David Weston (DWIZZZLE) Profile Banner
David Weston (DWIZZZLE) Profile
David Weston (DWIZZZLE)

@dwizzzleMSFT

Followers
24,749
Following
1,461
Media
1,165
Statuses
11,202

Vice President, OS Security and Enterprise @Microsoft || @CISAgov Technical Advisory Committee

/AppData/Roaming/SEA/LA
Joined April 2008
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@dwizzzleMSFT
David Weston (DWIZZZLE)
1 year
I have an IG for infosec stuff. Follow me at
Tweet media one
9
1
13
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
Tweet media one
39
7K
16K
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
Dope.
Tweet media one
29
363
2K
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Just a reminder with Windows (Pro and up) there is a straightforward way to visit sites in a VM with WDAG. This means attackers need a Chrome RCE, Chrome LPE, Bypass of CI, and HV EOP.
Tweet media one
Tweet media two
Tweet media three
41
399
1K
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
We just made updates to the Windows 11 PC Health Check App. It now provides more detailed info on requirements not met. This should help in cases where folks assumed CPU compat issues were TPM related
Tweet media one
254
305
1K
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
This is amazing, bought on sight
Tweet media one
32
234
972
@dwizzzleMSFT
David Weston (DWIZZZLE)
8 months
If you are worried about LAZARUS targeting you on twitter here is a power tip. You can launch twitter in a Windows MDAG hypervisor container with a simple shortcut using this argument to MS Edge. This provides an additional layer of isolation even for a full chrome 0day chain.
Tweet media one
Tweet media two
21
163
858
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
Windows 11 Security Book Update!!! Along with yesterday's release we updated on 74-page white paper on Windows security with new features like Smart App Control, Pluton, and tons more. 👀 it out!!!!
Tweet media one
42
256
753
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
dwrite font parsing ported to Rust? 😲😲😲
Tweet media one
15
102
648
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 months
New blog from my team: Killing NTLM in Windows 11 - This is BIG 🔥🔥🔥
9
184
567
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 months
Had a great time doing a keynote at @ProssimoISRG on Microsoft approach to memory safety. Made a huge announcement - @microsoft is going big on Rust and spending $10 million to make it 1st class language in our engineering systems + $1 million @rustlang foundation.
Tweet media one
Tweet media two
Tweet media three
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 months
HUGE move for security at Microsoft. Lets' go!!!!
4
13
80
24
176
541
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
My new blog: Windows 11 2022 and new security features - this is the most secure version of Windows we have ever produced. Proud of the work the entire team has done, Let's gooooo
Tweet media one
26
164
529
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Windows security book has been converted to web doc form, check it out!
Tweet media one
4
174
506
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
Posted my slides from my blackhat 2018 presentation evaluating the state of zero trust security. I was waaay behind on time so there is a ton of content attendees didn't see. Check it out:
8
202
504
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
New Windows security option: Enable more aggressive blocklist which includes vulnerable drivers
Tweet media one
22
138
500
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
App Guard for Office has been released!!!!!!.
Tweet media one
11
186
487
@dwizzzleMSFT
David Weston (DWIZZZLE)
1 year
Windows is putting Rust in the kernel 🤯 learn more at my @BlueHatIL talk.
17
97
479
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
3 simple things that impact most mainstream Windows attacks on Windows: 1) Enable app control with AI and VBS (malware) 2) Enable app guard for Office/Browser (exploits) 3) Enable passwordless/hello/fido keys (phishing)
Tweet media one
Tweet media two
Tweet media three
Tweet media four
8
128
459
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Windows 11 security book is available now!!
Tweet media one
8
190
455
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 years
New blog with technical details of Chrome exploitation research from Windows OSR team
8
327
425
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
Summarizing Windows 11 Security Announcements: ✅Pluton SHIPPING ✅HVCI/VBS on default ALL CPUs ✅Credguard default ON ✅LSASS Protection default ON ✅EXE signed or rep REQUIRED ✅Script Blocking from Internet ON ✅Enhanced Phishing ON ✅File Layer Encryption with Hello ON
25
116
431
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
This is HUGE. Kernel Control Flow Guard, HVCI, Hyper Guard and bunch of other goodness are now available on non-Enterprise Windows SKUs. Turn it on, now.
@j3ffr3y1974
Jeffrey Sutherland
6 years
Any Windows 10 device that includes Hyper-V hypervisor can now turn on HVCI, a powerful mitigation against kernel exploits. This method uses a WDAC/config CI audit policy to enable HVCI.
