fabian_bader Profile Banner
Fabian Bader Profile
Fabian Bader

@fabian_bader

Followers
9K
Following
15K
Media
923
Statuses
7K

#Security #Azure #AAD #MDE #M365 #AD #PKI Microsoft MVP Tweets and opinions are my own @[email protected]

Hamburg, Germany
Joined November 2016
Don't wanna be here? Send us removal request.
@fabian_bader
Fabian Bader
3 years
📢If you missed my talk about Azure Attack Path at the @identitysummit, I just updated my blog with content created for the conference. New analytic rules, demo attack script and the slides are not available. #Azure #Security #Defend #Attack #Sentinel.
Tweet card summary image
cloudbrothers.info
Creating and maintaining a secure environment is hard. And with every technology or product added to your environment it gets more complicated. Microsoft Azure as a cloud environment is no exception...
3
107
306
@fabian_bader
Fabian Bader
3 days
RT @hkashfi: I just noticed CVE-2025-25257 and had a giggle. Not because it's yet another Fortinet remote bug. But because it's a SQLi, in….
0
40
0
@grok
Grok
2 days
Join millions who have switched to Grok.
65
151
771
@fabian_bader
Fabian Bader
4 days
You might want to check your XDR streaming API as well and do some late summer cleaning. You might be surprised to find a Sentinel from the past. #XDR.
0
0
7
@fabian_bader
Fabian Bader
5 days
RT @TEMP43487580: I just started a new blog, and this is my first post. I took a bit of PTO, so this is a little record of some fun I had p….
Tweet card summary image
temp43487580.github.io
Ways of device ownership spoofing and more for persistent access to Intune
0
66
0
@fabian_bader
Fabian Bader
6 days
RT @g0njxa: A Windows #Clickfix alternative seen in the wild on a mass-spreading malware campaign bypassing traditional Win+R shortcut rest….
0
59
0
@fabian_bader
Fabian Bader
6 days
You work with #XDR and always wanted to the process tree data outside of the Defender portal?. With XDR Story Parser you can.▫️Redact sensitive information.▫️Export process tree as screenshot.▫️Extract PowerShell and command-lines.▫️Zoom in onto a process.
Tweet media one
2
26
133
@fabian_bader
Fabian Bader
7 days
RT @JohnLaTwC: In KQL, if you have a base table with many columns, you may want a simplifed view--just a subset of columns that are arrange….
0
5
0
@fabian_bader
Fabian Bader
7 days
RT @DuRM365: #Security & #Governance sind zentrale Bestandteile einer sicheren Verwendung von IT Ressourcen. Auch in #Microsoft365 müssen w….
0
1
0
@fabian_bader
Fabian Bader
7 days
Wanna play around with #KQL and #Graph. Microsoft just released sample datasets to play around and look at this gorgeous visualization for the #Bloodhound schema they offer!. Thanks @cosh23 🥰.
Tweet media one
0
33
129
@fabian_bader
Fabian Bader
7 days
Token Protection in Microsoft Entra Conditional Access for Windows is now GA! 🎉. #EntraID #Token.
Tweet media one
5
44
205
@fabian_bader
Fabian Bader
9 days
RT @schnoll: No more MOERA domains for email (which you shouldn't be using the first place 😉). Limiting Onmicrosoft Domain Usage for Sendin….
Tweet card summary image
techcommunity.microsoft.com
We are announcing that all Exchange Online customers who send external email should start switching to custom (aka vanity) domain names.
0
8
0
@fabian_bader
Fabian Bader
9 days
RT @ExpelSecurity: 🚨 A NEW trojan on the block spotted by our threat intel team 👀. We saw files with the code-signing signature “GLINT SOF….
0
18
0
@fabian_bader
Fabian Bader
9 days
RT @_dirkjan: If you didn't find my Black Hat / Def Con slides yet, they are available on . Also includes the demo….
dirkjanm.io
0
68
0
@fabian_bader
Fabian Bader
9 days
Want to watch how Microsoft is removing the XDR deception configuration. Initially I had written this for debugging, but not I guess we only will see how stuff get's removed over time. #XDR #Deception #RIP. Thanks @DylanInfosec for the initial idea.
Tweet card summary image
gist.github.com
Troubleshooting Deception - Deception in XDR is deprecated starting 18.08.2025 - XDRDeceptionTroubleshooting.kql
2
5
14
@fabian_bader
Fabian Bader
10 days
RT @4ndr3w6S: Still need a ticket to @DEATHCon2025 in Austin?. Just a few left. Grab yours before they’re gone ⬇️.
0
3
0
@fabian_bader
Fabian Bader
10 days
RT @PyroTek3: One of the things that can be challenging when creating a honeypot account in Active Directory is making it look like a real….
0
58
0
@fabian_bader
Fabian Bader
10 days
New Microsoft Graph based API for response actions in #MDI . Disable, Enable, ForcePasswordReset and RevokeAllSessions finally available for your automations.
Tweet media one
2
26
146
@fabian_bader
Fabian Bader
10 days
Deception feature in Microsoft Defender for Endpoint will be retired by 31. October 2025 #deception #xdr .
@rucam365
Ru Campbell
10 days
Heads up. Spotted by a colleague this morning: deception capabiliites in MDE are not making it past public preview.
Tweet media one
Tweet media two
1
3
11
@fabian_bader
Fabian Bader
11 days
RT @dmcxblue: Back from PTO and back on my Azure vulnerable lab project Function Apps, Runbooks, VMs, DBs, SPNs & more. Built to learn Azur….
Tweet card summary image
github.com
An HTA Application which builds Azure (Entra) Scenarios for Red Team Simulations - dmcxblue/AzureStrike
0
38
0
@fabian_bader
Fabian Bader
13 days
RT @shodanhq: $5 Membership sale is live for the next 24 hours:
0
657
0