@techspence

🛠️ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack | @SecurIT360 & @CyberThreatPOV

🏰AD Security Resource Kit ⬇️
Joined November 2010
I've seen a lot of Active Directory environments in the last 5+ years. These are some of the most dangerous issues I recommend reviewing and addressing in your environment. Treat it like a check list. If you have 0 of these, you're doing a great job.
7
135
2
655
170,838
We built @ThinkstCanary for this. Some of the best security teams in the world use our Canaries && Canarytokens for this. (You can get pretty far with even just our free tokens at canarytokens.org)
I been saying! If zero days are cheap. Detections get much more important. Zero days are not invisibility cloaks.
6
18
2
88
11,741
Microsoft issued only 1 single notice about the passkeys rollout prior to it starting in September. Someone fact check this. Is this correct @merill mc.merill.net/message/MC1426…
5
4
35
6,133
If this is true, that's 50 total days notice.... which is only 36 weekdays. That's subpar communication in my opinion, especially for such an important rollout
1
371
spencer retweeted
Google / Mandiant linked this activity to ShinyHunters! cloud.google.com/blog/topics…
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
2
10
43
4,379
THIS Bad guys need a network connection to do bad stuff
Don’t underestimate properly deployed and tuned NDR. The clients I’ve pentested that have had it configured well have caught me with it way before anything else did, including EDR. I know the downsides, it’s expensive and complex and difficult to tune. But I think that’s a fair trade.
1
2
445
Monitoring privileged groups (tier 0) for changes is super important but if you can get to a point where you’re also detecting abnormal changes, that’s better. Eg, if somehow joe the sql guy has added an account to Domain Admins even though he shouldn’t be able to, that’s a big red flag.
2
8
37
2,500
Am I weird or is a lot what was in the Anthropic September Threat Report (related to cybersecurity) not really all that surprising? That being said, one of the more interesting parts for me was how TA are beginning to use AI to streamline obfuscation and evasion. This is an area I think there will continue to be progress and developments made, for offsec people and for TA. offsec.blog/one-hacker-42-ta…
3
7
846
Inventory your service accounts, force unique passwords or certs, and disable or delete any that IT can't attribute.
In security, there’s a lot of things that are out of our control. But weak passwords, on service accounts, provisioned by IT…. Come on. This is also not an uncommon finding during internal pentests. IT teams who let this happen either don’t know they should do this or they don’t care. I tend to think it’s the former but man…
1
1
2
703
There's a super disappointing trend happening as a result of AI. It's the lack of judgement and taste. If your AI agent does everything for you, analyzes everything for you, interprets everything for you, writes everything for you.... then what is it you're actually doing? Reviewing the output of some(thing)one else's work? Babysitting a cron job? I think this matters greatly in some areas and virtually not at all in others. I don't necessarily care how my AI agent writes a quick powershell script to do some small task or even a full blown tool to do some thing, so long as it does the thing I need it to do, correctly. But I certainly don't want it replacing my judgement and opinions and thoughts and perspectives on things that could materially impact an organization. Like say, the specifics of a pentest finding. Or the potential impact of that finding in the context of the environment and everything else I've found and discussions I’ve had with the client. Why would I want to leave that up for interpretation by an AI agent that has incomplete data no matter how much I try and feed it. Thats the ugly trend of offshoring all thinking and judgement and calling it "ok" because we're "reviewing the output." The review is likely just going to be as agreeable as the AI that fed the answers. The way you would write up a risk or a finding is not at all how an AI agent would right it up. I think that difference really matters. I don’t say this as a condemnation for using AI but more so of the complete offshoring of all thinking and judgment and taste and perspective. It’s a trap I’ve fallen into myself. In an effort to speed things up. So I write this even as a reminder to myself and to hold myself accountable to that. In a race to speed everything up and be more efficient we’re sacrificing so much of our judgment and perspective and our expertise. In the end I think it just makes everyone all sound the same and come to all the same conclusions.
13
8
1
48
2,878
💯👇
AI Agent may be the new "it was an APT" cop-out. If it's an old known vulnerability in your internet accessible attack surface that an AI Agent was capable of finding, then it was a preventable initial vector. It does matter, but it needs to be contextualized. When FireEye got compromised by Russian Foreign Intelligence, it was through a completely novel supply chain attack. The world understood the difference between that and a highly porous (see neglected) outer perimeter.
1
17
1,241
Don’t underestimate properly deployed and tuned NDR. The clients I’ve pentested that have had it configured well have caught me with it way before anything else did, including EDR. I know the downsides, it’s expensive and complex and difficult to tune. But I think that’s a fair trade.
10
22
2
120
6,801
In security, there’s a lot of things that are out of our control. But weak passwords, on service accounts, provisioned by IT…. Come on. This is also not an uncommon finding during internal pentests. IT teams who let this happen either don’t know they should do this or they don’t care. I tend to think it’s the former but man…
What are we even doing here?!? But sure, let's worry about million dollar AI swarms
3
6
1
35
3,165
‘If you're an IT admin and you have nothing to do’ lol 🤣 I’ve interviewed hundreds and hundreds of people across a lot of orgs and I’ve never met people with nothing to do ;) But …. That being said; he’s got a good tip for improving AD security! 🫡🤙❤️🛡️🦾
If you're an IT admin and you have nothing to do, check for these issues in your Active Directory environment. I promise if you fix these issues your environment will be harder to attack. nitter.cf/techspence/status/2097…
6
3
54
5,492
ClickFix started as "just paste this command." Now we're talking LLM-themed lures, fake AI skills, and Click-Fix MCPs as backend infrastructure. Where do you think this goes next? 👇 We all have our theories, this is Tyler's.
3
9
477
spencer retweeted
The vulnpocalypse is turning out a lot like Y2K. InfoSec already had a 0day/Nday problem. The pitch was that everything on the internet would face a constant stream of 0days. Instead, Glasswing, other projects, and people collecting CVEs like Pokemon have resulted in a bunch of things getting patched. We still haven’t seen a Log4j, Heartbleed, Shellshock, EternalBlue, etc equivalent out of all this. Even if one or two showed up today, based on the predictions, weren’t these supposed to be happening weekly or monthly?
20
17
6
137
11,102
I admire innovation, but can someone please tell me how “the physics of cyber” have changed? 😮‍💨
13
4
33
2,867
spencer retweeted
Happy Thursday - stop some RMMs. Get at it folks. Free prevention - @magicswordio at magicsword.io
🤖 Made with AI
1
3
7
739
Dang what a thread 🤘
I've been doing down a deep and windy rabbit hole with this. What I'm finding is there's a whole lot involved here, and some of it is somewhat hidden and weird since around 2013 when things were changed by Microsoft. Allow me to brain-dump a bit, and correct me if I am wrong...
2
1,326
Getting a job as an internal pentester without getting IT experience first is a mistake. You will benefit so much from this experience and skills you learn as a result. You might even realize you actually really like IT and stay there. At the right company, it’s such a great career. 🙏💪
1
21
1,312
This is one of the easiest ways I’ve found to discover dangerous permissions in Active Directory. nitter.cf/techspence/status/2102…
🧵Literally my best advice for finding dangerous permissions in Active Directory, quickly and easily.
2
5
34
3,038