Rob Winter
@2code_monte
Followers
92
Following
1K
Media
49
Statuses
2K
Frustration is my fuel
Joined December 2012
Latest Intune blog is up where we show how to add exclusions to Windows ASR Rules. #blueteam #cybersecurity #securebydefault #intune #microsoftsecurity
https://t.co/SDODKiX5pT
strategic-cyber.co.uk
In Intune guide number 15 we covered configuring ASR Rules with an Intune policy to harden our endpoints and reduce their attack surface. In this guide we are going to show how granular these contr…
0
0
0
The next guide is up in our #intune series "Mobile Application Policies for iOS". We show how you can control #byod devices with a simple set of policies. https://t.co/FrfIrSgJAC
#blueteam #cybersecurity #securebydesign
strategic-cyber.co.uk
Introduction Mobile Application Management Policies can used to secure data on both managed and unmanaged devices. If you have Intune, and you have a problem with BYOD in your organisation, then th…
0
0
0
I'm getting email from pr people offering quotes from CEO's about "ban on the use of Kaspersky software." USE of the software IS NOT banned. New *sales* of the software is banned, and Kaspersky can't provide software updates to existing customers in US. But people can still use
5
10
59
#sentinel Part 2 out now as we continue to cover deployment from scratch. We look at using the free data feeds, and creating our first workbooks. #blueteam #cybersecurity #SIEM #SOAR #securebydefault
https://t.co/9xqZLrvii9
strategic-cyber.co.uk
Introduction. We are going to cover the initial deployment of a Sentinel Workspace, and onboard the free data sources. Even though Microsoft lists the free data sources in the handy table shown bel…
0
0
0
This week we're looking at installing #microsoft #sentinel from scratch. Over this series we will start from the basics and free data sources, then progress onto more advanced configurations. #blueteam #securebydefault #cybersecurity
https://t.co/apDZUux616
strategic-cyber.co.uk
Introduction Microsoft Sentinel is a cloud native Security Information and Event Management (SIEM), and Security Orchestration Automation and Response (SOAR) solution. It allows organisations to in…
0
0
0
Next #intune blog is up. hashtag#windows and Driver Updates. We look at #patchmanagement via Intune update rings #cybesecurity #securebydefault #blueteam Microsoft Intune 16 – Windows and Driver Updates. – @2codemonte ( https://t.co/5pWGdfne5y)
strategic-cyber.co.uk
Frustration is my fuel
0
0
0
1. I'm legit shocked by the design of @Meta's new notification informing us they want to use the content we post to train their AI models. It's intentionally designed to be highly awkward in order to minimise the number of users who will object to it. Let me break it down.
369
3K
12K
Google Cloud accidentally deleted a company's entire cloud environment (Unisuper, an investment company, which manages $80B). The company had backups in another region, but GCP deleted those too. Luckily, they had yet more backups on another provider. https://t.co/v5WFxqUtaB
theguardian.com
Super fund boss and Google Cloud global CEO issue joint statement apologising for ‘extremely frustrating and disappointing’ outage
487
4K
18K
ANNOUNCING general availability!!! Microsoft Defender for Endpoint streamlined connectivity consolidates service URLs and provides IP ranges, for use in a variety of network scenarios.
learn.microsoft.com
Learn how to use a streamlined domain or static IP ranges during onboarding when connecting devices to Microsoft Defender for Endpoint.
3
37
111
We do not want apps bypassing #MFA or #conditionalaccess in #sharepoint so this is an important setting to review, and implement if possible. #cybersecurity #blueteam #securebydefault
https://t.co/qMG5GBakrA
strategic-cyber.co.uk
In previous series’ and blogs we have covered disabling legacy authentication to protect Exchange Online, Azure and Office 365, however while going through the Microsoft Cloud Security Benchm…
0
0
0
folks please help me get this word out. @Crowdstrike named some ransomware PunkSpider, literally the name of one of the pieces of software I made. Completely unrelated of course, mine is a security tool. This is NOT cool, appreciate RTs to get them to change this.
22
321
521
We continue our #intune deep dive by looking at #asrrules
#blueteam #cybersecurity #securebydesign
https://t.co/s2UcvQKDpk
strategic-cyber.co.uk
If you haven’t been following this series from the start, we have gone from setting up Intune from scratch which included device onboarding, autopilot, MDE, LAPs and compliance and configurat…
0
0
0
Continuing the #intune series here we look at how to block and control device enrolment. #blueteam #cybersecurity #securebydefault #endpointmanagement
https://t.co/Kd7FCW4hb7
strategic-cyber.co.uk
Intune allows us to control which device types can join Microsoft Entra based on the platform they have installed. As we have covered many times previously, there are no technical control silver-bu…
0
0
0
The next in the series of "Cyber security is easy, right?" is available. Grab a coffee, select read aloud and listen to me ramble for 5 minutes (in the AI voice of your choosing) about cyber security :) #blueteam #cybersecurity #securebydefault
https://t.co/z8rVuLRmkh
strategic-cyber.co.uk
What is this about I hear you shout!? Stick with me on this. We can all agree that cyber security is a complex, almost seemingly impossible problem to solve. Cyber security is a relatively new prob…
0
0
0
The latest newsletter has two weeks of content! As always, it includes the latest updates from the Endpoint Management community and product updates from Microsoft! 🔗 https://t.co/GSfANy1Bny 🌟 Subscribe: https://t.co/DWEQefcCGB
#msintune #intune #entraid #powershell
2
6
15
How the hell did none of you all in my feed point out before this that Windows Firewall in Windows 11 now actually supports using WDAC AppID tagging to filter programs in firewall rules? 😄😄 Really. That's a nifty new feature.
@arekfurt @SwiftOnSecurity This is an undocumented parameter New-NetFirewallRule -PolicyAppId <Insert the tag> The feature has been available in Intune too for almost a year https://t.co/sJOnu7nyPi
3
9
67
The next in our series "Cyber Security is easy, right?" we take a look at #secops
#blueteam #cybersecurity
https://t.co/Db7l3fgLFd
0
0
0
boiling down cyber into words that most people can understand.... What are we trying to protect? What are we protecting it from? Who are we trying to defend against? What level of appetite do we have for risk? What is our threshold for risk? (Risk Tolerance) What budget and
10
9
43
This weeks edition of Cyber Security is easy, right? sees us take a look at #privilegedaccessmanagement
#blueteam #cybersecurity #securebydesign
https://t.co/69ZWbzbIXO
strategic-cyber.co.uk
We’re back with another blog, and this week we’re looking at privileged access, explaining its importance, and some considerations for implementation. Why is privileged access so import…
0
0
0
This is worth a read, new campaign stealing NTLM hashes via email zip attachments. Includes IOCs. #cybersecurity #blueteam
https://t.co/sgJ6MMgDOB
proofpoint.com
What happened Proofpoint identified notable cybercriminal threat actor TA577 using a new attack chain to demonstrate an uncommonly observed objective: stealing NT LAN Manager (NTLM)
0
0
0