“Just enable MFA. It’s easy.”

๐ Secure Bits ๐ก โ๐๐๐๐ ๐ฒ๐ป๐ฎ๐ฏ๐น๐ฒ ๐ ๐๐. ๐๐โ๐ ๐ฒ๐ฎ๐๐.โ Sureโฆ if you can rely on cloud identity. A lot of environments can. But ๐บ๐ฎ๐ป๐ – often the most critical ones – ๐ฐ๐ฎ๐ป๐ป๐ผ๐ be connected to the internet at all. And that changes everything. In fully ๐ผ๐ป-๐ฝ๐ฟ๐ฒ๐บ / ๐ผ๐ณ๐ณ๐น๐ถ๐ป๐ฒ Windows environments, MFA often ends up being […]
New RDP dialogs

๐ย Secure Bitsย ๐ก ๐ก๐ฒ๐ ๐ฅ๐๐ฃ ๐ฑ๐ถ๐ฎ๐น๐ผ๐ด๐ โ ๐ต๐ฎ๐๐ฒ ๐๐ผ๐ ๐๐ฒ๐ฒ๐ป ๐๐ต๐ฒ๐บ? With theย ๐๐ฝ๐ฟ๐ถ๐น ๐ฎ๐ฌ๐ฎ๐ฒ security update, the Remote Desktop Connection app (MSTSC) showsย new warnings when you open .๐ฅ๐๐ฃ ๐ณ๐ถ๐น๐ฒ๐. The point is simple: remind people thatย RDP files can be used for phishing / tricking users, and force you toย explicitly approve what the file is trying to […]
Capturing Network Traffic on Windows Server

๐ Secure Bits ๐ก ๐๐ฎ๐ฝ๐๐๐ฟ๐ถ๐ป๐ด ๐ป๐ฒ๐๐๐ผ๐ฟ๐ธ ๐๐ฟ๐ฎ๐ณ๐ณ๐ถ๐ฐ ๐ผ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ There is an issue on a Windows Server, and I need to capture network traffic to understand what is happening. The first thought is usually: โก๏ธ Letโs install ๐ช๐ถ๐ฟ๐ฒ๐๐ต๐ฎ๐ฟ๐ธ ๐ซ But that does not always work. In many environments I work in โ especially critical […]
Do you know what proper logging in Windows looks like?

๐ย Secure Bits ๐ก ๐๐ผ ๐๐ผ๐ ๐ธ๐ป๐ผ๐ ๐๐ต๐ฎ๐ โ๐ฝ๐ฟ๐ผ๐ฝ๐ฒ๐ฟ ๐น๐ผ๐ด๐ด๐ถ๐ป๐ดโ ๐ถ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐น๐ผ๐ผ๐ธ๐ ๐น๐ถ๐ธ๐ฒ? Most environments I see struggle with this. Logging is often leftย ๐ฑ๐ฒ๐ณ๐ฎ๐๐น๐, ๐ป๐ผ๐ถ๐๐, ๐ผ๐ฟ ๐๐ถ๐บ๐ฝ๐น๐ ๐บ๐ถ๐๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฒ๐ฑย โ which means you either miss real attacksโฆ or you drown in useless events. Thatโs why I builtย ๐ง๐ต๐ฟ๐ฒ๐ฎ๐๐๐ผ๐ด. ๐ฏย ThreatLog helps you ๐ฑ๐ฒ๐ฝ๐น๐ผ๐ ๐ฎ ๐ฝ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐๐๐ฑ๐ถ๐ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ + ๐ฆ๐๐๐บ๐ผ๐ป […]
RDP certificate warning

๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ Real configs. Real fixes. Windows & AD security. Have you ever seen this ๐ฅ๐๐ฃ ๐ฐ๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ ๐๐ฎ๐ฟ๐ป๐ถ๐ป๐ด? Do you know ๐๐ต๐ฎ๐ ๐ถ๐ ๐บ๐ฒ๐ฎ๐ป๐? It means the certificate presented by the target during RDP ๐ถ๐๐ปโ๐ ๐๐ฟ๐๐๐๐ฒ๐ฑ. Often itโs just a self-signed certโwhich isnโt a huge problem: you can make it trusted or distribute your […]
Is your UAC set properly?

๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ Real configs. Real fixes. Windows & AD security. ๐ค๐๐ถ๐ฐ๐ธ ๐๐ฒ๐๐: press Win + R โ type msconfig.exe โ Enter. Did the console open immediately? If yes, your ๐จ๐๐ ๐ถ๐๐ปโ๐ ๐ต๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ. ๐งจย ๐๐ ๐ฑ๐ฒ๐ณ๐ฎ๐๐น๐, UAC has exceptions for Windows binaries (Prompt for consent for non-Windows binaries)โattackers can abuse this behavior with known ๐จ๐๐ ๐ฏ๐๐ฝ๐ฎ๐๐๐ฒ๐. […]
Updating Secure Boot certificates on Windows Server

๐ Secure Bits ๐ก ๐จ๐ฝ๐ฑ๐ฎ๐๐ถ๐ป๐ด ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐๐ผ๐ผ๐ ๐ฐ๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ๐ ๐ผ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ โ ๐ณ๐ถ๐ป๐ฎ๐น ๐ป๐ผ๐๐ฒ๐ (๐บ๐ฒ๐ฟ๐ด๐ฒ๐ฑ ๐ด๐๐ถ๐ฑ๐ฒ) As promised, I merged all 3 parts of this Secure Boot series into one Field Notes document you can follow end-to-end. This process is not trivial: some servers go through smoothly, others hit issues depending on firmware / platform […]
New Microsoft procedure for Secure Boot Certificate Updates

๐ Secure Bits ๐ก ๐ก๐ฒ๐ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐ฑ๐๐ฟ๐ฒ ๐ณ๐ผ๐ฟ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐๐ผ๐ผ๐ ๐๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ ๐จ๐ฝ๐ฑ๐ฎ๐๐ฒ๐ I tested the new Microsoft procedure I shared last time (link in comments). Iโll be honest โ I was a bit ๐ผ๐๐ฒ๐ฟ๐๐ต๐ฒ๐น๐บ๐ฒ๐ฑ at first. There are multiple scripts, and I ran into a few โpaper cutsโ, so itโs still not as straightforward as […]
Secure Boot certificates are expiring pt. 3

๐ย Secure Bitsย ๐ก ๐จ๐ฝ๐ฑ๐ฎ๐๐ถ๐ป๐ด ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐๐ผ๐ผ๐ ๐ฐ๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ๐ ๐ผ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ฐ๐ผ๐ป๐๐ถ๐ป๐๐ฒ๐ (๐ฑ๐ต. 3) Last puzzle in this series isย ๐บ๐ผ๐ป๐ถ๐๐ผ๐ฟ๐ถ๐ป๐ด. Because as you can see, this process is ๐ป๐ผ๐ ๐๐ฟ๐ถ๐๐ถ๐ฎ๐น ๐ผ๐ฟ ๐๐๐ฟ๐ฎ๐ถ๐ด๐ต๐๐ณ๐ผ๐ฟ๐๐ฎ๐ฟ๐ฑ. Some devices will go through smoothly, others will hit different errors depending on firmware / platform / history โ and thatโs the worst case. Thatโs […]
Secure Boot certificates are expiring pt. 2

๐ Secure Bits ๐ก ๐จ๐ฝ๐ฑ๐ฎ๐๐ถ๐ป๐ด ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐๐ผ๐ผ๐ ๐ฐ๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ๐ ๐ผ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ฐ๐ผ๐ป๐๐ถ๐ป๐๐ฒ๐ (๐ฑ๐ต. 2) I believe I had to go through the worst-case scenario after all: โ GPO trigger โ KEK failure โ Broadcom idea (upgrade compatibility + delete/rename NVRAM) โ VM fails to boot โ Fixed the VM โ tried again โ KEK failure […]