Elektrine lite

← Feed

Lee Holmes :donor:

Lee_Holmes@infosec.exchange

<p>Partner Security Architect, Azure Security. Co-author of Threat Driven Software Development (<a href="https://www.amazon.com/Threat-Driven-Software-Development-Defending-services/dp/0135567386" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">amazon.com/Threat-Driven-Softw</span><span class="invisible">are-Development-Defending-services/dp/0135567386</span></a>) and author of the PowerShell Cookbook (<a href="https://www.amazon.com/PowerShell-Cookbook-Scripting-Ubiquitous-Object-Based/dp/109810160X" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">amazon.com/PowerShell-Cookbook</span><span class="invisible">-Scripting-Ubiquitous-Object-Based/dp

Posts

  • Post #4387547

    @sj@social.scriptjunkie.us Gross. They also invented renting your car&#39;s features to you. And this is just the visible money grubbing... If they&#39;re doing this, they&#39;re probably selling every bit of customer data and car telemetry they have to the lowest bidder too.

  • Post #4381358

    Ok, finally captured some thoughts about our new book, Threat Driven Software Development here: https://www.leeholmes.com/threat-driven-software-development/. If you are a Blue Teamer working on developing or securing online services - this is your jam and I hope you enjoy it.

  • Post #4358988

    Ok, here&#39;s the answer to the question that&#39;s always on your mind: what treats should you buy when you visit Canada? https://www.leeholmes.com/what-treats-to-buy-in-canada/

  • Post #4342174

    Got to fly with the Blue Angels today :)

  • Post #4337390

    Working on a simple online CMS for my Hugo blog - a WYSIWYG Markdown editor based on Quill, and some basic management around that. It still stores the raw backing Markdown files in OneDrive like I was using with Hugo directly. Hooboy is it nerve wracking! 20 years of content that exercises apparently every edge case in Markdown! Thankfully Commonmark has an excellent test suite that I&#39;ve been able to bootstrap a massive unit test infrastructure with.

  • Post #4168379

    You&#39;ve probably been in the situation of weighing the difference between buying something commercially or making it yourself -- and then stumbling on a YouTube of somebody where this is clearly their passion. They&#39;ve got dozens of videos of how to use these things. Make these things. Perfect these things. This is all they think about, and they also have a little store or Etsy where they sell what they make. The more I think about it, the more I realize: this is exactly the time to Suppo...

  • Post #4102590

    Saw Disclosure Day yesterday - it&amp;#39;s now solidly in the list of top films of all time to use PowerShell 🥳🥳🎉🎉🎉!

  • Post #4102589

    I&amp;#39;ve never liked Schneier&amp;#39;s phrasing of this: &amp;quot;Anyone, from the most clueless amateur to the best cryptographer, can create an algorithm that he himself can’t break.&amp;quot;. You can&amp;#39;t repeat it to somebody that you think it applies to when you want to use it for advice. It&amp;#39;s really only good for dunking. But the advice itself is super solid. Here&amp;#39;s a rephrasing that I was actually able to use with somebody and not feel guilty: “Anyone, from be...

  • Post #4102588

    @campuscodi The article is saying that it wasn&amp;#39;t digital dynamite, it was something else unspecified (dormant cyber pathogens rearing their ugly head again?) to be used at a later time 🤣

  • Post #4102587

    Was on the Microsoft Threat Intel Podcast recently with Sherrod, Michael, and Shawn about our new Threat Driven Software Development book. It was really great to have the chance to talk about the whole book end-to-end - https://thecyberwire.com/podcasts/microsoft-threat-intelligence/73/notes

  • Post #4070342

    I know it was fashionable for a while for infosec to mock people that use VPNs (ala &quot;Hello, it&#39;s 2026. Everything worth securing is transmitted over TLS anyways&quot;) but I still think it&#39;s an immature absolutist take. TLS doesn&#39;t save you when Russia hacks the routers in your hotel to send you to phishing sites rather than actual login pages: https://www.bleepingcomputer.com/news/security/authorities-disrupt-dns-hijacks-used-to-steal-microsoft-365-logins/

  • Post #4041860

    Application Security is an investment. Operational Security is a commitment. This quote comes from Threat Driven Software Development: I think it perfectly captures the difference between application security and operational security when it comes to services.

  • Post #3970170

    RE: https://infosec.exchange/@Lee_Holmes/116925875891679749 Woohoo! Now available at your favorite retailers! https://www.amazon.com/Threat-Driven-Software-Development-Defending-services/dp/0135567386

  • Post #3841304

    It&#39;s here! Super proud of this - it is such a perfect package of how to navigate operational security in the services world.

