16 Followers
88 Following
49 Posts
Securing big ships, Product management, Excel dark arts Gardening and a lot of things in between.

PSA if it this helps people - if you want a full Microsoft 365 subscription, with E5, test data etc - that you can add Defender MDE on too - for free, head here: https://developer.microsoft.com/en-us/microsoft-365/dev-program#Subscription

It's really good, you can test all the MS Office and security technology for free, access Threat Analytics (normally paywalled) etc.

Developer Program | Microsoft 365 Dev Center

Start developing on the Microsoft 365 platform today! Join the Developer Program to get a free instant sandbox and sample data packs including Teams.

Hey #product and #productmanagement peeps.

Are you still here?

I haven't seem much activity recently.

Don't want to link your fresh install of Windows 11 with a Microsoft account? (VM for test, reinstalled laptop or whatever)

Easy peasy! You have two options:

# First option: Provide locked Microsoft account (minimum hassle, requires internet)

When asked to provide a Microsoft account, use [email protected] and a random password. This account is locked, and Windows will error out, and tell you that.

You can then proceed to use any local only account.

# Second option: No internet trick (can also be used if you actually *don't* have internet)

Make sure there's no ethernet cable in the machine. Install like you'd normally do, right up to the point where it whines about internet connectivity requirement.

Press Shift-F10, and you get a command prompt. Enter this command:

OOBE\BYPASSNRO

Your installation will now restart, but at the network requirement part, theres a "I don't have internet" option. Click on that, and you can create a local only user.

Both tricks works for the latest Windows 11 22H2 too!

#windows11

Omron PLC Vulnerability Exploited by Sophisticated ICS Malware https://bit.ly/3hWMAq1
Omron PLC Vulnerability Exploited by Sophisticated ICS Malware | SecurityWeek.Com

A critical vulnerability affecting Omron products has been exploited by a sophisticated piece of malware designed to target industrial control systems (ICS).

#offshore but not off the radar for cybersecurity:
https://www.gao.gov/products/gao-23-105789

"GAO is making one recommendation: BSEE should immediately develop and implement a strategy to address offshore infrastructure risks. Such a strategy should include an assessment and mitigation of risks; and identify objectives, roles, responsibilities, resources, and performance measures, among other things."

The report is light on technical detail but familiar theme of #operationaltechnology being no longer isolated. A couple of #incident #casestudies I wasn't familiar with.

Offshore Oil and Gas: Strategy Urgently Needed to Address Cybersecurity Risks to Infrastructure

A network of over 1,600 offshore facilities produce a significant portion of U.S. domestic oil and gas. These facilities, which rely on technology to...

This is the best post I've seen on deploying FIDO2 keys at scale in an enterprise. The insights on how analytics, automation and notification services are used are fantastic. #authentication #fido2 #azuread

https://blog.palantir.com/hardware-selection-and-logistics-passwordless-authentication-series-1-cef0a4550fab

So many discussions in #productmanagement could be eliminated if only #PMs did proper discovery and understood actual customer use cases and objectives.

Soooooo many.

#product

Today’s poem is called ‘Love Excels’.

If you are new here,

I've compiled this list of posts I wrote with tips for newcomers. I hope these can be helpful to you! Welcome! 🐘✨

Profile Page 👤
https://infosec.exchange/@Em0nM4stodon/109316634420493334

Mastodon Features   ​
https://infosec.exchange/@Em0nM4stodon/109287715784844066

Content Warnings ⚠️
https://infosec.exchange/@Em0nM4stodon/109282181601490676

Alt-Text 📝
https://infosec.exchange/@Em0nM4stodon/109323425237412179

Filters 🚫
https://infosec.exchange/@Em0nM4stodon/109323462169819778

Lists 🗂
https://infosec.exchange/@Em0nM4stodon/109265634017886918

Culture  
https://infosec.exchange/@Em0nM4stodon/109299435630063038

Fediverse  
https://infosec.exchange/@Em0nM4stodon/109293952488692993

Questions ❓
https://infosec.exchange/@Em0nM4stodon/109305965618704182

More Resources 👇

‣ Browse this hashtag to see more of my tips: #TinyMastodonTip

‣ Browse this hashtag to see more Mastodon and Fediverse tips: #FediTips

‣ Follow this great account for regular Mastodon tips in your timeline: @FediTips

Em :official_verified: (@[email protected])

Tiny Mastodon Newbie Profile Page Tips 🐘✨: About your profile page 👤 If you just arrived here, before following lots of people, it’s a good idea to complete your profile page. This will increase the chances of people following you back and finding your profile. 1. Write about who you are and/or what you like in your profile bio (you can use hashtags there so people can find you). It’s okay if it’s short, but write something 📝 2. Personalize your profile picture with something you like. Don’t just let the Mastodon default, it makes you look like an anonymous bot. And you are not a bot! (unless you are) 🤖 3. You can write an introduction about yourself in a toot (post) and use the hashtag “# introduction” (minus the space). You can pin this toot to your profile page so that it stays at the top. You don’t have to write it right away, but it can help people finding you and deciding to follow you #️⃣ 4. Post or boost a few toots that you like, so that your profile timeline isn’t completely empty :boost_ok:​ 5. Then, when your profile looks like a page that represents you, follow the people that interest you. Interact with them. Be kind 💚 Make friends! :ablobsmile:​ 6. Magic!✨ #TinyMastodonTip #Mastodon

Infosec Exchange
@Kempley in my experience, velo is superior to osquery. It is written in go, uses a single standalone file for both server and client solution, leverages VQL over SQL, and has great agent management for live collection. Worth a quick spin if you haven't tried it out.