_dirkjan Profile Banner
Dirk-jan Profile
Dirk-jan

@_dirkjan

Followers
28K
Following
4K
Media
170
Statuses
2K

Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.

Joined December 2017
Don't wanna be here? Send us removal request.
@_dirkjan
Dirk-jan
4 years
Some big personal news: last year I decided to start my own company. Today I'm making it official and announcing Outsider Security (@OutsiderSec). My focus will be on Azure AD and Active Directory security, converting my research experience into in-depth tests and advice.
102
87
1K
@_dirkjan
Dirk-jan
3 days
RT @TEMP43487580: I just started a new blog, and this is my first post. I took a bit of PTO, so this is a little record of some fun I had p….
Tweet card summary image
temp43487580.github.io
Ways of device ownership spoofing and more for persistent access to Intune
0
63
0
@_dirkjan
Dirk-jan
5 days
If you didn't find my Black Hat / Def Con slides yet, they are available on . Also includes the demo videos where I use actor tokens from on-prem to access SharePoint online and get Global Admin.
dirkjanm.io
2
68
189
@_dirkjan
Dirk-jan
6 days
RT @RedTeamPT: 👀Turns out MS-EVEN can do a lot more than NULL auth:. In addition to leaking environment variables, it is possible to coerce….
0
44
0
@_dirkjan
Dirk-jan
9 days
This is awesome research and worth a watch!.
@RedByte1337
Keanu Nys
9 days
Thanks to everyone who joined my DEFCON33 talk!🎉.For those of you who missed it and are interested in seeing how we can extract cleartext credentials and bypass MFA directly from the official Microsoft login page, I just uploaded the recording to YouTube:.
Tweet media one
1
19
101
@_dirkjan
Dirk-jan
11 days
RT @NathanMcNulty: Le sigh. This isn't bypassing FIDO auth (it's called passkeys now btw). It's just asking the user to use a weaker met….
0
15
0
@_dirkjan
Dirk-jan
12 days
Digging through the API definition, it seems the new recommend Microsoft default is just allowing all permissions except file related ones (SharePoint/OneDrive), which is a significantly more risky setting than the middle one which was previously the recommended option. 🤦‍♂️.
1
0
8
@_dirkjan
Dirk-jan
12 days
While I'm a big fan of secure defaults, imo this new user consent setting is badly executed. There are no docs about what "current guidelines" means. Worse: the new default is now the "recommended" setting, while it's actually LESS secure than the prev recommended middle setting.
Tweet media one
1
10
43
@_dirkjan
Dirk-jan
12 days
More BroCi resources! Great write-up on a few cases where Nested App Authentication is useful 😀.
@Icemoonhsv
Hope Walker
12 days
Check out my new blog on nested app authentication and brokered authentication.
0
2
13
@_dirkjan
Dirk-jan
13 days
RT @Wietze: A special shoutout to the many 🇪🇺European cyber researchers presenting their work at #DEFCON, you were awesome. 🇳🇱@_dirkjan @J….
0
5
0
@_dirkjan
Dirk-jan
14 days
RT @PyroTek3: I am back to posting to in my free time (which I have again). I plan on adding new content relating….
0
112
0
@_dirkjan
Dirk-jan
15 days
RT @AmberWolfSec: You can read about our overall research project at and learn about a SAML Authentication bypass i….
blog.amberwolf.com
AmberWolf Security Research Blog
0
13
0
@_dirkjan
Dirk-jan
16 days
Dropped some ROADtools stickers at the @cloudvillage_dc CTF room 👀.
1
0
13
@_dirkjan
Dirk-jan
16 days
RT @olafhartong: Soooo close. Great stuff
Tweet media one
0
1
0
@_dirkjan
Dirk-jan
16 days
RT @olafhartong: Packed room for ⁦@_dirkjan⁩ speaking at ⁦@defcon awesome talk as usual.
Tweet media one
0
1
0
@_dirkjan
Dirk-jan
17 days
At the @msftsecresponse party with @secbughunter (and many others). Collecting all the clippy pins!
Tweet media one
1
0
26
@_dirkjan
Dirk-jan
17 days
If you missed the talk, I will give it at Def Con tomorrow, 13:00 in track 3.
1
2
14
@_dirkjan
Dirk-jan
17 days
Good article from Bleeping Computer about the Exchange hybrid tradecraft I dropped at Black Hat yesterday, with some of my comments on the techniques:
Tweet card summary image
bleepingcomputer.com
CISA has issued an emergency directive ordering all Federal Civilian Executive Branch (FCEB) agencies to mitigate a critical Microsoft Exchange hybrid vulnerability tracked as CVE-2025-53786 by...
3
22
94
@_dirkjan
Dirk-jan
18 days
I'm hyped for this one! Hacking cluster accounts with @unsigned_sh0rt
Tweet media one
1
3
38
@_dirkjan
Dirk-jan
18 days
RT @CISACyber: ⚠️MS Exchange server hybrid deployment elevation of privilege vulnerability CVE-2025-53786 could allow a threat actor with a….
0
122
0