-
Passkeys for dummies – Part 1
This post comes after 3 weeks of me feeling like a trashcan. But now is time for redemption, I have decided to sit down (not on the couch, not watching house on the third time), read all the new blog posts about passkeys, and actually understand them. The goal of this blog is to serve…
-
Does anyone even use GitHub for federated authentication?
I had some questions about azure application federated authentication with GitHub actions ..
-
I didn’t REALLY understand FOCI & BroCI… until now (Kinda)
I thought I understood FOCI and BroCI, until I tried explaining them. This post is the result of rebuilding my understanding from the protocol itself, with a few unexpected side quests along the way.
-
I’m going to try harder (Troopers 26 Summary)
No research here, just me being emotional about troopers, life and research
-
Troopers 2025 thoughts – Part 1
I missed Troopers25 this year, so the moment the recordings appeared on YouTube I basically stopped everything and hit play. Three talks immediately grabbed me. solving problems I had, teaching me new tricks, and reminding me why Entra research is so fun. Here’s my breakdown of them.
-
I just wanted to see what SSSO looks like
A hands-on look at Azure Seamless SSO – what it is, how it works under the hood, and why the AZUREADSSOACC account deserves your attention. No new attack, just curiosity and packet captures.
-
What No One Tells You About Non-Interactive Logs
Non-interactive logs aren’t just for token refreshes. You can found a brute-force attack hiding in one.
-
The new Dmsa Vuln for people who don’t know what Dmsa is
I just wanted to play with the new dmsa vulnerability too
-
Exploring dsreg Part 1
In this post, I dive into how the UpdateDevice function of dsregcmd works behind the scenes. From playing with registry values, tracing API calls in WinDbg, and intercepting requests with Burp, I explore how device attributes in Entra are managed—and what we can (and can’t) change. Along the way, I share some fun findings, a…