Why Nostr? What is Njump?
2023-10-26 23:09:41

IAintShootinMis on Nostr: Gonna write this up better later. But thanks to npub1tnm9d…fm9wq , we found a fluke ...

Gonna write this up better later. But thanks to , we found a fluke in Microsoft's SignonLogs table. Sometime in the last few days they made UserPrincipalName case sensitive.

So our alerts looking for breakglassadmin@CompanyName.onmicrosoft.com started failing because we were using (==) instead of (has).

Would highly recommend you check your alerting and see which operands you're using in your queries.

#InfoSec #threatintel #Logging
Author Public Key
npub12tapuwr7rylsqq9sjq734awjffnrf32jrtluadq6q2g9x8k5lkqq6hveam