
Eric Woodruff | MVP | CIDPRO
@ericonidentity
Followers
2K
Following
1K
Media
168
Statuses
1K
Security researcher @SemperisTech. Microsoft Security MVP, Entra nerd. Part-time hiker, full-time dad and partner. Opinions expressed are from my cat.
Joined September 2017
At @WEareTROOPERS I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable SaaS applications. The attack is still alive and well. You can read all about it here:. #Entra #M365 #infosec.
semperis.com
Think nOAuth abuse is old news? We wish. Our recent testing shows that nearly 10% of apps in the Microsoft Entra Gallery remain vulnerable.
0
39
80
Another great talk yesterday from @_dirkjan revealing a super interesting path - moving from exchange hybrid on-prem bits to owning Entra.
0
0
7
RT @SpecterOps: Check out this new blog post from @_wald0 discussing the fundamental components & mechanics that enable the emergence of cr….
0
48
0
If you consume multi-tenant apps in #EntraID, and they’ve been granted consent to do things in your tenant, you can spy on the auth choices your vendor makes - secrets or certs - in the logs available in your #Entra tenant. #infosec #azure #m365.
ericonidentity.com
Examining Entra ID sign-in and graph activity logs to determine what type of credentials your ISVs use in their multi-tenant applications.
0
9
30
RT @TEMP43487580: I finished my talk at BHEU! The attack methods and techniques shared in the talk are not a great deal, but I hope this se….
github.com
Contribute to secureworks/pytune development by creating an account on GitHub.
0
55
0
RT @DrAzureAD: New #AADInternals version is finally out now:.▪ Moved endpoint related stuff to new module: AADInternals-Endpoints.▪ Added b….
0
121
0
RT @TrimarcSecurity: Wednesday, December 11th, Trimarc Active Directory Security Assessment Service Lead Jake Hildreth joins the @Antisy_Tr….
0
6
0
RT @decoder_it: M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx.A Kerberos relay & forwarder for MiTM….
0
232
0
RT @cybersaiyanIT: Curious about the sessions you missed at #RomHack2024 this year?. Here you go: @ericonidentity - UnOAuthorized: The disc….
0
3
0
RT @DrAzureAD: A quick debriefing with @ericonidentity, @kfosaaen, and @Thomas_Live after @HIPConf at @crescentbrew 🍻 .
0
4
0
En route to #HIPConf24, where I’ll be presenting on #UnOauthorized, as well as joining a panel with @Thomas_Live, @gkirkpatrick, @GGrillen and @shorinsean on workload identities, and having some good hallway conversations. Looking forward to seeing folks!. #Entra #infosec
2
0
11
Redmond bound for @MSFTBlueHat, co-presenting with @SecretlyHidden1 “The Two Sides of UnOAuthorized” 😎. It will be my sixth trip out to the PNW - one of my favorite parts of the country to visit, so I’m excited for many reasons!
1
2
18
I propose that @cyberriskall would better serve their speakers if they didn’t give out speaker contact information to vendors. It takes a lot of time to prepare for big conferences… and the payment is “sorry we missed you” spam from vendors 🙄.
1
0
5
RT @clatent: Created an interactive web version of EntraFIDOFinder now too as well as updated the module. Made a quick blog post it, let me….
clatent.com
Yes, I know it may seem counter productive to make a web version of it, but I wanted to have an interactive web version so that it is easier for people to use then Microsoft’s version. The da…
0
6
0