HGB

@hgb.crowstrike.zip

DE&TH I like playing with malware, writing Sigma rules, and hoarding combo lists.

Some days on a thrunt, the TAs are indistinguishable from the engineer who is highly motivated to break the rules. Using a scheduled task to run net.exe to add yourself to the administrators group on every login is commitment.

Superintendent Chalmers: fentanyl labs? Principal Skinner: yes Chalmers: that the law enforcement folks were leaving alone? Skinner: yes Chalmers: localized entirely in Canada? Skinner: yes Chalmers: may I see them? Skinner: ...no

Regex is how I imagine eldritch horrors work. You look at it and it makes no sense and it's scary. As you stare, for a split second there is understanding. The universe expands before your eyes, reality unraveling. Then the madness sets in.

I am so excited to finally show you the stable alpha of Venture, a cross-platform GUI for parsing Windows Event Logs! github.com/mttaggart... Venture was developed with support from my employer with the intent of creating an open source tool for all. Thank you, UCLA Health!

GitHub - mttaggart/venture: Venture: Cross-Platform GUI tool for parsing and analyzing Windows event logs

Venture: Cross-Platform GUI tool for parsing and analyzing Windows event logs - mttaggart/venture

github.com

My daughter today was sitting at my desk and said she was working. When I asked what her job was she said "oh, I just do work". I feel this in my core.

Hey Bsky! I'm writing a piece on Python package security, and I'd really like to interview someone involved with the Debian Python team or someone who's a Fedora package sponsor to talk about the process. If you or anyone you know would be up for a 30-minute interview, drop me a DM! Thank you!

Well it turns out InTune Device Compliance policies don't matter at all. labs.jumpsec.com/tokensmith-b... Thankfully you can still detect intrusions with some older detection techniques like risky sign ins and looking for Check My Sign In (cmsi) events from the InTune company portal ID

TokenSmith - Bypassing Intune Compliant Device Conditional Access | JUMPSEC LABS

Conditional Access Policies (CAPs) are the core of Entra ID’s perimeter defense for the vast majority of Enterprise Microsoft 365 (M365) and Azure environments. The core ideas of conditional access ar...

labs.jumpsec.com