<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
        <title>Cloudbrothers</title>
        <link>https://cloudbrothers.info/</link>
        <description>Work and live with IT. A blog about all things I encounter on a day to day basis.</description>
        <generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>fabian@bader.cloud (Fabian Bader)</managingEditor>
            <webMaster>fabian@bader.cloud (Fabian Bader)</webMaster><copyright>Fabian Bader</copyright><lastBuildDate>Tue, 07 Apr 2026 00:00:00 &#43;0000</lastBuildDate>
            <atom:link href="https://cloudbrothers.info/index.xml" rel="self" type="application/rss+xml" />
        <item>
    <title>Avoid Entra Conditional Access using alternative token broker</title>
    <link>https://cloudbrothers.info/avoid-entra-conditional-access-sccauth/</link>
    <pubDate>Tue, 07 Apr 2026 00:00:00 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/avoid-entra-conditional-access-sccauth/</guid>
    <description><![CDATA[<p>In Entra ID, Conditional Access acts as the gatekeeper to any token material. Regardless of whether you want a bearer token or a refresh token, Entra ID will be the entity creating and signing them. But not before Conditional Access has checked your identity, device and network for different conditions. This is the reason why this security measure is the cornerstone of Microsoft&rsquo;s zero trust architecture and any <a href="/conditional-access-bypasses/" rel="">holes</a> in this construct can have far reaching consequences.</p>]]></description>
</item><item>
    <title>Run XDRInternals as GitHub Action</title>
    <link>https://cloudbrothers.info/run-xdrinternal-github-action/</link>
    <pubDate>Mon, 09 Feb 2026 00:48:37 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/run-xdrinternal-github-action/</guid>
    <description><![CDATA[<p>When Nathan and I released <a href="https://github.com/MSCloudInternals/XDRInternals" target="_blank" rel="noopener noreffer">XDRInternals</a> one of the biggest shortcomings for me was the lack of workload identity support. Since we are using the native API of the Defender portal only delegated permissions are supported, which makes it very hard to automate things in a pipeline.</p>
<p>But the fact that it makes it very hard should not prevent you from doing it. Security considerations and common sense are the reasons you should not do it, but let&rsquo;s throw them overboard for the fun of it.</p>]]></description>
</item><item>
    <title>Conditional Access bypasses</title>
    <link>https://cloudbrothers.info/conditional-access-bypasses/</link>
    <pubDate>Sun, 30 Nov 2025 00:00:00 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/conditional-access-bypasses/</guid>
    <description><![CDATA[<p>In Microsoft Entra, Conditional Access is, after the Authentication itself, the most crucial part of defense against attackers. It’s referenced as &ldquo;<a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview#:~:text=Conditional%20Access%20is%20Microsoft%27s%20Zero%20Trust%20policy%20engine" target="_blank" rel="noopener noreffer">zero trust policy engine</a>&rdquo; and the idea behind is, that in addition to your username and password you can also enforce additional requirements when you access a specific resource.</p>
<p>This could be any combination of</p>
<ul>
<li>a second factor (2FA),</li>
<li>a specific authentication method (e.g. passkey)</li>
<li>a device that is in a &ldquo;compliant&rdquo; state</li>
<li>a trusted or compliant network</li>
</ul>
<p>and a lot more, depending on your specific use case.</p>]]></description>
</item><item>
    <title>Remove old or orphaned Sentinels from the XDR Streaming API</title>
    <link>https://cloudbrothers.info/remove-orphaned-sentinels-xdr-streaming-api/</link>
    <pubDate>Mon, 25 Aug 2025 10:32:57 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/remove-orphaned-sentinels-xdr-streaming-api/</guid>
    <description><![CDATA[<p>This blog post is a sleeper. I documented it in 2023 and never came around to publish it. The post was always too short in my opinion, too niche. But today <a href="https://x.com/jonathanbourke" target="_blank" rel="noopener noreffer">Jonathan Bourke</a> reached out on <a href="https://x.com/jonathanbourke/status/1960014284941107681" target="_blank" rel="noopener noreffer">Twitter</a> and asked why he was getting this strange error message when trying to connect a new Sentinel workspace to his XDR instance.</p>
<div class="details admonition warning open">
        <div class="details-summary admonition-title">
            <i class="icon fas fa-exclamation-triangle fa-fw"></i>Warnung<i class="details-icon fas fa-angle-right fa-fw"></i>
        </div>
        <div class="details-content">
            <div class="admonition-content">The limit of 5 diagnostic settings was reached. <br>
To create new setting ‘SentinelExportSettings-log-sentinel’, delete an existing one.</div>
        </div>
    </div>
<p><figure><a class="lightgallery" href="/remove-orphaned-sentinels-xdr-streaming-api/images/twitterpost.png" title="Been trying to sort this for a while now - have any multi-instance @Microsoft #Sentinel users encountered this, or is it just me? (Apologies in advance for tagging some people I know for extra visibility)" data-thumbnail="/remove-orphaned-sentinels-xdr-streaming-api/images/twitterpost.png" data-sub-html="<h2>Post of Twitter</h2><p>Been trying to sort this for a while now - have any multi-instance @Microsoft #Sentinel users encountered this, or is it just me? (Apologies in advance for tagging some people I know for extra visibility)</p>]]></description>
</item><item>
    <title>Detect threats using GraphAPIAuditEvents - Part 3</title>
    <link>https://cloudbrothers.info/detect-threats-graphapiauditevents-part-3/</link>
    <pubDate>Thu, 14 Aug 2025 20:32:57 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/detect-threats-graphapiauditevents-part-3/</guid>
