Guy Leech
@guyrleech.bsky.social
1.2K followers 230 following 840 posts
PowerShell nut. Dog owner. Grandfather
Posts Media Videos Starter Packs
guyrleech.bsky.social
Note that the default in secpol.msc says "Not Configured" but it's on by default so enable auditing but don't enable Success. I don't believe that these events are useful - they cause log overwrite of ones that are like process creation & termination
guyrleech.bsky.social
Just dug this 2018 tweet out as seeing the issue at a customer:

#Windows Security event log being swamped by 4703 "A token right was adjusted" events? Disable "Audit Authorization Policy Change" by local or group policy. Common with #SCCM
learn.microsoft.com/en-us/previo...
guyrleech.bsky.social
Thanks although you spelt powershell.exe wrong 😂
guyrleech.bsky.social
What's the current thinking/consensus/experience of having duplicate machine SIDs on the same subnet & members of the same domain (different hostnames & MAC & IP addresses obviously)?
It's many years since @markrussinovich.bsky.social said changing SIDs wasn't necessary but what about RoW?
guyrleech.bsky.social
What a croc

Or is it?

What, a croc? 😄
Reposted by Guy Leech
psconf.eu
💡 Be Your Own Sherlock in the Realms of Microsoft Graph
👨‍🏫 @hcritter.bsky.social – Senior System Engineer at CANCOM GmbH
🗓️ 14 Oct | #PSConfEU MiniCon
👉 Free ticket: synedgy.com/psconfeu-minicon
#PowerShell #Microsoft #Graph #automation
guyrleech.bsky.social
I use thin sliced ham for my dogs
guyrleech.bsky.social
If you want to quickly figure out if & where a process is writing a logfile, create a filter (ctrl l) in @SysInternals procmon for your process(es) and also Category = Write & turn off registry & network capture in the toolbar
guyrleech.bsky.social
Any of you got experiences of packaging Adobe or AutoCAD apps into MSIX and delivering via App Attach? About to have a play myself but interested to know if others have tried. I think going App-V is probably not a sensible approach given its life expectancy.
guyrleech.bsky.social
Need to turn %USERDNSDOMAIN% into canonical form, eg for ADSI ?

"DC=$(($env:USERDNSDOMAIN -split '\.') -join ',DC=')"
guyrleech.bsky.social
They are indeed a croc ...
Reposted by Guy Leech
psconf.eu
💡 #PowerShell Security: A Journey Through Time
👨‍🏫👨‍🏫 @miriamwiesner.bsky.social - Security Researcher at Microsoft & Anam Navied - Software Engineer, PowerShell team at Microsoft
🗓️ 14 Oct | #PSConfEU MiniCon
👉 Free ticket: synedgy.com/psconfeu-minicon
#automation
guyrleech.bsky.social
In my Unix coding days I always preferred amber screens over green screens
guyrleech.bsky.social
"We're going to need a bigger bed" ! 😂
I had 4 with me last night although they are smaller & my bed is bigger
guyrleech.bsky.social
Cases for the old Nokia phones were to protect the floor, not the phone 😂
guyrleech.bsky.social
Out-gridview does indeed now seem to be working properly
guyrleech.bsky.social
Can still buy new Nokia phones!
guyrleech.bsky.social
A Windows phone? 😃
guyrleech.bsky.social
I'm just a jealous Guy 😃
guyrleech.bsky.social
It seems that the long standing PowerShell 7.5.* bug where Out-Gridview doesn't function properly is fixed in 7.5.3! Hurrah!
github.com/PowerShell/P...
guyrleech.bsky.social
It may be fixed - I'll give it a go