“Just enable MFA. It’s easy.”

๐Ÿ”’ Secure Bits ๐Ÿ’ก โ€œ๐—๐˜‚๐˜€๐˜ ๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐— ๐—™๐—”. ๐—œ๐˜โ€™๐˜€ ๐—ฒ๐—ฎ๐˜€๐˜†.โ€ Sureโ€ฆ if you can rely on cloud identity. A lot of environments can. But ๐—บ๐—ฎ๐—ป๐˜† – often the most critical ones – ๐—ฐ๐—ฎ๐—ป๐—ป๐—ผ๐˜ be connected to the internet at all. And that changes everything. In fully ๐—ผ๐—ป-๐—ฝ๐—ฟ๐—ฒ๐—บ / ๐—ผ๐—ณ๐—ณ๐—น๐—ถ๐—ป๐—ฒ Windows environments, MFA often ends up being […]

New RDP dialogs

๐Ÿ”’ย Secure Bitsย ๐Ÿ’ก ๐—ก๐—ฒ๐˜„ ๐—ฅ๐——๐—ฃ ๐—ฑ๐—ถ๐—ฎ๐—น๐—ผ๐—ด๐˜€ โ€” ๐—ต๐—ฎ๐˜ƒ๐—ฒ ๐˜†๐—ผ๐˜‚ ๐˜€๐—ฒ๐—ฒ๐—ป ๐˜๐—ต๐—ฒ๐—บ? With theย ๐—”๐—ฝ๐—ฟ๐—ถ๐—น ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ security update, the Remote Desktop Connection app (MSTSC) showsย new warnings when you open .๐—ฅ๐——๐—ฃ ๐—ณ๐—ถ๐—น๐—ฒ๐˜€. The point is simple: remind people thatย RDP files can be used for phishing / tricking users, and force you toย explicitly approve what the file is trying to […]

Capturing Network Traffic on Windows Server

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—–๐—ฎ๐—ฝ๐˜๐˜‚๐—ฟ๐—ถ๐—ป๐—ด ๐—ป๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐˜๐—ฟ๐—ฎ๐—ณ๐—ณ๐—ถ๐—ฐ ๐—ผ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ There is an issue on a Windows Server, and I need to capture network traffic to understand what is happening. The first thought is usually: โžก๏ธ Letโ€™s install ๐—ช๐—ถ๐—ฟ๐—ฒ๐˜€๐—ต๐—ฎ๐—ฟ๐—ธ ๐Ÿšซ But that does not always work. In many environments I work in โ€” especially critical […]

Do you know what proper logging in Windows looks like?

๐Ÿ”’ย Secure Bits ๐Ÿ’ก ๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ธ๐—ป๐—ผ๐˜„ ๐˜„๐—ต๐—ฎ๐˜ โ€œ๐—ฝ๐—ฟ๐—ผ๐—ฝ๐—ฒ๐—ฟ ๐—น๐—ผ๐—ด๐—ด๐—ถ๐—ป๐—ดโ€ ๐—ถ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—น๐—ผ๐—ผ๐—ธ๐˜€ ๐—น๐—ถ๐—ธ๐—ฒ? Most environments I see struggle with this. Logging is often leftย ๐—ฑ๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜, ๐—ป๐—ผ๐—ถ๐˜€๐˜†, ๐—ผ๐—ฟ ๐˜€๐—ถ๐—บ๐—ฝ๐—น๐˜† ๐—บ๐—ถ๐˜€๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฒ๐—ฑย โ€” which means you either miss real attacksโ€ฆ or you drown in useless events. Thatโ€™s why I builtย ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐—Ÿ๐—ผ๐—ด. ๐ŸŽฏย ThreatLog helps you ๐—ฑ๐—ฒ๐—ฝ๐—น๐—ผ๐˜† ๐—ฎ ๐—ฝ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—”๐˜‚๐—ฑ๐—ถ๐˜ ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† + ๐—ฆ๐˜†๐˜€๐—บ๐—ผ๐—ป […]

RDP certificate warning

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ Real configs. Real fixes. Windows & AD security. Have you ever seen this ๐—ฅ๐——๐—ฃ ๐—ฐ๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ ๐˜„๐—ฎ๐—ฟ๐—ป๐—ถ๐—ป๐—ด? Do you know ๐˜„๐—ต๐—ฎ๐˜ ๐—ถ๐˜ ๐—บ๐—ฒ๐—ฎ๐—ป๐˜€? It means the certificate presented by the target during RDP ๐—ถ๐˜€๐—ปโ€™๐˜ ๐˜๐—ฟ๐˜‚๐˜€๐˜๐—ฒ๐—ฑ. Often itโ€™s just a self-signed certโ€”which isnโ€™t a huge problem: you can make it trusted or distribute your […]

Is your UAC set properly?

