Sign in

spencer

@bsky.ethicalthreat.com
3.7K followers 112 following 1.2K posts

🛠️ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack Pentesting -> SecurIT360 Podcast -> CyberThreatPOV Active Directory Security Resources for IT Admins 👇 go.spenceralessi.com/adsecurity

PostsRepliesMedia
spencer @bsky.ethicalthreat.com · 12/03/2026
From an internal threat perspective, developer machines are as good as getting Domain Admin, and many times even more "lucrative" from an attack pov They have the keys and typically much less oversight. youtube.com/clip/UgkxqDZ...
youtube.com
Developer machines are higher risk than Domain Admin machines
010
spencer @bsky.ethicalthreat.com · 12/03/2026
Respect the game hah
010
spencer @bsky.ethicalthreat.com · 12/03/2026
Wow that’s… incredible hahah
110
spencer @bsky.ethicalthreat.com · 12/03/2026
Haha that’s so good
000
spencer @bsky.ethicalthreat.com · 11/03/2026
Right! Hah
010
spencer @bsky.ethicalthreat.com · 11/03/2026
Cat wallpaper
010
spencer @bsky.ethicalthreat.com · 11/03/2026
Haha did you get the donuts tho?
120
spencer @bsky.ethicalthreat.com · 11/03/2026
Yes, you should lock your computer when you get up and walk away while at the office. No, you're not gonna get hacked in the 3 minutes that you're gone from your desk getting some water. YMMV
410
spencer @bsky.ethicalthreat.com · 11/03/2026
You should speak to your AI so it can understand the intent and inflection in your voice. You really want it to know when you're ticked off because it's creating bugs in your code.
000
spencer @bsky.ethicalthreat.com · 11/03/2026
Imagine if one day we don’t see any more Kerberoastable domain admin accounts. It would be something right…
000
spencer @bsky.ethicalthreat.com · 11/03/2026
Tell me you’ve worked in IT without telling me you’ve worked in IT. I’ll go first… Did you try turning it off and back on again?
100
spencer @bsky.ethicalthreat.com · 10/03/2026
Y’all are focusing on the wrong thing. organizations don’t get better by automating pentesting and eliminating pentesting jobs. Organizations get better by making their systems more secure and resilient. Great, you found 4000 vulnerabilities in half the time, IT admin still need to fix that stuff
010
spencer @bsky.ethicalthreat.com · 10/03/2026
IT admin skills are absolutely foundational to cybersecurity. How can you get a degree in cybersecurity and not ever see a UAC prompt before?!
010
spencer @bsky.ethicalthreat.com · 10/03/2026
While no AI isn’t replacing pentesters just yet, I do believe it’s changing the game drastically. It’s forcing low quality pentesting to raise the bar. It’s also a signal of what’s to come. But also, I think in many ways the “market” will decide if these ai pentesting platforms have value or not.
000
spencer @bsky.ethicalthreat.com · 10/03/2026
The advancements in AI this last 12 months have been staggering… But AI will only take your pentesting job if all you did was run a vulnerability scan and ship the report. Pentesting, a professional pentest, is more than running tools youtube.com/shorts/joYT9...
youtube.com
AI is going to k*ll pentesting jobs!!
Follow me on X: @techspence
100
spencer @bsky.ethicalthreat.com · 10/03/2026
Smart
000
spencer @bsky.ethicalthreat.com · 10/03/2026
Haha exactly
010
spencer @bsky.ethicalthreat.com · 09/03/2026
As a defender, I want the advantage. I want my environment to be hostile territory to adversaries. I want them to know… that I know that they know I see them. Get wrecked.
020
spencer @bsky.ethicalthreat.com · 09/03/2026
How to get people to talk about your stuff. Make something that intersects with what people want and something that solves a deeply painful problem. Then make it really really good.
020
spencer @bsky.ethicalthreat.com · 09/03/2026
Whenever there’s an IT issue it’s always this (in order)… It’s not plugged in DNS
020
spencer @bsky.ethicalthreat.com · 09/03/2026
I don’t think you can have a true appreciation for IT support unless you’ve lived in and experienced it yourself
020
spencer @bsky.ethicalthreat.com · 06/03/2026
The best way to learn how secure something is the first use it then have to administer it 
030
spencer @bsky.ethicalthreat.com · 06/03/2026
Part of what makes you a good pentester is you know what rocks to turn over
000
spencer @bsky.ethicalthreat.com · 06/03/2026
Would you rather… Have to secure Wordpress or OpenClaw? (for the rest of your life if you had one singular job and this was it)
110
spencer @bsky.ethicalthreat.com · 06/03/2026
So who has interesting cybersecurity or IT-related use cases for openclaw they are playing around with? I wanna see some fun stuff…
000
spencer @bsky.ethicalthreat.com · 06/03/2026
Sure but I’d argue in this example, not accidentally configuring a template for ESC1 should be within their purview
100
spencer @bsky.ethicalthreat.com · 05/03/2026
