/03/2026
😅
010
Nathan McNulty @nathanmcnulty.com · 15/03/2026
Cut your cloud spending bills with this one weird trick! lol, honestly, I can't believe how well this worked 😅
030
Nathan McNulty @nathanmcnulty.com · 14/03/2026
Feed M365 Copilot a simple markdown file asking for a Word doc, and of course it chokes and dies... It's truly impressive just how bad this product is :-/
090
Nathan McNulty @nathanmcnulty.com · 14/03/2026
Merged some good XDRInternals updates :) Connect-XdrBySoftwarePasskey does exactly what it says, super easy to automate AI access to the portal 🤖 Get-XdrIdentityUserTimeline lets you extract the whole 180 days of user timeline data if you need it github.com/MSCloudIn...
140
Nathan McNulty @nathanmcnulty.com · 13/03/2026
Apparently OnlyCopilotFans is a thing... 🤢
120
Nathan McNulty @nathanmcnulty.com · 13/03/2026
Doing some napkin math, I estimate just under 3 hours (fully optimized) to wipe 200K devices via Intune API If an attacker were unaware of API limits being per app, that bumps to ~5.5 hours under ideal conditions What happens if all admin devices are wiped first? 🤔 😳 🥺 😭
140
Nathan McNulty @nathanmcnulty.com · 13/03/2026
When you don't require security keys and a dedicated device for your privileged admin roles
171
Nathan McNulty @nathanmcnulty.com · 13/03/2026
If you think Intune's multi-admin mode is going to save you from a phished Global Admin, I have bad news... GA can just create a second admin and approve their change ;)
091
Nathan McNulty @nathanmcnulty.com · 13/03/2026
I love how you design a harness with delays, and AI is like, no bro, that's gonna take to long, let me change that for you 😂
210
Nathan McNulty @nathanmcnulty.com · 13/03/2026
They couldn't have called it biztalk? 🙃
020
Nathan McNulty @nathanmcnulty.com · 02/03/2026
azd + maester = 😲 Soon ™️
010
Nathan McNulty @nathanmcnulty.com · 01/03/2026
If you have considered using my script to create software passkeys using ESTSAUTH cookies on a pentest or red team exercise, I have published a more secure option for you ;) Create an Azure Key Vault, grant yourself Key Vault Crypto Officer, and run this: github.com/nathanmcn...
041
Nathan McNulty @nathanmcnulty.com · 19/02/2026
There is absolutely no way I could have written a test harness, not to mention automated bug fix and re-test, and then left it for 4 hours Guaranteed weeks of testing during my free time cut down to a couple of days of reviewing and approving So freaking cool 😎
180
Nathan McNulty @nathanmcnulty.com · 19/02/2026
Game changer - use cap locks for voice to speak :)
100
Nathan McNulty @nathanmcnulty.com · 12/02/2026
Don't have PKI but want to use TLS inspection in Global Secure Access? This script sets up Azure Key Vault Premium (HSM backed keys, $5/month), creates the CA certificate in Key Vault, gets the CSR from GSA, signs it with Key Vault, and adds it to GSA 🔥 github.com/nathanmcn...
160
Nathan McNulty @nathanmcnulty.com · 09/02/2026
New features for my Defender Reporting solution :) 1️⃣ Azure deployment option - Automation runbook exports vulnerability data and builds the dashboard, compressed data stored in blob storage - Optional Container App hosts dashboard using Entra auth github.com/nathanmcn...
180
Nathan McNulty @nathanmcnulty.com · 09/02/2026
Ever need to find out what Entra authentication methods your users are using but don't have Log Analytics/Sentinel? :) It's not as difficult as you might think! To get started, log into the Entra portal, go to Sign-in logs, set the date range to 1 month, then download the JSON:
174
Nathan McNulty @nathanmcnulty.com · 05/02/2026
So, uhh, "winget install node" might not do what you think 😬 Someone pointed this out to me thinking it might be a name squatting type attack, lol. Doesn't look like it is on the surface, but be careful out there ;)
040