spencer's Avatar

spencer

@bsky.ethicalthreat.com

πŸ› οΈ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack Pentesting -> SecurIT360 Podcast -> CyberThreatPOV Active Directory Security Resources for IT Admins πŸ‘‡ https://go.spenceralessi.com/adsecurity

3,674
Followers
111
Following
1,153
Posts
09.11.2024
Joined
Posts Following

Latest posts by spencer @bsky.ethicalthreat.com

The best way to learn how secure something is the first use it then have to administer it οΏΌ

06.03.2026 19:12 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Part of what makes you a good pentester is you know what rocks to turn over

06.03.2026 17:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Would you rather…

Have to secure Wordpress or OpenClaw?

(for the rest of your life if you had one singular job and this was it)

06.03.2026 15:26 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

So who has interesting cybersecurity or IT-related use cases for openclaw they are playing around with? I wanna see some fun stuff…

06.03.2026 14:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Sure but I’d argue in this example, not accidentally configuring a template for ESC1 should be within their purview

06.03.2026 13:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Learn Active Directory and you’ll never work another day in your life….

You’ll work every day πŸ€ͺπŸ˜‚

05.03.2026 19:09 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If you’re an IT admin and you want upward career progression and you have any length of time left in your career, beginning to poke at these AI platforms and becoming comfortable with them is crucial.

Not to be an expert but so you know what’s coming.

05.03.2026 17:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I personally think IT admin cybersecurity skills should go beyond the basics. If you manage ADCS you should be familiar with certificate abuse for example

05.03.2026 16:59 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Badum chhhh hah

05.03.2026 16:58 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Pentesting findings don’t get fixed for a number of reasons. Some of which are out of the IT teams control.

But also, many IT teams are burnt out putting out fires and working on other β€œmore important” projects handed down to them by management that they don’t have time to fix security issues.

05.03.2026 15:53 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The infosec/cybersecurity space is funny because on social media, AI is taking over the world.

Then I go to conferences and meet people who are primarily defenders and they haven’t heard of OpenClaw, which is probably the biggest phenomenon since OpenAI launched ChatGPT.

Social media is a bubble.

05.03.2026 14:37 πŸ‘ 1 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

The unhealthy desire to β€œgo viral” hurts social media more than AI ever will.

04.03.2026 19:14 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

I’m at zero trust world today and tomorrow. If you see me say what’s up!

04.03.2026 17:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

How long until Active Directory is β€œdead?”

I don’t think it will ever be, look at this slide that Cliff Fisher shared on the hybrid identity podcast.

04.03.2026 17:22 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I’m currently a pentester, but I’m also a former sysadmin. Something that’s not lost on me is that it doesn’t matter how good you think your security is, if your backups and recovery processes haven’t been tested, you’re rolling the dice.

04.03.2026 15:55 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Famous last words by IT admins: I’m just testing…

04.03.2026 14:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

True or false, cybersecurity skills are necessary for IT admins?

03.03.2026 19:34 πŸ‘ 2 πŸ” 0 πŸ’¬ 3 πŸ“Œ 0
Post image

If you’re an IT admin or CIO/CISO, you probably want to know what cybersecurity threats you’re up against. This is that episode…

Ps - don’t focus on the numbers, focus on the trends and the techniques

Listen/watch here πŸ‘‡

🎧 offsec.blog/episode-170-...

03.03.2026 17:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Sure Pentest one a year, but also, don’t wait until your next pentest to:

Run Locksmith
Run ADeleginator
Run PingCastle/PurpleKnight
Check shares, sharepoint, wikis for creds

03.03.2026 15:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Are phishing/social engineering exercises actually useful? Or do they do more harm than good?

03.03.2026 13:52 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

As much as things change in cybersecurity, there’s an overwhelming portion that stays the same.

02.03.2026 19:14 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Your browser is up to date
Your browser is up to date You can use YouTube's latest features!

3 common Windows misconfigs I see during internal pentest.

1) weak local admin control

2) Insecurely installed/configured software

3) Weak endpoint security

I explain how these can be dangerous in my latest video πŸ‘‡

youtu.be/gcKejfmPea4

02.03.2026 17:46 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

It’s a great time to be a web pentester

02.03.2026 15:34 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

If you're on an internal pentest and you bust out tcpdump or wireshark, is it going well or going badly? πŸ˜†

02.03.2026 14:13 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Making frontier cybersecurity capabilities available to defenders Claude Code Security is one step towards our goal of more secure codebases and a higher security baseline across the industry.

This is great but how do we get orgs to not revert to RC4 on their service accounts….

Or login with domain admin everywhere

Or use the same password for all their admin accounts

27.02.2026 19:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Relatable IT admin scenario: you leave a job and shortly after the job you just left gets hacked/ransomwared.

Brutal honestly. Gut wrenching πŸ€•

27.02.2026 17:43 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

The barrier to entry for threat actors continues to get lower, but for defenders, it almost seems like its getting higher...

πŸ“°Source: awesomeagents.ai/news/ai-powe...

27.02.2026 15:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Supply chain attack that drops openclaw instead of malware or a more typical payload.

Buckle up folks! 🦞πŸ”₯

clawdint.com/cases/203

27.02.2026 14:09 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

I’ve had ideas to AI-ify Active Directory but I’m a man of principles. I’ll vibe code AD security tools instead! πŸ˜…

26.02.2026 19:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Even the vendor doesn’t know why it’s broke or how to fix it … so stupidly common -.-

26.02.2026 17:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0