10
183
374
6
240
405
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Everything you ever wanted to know about TPM. What's the diff between 1.2/2.0? Also lists the MASSIVE number of features that either require TPMs or are more secure with a TPM. *Hint* its WAY more that just Bitlocker or Secure Boot:
Tweet media one
29
145
409
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 years
Just posted my talk "Keeping Windows Secure" touching on security assurance process and vuln research in Windows from @BlueHatIL 2019:
11
158
403
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
Twitter: “exploit mitigations are so easy to bypass” Walking by office of someone who actually writes exploits: “damn, I’m still stuck trying to work around all this annoying shit”
11
62
373
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
@windowsinsider Win11 builds now have a DEFAULT account lockout policy to mitigate RDP and other brute force password vectors. This technique is very commonly used in Human Operated Ransomware and other attacks - this control will make brute forcing much harder which is awesome!
Tweet media one
20
141
367
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
security is just basic fundamentals. You don’t need to spend a bunch on magic Products. You need a organized process for ensuring the basics are put in place and stay in place. Patch, good auth, restricted priv, app control. There are no shortcuts, it’s not as hard as you think
@Alex_T_Weinert
Alex Weinert
5 years
This is a huge deal. Legacy hacking tools on legacy auth are responsible for the vast majority of attacks. Data point: account compromise rates in tenants who have disabled legacy auth are 67% lower than overall rates!
3
66
178
9
80
357
@dwizzzleMSFT
David Weston (DWIZZZLE)
1 year
Token binding is a "game changer" for zero trust. Bearer token exportation is something I identified as a major impediment to ZT in my Blackhat talk in 2018. In 2023 we finally have tokens bound to the hardware in Windows (using a TPM and VBS of course)
Tweet media one
Tweet media two
6
79
358
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
I posted the slides from my talk: "advancing windows security" at #bluehatshanghai
Tweet media one
Tweet media two
6
126
342
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 years
New blog from MSFT offensive security research. Windows 10 Kernel mitigations vs recent kernel exploits
2
252
325
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 years
If you are buying PCs take a look at this security hardware standard my team put together. Silicon matters
13
157
328
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
Macro you can pop all the UI you want but you can’t touch my filez. You are in a VM yo
Tweet media one
13
95
312
@dwizzzleMSFT
David Weston (DWIZZZLE)
1 year
My presentation slides for "Windows 11: security by-default" from @BlueHatIL covering: Rust in win32k, Adminless Windows, Token Binding, Sandboxing win32, and more! posted here:
Tweet media one
Tweet media two
10
92
308
@dwizzzleMSFT
David Weston (DWIZZZLE)
10 months
My team just released the public preview of Azure firmware scanning!! Scan all your IOT devices, routers, SSD firmware and anything else running embedded Linux. I suggest trying your home router for fun :)
7
91
299
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
Defenders, if you enable HVCI you can simply block mimikatz drivers certs. In conjunction with lsa ppl this will prevent dumping secrets from lsass without a pol bypass. Blog coming soon
@gentilkiwi
🥝🏳️‍🌈 Benjamin Delpy
5 years
Because I had question about "Protected Process" and LSA (RunAsPPL), don't forget that #mimikatz driver (mimidriver) can remove the Flags without any reboot or UEFI program😘 And yes, this is also for Windows 10 1903 x64 & x86 😉 >
4
206
503
3
94
300
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
Microsoft open source UEFI project with lots of cool security features and a reduced attack surface. Hope to see OEMs pick this up and more community PRs
5
149
294
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
The video from my #Bluehat talk "Advancing Windows Security" was posted. Details on XFG, Firmware Protection, and other new stuff:
Tweet media one
1
119
295
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
UPDATE: If you clean install RS4+ and have compatible hardware VBS/HVCI is now automatically enabled!! This means the Windows kernel now enforces by default: Kernel code integrity, runtime ACG, and control flow integrity via VBS. Huge for Windows security. Checkout WIP builds!
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
This is HUGE. Kernel Control Flow Guard, HVCI, Hyper Guard and bunch of other goodness are now available on non-Enterprise Windows SKUs. Turn it on, now.
6
240
405
5
174
287
@dwizzzleMSFT
David Weston (DWIZZZLE)
1 year
If you like 7zip, care about security, and are not using NanaZip your messing up
Tweet media one
15
35
296
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
It works! Windows 11 running OPEN SOURCE firmware with @coreboot_org and @9eSec EDK2 UEFI. Supports Secureboot (my own PK) and discrete TPM2, VBS, Etc. System meets all hardware requirements. Thanks to @nablahero for the port and @_miczyg_ for all the newb questions!!
Tweet media one
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
Holiday project — first Windows 11 @coreboot_org device? Courtesy of @9eSec @Supermicro_SMCI x11sch-f coffeelake port. Plan is to get it booting W11 with all the trimmings (edk2 secureboot, etc)
Tweet media one
3
6
70
12
79
275
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Did you know you can report a vulnerable or malicious driver to the Windows and Defender teams? We use these submissions as part of HVCI, KMCI, and Defender block lists.