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ Real configs. Real fixes. Windows & AD security. ๐—ค๐˜‚๐—ถ๐—ฐ๐—ธ ๐˜๐—ฒ๐˜€๐˜: press Win + R โ†’ type msconfig.exe โ†’ Enter. Did the console open immediately? If yes, your ๐—จ๐—”๐—– ๐—ถ๐˜€๐—ปโ€™๐˜ ๐—ต๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ. ๐Ÿงจย ๐—•๐˜† ๐—ฑ๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜, UAC has exceptions for Windows binaries (Prompt for consent for non-Windows binaries)โ€”attackers can abuse this behavior with known ๐—จ๐—”๐—– ๐—ฏ๐˜†๐—ฝ๐—ฎ๐˜€๐˜€๐—ฒ๐˜€. […]

Updating Secure Boot certificates on Windows Server

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ถ๐—ป๐—ด ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—•๐—ผ๐—ผ๐˜ ๐—ฐ๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ๐˜€ ๐—ผ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ โ€” ๐—ณ๐—ถ๐—ป๐—ฎ๐—น ๐—ป๐—ผ๐˜๐—ฒ๐˜€ (๐—บ๐—ฒ๐—ฟ๐—ด๐—ฒ๐—ฑ ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฒ) As promised, I merged all 3 parts of this Secure Boot series into one Field Notes document you can follow end-to-end. This process is not trivial: some servers go through smoothly, others hit issues depending on firmware / platform […]

New Microsoft procedure for Secure Boot Certificate Updates

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—ก๐—ฒ๐˜„ ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—ฝ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐—ฑ๐˜‚๐—ฟ๐—ฒ ๐—ณ๐—ผ๐—ฟ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—•๐—ผ๐—ผ๐˜ ๐—–๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ๐˜€ I tested the new Microsoft procedure I shared last time (link in comments). Iโ€™ll be honest โ€” I was a bit ๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐˜„๐—ต๐—ฒ๐—น๐—บ๐—ฒ๐—ฑ at first. There are multiple scripts, and I ran into a few โ€œpaper cutsโ€, so itโ€™s still not as straightforward as […]

Secure Boot certificates are expiring pt. 3

๐Ÿ”’ย Secure Bitsย ๐Ÿ’ก ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ถ๐—ป๐—ด ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—•๐—ผ๐—ผ๐˜ ๐—ฐ๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ๐˜€ ๐—ผ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐—ฐ๐—ผ๐—ป๐˜๐—ถ๐—ป๐˜‚๐—ฒ๐˜€ (๐˜ฑ๐˜ต. 3) Last puzzle in this series isย ๐—บ๐—ผ๐—ป๐—ถ๐˜๐—ผ๐—ฟ๐—ถ๐—ป๐—ด. Because as you can see, this process is ๐—ป๐—ผ๐˜ ๐˜๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—ฎ๐—น ๐—ผ๐—ฟ ๐˜€๐˜๐—ฟ๐—ฎ๐—ถ๐—ด๐—ต๐˜๐—ณ๐—ผ๐—ฟ๐˜„๐—ฎ๐—ฟ๐—ฑ. Some devices will go through smoothly, others will hit different errors depending on firmware / platform / history โ€” and thatโ€™s the worst case. Thatโ€™s […]

Secure Boot certificates are expiring pt. 2

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ถ๐—ป๐—ด ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—•๐—ผ๐—ผ๐˜ ๐—ฐ๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ๐˜€ ๐—ผ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐—ฐ๐—ผ๐—ป๐˜๐—ถ๐—ป๐˜‚๐—ฒ๐˜€ (๐˜ฑ๐˜ต. 2) I believe I had to go through the worst-case scenario after all: โœ… GPO trigger โ†’ KEK failure โœ… Broadcom idea (upgrade compatibility + delete/rename NVRAM) โ†’ VM fails to boot โœ… Fixed the VM โ†’ tried again โ†’ KEK failure […]