ericonidentity Profile Banner
Eric Woodruff | MVP | CIDPRO Profile
Eric Woodruff | MVP | CIDPRO

@ericonidentity

Followers
2K
Following
1K
Media
167
Statuses
1K

Security researcher @SemperisTech. Microsoft Security MVP, Entra nerd. Part-time hiker, full-time dad and partner. Opinions expressed are from my cat.

Joined September 2017
Don't wanna be here? Send us removal request.
@ericonidentity
Eric Woodruff | MVP | CIDPRO
11 days
At @WEareTROOPERS I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable SaaS applications. The attack is still alive and well. You can read all about it here:. #Entra #M365 #infosec.
0
37
77
@ericonidentity
Eric Woodruff | MVP | CIDPRO
5 months
If you work in, around, near, adjacent, or so on, to #identity, including #infosec and #Entra, you should fill out the #IDPro skills survey. It takes five minutes and really helps in understanding the industry landscape.
0
0
3
@ericonidentity
Eric Woodruff | MVP | CIDPRO
6 months
RT @SpecterOps: Check out this new blog post from @_wald0 discussing the fundamental components & mechanics that enable the emergence of cr….
0
48
0
@ericonidentity
Eric Woodruff | MVP | CIDPRO
6 months
If you consume multi-tenant apps in #EntraID, and they’ve been granted consent to do things in your tenant, you can spy on the auth choices your vendor makes - secrets or certs - in the logs available in your #Entra tenant. #infosec #azure #m365.
0
8
30
@ericonidentity
Eric Woodruff | MVP | CIDPRO
7 months
RT @TEMP43487580: I finished my talk at BHEU! The attack methods and techniques shared in the talk are not a great deal, but I hope this se….
0
54
0
@ericonidentity
Eric Woodruff | MVP | CIDPRO
7 months
RT @DrAzureAD: New #AADInternals version is finally out now:.▪ Moved endpoint related stuff to new module: AADInternals-Endpoints.▪ Added b….
0
121
0
@ericonidentity
Eric Woodruff | MVP | CIDPRO
7 months
RT @TrimarcSecurity: Wednesday, December 11th, Trimarc Active Directory Security Assessment Service Lead Jake Hildreth joins the @Antisy_Tr….
0
6
0
@ericonidentity
Eric Woodruff | MVP | CIDPRO
7 months
RT @decoder_it: M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx.A Kerberos relay & forwarder for MiTM….
0
231
0
@ericonidentity
Eric Woodruff | MVP | CIDPRO
8 months
RT @fabian_bader: Device-bound #passkeys in #EntraID are finally GA . #AiTM #Security #FIDO2 .
0
22
0
@ericonidentity
Eric Woodruff | MVP | CIDPRO
8 months
RT @cybersaiyanIT: Curious about the sessions you missed at #RomHack2024 this year?. Here you go: @ericonidentity - UnOAuthorized: The disc….
0
3
0
@ericonidentity
Eric Woodruff | MVP | CIDPRO
8 months
For those that *really* miss the old AAD portal:. #Entra #EntraID
Tweet media one
0
0
12
@ericonidentity
Eric Woodruff | MVP | CIDPRO
8 months
Still hard to not laugh when you see things like this in a #Entra tenant 😅
Tweet media one
4
0
20
@ericonidentity
Eric Woodruff | MVP | CIDPRO
8 months
RT @DrAzureAD: A quick debriefing with @ericonidentity, @kfosaaen, and @Thomas_Live after @HIPConf at @crescentbrew 🍻 .
0
4
0
@ericonidentity
Eric Woodruff | MVP | CIDPRO
8 months
En route to #HIPConf24, where I’ll be presenting on #UnOauthorized, as well as joining a panel with @Thomas_Live, @gkirkpatrick, @GGrillen and @shorinsean on workload identities, and having some good hallway conversations. Looking forward to seeing folks!. #Entra #infosec
Tweet media one
2
0
11
@ericonidentity
Eric Woodruff | MVP | CIDPRO
8 months
Redmond bound for @MSFTBlueHat, co-presenting with @SecretlyHidden1 “The Two Sides of UnOAuthorized” 😎. It will be my sixth trip out to the PNW - one of my favorite parts of the country to visit, so I’m excited for many reasons!
Tweet media one
1
2
19
@ericonidentity
Eric Woodruff | MVP | CIDPRO
9 months
To those people attending your session that nod along and smile and seem to understand what you’re talking about - 🫡
Tweet media one
1
0
22
@ericonidentity
Eric Woodruff | MVP | CIDPRO
9 months
I propose that @cyberriskall would better serve their speakers if they didn’t give out speaker contact information to vendors. It takes a lot of time to prepare for big conferences… and the payment is “sorry we missed you” spam from vendors 🙄.
1
0
6
@ericonidentity
Eric Woodruff | MVP | CIDPRO
9 months
RT @clatent: Created an interactive web version of EntraFIDOFinder now too as well as updated the module. Made a quick blog post it, let me….
0
6
0
@ericonidentity
Eric Woodruff | MVP | CIDPRO
9 months
- Using “we” in writing when representing a team, even if (I’m presuming) the research was performed by a single person 💪. I know for my own writing and research I’m going to try and steal a page or two from this as a guide 🫡. 4/4.
0
0
2
@ericonidentity
Eric Woodruff | MVP | CIDPRO
9 months
- Bonus points in particular for not just going into the “by design” 💩 on MS that even I’m guilty of 😅, and instead talking about the features in a neutral way. - The appendix 😍. The level of clear detail in how the research was performed is top notch. 3/4.
1
0
1