Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…
138
899
3,173
481,340
Back on AD security research for a change 😎.
19
5
182
8,521
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/askWAM
7
75
233
18,493
The release contains a .NET Framework, a native and a BOF version that request this token without external dependencies.
1
1,401
Dirk-jan retweeted
🔥 What are you bringing to #Entrypoint? New technique? Tool release? Real-world compromise? Deep technical offensive security talk? 🎤 CFP closes 20 September. 📅 19-20 March 2027 | 📍 Paris ➡️ cfp.entrypoint.fr/entrypoint…
1
11
14
2,084
Awesome work by @c3c: cracking netntlmv1 challenge/response in the browser in minutes without having to download and store TBs of tables!
NetNTLMv1 is dead. Long live NetNTLMv1. 🌈 Today we're releasing NTLMRain: recovering NT hashes from NetNTLMv1 responses. 🌐 Browser-based cracking ⌨️ Cross-platform CLI with GPU/CPU support 💾 Searchable tables that fit on a 4 TB disk Read the blog: outflank.nl/blog/2026/09/08/…
2
22
145
14,462
Dirk-jan retweeted
There seems to be some confusion about token theft via Attacker in the middle, so I made this diagram
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations bleepingcomputer.com/news/se… bleepingcomputer.com/news/se…
13
17
159
22,458
RedTreat day 2 😎
5
3
56
4,368
Spent way too much time figuring out why RDP with a FIDO2 key didn't work. Turns out unlike the WHFB path, using web sign-in for RDP uses a TPM bound (temp, I think) key for TLS. TPM 2.0 up to certain spec versions don't properly implement the required algos for TLS 1.3 signing, breaking it all... And of course the RDP client gives you only a vague error message that maybe your password is expired 🙄
3
7
155
11,142
Unfortunately, the only "fix" for this is to either get a newer TPM, or to disable TLS 1.3 and the schannel algorithms that break RDP on Windows. Neither is great.
1
9
1,635
📢 The next edition of my offensive Entra ID security class just opened up for registration! November 16-19 in The Hague, Netherlands. In this 4 day class we deep dive into Entra ID security, tokens, oauth2 and Conditional Access. More info and reg: events.outsidersecurity.nl/e…
2
17
109
7,676
Dirk-jan retweeted
We know attackers are registering devices. They know we know🙃 So they’re getting smarter, and we need to stay one step ahead. @shahardorf & I wrote a new post on how to outsmart them, and it's pretty good! wiz.io/blog/detecting-entra-…
3
44
143
14,437
Want to run an entire Tailscale daemon from memory inside a C2 implant with zero disk artifacts, no kernel drivers, traffic indistinguishable from HTTPS to a CDN, and relay connections from the victim network back through the tailnet. Now you can. Enjoy! netspi.com/blog/technical-bl…
15
197
753
67,609
Weaponising MDM - running a fake MDM server and pwning people as SYSTEM with two clicks (if they have permission to elevate). Poc included. blog.amberwolf.com/blog/2026…
1
23
58
4,236
Dirk-jan retweeted
That’s what surviving a course with Dirk-Jan looks like! An absolutely fantastic instructor teaching some obscure Microsoft Entra ID black magic. Had an absolute blast! 🔥 (And also half an heart attack to survive the jetlag)
3
1
57
4,732
Dirk-jan retweeted
The latest roadtx update makes it quite easy to turn device code phishing into passkey registration. The best time to block device code auth in your tenant was yesterday.
✈️ blog to kick off BH/DC week: Borrowing Windows Hello keys for authentication and persistence. dirkjanm.io/borrowing-window…
2
6
33
4,763
If you're at Black Hat, check out this booth. Probably the only one where they deliver what they say too 😅.
First time having a booth at @BlackHatEvents and the experience so far is eyeopening. Anyhow, if you are interested in internal network pentest tooling check us out at booth 6312, ppl who understand hacking really loved the demo :)
2
28
5,943