EDR is one of the best investments you can make. But after performing thousands of hours of internal pentests I’ve come to realize, it’s just not enough.
I’ve been doing internal network security, (traditional Active Directory environments), for 15 years. The difference between a mature security program and those who get breached, is how well they detect threats.
How to identify attack paths in Active Directory without BloodHound
I’ved logged more than 1,000 hours of internal pentesting in 2025 alone. I promise you, attack paths are everywhere. And attackers are counting on you not caring enough to find and fix them.