Daniel Chronlund | Security MVP
@DanielChronlund
Followers
3K
Following
2K
Media
70
Statuses
686
Microsoft Security MVP, Microsoft 365 security expert, blogger, and consultant at Truesec.
Örebro, Sverige
Joined November 2018
Finally!! I'm consolidating all of my official PowerShell scripts around Microsoft Graph management, Conditional Access automation, etc, into one PowerShell module. Run Install-Module DCToolbox and Get-DCHelp to get started. https://t.co/J0Z10QtFgf
3
24
77
#AzureAD PIM makes it possible to configure activation and expiration settings on a per-role basis. Read my latest blog post for some cool PowerShell role automation based on role impact :) https://t.co/HbMBdUuF4E
1
8
40
I've added a simple tool to #DCToolbox to quickly request a refresh token from #AzureAD using the OAuth 2.0 device code flow. For me, the clipboard integration is the killer feature! Install/update with 'Install-Module -Name DCToolbox -Force'
0
4
24
I'm currently investigating the potential threat of #Microsoft365 wiper #malware. Simulate an attack with 'Invoke-DCM365DataWiper' today, and take precautions in your #AzureAD tenant! https://t.co/YZvptoPSPz
danielchronlund.com
Ransomware has been the major cyber threat the last couple of years, and it still is! But a new trend I see is the rise of wiper malware, which basically tries to destroy your data, instead of encr…
0
25
46
My latest blog post is a proof of concept of how poorly protected #AzureAD app permissions can be used in a data exfiltration #cybersecurity attack. I’ve added a new tool to my DCToolbox PowerShell module called Invoke-DCM365DataExfiltration. Interested? https://t.co/0ZVHiUb4qU
danielchronlund.com
Attackers are turning their eyes towards the cloud, and since heavy data exfiltration is now part of any ransomware attack, I wanted to create an eyeopening PoC of how bad app permissions in Azure …
0
11
65
A somewhat different blog post for me where I share some thoughts on #Microsoft #cloudsecurity in 2023. https://t.co/QkRYEUp2gt
danielchronlund.com
This is my first blog post for 2023, and I usually write fairly technical and practical articles, but this time I wanted to stop for a few minutes and give you some insight of what’s going on…
0
0
1
📢 My latest blog on Sentinel 🛡️ Integrate your #Microsoft Defender for Identity health alerts into #Sentinel incidents and use custom alert mapping to make you live easier. #MDI #MDO #M365D #Security
https://t.co/is0RSIdfRV
cloudbrothers.info
Integrate MDI health alerts in Microsoft Sentinel or how to turn every e-mail notification in a custom alert in Sentinel and customize alert details for your benefit.
2
46
135
I've just updated my #MicrosoftSentinel repo with some new #threathunting queries for #MicrosoftDefender (and some improvements to existing queries), based on the recent incident deep dives posted by Microsoft Detection and Response Team (DART). https://t.co/q5qJBwiO8W
2
40
128
I'm happy to announce that my #MicrosoftSentinel #MicrosoftDefender 'Attack Surface Reduction Dashboard' is now included in Sentinel. You'll find it in your Sentinel workspace today under Workbooks > Templates!
5
60
278
microsoft.com
0
0
3
Use #MicrosoftSentinel #UEBA and #DefenderForCloudApps to hunt for recent tenant cloud app activity originating from, by Microsoft, known bad IP addresses (botnets, anonymization services...). Check out the latest hunting queries in #DCSecurityOperations: https://t.co/q5qJBw1cKm
0
1
7
Exactly one year ago today, I wrote this blog post about removing telecom based #MFA factors from #AzureAD. With rising numbers of MFA targeted attacks, we all need to look at implementing phishing resistent MFA methods like #FIDO2 instead. https://t.co/j9DxVWMYnS
0
11
36
I've updated my #AzureAD stale accounts report tool in DCToolbox to take non-interactive sign-ins into consideration. Also, you can now filter the report by adding -OnlyGuests or -OnlyMembers. Install/update DCToolbox with 'Install-Module -Name DCToolbox -Force' to get started!
0
15
82
New - I attempted to boil down the key things businesses should be looking at when it comes to stopping identity-based attacks: https://t.co/h8RCL3yl0K w/ commentary from @vasujakkal @toddmckinnon @RachelTobac @MarkMcClainCEO @DrAzureAD @dwizzzleMSFT & many more
7
26
60