
Kim Oppalfens (MVP) ✖️
@TheWMIGuy
Followers
5K
Following
6K
Media
220
Statuses
16K
#MemCM #Infosec enthusiast. “Non-limited code execution will almost certainly result in full system compromise over time.” #WDAC. 20 years of MVP citizenship.
somewhere
Joined April 2010
IBM demonstrating why your #wdac policy should use defined packaged apps as opposed to relying on Package Family names. #appcontrol.ai https://t.co/to9lt6dPSh Bypassing Windows Defender Application Control with Loki C2
learn.microsoft.com
Packaged apps, also known as Universal Windows apps, allow you to control the entire app by using a single App Control for Business rule.
0
1
2
So excited for this Conditional Access session with @ThatLewisBarry Such a fitting topic for Music City Edition, because even though CA and music are both technical skills, they're also an art that is perfected by understanding the theory behind them :) Come join us! #MMSMOA
2
8
43
The nitty gritty details on dot sourcing and PowerShell constrained language mode. #wdac.
🔒 PowerShell scripts suddenly breaking after deploying WDAC? You've hit Constrained Language Mode! Learn why -File + [CmdletBinding()] causes failures, how language mode boundaries work, and what those cryptic errors actually mean. Essential read for sysadmins ! @TheWMIGuy
0
0
5
🔒 PowerShell scripts suddenly breaking after deploying WDAC? You've hit Constrained Language Mode! Learn why -File + [CmdletBinding()] causes failures, how language mode boundaries work, and what those cryptic errors actually mean. Essential read for sysadmins ! @TheWMIGuy
0
6
13
Next run of our #wdac training starts in exactly 1 week. Still 2 seats left.
linkedin.com
looking forward to engaging with people that take an active interest in Application Allowlisting. oh, and a few, in this post now means 3, with 1 closing in on approval. Joining us for this run will...
0
0
1
The next run of our #wdac training starts in exactly 1 week. 2 Seats left, want application allowlisting trrining, sign up quickly. https://t.co/s1Frntdvxw
linkedin.com
looking forward to engaging with people that take an active interest in Application Allowlisting. oh, and a few, in this post now means 3, with 1 closing in on approval. Joining us for this run will...
0
3
8
Join us in a couple of hours where we'll show off what our teams have been working on the last few months.
Mac management without the headache? Yes, please. Join us Aug 27th 📅 for a live walkthrough: ✅ macOS app support ✅ Fresh #AdvancedInsights dashboards ✅ Sneak peek at ARM + #PSADT v4.1 Save your spot: https://t.co/voTI4GlDBP
#PSAppDeployToolkit #ITCommunity #PatchMyPC
1
2
7
⚡JUST AROUND THE CORNER! Turn the tables on malware! Starts SEPT. 11 🕘 9:00AM - 12:30PM CDT💻MASTERING #WDAC USING #CONFIGMGR AND #INTUNE w/ @TheWMIGuy and @TomDegreef 👨💻 Raise your organization's security posture with this class! Enroll Here! https://t.co/KUUBzHShcP
0
3
2
Stop drowning in WDAC events! There is a better way to see what's going on in your environment. Check out our linkedin post for the details : https://t.co/Ofy1tWmO5S Join @TheWMIGuy and me and become true #WDAC Warriors !
4
2
10
𝗥𝗲𝗮𝗱𝘆 𝘁𝗼 𝗧𝘂𝗿𝗻 𝘁𝗵𝗲 𝗧𝗮𝗯𝗹𝗲𝘀 𝗼𝗻 𝗠𝗮𝗹𝘄𝗮𝗿𝗲? Join @TheWMIGuy and myself for our newest edition of the WDAC Training and become a true #WDAC warrior with us! Read about it here :
linkedin.com
🛡️ 𝗥𝗲𝗮𝗱𝘆 𝘁𝗼 𝗧𝘂𝗿𝗻 𝘁𝗵𝗲 𝗧𝗮𝗯𝗹𝗲𝘀 𝗼𝗻 𝗠𝗮𝗹𝘄𝗮𝗿𝗲? 🛡️ Fighting malware feels like an uphill battle these days – but what if I told you there's a security control that can drasti...
9
6
9
Blogged: Recovering a Windows 365 Cloud PC that was de-provisioned due to license expiration- this is another joint effort from myself and Paul ( https://t.co/aKFzia9S7X)
https://t.co/9saoCBkaa3
#Windows365 #CloudPC #Windows11 #MSIntune
2
14
32
The wait is over... #PatchMyMac is here! Effortless #macOS support in #Intune has arrived. Manage 5 or 50,000 Macs just like Windows, all from the Patch My PC cloud. Secure, simple, and ready to scale. Start managing macOS today ➡️ https://t.co/HX5oHkyz7T
#EndpointManagement
2
25
72
If you missed the talk, we uploaded the video here: https://t.co/J6DBUfiL50
Breaking Into Your Network? Zer0 Effort. - DEF CON 33 Overview and Advisory - Zscaler SAML Authentication Bypass (CVE-2025-54982). Following on from our DEF CON 33 presentation, the first two blog posts in our series on Zero Trust Network access abuse are now live.
0
20
81
You really should read this, here's an excerpt ;)
@NathanMcNulty A few thoughts on this problem... (random https://t.co/oqdSYHLDmd)
https://t.co/Dt04WzettK
2
10
38
This, so 100%, this. We've started putting a ton of effort in it 8 years ago. We're now delivering training, consultancy and our https://t.co/qJKAv4CAX9 solution. But the most important thing is still, just start.
appcontrol.ai
AppControl allows you to easily create a catalog of your applications and generate security policies for the applications
The reasons we fear app control are industry-made problems If we invested half the effort into improving app control that we do into EDR, we would be a lot more secure and have more resources to devote to the next things Instead, we'll forever chase arbitrary code execution...
1
3
19
I downloaded the latest #Windows11 24H2 2025-07 ISO image and tested how much "newer" the built-in Store apps are. They are newer, but the main ones have still pretty old versions. E.g. Snipping tools version is from 2023, Paint from late 2024. 😟 https://t.co/GG8srhog5S
7
12
50
This is a big milestone for us. Packaged apps are a great step forward for the Windows platform as it introduces a concept of Application identity. The reason this is big for us, is because it shows what we're in the process of doing and already do reasonably well for win32 apps.
🚀 NEW: https://t.co/9xLrNoqGhs now manages Microsoft Store apps with one-click policy generation based on the apps you have ! No more whack-a-mole with https://t.co/bDTWuHOar2, PowerShell installs, or unwanted tools like PsExec slipping through. ✅ Full packaged app visibility
0
4
16
Anyone looking for an @MSIntune @PatchMyPC Application Expert? I’m available for part / full time hire.
0
20
21