How to get URL link on X (Twitter) App
You should definitely not download the maybe-abandonware After Dark 4.0 ISO from the internet and install it on your Windows 11 PC. On the other hand, if you *do*, it will really mess up the app usage metrics that your computer ships to Microsoft.
https://twitter.com/lkarlslund/status/1478342455296774144Hardening against computer ownership requires your Domain Controllers to be running at least Windows 2008, and if they're not just stop reading this and get upgrading, you have bigger problems. Anyway, the nitty gritty is described here 2/11 learn.microsoft.com/en-us/openspec…
First some basics: when you join a computer to an Active Directory, it gets a machine account in the AD. This is like a user account, but with objectClass value 'computer' (and others) and some userAccountControl flags indicating it to be a computer (0x1000). But ... 2/🧵
Many of you probably know that this group shouldn't be used, but not all know the details of WHY. Here's the description from Microsoft. Just by reading this it becomes fairly evident what the issue is ... 2/n
Here are my settings for the search - it's reverse because we're investigating "what can my selection pwn of the rest of the infrastructure"
If you're running Windows 11, it's preloaded onto the system, so you can skip this part. On Windows 10, go to the Microsoft Store and search for "app installer". Here is my laptop which hasn't been powered on for quite a while - ironically it has a winget update available :-) 2/5
The screenshot shows a foreign security principal impacting a DC. Pwning that foreign AD or just that user will cost you the domain with the outgoing trust. Whooops! 2/5