Tweet media one
12
112
278
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 months
If you are a high value target and running Lockdown mode for you iPhone but running a router from your ISP or Best Buy your doing it all the way wrong.
35
29
279
@dwizzzleMSFT
David Weston (DWIZZZLE)
1 year
Rust can’t and won’t be the only solution to increasing memory safety in Windows. This is an excellent paper evaluating a variety of CPU based memory tagging approaches and their ROI against vulnerabilities.
7
67
269
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
I posted my slides from @BlueHatIL 2018 here: 2017 slides I never posted to follow!
7
127
270
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
I have not seen any other OS vendors share data with this level of transparency. One of things that gives me hope (and pride) is that most of the mitigations are coming from tight integration between our internal exploit writers and engineering teams. This is my def of maturity
Tweet media one
4
65
260
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
I built a WinUI3 Desktop app for system wide security configuration - including some obscure settings. It also supports JSON import/export so you can share you hardening configs with your friends.
Tweet media one
15
43
256
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 years
Windows 1709 is finally here. Go forth and browse in a tiny hypervisor!! #WDAG
Tweet media one
14
124
244
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 months
The biggest anxiety driver in the modern workplace is the expectation of immediate response. Teams, email, text... Neuroscience has proven our brains our single threaded no matter how badly we want to expand "productivity" and our work culture really needs to evolve.
14
35
245
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
If you are panicking about CPU bugs but allowed unsigned exes on your machines you are hustling backwards
5
55
240
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
Windows Defender Application Guard will support opening downloaded PDFs in a Hypervisor container in upcoming Insider Preview builds.
@MsftSecIntel
Microsoft Threat Intelligence
6 years
CVE-2018-4990 is one of two zero-day vulnerabilities exploited by a malformed PDF found by ESET, the other being CVE-2018-8120. Update your Adobe software and your Windows 7 and Server 2008 systems.
Tweet media one
Tweet media two
3
46
64
5
102
234
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
The energy to improve security @Microsoft rn is the best I have seen in my 10+ years deep down in the trenches. No Cap. If you *really* want to change things for the better you can do it here.
7
21
238
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 years
Vulnerable driver blocking is active the latest builds
Tweet media one
10
60
232
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
@tomwarren Almost every CPU in the last 5-7 years has a TPM. For Intel its called the "Intel PTT" which you set to enabled. For AMD it would be "AMD PSP fTPM". TPMs have been required for OEM certification since at least 2015 and was announced in 2013:
60
59
229
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
People talk about kernel developers with reverence for their ability to manage complexity - have you ever written modern UI code? - 17 file changes later my button and progress bar are event linked
12
15
230
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
I wrote a tool to take memory dumps of my machines and analyze them in azure using debug scripts I wrote. Memory dumps are the only detection method where source data is never the gap. You never have to “turn on more logs” and hope it happens again, it’s all there. Underrated.
17
24
226
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 years
Tweet media one
3
48
223
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
New Windows 11 Privacy Auditing features allow you to see history of sensitive device access like the Microphone
Tweet media one
7
58
219
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
My 20 min @Windows 11 security breakout session is LIVE. If you do ANYTHING with Windows security I highly recommendation watching. I demo and breakdown a laundry list of Windows 11 security improvements. Let’s Gooooooooo
Tweet media one
10
54
221
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 years
The video from my talk “Keeping Windows Secure” is up on the youtubeZ:
Tweet media one
2
48
211
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
I have this idea for a YouTube channel where @SwiftOnSecurity and I do tech make overs of infosec ppls horrible workspaces, security baselines, and monitoring. “Well team, we started by ripping out the Old AV and installing sysmon…”
19
10
212
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 years
Truth is all fancy EDRs and endpoint security can be disabled by an attack like this. With Driver control using HVCI on Windows 10 this attack is prevented. You don’t need to buy this, it’s included in Windows 10 pro and up. All Secured core PCs have it on by default.
@SwiftOnSecurity
SwiftOnSecurity
4 years
Absolutely fantastic post by @Sophos . As a defender, highly detailed breakdowns of the precise operation of malware with annotated decompilations is greatly appreciated.
5
48
229
4
61
213
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 years
You should check out the MSFT Privileged Access Workstation architecture. Effective approach to endpoint hardening
1
109
209
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 months
New Google Chrome Blog: Windows 11 VBS and TPM defaults are used by Chrome to prevent cookie theft. "Chrome will use facilities such as Trusted Platform Modules (TPMs) for key protection, which are becoming more commonplace and are required for
7
62
211
@dwizzzleMSFT
David Weston (DWIZZZLE)
6 years
Really cool paper on protecting kernel memory with a Hypervisor:
4
104
204
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
In case you missed it @dispensa announced PAM support from Intune for Windows 11 which is really cool. Standard user everything.
