Skip to content

Instantly share code, notes, and snippets.

View azurekid's full-sized avatar
:octocat:
Coding

Rogier Dijkman azurekid

:octocat:
Coding
View GitHub Profile
@azurekid
azurekid / README.md
Last active August 6, 2026 20:55
Cyb3rCat - Scr4pb00k

Mr Robot fonts Typing SVG

Cookie Quick Manager: A complete manager for cookies accumulated during browsing. It allows you to view, edit, create, delete, backup, restore cookies and search them by domain names. Contextual Identities such as Private Browsing, First-Party Isolation, and SameSite flag are also supported. In addition, the LocalStorage of the page viewed can be deleted (see below).

Injection Probe CLI README

This document explains how to run injection_probe.py from the command line and how to map custom request fields used by your own backend login form.

Pre-Run Checklist

Before running the probe, confirm these 5 items:

  1. You have explicit authorization to test this target.
  2. The URL points to the real login endpoint (action target), not just the page URL.

Mr Robot fonts

Typing SVG

FastBuster Help

FastBuster is a high-speed, async, wordlist-driven web path scanner for authorized security testing.

Install

# Defender XDR Detection Rule
# Detects PowerShell download cradles used for malware delivery
metadata:
id: ehv-002-suspicious-powershell-download
platform: defender-xdr
status: experimental
author: Rogier Dijkman
created: 2026-02-09
modified: 2026-02-17

Phase 1

# Step 1: DNS record discovery
Find-DnsRecords -Domains "bluemountaintravel.uk"
# Step 2: Find DNS records for Azure resources
Find-AzurePublicResource -Name "bluemountaintravel" `
# Find-AdmxUsage.ps1
param(
[Parameter(Mandatory=$true)][string]$AdmxFileName
)
Import-Module Microsoft.Graph.DeviceManagement -ErrorAction Stop
Connect-MgGraph -Scopes "DeviceManagementConfiguration.Read.All","Directory.Read.All"
$keywords = @($AdmxFileName.ToLower(), "mozilla", "firefox", "software\\policies\\mozilla", "mozilla.firefox")

Impairing Azure Defenses Through Diagnostic Setting Manipulation

MITRE ATT&CK: T1562.008 — Impair Defenses: Disable or Modify Cloud Logs
Tactic: TA0005 — Defense Evasion
BlackCat Function: Disable-DiagnosticSetting


Introduction

Azure Functions Key Encryption: A Deep Dive into Security Mechanisms and Vulnerabilities

Author: Security Research Team
Date: January 26, 2026
Classification: Security Research


Executive Summary

<#
.SYNOPSIS
Performs comprehensive email security reconnaissance on one or more domains.
.DESCRIPTION
Invoke-EmailRecon performs parallel DNS lookups and HTTP requests to gather
email security configuration data for specified domains. It collects information
about MX records, SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT, DANE/TLSA, DNSSEC,
CAA records, Microsoft 365/Entra ID tenant details, ADFS federation, and
DNS blocklist status.
@azurekid
azurekid / entra_id_privileged_group_self_assignment.yml
Created December 30, 2025 13:48
Sigma rule for: Self Assignment Privileged Group
title: PIM-Enabled Group Self-Assignment
id: b3d4e5f6-a7b8-4c9d-8e1f-2c3d4e5f6a7c
status: stable
description: |
Detects when a user assigns themselves as an active or eligible member or owner of a group
via Entra ID Group Management. This identifies potential indirect privilege escalation
where a user adds themselves to a group that has been granted privileged administrative roles.
references:
- learn.microsoft.com
author: Security Operations Center