🛠️ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack | @SecurIT360 & @CyberThreatPOV

🏰AD Security Resource Kit ⬇️
Pinned Tweet
I've seen a lot of Active Directory environments in the last 5+ years. These are some of the most dangerous issues I recommend reviewing and addressing in your environment. Treat it like a check list. If you have 0 of these, you're doing a great job.
Article

Attack paths in Active Directory you can fix in a day-week-month-year

Here's a list of (realistic), high-impact Active Directory hardening measures that you can do, in reasonable time-frames. Active Directory hardening that actually matters One day You're trying to

7
135
655
171,269
🧵If cyber deception is not part of your defensive security strategy, you’re missing out. If you work in IT or security and don’t know where to start, do this…
2
3
16
1,136
PS - While Simo (creator of defused) is a friend, neither thinkst nor defused are paying me to say any of this. Just really bullish on deception and it's ROI.
1
1
108
PPS - if you're like wow this deception stuff sounds cool, I've talked more about it in podcasts and webinars. You can find those here: offsec.blog/?s=deception
1
112
IT Admin Monday Checklist: 1. Run Locksmith/Locksmith2 2. If any ESC1 are identified, and the templates are enabled, put a 1-hour block on your calendar to triage This privilege escalation path is ridiculously trivial to identify and exploit. Don't ignore the other results of course, but if you have any ESC1, they are fix-immediately types of deals...
1
2
13
894
spencer retweeted
We built @ThinkstCanary for this. Some of the best security teams in the world use our Canaries && Canarytokens for this. (You can get pretty far with even just our free tokens at canarytokens.org)
I been saying! If zero days are cheap. Detections get much more important. Zero days are not invisibility cloaks.
6
18
96
14,030
Microsoft issued only 1 single notice about the passkeys rollout prior to it starting in September. Someone fact check this. Is this correct @merill mc.merill.net/message/MC1426…
8
6
49
9,505
If this is true, that's 50 total days notice.... which is only 36 weekdays. That's subpar communication in my opinion, especially for such an important rollout
3
496
spencer retweeted
Google / Mandiant linked this activity to ShinyHunters! cloud.google.com/blog/topics…
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
2
11
57
6,334
THIS Bad guys need a network connection to do bad stuff
Don’t underestimate properly deployed and tuned NDR. The clients I’ve pentested that have had it configured well have caught me with it way before anything else did, including EDR. I know the downsides, it’s expensive and complex and difficult to tune. But I think that’s a fair trade.
1
2
615
Monitoring privileged groups (tier 0) for changes is super important but if you can get to a point where you’re also detecting abnormal changes, that’s better. Eg, if somehow joe the sql guy has added an account to Domain Admins even though he shouldn’t be able to, that’s a big red flag.
2
8
40
2,779
Am I weird or is a lot what was in the Anthropic September Threat Report (related to cybersecurity) not really all that surprising? That being said, one of the more interesting parts for me was how TA are beginning to use AI to streamline obfuscation and evasion. This is an area I think there will continue to be progress and developments made, for offsec people and for TA. offsec.blog/one-hacker-42-ta…
3
7
900
Inventory your service accounts, force unique passwords or certs, and disable or delete any that IT can't attribute.
In security, there’s a lot of things that are out of our control. But weak passwords, on service accounts, provisioned by IT…. Come on. This is also not an uncommon finding during internal pentests. IT teams who let this happen either don’t know they should do this or they don’t care. I tend to think it’s the former but man…
1
1
2
738
There's a super disappointing trend happening as a result of AI. It's the lack of judgement and taste. If your AI agent does everything for you, analyzes everything for you, interprets everything for you, writes everything for you.... then what is it you're actually doing? Reviewing the output of some(thing)one else's work? Babysitting a cron job? I think this matters greatly in some areas and virtually not at all in others. I don't necessarily care how my AI agent writes a quick powershell script to do some small task or even a full blown tool to do some thing, so long as it does the thing I need it to do, correctly. But I certainly don't want it replacing my judgement and opinions and thoughts and perspectives on things that could materially impact an organization. Like say, the specifics of a pentest finding. Or the potential impact of that finding in the context of the environment and everything else I've found and discussions I’ve had with the client. Why would I want to leave that up for interpretation by an AI agent that has incomplete data no matter how much I try and feed it. Thats the ugly trend of offshoring all thinking and judgement and calling it "ok" because we're "reviewing the output." The review is likely just going to be as agreeable as the AI that fed the answers. The way you would write up a risk or a finding is not at all how an AI agent would right it up. I think that difference really matters. I don’t say this as a condemnation for using AI but more so of the complete offshoring of all thinking and judgment and taste and perspective. It’s a trap I’ve fallen into myself. In an effort to speed things up. So I write this even as a reminder to myself and to hold myself accountable to that. In a race to speed everything up and be more efficient we’re sacrificing so much of our judgment and perspective and our expertise. In the end I think it just makes everyone all sound the same and come to all the same conclusions.
13
8
50
3,025
💯👇
AI Agent may be the new "it was an APT" cop-out. If it's an old known vulnerability in your internet accessible attack surface that an AI Agent was capable of finding, then it was a preventable initial vector. It does matter, but it needs to be contextualized. When FireEye got compromised by Russian Foreign Intelligence, it was through a completely novel supply chain attack. The world understood the difference between that and a highly porous (see neglected) outer perimeter.
1
17
1,306