    <description><![CDATA[<p>For a <a href="/detect-threats-microsoft-graph-logs-part-1/" rel="">long time now</a>, defenders had the ability to monitor behavior of human- and workload identities in Entra tenants not only through <code>AuditLogs</code> but with high level of insight with the <code>MicrosoftGraphActivityLogs</code> logs. The <a href="/detect-threats-microsoft-graph-logs-part-1/" rel="">last</a> <a href="/detect-threats-microsoft-graph-logs-part-2/" rel="">two</a> articles of this series gave you detection ideas and hunting queries for this logs source and were meant as a kick starter for detection engineers. But in the end the high cost of this log prevented many companies from putting it into operation. This is about to change with the release of <code>GraphAPIAuditEvents</code> logs in the XDR portal.</p>]]></description>
</item><item>
    <title>Workshop: Kusto Graph Semantics Explained</title>
    <link>https://cloudbrothers.info/workshop-kusto-graph-semantics-explained/</link>
    <pubDate>Fri, 06 Dec 2024 01:08:51 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/workshop-kusto-graph-semantics-explained/</guid>
    <description><![CDATA[<p>Ho, ho, ho&hellip; In Germany on the 6th of December we celebrate &ldquo;Nikolaus&rdquo;. Kids put out one shoe the night before in the hopes that, in the morning, it is filled with nuts, mandarin oranges, chocolate or even small gifts. Lucky for you, it seems that you also put out your shoe last night, because I have a gift for you as well. But please don&rsquo;t confuse me with Nikolaus ;)</p>]]></description>
</item><item>
    <title>EDR Silencers and Beyond: Exploring Methods to Block EDR Communication - Part 1</title>
    <link>https://cloudbrothers.info/edr-silencers-exploring-methods-block-edr-communication-part-1/</link>
    <pubDate>Sun, 01 Dec 2024 01:08:51 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/edr-silencers-exploring-methods-block-edr-communication-part-1/</guid>
    <description><![CDATA[<p>For red teams and adversary alike it’s important to stay hidden. As many companies nowadays have EDR agents deployed those agents are always in focus and tools like EDRSilencer or EDRSandblast use different techniques to prevent further communications of the EDR agent with the log ingestion endpoint.</p>
<p>A few weeks ago Mehmet Ergene and I were discussing other ways to prevent agent communications and ways to detect such tampering. The idea for a a two part blog post was born. While I cover only one &ldquo;novel&rdquo; way to block EDR Mehmet has <a href="https://academy.bluraven.io/blog/edr-silencer-and-beyond-exploring-methods-to-block-edr-communication-part-2" target="_blank" rel="noopener noreffer">released part 2</a> which covers other angels.</p>]]></description>
</item><item>
    <title>You always trust your CSP - Cross Tenant MFA and GDAP</title>
    <link>https://cloudbrothers.info/trust-csp-cross-tenant-mfa-gdap/</link>
    <pubDate>Fri, 23 Aug 2024 11:52:55 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/trust-csp-cross-tenant-mfa-gdap/</guid>
    <description><![CDATA[<p>Entra ID Multifactor Authentication is on everyone&rsquo;s mind, as Microsoft will enforce the usage of MFA for most of the Admin portals starting October 2024. But many in the industry are a step ahead and had MFA enforced already and are thinking about how to make MFA more convenient for everybody involved.</p>
<p>Let me introduce you to cross-tenant access settings for B2B collaboration and especially <a href="https://learn.microsoft.com/en-us/entra/external-id/cross-tenant-access-settings-b2b-collaboration#to-change-inbound-trust-settings-for-mfa-and-device-claims" target="_blank" rel="noopener noreffer">inbound trust settings for MFA</a>. With this you can configure if you trust another tenants MFA configuration and don&rsquo;t require the users from this tenant to setup a second set of MFA in your tenant.</p>]]></description>
</item><item>
    <title>Find lateral movement paths using KQL Graph semantics</title>
    <link>https://cloudbrothers.info/find-lateral-movement-paths-kql-graph-semantics/</link>
    <pubDate>Mon, 08 Jul 2024 01:08:51 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/find-lateral-movement-paths-kql-graph-semantics/</guid>
    <description><![CDATA[<p>Graph databases offer great insights into existing data, that relational databases cannot or can only solve with more resources. Tools that leverage this ability to find lateral movement paths (edges) between user, computers and other entities (nodes) like Bloodhound offer an amazing data source for red teams and blue teams alike. But still the use in the defender world is yet limited. This might be because blue teams don&rsquo;t like to use red teamers toolkit (really?) or companies often don&rsquo;t see the immediate value of such additional data sources. But what we as defenders like to use is SIEM systems, EDR agents and other sensors that give us great, near real time insights into the companies IT landscape.</p>]]></description>
</item><item>
    <title>Data Protection Made a Breeze: MDA integration in Edge for Business</title>
    <link>https://cloudbrothers.info/data-protection-breeze-mda-integration-edge-business/</link>
    <pubDate>Wed, 19 Jun 2024 16:10:12 &#43;0000</pubDate>
    <author>Autor</author>
    <guid>https://cloudbrothers.info/data-protection-breeze-mda-integration-edge-business/</guid>
    <description><![CDATA[<div class="featured-image">
                <img src="/images/banner.png" referrerpolicy="no-referrer">
            </div><p>Microsoft Defender for Cloud Apps is one of the many puzzle pieces of the Microsoft XDR solution that helps you to secure your corporate environment. While Defender for Endpoint and Defender for Office 365 may be the more prominent names in this puzzle, Defender for Cloud Apps has a few aces up it’s sleeve that help you to protect access to corporate data on a complete other level.</p>
<p>Many of you might already know the cloud discovery capabilities, which help you to get a deep insight into your companies usage of Software as a Service solutions.</p>]]></description>
</item></channel>
</rss>
