DirectoryRanger Profile Banner
DirectoryRanger Profile
DirectoryRanger

@DirectoryRanger

Followers
35K
Following
731
Media
386
Statuses
16K

This account assembles and disseminates information related to Active Directory and Windows security.

Joined December 2017
Don't wanna be here? Send us removal request.
@DirectoryRanger
DirectoryRanger
3 years
24/7 Active Directory Incident Response Contact: Tel. +49 (0) 6221 7569637 E-mail: incident-response@ernw.de
1
15
83
@Enno_Insinuator
Enno Rey
15 days
.@MCTTP_Con 2025 was a great event, thanks again @CyberWarship for so many things! Slides & transcript of my keynote can be found in this @Insinuator post: https://t.co/Wq0GQFDDWq
0
2
8
@AEGworldwide
AEG
1 day
Ready to make your mark? At AEG, we turn ambition into action. Let’s bring your dreams to life. Join us
0
0
4
@Insinuator
Insinuator
4 months
New post: Windows Hello for Business – The Face Swap
0
11
20
@Enno_Insinuator
Enno Rey
25 days
That's a very interesting new training from the fine folks of @ERNW_ITSec Research: https://t.co/5ZzFeGCIli
2
6
5
@Oddvarmoe
Oddvar Moe
1 month
The #mcttp event is over and I am on my way home. Thanks again for having me this year again. Special thanks to @CyberWarship and Sonja for taking care of us during October fest. Truly amazing event and I finally got to meet @Enno_Insinuator and @DrAzureAD IRL. Also awesome to
1
4
23
@DirectoryRanger
DirectoryRanger
2 months
Malicious Encoded PowerShell: Detecting, Decoding & Modeling https://t.co/D2VJlJYizw
Tweet card summary image
detect.fyi
The challenges and insights from dealing with this PS one-liner
0
22
86
@DirectoryRanger
DirectoryRanger
3 months
Kudos also to @SecurityThunder and @kidtronnix
0
2
4
@Insinuator
Insinuator
9 months
New post: Jigsaw RDPuzzle: Piecing Attacker Actions Together
0
13
31
@techspence
spencer
2 months
Domain Admin shouldn’t logon to workstations. Here’s one way to restrict DA logins to workstations: Create a GPO… Computer Config → Windows Settings → Security Settings → Local Policies → User Rights Assignment → ‘Deny log on locally’ & ‘Deny log on through RDP’ → add
34
66
540
@reprise_99
Matt Zorich
2 months
Highly recommend everyone read the latest @MsftSecIntel blog, especially if you are involved in identity or cloud security. It details how threat actors can pivot between both your on-premises and cloud identity planes and cause destruction across both. Without proper guardrails
4
77
293
@fleetistics
Fleetistics - Fleet Tech
17 hours
Fleet dashcams for commercial vehicles. Full integration with telematics for video exceptions, driver coaching and accident video. Live view. In &/or Out recording.
0
0
1
@merill
Merill Fernando
2 months
🚨 Microsoft admins, are your conditional access policies weak? 😱 @fabian_bader shares some common bypasses in our latest https://t.co/v0cFtrPykt podcast episode! 🔒 Dive into this thread for must-know insights to secure your tenant! 🧵👇 #Cybersecurity #MicrosoftEntra
2
36
163
@DirectoryRanger
DirectoryRanger
2 months
The Windows Registry Adventure, contd., by @j00ru #5: The regf file format https://t.co/rxLCJvSVxe #6: Kernel-mode objects https://t.co/8Iir8GMuEt #7: Attack surface analysis https://t.co/1Xj8GASqbq #8: Practical exploitation of hive memory corruption
0
2
5
@DirectoryRanger
DirectoryRanger
2 months
The Windows Registry Adventure, by @j00ru #1: Introduction and research results https://t.co/sp1c4x5SA8 #2: A brief history of the feature https://t.co/Wt6YK9v2nn #3: Learning resources https://t.co/tIte5saaOA #4: Hives and the registry layout
2
31
114