Mike · @miketheitguy
777 followers · 1779 posts · Server ioc.exchange

Okay. More tech. You know, Microsoft has some of the best documentation out there on the internet for their technologies. That said, finding some of it can be a bit brutal, but it does exist. And now so much more shit makes so much more sense now. And I love it.

#activedirectory #windows #microsoft #Windowsserver

Last updated 2 years ago

Mike · @miketheitguy
763 followers · 1701 posts · Server ioc.exchange

I am disappointed that openldap (and by extension python-ldap) doesn't support connectionless LDAP. Makes using it in a Windows environment a little more painful. Might have to figure something else out, but for now, what I'm doing works.

#activedirectory #Windowsserver #opensource

Last updated 2 years ago

Mike · @miketheitguy
676 followers · 1463 posts · Server ioc.exchange

Aight Microsoft. You caused me some work today. I had to actually open the laptop on a holiday weekend because of your bum patches.

#infosec #activedirectory #Windowsserver

Last updated 2 years ago

Mike · @miketheitguy
663 followers · 1386 posts · Server ioc.exchange

If you can't generate new keytabs for some reason, or your platforms don't support AES Kerberos--you can use Set-ADUser/Computer to set the supported encryption types to RC4 on that account--which resolves any Kerberos auth issues after applying the new patch.

#Windowsserver #infosec #cybersecurity #activedirectory

Last updated 2 years ago

Mike · @miketheitguy
663 followers · 1382 posts · Server ioc.exchange

With the November Microsoft patches, Microsoft has changed the default Kerberos Session Key encryption to AES-256. The documentation for this flag change in the Kerberos Encryption Types is buried in an errata document that has no indication it's been changed unless you open the errata doc: learn.microsoft.com/en-us/open

#infosec #activedirectory #cybersecurity #Windowsserver

Last updated 2 years ago

Mike · @miketheitguy
616 followers · 1267 posts · Server ioc.exchange

I'll throw this out there. and are rather great platforms if you care about security, particularly in some of the more obscure situations like firmware attacks and APTs. I'd recommend every professional spend some quality time learning some of the underlying technology, including their usage of TPM, Secure Boot, Secure Launch, and Defender Application Control. No platform is perfect; But Windows has done some really awesome stuff using hardware security.

#windows11 #Windowsserver #infosec

Last updated 2 years ago

dispatch · @dispatch
472 followers · 2723 posts · Server ioc.exchange
dispatch · @dispatch
472 followers · 2723 posts · Server ioc.exchange