Sign in

spencer

@bsky.ethicalthreat.com
3.7K followers 112 following 1.2K posts

🛠️ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack Pentesting -> SecurIT360 Podcast -> CyberThreatPOV Active Directory Security Resources for IT Admins 👇 go.spenceralessi.com/adsecurity

PostsRepliesMedia
spencer @bsky.ethicalthreat.com · 04/03/2026
I’m at zero trust world today and tomorrow. If you see me say what’s up!
100
spencer @bsky.ethicalthreat.com · 04/03/2026
How long until Active Directory is “dead?” I don’t think it will ever be, look at this slide that Cliff Fisher shared on the hybrid identity podcast.
020
spencer @bsky.ethicalthreat.com · 03/03/2026
If you’re an IT admin or CIO/CISO, you probably want to know what cybersecurity threats you’re up against. This is that episode… Ps - don’t focus on the numbers, focus on the trends and the techniques Listen/watch here 👇 🎧 offsec.blog/episode-170-...
000
spencer @bsky.ethicalthreat.com · 02/03/2026
It’s a great time to be a web pentester
021
spencer @bsky.ethicalthreat.com · 27/02/2026
The barrier to entry for threat actors continues to get lower, but for defenders, it almost seems like its getting higher... 📰Source: awesomeagents.ai/news/ai-powe...
000
spencer @bsky.ethicalthreat.com · 27/02/2026
Supply chain attack that drops openclaw instead of malware or a more typical payload. Buckle up folks! 🦞🔥 clawdint.com/cases/203
001
spencer @bsky.ethicalthreat.com · 26/02/2026
Funny because it’s true right… 😆😂
001
spencer @bsky.ethicalthreat.com · 26/02/2026
🔔TADA! Cyber Threat Perspective podcast videos are now on Spotify! 🔗https://open.spotify.com/episode/3EJzP3qAasERZHKWBU2jQQ?si=bfc148cdb9e74432
000
spencer @bsky.ethicalthreat.com · 25/02/2026
Things that seem like a bad idea: ATMs running on Windows
210
spencer @bsky.ethicalthreat.com · 25/02/2026
How many average commits are there on a large open source project per day, week, month, year? The Linux kernel had 75k commits in 2025 according to grok. So 1.2% is 900. 900 potential bugs. Now extrapolate that out to “vibe coding” where there’s probably 10x more commits than that. 🤯
011
spencer @bsky.ethicalthreat.com · 25/02/2026
What I’ve learned maybe the most from this AI revolution thing is that, if you want to have an impact, build things that solve problems you have yourself or that scratch your own itch and then release it to the world. If it gains traction, double down on it.
000
spencer @bsky.ethicalthreat.com · 25/02/2026
The difficult part about "misconfigs" is that you have to know 1) where to look and 2) what to look for. If you manage Windows endpoints, this video is for you! youtu.be/gcKejfmPea4?...
110
spencer @bsky.ethicalthreat.com · 24/02/2026
If thoughts were actions
020
spencer @bsky.ethicalthreat.com · 24/02/2026
The more things change the more they stay the same.
000
spencer @bsky.ethicalthreat.com · 24/02/2026
👨‍💻 I'm presenting a super cool Active Directory hacking lab at Zero Trust World, next week, Wed March 4th. It's at 4:30pm but I recommend getting there early. If you're going to be there, come say what's up.🤘Adam Savage has a keynote this year, thats cool 🗺️https://ztw.com/agenda cc @threatlocker
000
spencer @bsky.ethicalthreat.com · 24/02/2026
Heads up IT admins…Kerberos (AES) changes coming in April Source: www.linkedin.com/posts/jerry-...
110
spencer @bsky.ethicalthreat.com · 10/02/2026
Who you choose to test your environment matters just as much as what they test... Read here👇 📖https://x.com/techspence/status/2021223106434506863
100
spencer @bsky.ethicalthreat.com · 07/07/2025
In cybersecurity and in life...
050
spencer @bsky.ethicalthreat.com · 01/07/2025
more alerts != better threat detection i'm a big fan of deception for a couple reasons: 1) because of the quality of the alerts
110
spencer @bsky.ethicalthreat.com · 24/06/2025
What a great idea...time to spin up an AI agent to analyze all of John Hammond's videos 😋😎 For real though someone build this and open source it. 10/10 would use it
010
spencer @bsky.ethicalthreat.com · 20/06/2025
If you think these graphic design skills are good, just wait until you see the webinar... Agenda: convince anyone not using deception currently to start... us06web.zoom.us/webinar/regi...
000
spencer @bsky.ethicalthreat.com · 18/06/2025
