@techspencei
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
🛠️ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack | @SecurIT360 & @CyberThreatPOV
🏰AD Security Resource Kit ⬇️
Joined November 2010
- Tweets56.5K
- Following3K
- Followers18.3K
- Likes138K
Pinned Tweet
I've seen a lot of Active Directory environments in the last 5+ years. These are some of the most dangerous issues I recommend reviewing and addressing in your environment.
Treat it like a check list.
If you have 0 of these, you're doing a great job.
spencer retweeted
We built @ThinkstCanary for this.
Some of the best security teams in the world use our Canaries && Canarytokens for this.
(You can get pretty far with even just our free tokens at canarytokens.org)
Microsoft issued only 1 single notice about the passkeys rollout prior to it starting in September.
Someone fact check this. Is this correct @merill
mc.merill.net/message/MC1426…
spencer retweeted
Google / Mandiant linked this activity to ShinyHunters! cloud.google.com/blog/topics…
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation.
Source IPs and the full indicators are available on Defused Radar.
console.defusedcyber.com/sig…
spencer retweeted
THIS
Bad guys need a network connection to do bad stuff
Monitoring privileged groups (tier 0) for changes is super important but if you can get to a point where you’re also detecting abnormal changes, that’s better.
Eg, if somehow joe the sql guy has added an account to Domain Admins even though he shouldn’t be able to, that’s a big red flag.
Am I weird or is a lot what was in the Anthropic September Threat Report (related to cybersecurity) not really all that surprising?
That being said, one of the more interesting parts for me was how TA are beginning to use AI to streamline obfuscation and evasion. This is an area I think there will continue to be progress and developments made, for offsec people and for TA.
offsec.blog/one-hacker-42-ta…
spencer retweeted
Inventory your service accounts, force unique passwords or certs, and disable or delete any that IT can't attribute.
In security, there’s a lot of things that are out of our control. But weak passwords, on service accounts, provisioned by IT….
Come on.
This is also not an uncommon finding during internal pentests.
IT teams who let this happen either don’t know they should do this or they don’t care. I tend to think it’s the former but man…
There's a super disappointing trend happening as a result of AI. It's the lack of judgement and taste. If your AI agent does everything for you, analyzes everything for you, interprets everything for you, writes everything for you.... then what is it you're actually doing? Reviewing the output of some(thing)one else's work? Babysitting a cron job?
I think this matters greatly in some areas and virtually not at all in others.
I don't necessarily care how my AI agent writes a quick powershell script to do some small task or even a full blown tool to do some thing, so long as it does the thing I need it to do, correctly.
But I certainly don't want it replacing my judgement and opinions and thoughts and perspectives on things that could materially impact an organization. Like say, the specifics of a pentest finding. Or the potential impact of that finding in the context of the environment and everything else I've found and discussions I’ve had with the client.
Why would I want to leave that up for interpretation by an AI agent that has incomplete data no matter how much I try and feed it.
Thats the ugly trend of offshoring all thinking and judgement and calling it "ok" because we're "reviewing the output."
The review is likely just going to be as agreeable as the AI that fed the answers. The way you would write up a risk or a finding is not at all how an AI agent would right it up.
I think that difference really matters.
I don’t say this as a condemnation for using AI but more so of the complete offshoring of all thinking and judgment and taste and perspective.
It’s a trap I’ve fallen into myself. In an effort to speed things up. So I write this even as a reminder to myself and to hold myself accountable to that.
In a race to speed everything up and be more efficient we’re sacrificing so much of our judgment and perspective and our expertise.
In the end I think it just makes everyone all sound the same and come to all the same conclusions.
💯👇
AI Agent may be the new "it was an APT" cop-out. If it's an old known vulnerability in your internet accessible attack surface that an AI Agent was capable of finding, then it was a preventable initial vector.
It does matter, but it needs to be contextualized. When FireEye got compromised by Russian Foreign Intelligence, it was through a completely novel supply chain attack. The world understood the difference between that and a highly porous (see neglected) outer perimeter.
Don’t underestimate properly deployed and tuned NDR. The clients I’ve pentested that have had it configured well have caught me with it way before anything else did, including EDR.
I know the downsides, it’s expensive and complex and difficult to tune. But I think that’s a fair trade.
In security, there’s a lot of things that are out of our control. But weak passwords, on service accounts, provisioned by IT….
Come on.
This is also not an uncommon finding during internal pentests.
IT teams who let this happen either don’t know they should do this or they don’t care. I tend to think it’s the former but man…
spencer retweeted
‘If you're an IT admin and you have nothing to do’ lol 🤣
I’ve interviewed hundreds and hundreds of people across a lot of orgs and I’ve never met people with nothing to do ;)
But …. That being said; he’s got a good tip for improving AD security! 🫡🤙❤️🛡️🦾
If you're an IT admin and you have nothing to do, check for these issues in your Active Directory environment.
I promise if you fix these issues your environment will be harder to attack.
nitter.cf/techspence/status/2097…
spencer retweeted
ClickFix started as "just paste this command." Now we're talking LLM-themed lures, fake AI skills, and Click-Fix MCPs as backend infrastructure.
Where do you think this goes next? 👇
We all have our theories, this is Tyler's.
spencer retweeted
The vulnpocalypse is turning out a lot like Y2K. InfoSec already had a 0day/Nday problem. The pitch was that everything on the internet would face a constant stream of 0days. Instead, Glasswing, other projects, and people collecting CVEs like Pokemon have resulted in a bunch of things getting patched.
We still haven’t seen a Log4j, Heartbleed, Shellshock, EternalBlue, etc equivalent out of all this. Even if one or two showed up today, based on the predictions, weren’t these supposed to be happening weekly or monthly?
Happy Thursday - stop some RMMs.
Get at it folks. Free prevention - @magicswordio at magicsword.io
🤖 Made with AI
Getting a job as an internal pentester without getting IT experience first is a mistake. You will benefit so much from this experience and skills you learn as a result.
You might even realize you actually really like IT and stay there. At the right company, it’s such a great career. 🙏💪
This is one of the easiest ways I’ve found to discover dangerous permissions in Active Directory.
nitter.cf/techspence/status/2102…