Dirk-jan
@dirkjanm.io
1.9K followers
66 following
68 posts
Hacker at outsidersecurity.nl. Researches Entra ID, AD and occasionally Windows security. I write open source security tools and do blogs/talks to educate others on these topics. Blog: dirkjanm.io
Posts
Media
Videos
Starter Packs
Dirk-jan
@dirkjanm.io
· 24d
Dirk-jan
@dirkjanm.io
· 24d
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
dirkjanm.io
Dirk-jan
@dirkjanm.io
· Aug 26
GitHub - Paradoxis/ADSyncDump-BOF: The ADSyncDump BOF is a port of Dirkjan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.
The ADSyncDump BOF is a port of Dirkjan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies. - Paradoxis/ADSyncDump-BOF
github.com
Reposted by Dirk-jan
Katie Knowles
@siigil.bsky.social
· Aug 14
I SPy: Escalating to Entra ID's Global Admin with a first-party app | Datadog Security Labs
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led...
securitylabs.datadoghq.com
Dirk-jan
@dirkjanm.io
· Aug 6
Dirk-jan
@dirkjanm.io
· Jul 30
Extending AD CS attack surface to the cloud with Intune certificates
Active Directory Certificate Services (AD CS) attack surface is pretty well explored in Active Directory itself, with *checks notes* already 16 “ESC” attacks being publicly described. Hybrid attack pa...
dirkjanm.io
Reposted by Dirk-jan
Reposted by Dirk-jan
Dirk-jan
@dirkjanm.io
· Jun 24
Reposted by Dirk-jan
Dirk-jan
@dirkjanm.io
· Jun 18
Dirk-jan
@dirkjanm.io
· Jun 10
Dirk-jan
@dirkjanm.io
· May 20
Dirk-jan
@dirkjanm.io
· Apr 25
Reposted by Dirk-jan
Dr Nestori Syynimaa
@drazuread.com
· Apr 18
Dirk-jan
@dirkjanm.io
· Apr 16
Dirk-jan
@dirkjanm.io
· Apr 10