What a time to be alive…
041
spencer @bsky.ethicalthreat.com · 09/06/2025
Scare a sysadmin in 3 words or less
030
spencer @bsky.ethicalthreat.com · 30/05/2025
💸💸💸💸
051
spencer @bsky.ethicalthreat.com · 28/05/2025
What’s the cybersecurity equivalent of a tourniquet? Isolation/containment via EDR… Logging a user out everywhere in M365… Pulling the power cord… What else?
120
spencer @bsky.ethicalthreat.com · 27/05/2025
I was trying to get ChatGPT to create mock-ups of heatmaps or "x-rays" I can use to better articulate where specific risks/vulns/misconfigs are present. This is my first attempt...is it wrong? 😅😂
111
spencer @bsky.ethicalthreat.com · 26/05/2025
You know you're doing this security thing right....or horribly terribly wrong when you log into your VM and upon logon to a host you see this... Did I do that? 🤔😅
010
spencer @bsky.ethicalthreat.com · 22/05/2025
🤣😂😅
010
spencer @bsky.ethicalthreat.com · 20/05/2025
This question…but for cybersecurity. My response: Trust by default. Now it’s verify everything, assume breach, least privilege, segmentation, etc. What do you think?
000
spencer @bsky.ethicalthreat.com · 16/05/2025
👀😂😅
001
spencer @bsky.ethicalthreat.com · 16/05/2025
The thing is... I don't see this ever changing. People will always find the path of least resistance to get their work done. We have to design and secure in spite of that, not try to change it. Source: 2025 Verizon DBIR
230
spencer @bsky.ethicalthreat.com · 16/05/2025
This stuff takes time...💃🕺 Source: 2025 Verizon DBIR
010
spencer @bsky.ethicalthreat.com · 13/05/2025
Every Monday I send a free weekly newsletter that includes a combination of...My take on current events and actionable tips for defenders to help you secure your environments. Inboxes are noisy these days, but I would love the chance to earn a spot in yours. go.spenceralessi.com/mylinks
010
spencer @bsky.ethicalthreat.com · 06/05/2025
You've got about 2 weeks to patch edge devices when vulnerability or exploitation information is publicly disclosed, but to be honest I think that's a bit generous... Source: Mandiant M-Trends 2025
020
spencer @bsky.ethicalthreat.com · 05/05/2025
As much as the industry is moving forward and security is getting so much better, there's an equal amount of systems and processes that are still very much stuck in the past...
000
spencer @bsky.ethicalthreat.com · 02/05/2025
Been there? 🫣😭
130
spencer @bsky.ethicalthreat.com · 01/05/2025
It’s probably time we retire VPNs. There’s much better options now, like zscaler and tailscale and others. The rate at which these VPN appliances are being attacked and exploited doesn’t seem to be slowing down Source: 2025 Verizon DBIR
321
spencer @bsky.ethicalthreat.com · 22/04/2025
Prevention > Detection. Let’s make attackers hate their life. No doubt EDR is essential, but it’s not a silver bullet.
040
spencer @bsky.ethicalthreat.com · 08/04/2025
ChatGPT knows us so well 😂😅
001
spencer @bsky.ethicalthreat.com · 07/04/2025
Life as a sysadmin, am I right? Sometimes I miss the job… 😅🤘🎸
021
spencer @bsky.ethicalthreat.com · 03/04/2025
Security is a journey, we all know that...You don’t need to overhaul everything overnight, nor could you even if you wanted to. But you do need to start. Prioritize one item per month. Small wins over time really add up...
041
spencer @bsky.ethicalthreat.com · 25/03/2025
Who needs the latest and greatest C2 when you've got RMM, RDP and a dream...
000
spencer @bsky.ethicalthreat.com · 24/03/2025
You can always count on Reddit.. “Landlord added two factor authentication”
110
spencer @bsky.ethicalthreat.com · 22/03/2025
Too soon? 😅
040
spencer @bsky.ethicalthreat.com · 22/03/2025
The classic… 😈😂🤷‍♂️
040
spencer @bsky.ethicalthreat.com · 22/03/2025
Weekends are for memes..😂😅
050
spencer @bsky.ethicalthreat.com · 22/03/2025
Posted this on social media 5 years ago. Crazy how fast time passes us by…
120
spencer @bsky.ethicalthreat.com · 18/03/2025
Make no mistake about it…if it’s exploitable and on the internet you have ~24 hours to patch it or take it offline
030
spencer @bsky.ethicalthreat.com · 14/03/2025
👨‍💻 Me: ‘Hey, we should invest in cybersecurity.’ 💼 Execs: ‘Nah, we’re fine.’ 🔥 Breach happens. 💼 Execs: ‘How much $$$ do you need??’ Classic.
020
spencer @bsky.ethicalthreat.com · 13/03/2025
060