by The Collective | Jul 11, 2022 | Blog
When auditing Microsoft 365 Defender environments, I notice the service-level configuration for Microsoft Defender for Endpoint (MDE) is often overlooked. Each tenant has a specific set of parameters that can be configured to update the behavior and feature set of...
by The Collective | Apr 19, 2022 | Blog
Just last week, a new vulnerability was identified in the 7-zip application with ID ‘CVE-2022-29072’. This vulnerability allows for local privilege escalation due to a misconfiguration of the 7z.dll file. By exploiting this vulnerability, a user can receive local...
by The Collective | Jan 13, 2022 | Blog
In every Microsoft 365/Azure environment there are multiple Service Principals. Service Principals can be used for your own custom-built apps, to deploy Azure resources through Azure DevOps, or to integrate with third applications. Authentication with a Service...
by The Collective | Dec 22, 2021 | Blog
At The Collective, we are constantly looking to innovate and push the boundaries of the existing (Microsoft) capabilities. For the 2021 Microsoft Sentinel Hackathon, we developed an assistant for Microsoft Sentinel which will ease the day-to-day management of the SIEM...
by The Collective | Jul 22, 2021 | Blog
It’s been only three weeks since the PrintNightmare debacle, which introduced several zero-days into the world of Microsoft affecting all Windows Operating Systems. Since my blog post on this mitigation, several other zero-days related to print spoolers have also...
by The Collective | Jul 6, 2021 | Blog
Unless you have been living underneath a rock these last few days, you probably have heard of the ‘Printer Nightmare’ vulnerability. This is an unpatched exploit which affects all version of Windows. On July 6th, an out-of-band update was released by Microsoft that...