Koos's Tech Blog
  • Home
  • Recent Posts
  • About
  • Posts
  • Notes
  • Dark Theme
    Light Theme Dark Theme System Theme
  • Posts
  • defender
    • Service Executable Path ACL Review
  • Devices
    • Devices
  • entraid
    • break-the-glass Accounts
  • tools
    • IP Validation Tool
Hero Image
Finding Weak Service Executable Paths with Defender TVM and PowerShell

Microsoft Defender can flag services that run outside common protected locations. This post shows how to use KQL to identify the affected service paths and PowerShell to validate whether the base folders are writable by broad user groups.

  • Defender for Endpoint
  • Defender Vulnerability Management
  • Exposure Management
  • KQL
  • PowerShell
  • Service Hardening
Friday, May 8, 2026 | 12 minutes Read
Hero Image
IP Validation Tool

This tool generates structured SOC ready IP triage output including location, ISP, VPN detection, and risk scoring using Scamalytics, ProxyCheck and Abuseipdb APIs with secure secret handling via Powershell Secret Management.

  • PowerShell
  • SOC
  • Triage
  • VPN
  • Investigation
  • Create your own tools
Saturday, March 28, 2026 | 16 minutes Read
Hero Image
Break-the-glass accounts: Ownership and common mistakes that weaken posture in EntraID

A practical overview of common break-the-glass account implementation mistakes and recommendations for tenant recovery design.

  • Break the Glass
  • BG
  • Governance
  • Identity Security
Friday, March 13, 2026 | 7 minutes Read
Hero Image
ASR Validation via TVM, Registry, and PowerShell

Learn how to validate ASR posture using Defender TVM, registry-based policy evidence, and local PowerShell checks, and understand why these sources do not always match the Defender portal UI.

  • ASR
  • Microsoft Defender for Endpoint
  • TVM
  • Advanced Hunting
  • PowerShell
  • Registry
  • Configuration
  • Endpoint
Tuesday, March 10, 2026 | 6 minutes Read
Navigation
  • Recent Posts
  • About
Contact me:
  • koos@koosjanse.com
  • Koosjuh

Stay up to date with email notification


By entering your email address, you agree to receive the newsletter of this website.

Toha Theme Logo Toha
© 2026 Copyright.
Powered by Hugo Logo