- Ethical Threat
- Active Directory Security Connoisseur
- offensive stuff > securit360.com
- Host Cyber Threat POV > offsec.blog
- SWAG > swag.ethicalthreat.com
- free newsletter > https://click.spenceralessi.com/mylinks
cybersecurity, infosec, pentesting, assume breach, Active Directory, PowerShell, occasional memes, occasional t-shirt and sticker drops
Ethos: spirit of a hacker heart of a defender
I post to provide value, I hope I deliver on that for you!
- credentials on file shares/sharepoint/dms
- local admin password reuse
- kerberoastable domain admins
- ADCS Misconfigs
- spooler running on DCs
- lack of powershell restrictions
- EDR missing on hosts
- credentials on file shares/sharepoint/dms
- local admin password reuse
- kerberoastable domain admins
- ADCS Misconfigs
- spooler running on DCs
- lack of powershell restrictions
- EDR missing on hosts
It can’t be disguised as private messages in Slack
It can’t plant documents in Teams
It can’t be installed on ICS
Deception can go where traditional endpoint security cannot...
It can’t be disguised as private messages in Slack
It can’t plant documents in Teams
It can’t be installed on ICS
Deception can go where traditional endpoint security cannot...
This is a format petition to Microsoft to open source it. Pretty please with a cherry on top
This is a format petition to Microsoft to open source it. Pretty please with a cherry on top
Security awareness training helps users better perceive the risks of such techniques
Security awareness training helps users better perceive the risks of such techniques
That’s not always the case for other security tools
That’s not always the case for other security tools
i'm a big fan of deception for a couple reasons:
1) because of the quality of the alerts
i'm a big fan of deception for a couple reasons:
1) because of the quality of the alerts
Security hardening is often seen as adding layers of controls, however, it’s more similar to taking away or locking down things that could be misused by attackers… while still making sure everything works the way it’s supposed to.
Security hardening is often seen as adding layers of controls, however, it’s more similar to taking away or locking down things that could be misused by attackers… while still making sure everything works the way it’s supposed to.
us06web.zoom.us/webinar/regi...
us06web.zoom.us/webinar/regi...
I'll do my best to provide my thoughts on the ROI of deception and what it means in terms of defensive security spending.
us06web.zoom.us/webinar/regi...
I'll do my best to provide my thoughts on the ROI of deception and what it means in terms of defensive security spending.
us06web.zoom.us/webinar/regi...
For real though someone build this and open source it. 10/10 would use it
For real though someone build this and open source it. 10/10 would use it