Tweet media one
Tweet media two
9
64
195
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
Windows 11 now has BY DEFAULT: ✅ TPM ✅ LSA PPL ✅ HVCI with block list updates ✅ credential guard ✅ enhanced sign in (Hello in VBS) And there’s more…
@_dirkjan
Dirk-jan
4 years
Another blog on the Primary Refresh Token! Thx @gentilkiwi for figuring this out with me! Tl;Dr: PRT can be extracted from lsass with #mimikatz 🥝. If with TPM, session key is protected. Still possible to extract derived keys and sign your own PRT cookies.
7
158
315
14
54
195
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 years
Xbox is x86 based and threat model assumes full physical access
6
27
198
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Nope, nope, and nope. All CPUs on the compatible list already have an embedded TPM. TPMs have been required for Windows certified devices since 2015! A very small number (mostly DIY) will have to enable it. We have some instructions and an update to the tool to make it easier.
35
44
191
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Creating a security feature is 1000x easier than turning on a security feature. Ask me how I know. Optional security nearly always means low volume. Evangelism doesn’t usually escape the tech people “bubble”
@RachelTobac
Rachel Tobac
3 years
In our Infosec circle we hear people talk about multi-factor authentication as if it's obvious but the reality is very different. Twitter released their numbers -- only *2.3%* of Twitter users had any MFA method enabled during this reporting period.
Tweet media one
51
303
859
11
38
192
@dwizzzleMSFT
David Weston (DWIZZZLE)
8 months
Is this the moment we acknowledge that building the browser into a remotely programmable OS had some downsides?
Tweet media one
9
36
191
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Security person X says: "This product came from country Y, must have a backdoor" Same person has never reversed the code or even looked at the network traffic. If you don't know, say you don't know. Security research has always been about getting to the truth.
6
26
189
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
I wish Apple would list security advancements as part of product launch. The primary reason I buy new iPhones is for improved hardware security. I’m sure I’m not the only one.
13
21
187
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 months
Windows 11 in 2024 is major progress - just took a @Lenovo ThinkPad Z16 Gen 2 out of the box and installed latest build: ✅Standard USER DEFAULT!!! (Adminless) ✅Signed-only apps (Smart App Control SAC) ✅Win32 App Isolation (AppSilo) ✅Pluton default, DRTM firmware
Tweet media one
16
34
185
@dwizzzleMSFT
David Weston (DWIZZZLE)
1 year
New shorts acquired
Tweet media one
11
9
180
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
Found a classic in the coffee room
Tweet media one
13
5
179
@dwizzzleMSFT
David Weston (DWIZZZLE)
7 years
Technical details on two different kernel 0days, includes how windows 10 mitigates them. #strontium #hankray #wdatp
1
153
175
@dwizzzleMSFT
David Weston (DWIZZZLE)
5 years
I used to find security vulnerabilities. I just spent the last hour approving expense reports.
15
11
174
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
Security definitely follows the: "10% inspiration, 90% perspiration" rule. Security people always want to build the cool 10% thing, then move on to the next research. Getting it deployed, turned on, or into the scale process is the hardest and most important part. Do that.
11
23
175
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
Oh look I made an SBOM for my Wireless AP just by uploading the current firmware to @Azure
Tweet media one
11
25
170
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Today I'm very excited to announce that @RefirmLabs will be joining the Microsoft family to help improve firmware security capabilities in Azure Defender and across devices on the intelligent edge.
Tweet media one
8
55
170
@dwizzzleMSFT
David Weston (DWIZZZLE)
10 months
Anyone have a windows question?
Tweet media one
13
7
166
@dwizzzleMSFT
David Weston (DWIZZZLE)
9 months
I think Atomic Red Team is one of the most important projects around. Understanding exposure through verifiable, deterministic prevention capabilities has positive cascading effects across your entire defense strategy. Hoping you can detect something is not enough.
7
36
165
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 years
@SwiftOnSecurity 1) Firmware is the MOST PRIVILEGED software on your device. Including hypervisor and kernel. Your EDR cannot effectively monitor it. You can't really see what,s going on there
3
25
159
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 years
Today I am running Microsoft Edge, Microsoft Teams, and Microsoft VS Code on a Microsoft Linux distro. That is all.
11
7
156
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
I am totally getting one of these Windows 11 Phones and trying project renegade:
Tweet media one
6
13
155
@dwizzzleMSFT
David Weston (DWIZZZLE)
2 years
I'll never ever ever ever understand why people setup these advanced hunting functions in their org BEFORE they do even basic systems hardening and attack surface reduction. Hustling backwards.
15
21
152