justinverstijnen.nljustinverstijnen.nl
  • Home
  • Blog
  • Tools
  • About
    • LinkedIn
    • Reddit
    • GitHub
    • @

Microsoft Defender XDR

All pages referring or tutorials for Microsoft Defender XDR.

On this page
  • Requirements
  • Starting out
  • Generating DNS lookup alerts
  • Enumerate all users and groups in Active Directory
  • List alerts in Defender for Identity portal
  • Enumerate the SYSVOL folder
  • Launching a Pass-The-Hash attack on the computer (Windows 10 only)
  • Honeytokens in Defender for Identity
  • Use the Honeytoken to try and gain access
  • Summary

Categories

  • Azure Master Class (12)
  • Azure Virtual Desktop (16)
  • Flying (12)
  • Intune (2)
  • Microsoft 365 (11)
  • Microsoft Azure (25)
  • Microsoft Defender XDR (4)
  • Microsoft Entra (9)
  • Networking (5)
  • Powershell (15)
  • Uncategorized (1)
  • Windows 365 (2)
  • Windows Server (10)
Microsoft Defender XDR

Penetration testing Defender for Identity and Active Directory

In this guide, i will show how to do some popular Active Directory attacking tests and show how Defender for Identity (MDI) will alert you about the attacks. Not everyting detected by Defender for Identity will be directly classified as potential attack. When implementing the solution, it will learn during Read more

By Justin, 9 monthsFebruary 21, 2025 ago
Microsoft Defender XDR

How to monitor your Active Directory with Defender for Identity

When it comes to security, it is great to secure every perimeter. In the Zero Trust model, it has been stated that we have to verify everything, everytime, everywhere. So why consider not monitoring and defending your traditional Active Directory that is still in use because of some legacy applications? Read more

By Justin, 9 monthsFebruary 15, 2025 ago
Microsoft Defender XDR

Microsoft Defender External Attack Surface Management (EASM)

Microsoft Defender External Attack Surface Management (EASM) is a security solution for an organization’s external attack surfaces. It operates by monitoring security and operational integrity across the following assets: In addition to these components, EASM can also forward all relevant information and logs to SIEM solutions such as Microsoft Sentinel. Read more

By Justin, 12 monthsDecember 1, 2024 ago
Microsoft Defender XDR

The MITRE ATTACK Framework

The MITRE ATTACK (ATT&CK) Framework is a framework which describes all stages and methods cyberattacks attacks are launched on companies in the last 15 years. The main purpose of the framework is to help Red and Blue security teams to harden their systems and to provide a library of known Read more

By Justin, 12 monthsNovember 25, 2024 ago

Terms and Conditions applies to this page.

© 2025


  • Home
  • Blog
  • Tools
  • About
Hestia | Developed by ThemeIsle