Learn Active Directory and you’ll never work another day in your life…. You’ll work every day 🤪😂
020
spencer @bsky.ethicalthreat.com · 05/03/2026
If you’re an IT admin and you want upward career progression and you have any length of time left in your career, beginning to poke at these AI platforms and becoming comfortable with them is crucial. Not to be an expert but so you know what’s coming.
000
spencer @bsky.ethicalthreat.com · 05/03/2026
I personally think IT admin cybersecurity skills should go beyond the basics. If you manage ADCS you should be familiar with certificate abuse for example
110
spencer @bsky.ethicalthreat.com · 05/03/2026
Badum chhhh hah
010
spencer @bsky.ethicalthreat.com · 05/03/2026
Pentesting findings don’t get fixed for a number of reasons. Some of which are out of the IT teams control. But also, many IT teams are burnt out putting out fires and working on other “more important” projects handed down to them by management that they don’t have time to fix security issues.
010
spencer @bsky.ethicalthreat.com · 05/03/2026
The infosec/cybersecurity space is funny because on social media, AI is taking over the world. Then I go to conferences and meet people who are primarily defenders and they haven’t heard of OpenClaw, which is probably the biggest phenomenon since OpenAI launched ChatGPT. Social media is a bubble.
310
spencer @bsky.ethicalthreat.com · 04/03/2026
The unhealthy desire to “go viral” hurts social media more than AI ever will.
000
spencer @bsky.ethicalthreat.com · 04/03/2026
I’m at zero trust world today and tomorrow. If you see me say what’s up!
100
spencer @bsky.ethicalthreat.com · 04/03/2026
How long until Active Directory is “dead?” I don’t think it will ever be, look at this slide that Cliff Fisher shared on the hybrid identity podcast.
020
spencer @bsky.ethicalthreat.com · 04/03/2026
I’m currently a pentester, but I’m also a former sysadmin. Something that’s not lost on me is that it doesn’t matter how good you think your security is, if your backups and recovery processes haven’t been tested, you’re rolling the dice.
031
spencer @bsky.ethicalthreat.com · 04/03/2026
Famous last words by IT admins: I’m just testing…
000
spencer @bsky.ethicalthreat.com · 03/03/2026
True or false, cybersecurity skills are necessary for IT admins?
320
spencer @bsky.ethicalthreat.com · 03/03/2026
If you’re an IT admin or CIO/CISO, you probably want to know what cybersecurity threats you’re up against. This is that episode… Ps - don’t focus on the numbers, focus on the trends and the techniques Listen/watch here 👇 🎧 offsec.blog/episode-170-...
000
spencer @bsky.ethicalthreat.com · 03/03/2026
Sure Pentest one a year, but also, don’t wait until your next pentest to: Run Locksmith Run ADeleginator Run PingCastle/PurpleKnight Check shares, sharepoint, wikis for creds
000
spencer @bsky.ethicalthreat.com · 03/03/2026
Are phishing/social engineering exercises actually useful? Or do they do more harm than good?
110
spencer @bsky.ethicalthreat.com · 02/03/2026
As much as things change in cybersecurity, there’s an overwhelming portion that stays the same.
100
spencer @bsky.ethicalthreat.com · 02/03/2026
3 common Windows misconfigs I see during internal pentest. 1) weak local admin control 2) Insecurely installed/configured software 3) Weak endpoint security I explain how these can be dangerous in my latest video 👇 youtu.be/gcKejfmPea4
youtu.be
Your browser is up to date
You can use YouTube's latest features!
010
spencer @bsky.ethicalthreat.com · 02/03/2026
It’s a great time to be a web pentester
021
spencer @bsky.ethicalthreat.com · 02/03/2026
If you're on an internal pentest and you bust out tcpdump or wireshark, is it going well or going badly? 😆
010
spencer @bsky.ethicalthreat.com · 27/02/2026
This is great but how do we get orgs to not revert to RC4 on their service accounts…. Or login with domain admin everywhere Or use the same password for all their admin accounts
anthropic.com
Making frontier cybersecurity capabilities available to defenders
Claude Code Security is one step towards our goal of more secure codebases and a higher security baseline across the industry.
000
spencer @bsky.ethicalthreat.com · 27/02/2026
Relatable IT admin scenario: you leave a job and shortly after the job you just left gets hacked/ransomwared. Brutal honestly. Gut wrenching 🤕
030
spencer @bsky.ethicalthreat.com · 27/02/2026
The barrier to entry for threat actors continues to get lower, but for defenders, it almost seems like its getting higher... 📰Source: awesomeagents.ai/news/ai-powe...
000
spencer @bsky.ethicalthreat.com · 27/02/2026
Supply chain attack that drops openclaw instead of malware or a more typical payload. Buckle up folks! 🦞🔥 clawdint.com/cases/203
001
spencer @bsky.ethicalthreat.com · 26/02/2026
I’ve had ideas to AI-ify Active Directory but I’m a man of principles. I’ll vibe code AD security tools instead! 😅
000