This website uses cookies
Read our Privacy policy and Terms of use for more information.
Former Sysadmin, Pentester, Microsoft MVP | I help IT teams make their environment harder to attack
Active Directory
Jun 8, 2026
•
2 min read
Defense is a state of invincibility achieved through strategy.
+1
Jun 2, 2026
Attackers love shortcuts. Hidden insecure permissions are their express lane to Domain Admin.
Leadership
May 26, 2026
Here’s what I would do instead.
Permissions
May 18, 2026
Attackers thrive on easy targets, don’t be one.
+3
May 11, 2026
Do this to mitigate lateral movement
Question CTA
+2
May 4, 2026
Three ways to prevent service account compromise.
Apr 27, 2026
If I had 10 minutes inside your environment this is where I’d start.
Apr 21, 2026
1 min read
If everyone's an admin, no one is in control.
Mar 30, 2026
3 min read
There’s an easier way to find attack paths in Active Directory than using Bloodhound.
CTP Podcast CTA
Mar 23, 2026
There’s a lot of hype around “AI security risks,” but most of it boils down to two things...
Deception
Mar 9, 2026
Attackers are trying to find interesting things. Give them interesting things.
Firewalls
Mar 2, 2026
Attackers are exploiting edge devices and firewalls more than ever before.
Feb 23, 2026
Security applied blindly is just another outage waiting to happen.
Feb 16, 2026
But when I ran the ESC8 relaying attack, it failed. The reason was ...
Feb 9, 2026
4 min read
The next worm will propagate through agent skills, mark my words.
Pentest Reports
Feb 2, 2026
5 min read