DebugPrivilege
@DebugPrivilege
Followers
41K
Following
21K
Media
479
Statuses
8K
System Administrator | Ex-MSFT | Microsoft MVP in Windows and Devices | Interested in Security, Debugging, and Windows Internals. Tweets are my own.
Home Office
Joined February 2017
BSOD is just the Windows kernel rage-quitting with a blue PowerPoint slide
2
2
9
I've emailed Citrix about this and they have updated their documentation, so no more Authenticated Users with GenericAll on the template
2
0
28
THIS IS SIMPLE - This is Wall Street-level accumulation happening right in front of you. THIS IS An OPPORTUNITY ! DONT BLINK DYOR
16
9
98
Do we have too many managers in this field? I've worked for a few Software firms and I see too often more managers than actual engineers lol
3
1
12
Great talk from @OutflankNL where they are talking about applying Blue Team Techniques in their Red Team Operations.
1
4
34
Take on your Tokyo Mission ā” The Sonic Movie 3 crossover event returns with the Shibuya Crossing event stage! Team up with other Rumblers, face Movie Shadow on his Dark Rider, and dash through the mayhem to collect your rewards.
16
143
714
We always hear that granting an App https://t.co/s8xQgcwn04 and AppRoleAssignment.ReadWrite.All is dangerous. I often see these permissions asked by IAM solutions like SailPoint or backup solutions that need to backup Entra ID. Any other valid reasons for giving these permissions
5
0
17
These default configs exists in real environments...
Liked part 1 on vendors pushing ESC1 templates? Hereās a real-world case: a Citrix FAS setup with default perms exposes an ESC3 path. Domain Computers can enroll on Citrix_RegistrationAuthority and chain to Citrix_SmartcardLogon, ending in DA.
2
3
15
Document was also not that long ago published or updated š«£
0
0
9
If youāre into memes, nerd rages, and me making Cyber jokes. Follow @DebugDiag
1
0
9
Great to see there are still people interested in kernel debugging and crash dump analysis. Analyzing crashes is a great way to learn more about Windows Internals. It might not be as sexy as red teaming, but itās an underrated skill set that builds problem-solving skills.
2
7
112
I have to admit, but Iām starting to enjoy Reddit š
4
0
11
Liked part 1 on vendors pushing ESC1 templates? Hereās a real-world case: a Citrix FAS setup with default perms exposes an ESC3 path. Domain Computers can enroll on Citrix_RegistrationAuthority and chain to Citrix_SmartcardLogon, ending in DA.
medium.com
Citrix Federated Authentication Service (FAS) is a Citrix component that works with Active Directory Certificate Services to issueā¦
0
25
68
Happy Sunday, friends! I hope you all are getting the rest you deserve and need. For those who havent seen, Merill and I sat down for a chat a couple months ago to talk about the some of the security challenges in M365 and how they're almost all preventable. The reality is
š From Dispensing Pills to Dismantling Cyber Threats: One Woman's Epic Pivot In 2009, @IAMERICAbooted was ordering drugs with shared passwordsāfast-forward to 2022, and she's pen-testing Azure tenants like a boss. This week on https://t.co/v0cFtrPykt, Erica recounts her DEFCON
1
6
50
I decided to join @Reddit so if you have reddit. Give me a follow!
reddit.com
Explore DebugDiagās posts and comments on Reddit
5
0
12
"I was a former Red Teamer" is the equivalent of "I used to be a Navy SEAL... back in Call of Duty." #badjoke
5
5
32
Who still remembers the InfoSec days when people would insult each other by calling them āscript kiddiesā ? š«£
8
1
43
As a fun side project - Iāve started tracking vendors whose guides ask customers to create ESC1-style certificate templates, leaving an entire environment exposed š
medium.com
This post isnāt about vendor-bashing. With attacks against Active Directory Certificate Services (ADCS) increasing, I want to show howā¦
5
39
138