Nathan McNulty(@NathanMcNulty) 's Twitter Profileg
Nathan McNulty

@NathanMcNulty

Loves Jesus, loves others | Husband, father of 4, security solutions architect, love to learn and teach | @TribeOfHackers | 🐘infosec.exchange@nathanmcnulty

ID:52462500

linkhttps://blog.nathanmcnulty.com calendar_today30-06-2009 17:45:09

31,8K Tweets

13,2K Followers

946 Following

Follow People
Nathan McNulty(@NathanMcNulty) 's Twitter Profile Photo

Had an interesting question about scheduling Defender AV scans against custom locations

In case anyone needs it, here's one of a few ways to do it :)

'%ProgramFiles%\Windows Defender\MpCmdRun.exe' -Scan -ScanType 3 -File 'C:\Path\To\Directory'

learn.microsoft.com/en-us/defender…

account_circle
Nathan McNulty(@NathanMcNulty) 's Twitter Profile Photo

Sometimes on calls people ask about an API or we're curious about automating something

I usually start with Developer Tools - Network tab, and when I open it, I frequently hear 'Shoot, I forgot that existed!'

This is your reminder that it exists, and it is awesome :)

account_circle
Rudy Ooms | MVP 🇳🇱(@Mister_MDM) 's Twitter Profile Photo

If you still have issues with the Enterprise subscription activation during (uplift from pro to Enterprise), you must read the latest update on my blog.

Microsoft is indeed aware of this issue, and they already have a fix in place. That's lovely! Why?…

account_circle
Louis Mastelinck | LouSec | MVP(@LouisMastelinck) 's Twitter Profile Photo

Developed custom detections for some crucial events in MDE:
- Detection of offboarding package downloads
- Device isolation events (detects what is isolation type was applied)
- Tamper protection disablements
- File retrieval via Live Response

lousec.be/mde/microsoft-…

Developed custom detections for some crucial events in MDE: - Detection of offboarding package downloads - Device isolation events (detects what is isolation type was applied) - Tamper protection disablements - File retrieval via Live Response lousec.be/mde/microsoft-… #MDE
account_circle
Nathan McNulty(@NathanMcNulty) 's Twitter Profile Photo

In case you ever need it, Entra Password Protection forest registration information can be found in the Configuration naming context ;)

I don't believe there is a native cmdlet, but you could do something like this:
Get-ADObject 'CN=Azure AD Password…

In case you ever need it, Entra Password Protection forest registration information can be found in the Configuration naming context ;) I don't believe there is a native cmdlet, but you could do something like this: Get-ADObject 'CN=Azure AD Password…
account_circle
Nathan McNulty(@NathanMcNulty) 's Twitter Profile Photo

For Defender AV catch-up scans, the default for DisableCatchupFullScan and DisableCatchupQuickScan is Disable, which is a value of 1

To disable catch-up scans, we have to set the value to Enable, which is a value of 0

🫠

For Defender AV catch-up scans, the default for DisableCatchupFullScan and DisableCatchupQuickScan is Disable, which is a value of 1 To disable catch-up scans, we have to set the value to Enable, which is a value of 0 🫠
account_circle
Sam Erde(@SamErde) 's Twitter Profile Photo

Don't sleep on this underutilized protection in Active Directory--but also don't be a dummy and turn it on without reading the details! 🔎🔐

account_circle
Nathan McNulty(@NathanMcNulty) 's Twitter Profile Photo

I've seen this MDE issue with several clients now. Anyone else?

Servers are discovered and assigned a tag prior to onboarding

Once onboarded, the 'Can be onboarded' object is still there and not the onboarded one

The onboarded object can be found by searching senseId or this:

account_circle
Nathan McNulty(@NathanMcNulty) 's Twitter Profile Photo

Always worth it though. I'll never get a chance to have those moments again, but the tech stuff will still be there any time :)

I probably seem very sporadic, disappear mid conversation even, but with 4 kids, it's non-stop interruption. Trying my best to maximize time :p

account_circle