http://e26whn2524322mkxb3cbyk27ev2ihhq2biz35hty7gzgsyrwrygq27yd.onion/posts/blog/security/misuing-microsoft-defender-for-cloud-apps-to-bypass-outlink-protections.html
If we pull the certificates, though, we can see that they're not generated dynamically and are in fact wildcard certificates issued against various TLD variations: $ echo | openssl s_client -connect bentasker.co.uk.example.com:443 -servername bentasker.co.uk.example.com 2>&1 | openssl x509 -noout -text
Validity
Not Before: Jun 17 17:55:29 2022 GMT
Not After : Jun 12 17:55:29 2023 GMT
Subject: C = US, ST = WA, L = Redmond, O = Microsoft Corporation, CN =...