_dirkjan Profile Banner
Dirk-jan Profile
Dirk-jan

@_dirkjan

Followers
29K
Following
4K
Media
174
Statuses
2K

Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.

Joined December 2017
Don't wanna be here? Send us removal request.
@_dirkjan
Dirk-jan
3 months
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
dirkjanm.io
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise...
141
905
3K
@_dirkjan
Dirk-jan
11 days
I hope @MGrafnetter kept his FOCI card though 😅.
1
0
2
@liftedtrucks
Lifted Trucks
3 months
Follow America's Number One Custom Truck Dealer on X
0
49
202
@_dirkjan
Dirk-jan
11 days
It appears this was inaccurate, the client still exists but Microsoft just disabled the service principal for no apparent reason in my tenant. Along with an Intune one and a few others which broke things that still work fine in other tenants. No clue why they'd do this 🤔.
@_dirkjan
Dirk-jan
2 months
Seems Microsoft is doing some app and permission cleanups and tenant restrictions lately. RIP Microsoft Planner FOCI client.
9
1
53
@fabian_bader
Fabian Bader
12 days
I finally came around and documented all the Conditional Access bypasses in a single blog post. It contains not only the documented bypasses, but also the results of new research. #Entra #ConditionalAccess #Security #Cheese https://t.co/YWBfY0NhHl
Tweet card summary image
cloudbrothers.info
In Microsoft Entra, Conditional Access is, after the Authentication itself, the most crucial part of defense against attackers. It’s referenced as “zero trust policy engine” and the idea behind is,...
9
153
469
@_dirkjan
Dirk-jan
12 days
Really great blog, very well explained 😀 Releasing actual data on how common certain attacks are in the wild is super useful! And even detections for the blue side. Worth reading if you haven't yet.
@sapirxfed
sapir federovsky
16 days
My gift for Thanksgiving 💜 I wrote for you the blog post I always wanted to read! Happy holiday!🦃 PLEASE READ IT!!! https://t.co/Pr3P3jOh8s
1
7
82
@fabian_bader
Fabian Bader
16 days
@_dirkjan and my joint talk at #TROOPERS25 is now available on YouTube. "Finding Entra ID CA Bypasses - the structured way" @WEareTROOPERS https://t.co/fAQ0aCreKj
0
25
91
@1ns0mn1h4ck
Insomni'hack
22 days
📢 CFP Closing Soon! Only one week left to submit your talk proposal for Insomni’hack 2026 (Thursday & Friday sessions)! 🎙️ Want to speak or share a case study? 🚀 Don’t miss your chance! 🔗 Submit: https://t.co/lSpoIHVifc #INSO26 #CFP #Cybersecurity #Infosec #TechTalks
0
7
10
@SkelSec
SkelSec
24 days
Ohh, I missed this. It was an ... experience dealing with MSRC, I won't do this ever again. https://t.co/7NbOIT8Snx
0
6
32
@olafhartong
Olaf Hartong
26 days
The @ThinkstCanary ThinkstScapes Q3 report is out. A great quarterly overview of interesting research shared in the security community. It made my day to see my ETW research highlighted in this edition. https://t.co/vtruyuPrYc
Tweet card summary image
thinkst.com
Keeping up with security research is near impossible. ThinkstScapes helps with this. We scour through thousands of blog posts, tweets and conference proceedings to give you an overview of the work we...
1
8
37
@fabian_bader
Fabian Bader
1 month
@UK_Daniel_Card @Cloudflare Shameless adoption of the original sticker by @sannemaasakkers and @_dirkjan
0
4
35
@JimSycurity
Jim Sykora
1 month
AdminSDHolder is kinda my jam. I wrote the e-book on it. If you work with Activity Directory, I highly recommend you give this a skim, or at least check the spoilers in the blog.
@SpecterOps
SpecterOps
1 month
AdminSDHolder: the AD security feature everyone thinks they understand but probably don't. 😬 @JimSycurity went to the source code to debunk decades of misconceptions — including ones in Microsoft's own docs. Read more ⤵️ https://t.co/Vo9XksEfmn
2
34
195
@merill
Merill Fernando
1 month
🎙️ @_sigil has done some amazing research on Entra recently. Here's a recent post she shared about the unique relationship between App Registrations and Service Principals. Here's the full blog post on her app research titled I SPy: Escalating to Entra ID's Global Admin with a
3
30
143
@AIwithSam
Sam Joshi
1 day
Stripe builders: how do you handle Stripe account health?
2
0
6
@_dirkjan
Dirk-jan
1 month
It appears the end is near(er) for the Azure AD Graph API with usage of the API now being blocked in one of my tenants with the AAD PowerShell module client ID. Found this out when trying to demo roadrecon 😬. Time to prioritize merging the MS Graph PR from @Thomasbyrne__
5
24
136
@_dirkjan
Dirk-jan
2 months
Seems Microsoft is doing some app and permission cleanups and tenant restrictions lately. RIP Microsoft Planner FOCI client.
3
5
66
@1ns0mn1h4ck
Insomni'hack
2 months
Time is running out! Submit your workshop proposal by October 31st and join our Swiss cyber community. Ready to contribute? Find details & submit here: https://t.co/hPpJq7jHK5 #Insomnihack #CFP #Cybersecurity #Infosec #INSO2026
0
6
10
@merill
Merill Fernando
2 months
@_dirkjan found one of the most severe vulnerabilities ever discovered in Microsoft Entra ID. One that could have compromised every tenant in the cloud. In this episode, we unpack the story, the stress, and the mindset behind responsible disclosure. 🔥 We dive deep into his
4
43
157
@ISI
Intercollegiate Studies Institute
4 days
How is AI reshaping the American family? (0:00) Framing the Technology Debate (4:35) Tech, AI & the American Family (14:45) Faith, Ethics & the Digital Age (26:40) Education, Human Skills & AI (44:40) Policy, Innovation & Global Competition (57:00) Family Policy, Fertility &
9
26
96
@thezdi
Trend Zero Day Initiative
2 months
📢 Confirmed! The @compasssecurity team combined an arbitrary file write and cleartext transmission of sensitive data to exploit the @home_assistant Green. The unique bugs in their third round win earns them $20,000 and 4 Master of Pwn points. #Pwn2Own
0
3
29
@merill
Merill Fernando
2 months
Just wrapped up recording this week's https://t.co/v0cFtrPykt podcast with the LEGENDARY Dirk-jan Mollema!! Can't wait to share Dirk-jan's story on how he uncovered one of the biggest security findings of the year. Subscribe to the podcast and be the first to listen.
1
7
64
@Icemoonhsv
Hope Walker
2 months
Check out my new blog post diving deeper into BroCI.
@SpecterOps
SpecterOps
2 months
Microsoft introduced nested application auth (NAA) in 2024. Researchers spotted FOCI similarities & dubbed it brokered client IDs (BroCI). @Icemoonhsv documents NAA flows and BroCI—filling a gap for research on Microsoft identity protocols.
1
10
27
@merill
Merill Fernando
2 months
👋 Folks, next week I'm recording an Entra Chat podcast with the one and only @_dirkjan 🤩 What do you want me to ask him? Post your question below, hit like on the questions so I know which ones are popular. 👍
9
9
96
@OverkillTrading
Overkill Trading
5 days
BITCOIN GIVING HUGE SIGNAL 🚨 DECEMBER 8
41
77
637