Fabian Bader

@fabian.bader.cloud

#Security #Azure #EntraID #XDR #MDE #Identity #M365 #AD #PKI #KQL Microsoft MVP Tweets and opinions are my own

In my latest blog "Now You See Me: AADGraphActivityLogs" I explore the newly released Azure AD Graph logs and demonstrate how you can detect tools like ROADtools and AADinternals that rely on this API and have been under the radar for defenders so far. cloudbrothers.info/en/aadgrapha...

Now You See Me: AADGraphActivityLogs

KQL hunting queries for the new AADGraphActivityLogs table to detect Entra ID reconnaissance tooling based on UserAgent, RequestUri, and volume.

cloudbrothers.info

Attackers found a clever way to abuse legitimate, digitally signed software to load malware and it's working. Expel Intel’s Marcus Hutchins (@malwaretech.com) breaks down a campaign that weaponizes Greenshot, a legit screenshot tool, to evade detection at multiple layers. 🧵

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...

One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens

While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...

dirkjanm.io

🚨 PSA - Zero day in SharePoint on-prem is actively exploited! ◽ Have Defender AV active ◽ Don't disable AMSI integration of SharePoint ◽ Keep an eye out for the alerts outlined in the article ◽ Look for post exploitation with the hunting query msrc.microsoft.com/blog/2025/07...

Customer guidance for SharePoint vulnerability CVE-2025-53770 | MSRC Blog | Microsoft Security Response Center

Customer guidance for SharePoint vulnerability CVE-2025-53770

msrc.microsoft.com