  • Post #3700715

    There&#39;s a famous joke: &quot;I took one of those rapid-reading courses, and was able to read “War and Peace” in 20 minutes! It’s about Russia. Beyond that, I’m vague.” I thought it&#39;d be funny to write a map-reduce algorithm to have LLM summarize the book into 10 words. OpenAI refused to play along 🤣

  • Post #1876109

    Shout out to my homies that still remember the track numbers on the CDs for their favorite songs.

  • Post #1876108

    Here&amp;#39;s one thing AdTech could do to instantly change the content dynamics of the internet: &amp;quot;Unvisit.&amp;quot; Landed on an AI slop page laden with ads and referral links? Click &amp;quot;Unvisit&amp;quot; and they&amp;#39;ll never see a penny from your impression. Got ambushed by a page full of taboola ads and auto-play videos? Unvisit. Can&amp;#39;t use the back button? Unvisit. Unvisit, Unvisit, Unvisit, and punish them where it hurts.

  • Post #1876107

    Love this compilation of &amp;quot;The Defender&amp;#39;s Mindset&amp;quot; from John Lambert. John does a lot of hiking and clearly occupies that time figuring out how to phrase things perfectly: https://medium.com/@johnlatwc/defenders-mindset-319854d10aaa

  • Post #1876106

    LOL, you think reading it takes a lot of effort - try writing it 🤣

  • Post #1876105

    Startup: Look at how agile we are! How quickly we can pivot!

  • Post #1621591

    Just had an internal web application break, and when I dug in through DevTools there was some dependent fetch running into a server error. The server error message provided the internal DRI contact to reach out to for how to engage and report. This is so. smart. If you&amp;#39;ve figured out the DRI contact by going through DevTools, you clearly don&amp;#39;t need any central helpdesk support on basic troubleshooting like checking your adblocker. Makes me think of @shanselman &amp;#39;s &amp;q...

  • Post #1621590

    Where the hell did irm-iex-ing come from? As in &amp;quot;irm &amp;lt;url&amp;gt; | iex&amp;quot; Invoke-RestMethod in PowerShell has ALWAYS been a way to get objects out a website that exposes content as JSON, XML, etc. Invoke-WebRequest is the one that gives you raw text back. The fact that tools using irm-iex work at all is just a magic accident that converting an object (that&amp;#39;s a string) into a string doesn&amp;#39;t introduce any artifacts.

  • Post #1621589

    Ok, this is the weirdest thing to notice, but I can&amp;#39;t un-notice it. When people use text-to-speech to narrate things, they tend to just pick the first voice that sounds great. Her name is Ava, and I now hear her everywhere :) Most recent example this weekend - the new Link Light Rail station in Seattle.

  • Post #1621588

    Holy smokes! Upgraded to a GAN speed cube with magnetic registration, and it knocked 30 seconds off of my solve time (~ 2 minutes to 1:30) compared to the classic Rubik&amp;#39;s Cube model. It&amp;#39;s also more fun to use!

  • Post #1621587

    RE: https://infosec.exchange/@malwaretech/116449469685838416 One of the things I love about this investigation is that it actually imposed cost: - Found malware: reported to AV vendors - Saw abuse of Cursor: reported to Cursor, got the accounts suspended - Saw abuse of ChatGPT: reported to OpenAI - Saw that a front website was implemented / hosted on Anima: reported to Anima, got the account suspended We don&amp;#39;t have to just report on the bad guys. We can actually fight them.

  • Post #1260250

    PowerShell Desired State Configuration supports a feature I&amp;#39;m very proud of: you can tell nodes to only allow configuration documents signed by a specified publisher. So if the host these things are pulling their configuration documents from gets popped, you have no risk of company-wide remote code execution unless they also got your signing key. This saves you from attacks like this that leverage trusted internal supply chains like Group Policy: https://blog.quest.com/how-attackers-abu...

  • Post #1260249

    This is amazing. An hour ago, had an idea of an app to convert howto videos into descriptive text. Now it&amp;#39;s done.

  • Post #896732

    Interested in attending BlueHat 2026? Registration is closing TODAY and is extremely limited, so please fill out the application to attend here if interested! https://microsoft.eventsair.com/bluehat2026/reg/Site/Register

  • Post #789048

    THE BLOOMSCROLLING WILL CONTINUE UNTIL MORALE IMPROVES