home.social

#cyber-security-tools — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyber-security-tools, aggregated by home.social.

fetched live
  1. ----------------

    🛠️ Tool
    ===================

    EntraFalcon is a PowerShell-based assessment tool designed for pentesters, security analysts, and system administrators to evaluate the security posture of Microsoft Entra ID environments.

    Key Features
    • Compatible with PowerShell 5.1 and 7 on both Windows and Linux.
    • Does not require additional PowerShell modules or installations.
    • Bypasses Microsoft Graph API consent prompts by using first-party Microsoft applications with pre-consented scopes.
    • Generates navigable HTML reports that support filtering, sorting, and data export.

    Technical Implementation
    • Performs over 90 automated checks summarized in a Security Findings Report.
    • Evaluates weak tenant configurations, risky object properties, and excessive permissions.
    • Calculates basic impact, likelihood, and risk scoring to highlight weakly protected high-privilege objects.
    • Enumerates a wide array of Entra ID objects including Agent Users, PIM assignments (Entra Roles, Groups, Azure Roles), Entra Role Assignments, Intune RBAC, Access Packages, and Conditional Access Policies.

    Use Cases
    • Auditing external or internal enterprise applications with excessive permissions.
    • Identifying privileged accounts synced from on-premises.
    • Detecting inactive users or users lacking MFA capability.
    • Finding unprotected groups used in sensitive assignments like Conditional Access exclusions.

    Setup and Requirements
    • Requires the Global Reader role in Entra ID.
    • Optionally requires the Reader Azure role on every Management Group or Subscription to assess Azure IAM assignments.
    • Clone the repository and run the script with the -AuthFlow BroCi parameter for the default interactive authentication flow.

    🔹 EntraID #PowerShell #MicrosoftGraph #CybersecurityTools #tool

    🔗 Source: github.com/CompassSecurity/Ent

  2. Admin Console 17.10.2 builds upon features introduced in 17.9.0 and 17.10.0.

    - Admins can configure approval workflows for AI-related request types introduced with the Agentic AI Governance feature for Keeper Endpoint Privilege Manager.
    - Admins can directly view Non-Human Identity UIDs, including specific app UIDs for Keeper Secrets Manager devices.
    - New event types for Advanced Reporting and Alerts Module include Revealed Password, Moved Folder, Updated Folder and Moved Record.

    #KeeperSecurity #IdentitySecurity #CybersecurityTools

  3. Keeper Commander 18.0.10 introduces new features, including:

    - Vault-style passphrase generation
    - New [pam action service map] command to map users to discovered Windows services.
    - KeeperAI setting [pam connection ai] now supports [--enabled]/[-e] and [--session-terminate]/[-st] flags to configure resource-level AI settings

    #KeeperSecurity #CybersecurityTools #DeveloperTools

  4. Cybersecurity Tool of the Day: Wireshark 🦈

    Your Friendly Network Detective! 🕵️

    🔍 Ever wondered what’s really going on in your network?
    💻 Wireshark is the world's most popular network protocol analyzer!

    ✨ With Wireshark, you can:

    🔹Visualize real-time data traffic
    🔹Inspect protocols at every level
    🔹Spot anomalies and troubleshoot issues
    🔹Monitor your system for suspicious activities
    🔹Learn how devices communicate on the web

    It’s like X-ray vision for your internet connection!
    Perfect for students, IT pros, or just curious minds!

    Note: Wireshark is a legal and powerful analysis tool — it’s used for diagnostics and learning, not for any unauthorized spying!

    ⚠️ Use only on networks you own or have permission to analyze!

    Ready to explore your digital world? Let Wireshark guide you!

    Download it at: wireshark.org

    #Wireshark #CybersecurityTools #NetworkAnalyzer #TechTips #InfosecDaily #LearnCybersecurity #DigitalSafety #EthicalTech #CyberAwareness