@PyroTek3i
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Identity Security Architect @ TrustedSec. Microsoft Certified Master #ActiveDirectory & former Microsoft MVP. Co-Host @ Enterprise Security Weekly. He/Him. #BLM
4°08'15.0N 162°03'42.0E
Joined August 2014
- Tweets23.3K
- Following714
- Followers37K
- Likes42.4K
Pinned Tweet
To my black family, friends, and people seeing this:
I love you
You matter
I'm here for you
#BlackLivesMatter
Sean Metcalf retweeted
Microsoft just moved Endpoint Privilege Management into base Microsoft 365 E5. No more separate add-on cost for a feature that lets standard users elevate one task without ever getting admin rights.
Sean Metcalf retweeted
Saddle up, Deadwood, you won't want to miss this! Identity Security Architect @PyroTek3 is presenting "Entra the Dragon: Entra ID Red vs Blue" at @WWHackinFest on October 8 at 10:00AM. Plus, find the rest of the team at our booth—see you there 🤠 hubs.la/Q04ymDmw0
Sean Metcalf retweeted
Monitoring privileged groups (tier 0) for changes is super important but if you can get to a point where you’re also detecting abnormal changes, that’s better.
Eg, if somehow joe the sql guy has added an account to Domain Admins even though he shouldn’t be able to, that’s a big red flag.
Sean Metcalf retweeted
Agentic AI is part of the team now and our CTO @HackingLZ has thoughts 👀 Tune in next week to #SecurityNoise as we dig into the risks, practical uses, and how red team pentesters are keeping humans in the loop. Search "Security Noise" in your podcast app and subscribe today!
Sean Metcalf retweeted
Microsoft Defender for Office 365 will enable Teams user reporting by default starting late October 2026 for licensed organizations. Users can report suspicious Teams content to improve threat detection. SOC can implement custom detection to monitor Teams user Reporting incident for prompt follow up.
#MicrosoftDefender #Teamsuserreporting
Sean Metcalf retweeted
Our call for papers is over, now we start a call for volunteers!
If you want to help with the BSides NOVA conference on Oct 30-31st, read this forms.gle/nZCDR6MPRgs8DQV28, fill out what you'd like to do and submit!
We need volunteers to run the conference, thanks if you can help!
Sean Metcalf retweeted
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
bleepingcomputer.com/news/se…
bleepingcomputer.com/news/se…
Sean Metcalf retweeted
Probably a good time to point you all to a tool I released not to long ago called SecretsStalker. If you have found an exposed client ID and secret to s service principal, SecretsStalker will authenticate you into the environment and recon the exact rights that it has.
github.com/rootsecdev/Secret…
Microsoft Security Research has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. msft.it/6015a9lob
Two compromised service principals divided discovery, destruction, and credential collection, with timing and overlapping token streams strongly indicating automated or scripted execution that included more than 100 storage account deletion attempts in about seven minutes.
Discovered by Sysdig in July 2026, JADEPUFFER is reported to be the first documented agentic ransomware operation. These new findings expand publicly documented activity associated with Storm-3168 and indicate an evolution in the threat actor's cloud operations.
Read the blog for analysis, Microsoft Defender detections, and mitigation guidance on protecting workload identities, revoking or rotating exposed credentials, and safeguarding backup and recovery resources.
Sean Metcalf retweeted
ISOC in Microsoft Defender is a benefit for M365 E5 and E7 customers, it is not a new product. Those lucky customers will save 44% off 3P security log ingestion.
I spent all day reading and broke it down here to bring it to you straight:
patriotconsulting.com/blogs/…
XDR and SIEM now in one platform. Meet the new ISOC in Microsoft Defender—a SOC built for agentic security. Here to help you investigate and respond more efficiently. msft.it/6019ag5T1
Sean Metcalf retweeted
At #GrrCon? Swing by the @TrustedSec and @Binary_Defense booths
#TrustedSec - booth #97
#BinaryDefense - booth #121
Great folks over there, see NightBeacon live in action, chat with our folks at TS to talk about what we're doing on offense and defense.
Sean Metcalf retweeted
I just wanted to do a special shoutout to @P1nkN1ghtmare @EggDropX and all of the amazing folks that put on @GrrCON and its volunteers, staff, and sponsors.
One of my favorite cons of all times, superb every year - so many great friends there and super well run.
Appreciate all the time, effort, and work that goes into making that place magical. Know the level of effort and attention to detail it takes.
Had a blast speaking again this year, so many great talks, good people - and many memories forged.
Thank you all!
Sean Metcalf retweeted
🔁 Microsoft Entra Connect (Azure AD Connect) version 2.6.92.0 is now available
🔒 This is a hotfix release with security fixes. Microsoft recommends upgrading as soon as possible.
🛠️ It fixes an issue in 2.6.91.0 where enabling Pass-through Authentication through the wizard could fail while registering the local Authentication Agent. If you planned to deploy 2.6.91.0, go straight to 2.6.92.0.
The .msi must be downloaded from the Microsoft Entra admin center:
entra[.]microsoft[.]com > Identity > Hybrid Management > Microsoft Entra Connect > Connect Sync > Get started > Manage tab
🚨 Reminder: on September 30, 2026, every server below 2.5.79.0 stops synchronizing until it is upgraded. Less than a week left.
🔗 Official release notes:
learn.microsoft.com/en-us/en…
🔗 Previous versions list, you can download older versions there:
l.itpro.tips/entraconnectsyn…
Sean Metcalf retweeted
I've begun publishing a set of more detailed Active Directory Certificate Services modules. Here is the first on determining topology and role deployment. learn.microsoft.com/en-us/tr…
Sean Metcalf retweeted
I'm planning my conference talks for 2027.
What do you want to hear about?
26%Active Directory
23%Entra ID
51%Both!
0%Other (comment)
105 votes • Final results Sean Metcalf retweeted
We...worked on this story for a year...and...they just...they tweeted it out.
Keeping your fridge and freezer closed is the best way to keep food fresh for as long as possible. - @nbcselected nbcnews.com/select/shopping/…