Advertisement · 728 × 90

Posts by spencer

Preview
Developer machines are higher risk than Domain Admin machines

From an internal threat perspective, developer machines are as good as getting Domain Admin, and many times even more "lucrative" from an attack pov

They have the keys and typically much less oversight.

youtube.com/clip/UgkxqDZ...

1 month ago 0 0 0 0

Respect the game hah

1 month ago 1 0 0 0

Wow that’s… incredible hahah

1 month ago 1 0 1 0

Haha that’s so good

1 month ago 0 0 0 0

Right! Hah

1 month ago 1 0 0 0

Cat wallpaper

1 month ago 1 0 0 0

Haha did you get the donuts tho?

1 month ago 2 0 1 0
Advertisement

Yes, you should lock your computer when you get up and walk away while at the office. No, you're not gonna get hacked in the 3 minutes that you're gone from your desk getting some water. YMMV

1 month ago 1 0 4 0

You should speak to your AI so it can understand the intent and inflection in your voice. You really want it to know when you're ticked off because it's creating bugs in your code.

1 month ago 0 0 0 0

Imagine if one day we don’t see any more Kerberoastable domain admin accounts. It would be something right…

1 month ago 0 0 0 0

Tell me you’ve worked in IT without telling me you’ve worked in IT.

I’ll go first…

Did you try turning it off and back on again?

1 month ago 0 0 1 0

Y’all are focusing on the wrong thing. organizations don’t get better by automating pentesting and eliminating pentesting jobs.

Organizations get better by making their systems more secure and resilient.

Great, you found 4000 vulnerabilities in half the time, IT admin still need to fix that stuff

1 month ago 1 0 0 0

IT admin skills are absolutely foundational to cybersecurity. How can you get a degree in cybersecurity and not ever see a UAC prompt before?!

1 month ago 1 0 0 0

While no AI isn’t replacing pentesters just yet, I do believe it’s changing the game drastically. It’s forcing low quality pentesting to raise the bar.

It’s also a signal of what’s to come. But also, I think in many ways the “market” will decide if these ai pentesting platforms have value or not.

1 month ago 0 0 0 0
AI is going to k*ll pentesting jobs!!
AI is going to k*ll pentesting jobs!! Follow me on X: @techspence

The advancements in AI this last 12 months have been staggering…

But AI will only take your pentesting job if all you did was run a vulnerability scan and ship the report.

Pentesting, a professional pentest, is more than running tools

youtube.com/shorts/joYT9...

1 month ago 0 0 1 0

Smart

1 month ago 0 0 0 0
Advertisement

Haha exactly

1 month ago 1 0 0 0

As a defender, I want the advantage. I want my environment to be hostile territory to adversaries.

I want them to know…
that I know
that they know
I see them.

Get wrecked.

1 month ago 2 0 0 0

How to get people to talk about your stuff.

Make something that intersects with what people want and something that solves a deeply painful problem.

Then make it really really good.

1 month ago 2 0 0 0

Whenever there’s an IT issue it’s always this (in order)…

It’s not plugged in
DNS

1 month ago 2 0 0 0

I don’t think you can have a true appreciation for IT support unless you’ve lived in and experienced it yourself

1 month ago 2 0 0 0

The best way to learn how secure something is the first use it then have to administer it ďżź

1 month ago 3 0 0 0

Part of what makes you a good pentester is you know what rocks to turn over

1 month ago 0 0 0 0

Would you rather…

Have to secure Wordpress or OpenClaw?

(for the rest of your life if you had one singular job and this was it)

1 month ago 1 0 1 0

So who has interesting cybersecurity or IT-related use cases for openclaw they are playing around with? I wanna see some fun stuff…

1 month ago 0 0 0 0

Sure but I’d argue in this example, not accidentally configuring a template for ESC1 should be within their purview

1 month ago 0 0 1 0
Advertisement

Learn Active Directory and you’ll never work another day in your life….

You’ll work every day 🤪😂

1 month ago 2 0 0 0

If you’re an IT admin and you want upward career progression and you have any length of time left in your career, beginning to poke at these AI platforms and becoming comfortable with them is crucial.

Not to be an expert but so you know what’s coming.

1 month ago 0 0 0 0

I personally think IT admin cybersecurity skills should go beyond the basics. If you manage ADCS you should be familiar with certificate abuse for example

1 month ago 1 0 1 0

Badum chhhh hah

1 month ago 1 0 0 0