Core Infrastructure and Security Blog

Options
45.2K
Christian Heim on Jan 28 2021 01:39 PM
3,348
Christian Heim on Jan 21 2019 07:00 PM
1,327
Christian Heim on Jan 21 2019 06:57 PM
3,584
Christian Heim on Jan 21 2019 06:56 PM
3,840
Christian Heim on Jan 21 2019 06:56 PM
577
Christian Heim on Jan 21 2019 06:55 PM
17.5K
Christian Heim on Jan 21 2019 06:55 PM
478
Christian Heim on Jan 21 2019 06:53 PM
2,786
Christian Heim on Jan 21 2019 06:51 PM
2,689
Christian Heim on Jan 21 2019 06:49 PM
4,974
Christian Heim on Jan 21 2019 06:44 PM
1,569
Christian Heim on Jan 21 2019 06:44 PM
1,697
Christian Heim on Jan 21 2019 06:43 PM

Latest Comments

Hi @Lee Dandridge - First enable msDS-SupportedEncryptionType to support AES on all accounts with a SPN then monitor 4769 events for any use of RC4. Additionally you should capture and analyze 4768 events for RC4 use which will identify RC4 using when requesting a TGT. My lasted blog post explains w...
0 Likes
Great information in the article and the comments; great to know there are such complete references out there. One question @Jerry Devore , we are trying to update all the supported ciphers on our internal domain and want to know which should come first, Remove the RC4 ciphers 1st, or set the msDS-S...
0 Likes
@pk_Tech It's seem similar my previous situation.For my last problem, I was point to the related OU and some of the user doesn't have the email so the script will stuck and stop to send. How I resolve the problem?I create another same OU, and move the user which do not have email to this OU.
0 Likes
Hello,thank you for sharing the script, it works perfectly after too much testings.just to let you know that we can also adjust the script to lookup users in a specific OU; this way you can send different emails to each group of users/departments.
0 Likes
Hello @v-liangchen , was it about authenticating from an Azure VM, an Arc-Enabled VM or from Automation Account? I am not aware of any change and the replacement you did was basically changing the target to a different resource not Azure Monitor. Did you grant the necessary permission to the managed...
0 Likes