Directory service created by Microsoft for Windows domain networks
POPULARITY
Hello friends! Today's tale of pentest pwnage isn't a start-to-finish march to DA – it's me finally emptying out the backlog of "gosh, I've got to share this next time" internal network tips that have been rattling around in my head. Here's what we get into: Don't skip the boring stuff. Even when I'm testing the same network for the third or fourth time, I've got an ever-growing list of things I check every single time – because config drift has a nasty habit of quietly reintroducing problems that were fixed years ago. Get a second opinion on your tools. Lately I've had BloodHound tell me a network is squeaky clean, and then gone and checked manually only to find the exact opposite sprawled all over the place. I don't know how to account for it, but it's changed how I work. (If you know the source of truth here, please write in!) Ghost machines. That innocent little checkbox in Active Directory that turns a computer object into a gift-wrapped present for an attacker. We keep finding these in environments that had zero of them last year – and I share the two-pass trick that shakes even more of them loose. The weekend freebie. Why I like to get my box lit up on a Friday even when the test doesn't officially start until Monday, and what tends to come wandering into my capture over 48 quiet hours. SNMP sweeps. I've never been caught doing one, and yet they'll happily hand over the make, model and firmware of some firewalls, switches and storage systems in the building. I think this finding deserves way more attention than it gets. (There are a few little commandlets waiting for you over at 7MinSec.wiki.) Be a consultant, not a Terminator 1000. Why I run certain checks even when I'm 99% sure I'll find nothing, why "you don't have this thing at all" belongs in the accolades section, and how that one habit has led to some of the most appreciated conversations we've had in report delivery meetings. Tangent department: the dumb-but-glorious AI project that gave me the giggidies – a fully automated lobby bot for a Steam game that is absolutely, positively not for the kiddos. Also: the one line I won't cross with it, no matter how much my buddy eggs me on. Got a tip of your own I should be adding to the "always check this" list? I'd love to hear it! 7MinSec.com for security services and show notes | 7MinSec.club for our Substack and weekly TuesdayTOOLSdays | 7MinSec.wiki for pentesting tips, scripts and cheat sheets
Hey friends! Today's episode is a two-parter: some security stuff up front, and then a big ol' personal celebration on the back half. If you're strictly here for the security bits, I love you and you're free to bail after the first half. If you're here for both, God bless you. Part 1: Kicking the tires on Insight Recon What it is: Insight Recon is an Active Directory security assessment tool out of Heath Adams' new venture, Breach Point. I signed up for early access a while back, finally got a login, and took it for a spin this week in my GOAD lab. Not a sponsor, not an ad — just a tool I was curious about. Watch it in action: I covered the install, a couple of hiccups I hit, and some of the report output in this week's TuesdayTOOLSday video over at 7MinSec.club. The setup: Log into the portal, grab the installer, run it on a domain-joined box, then pick whether you want to scan as your current user or specify creds. Say go, wait a few minutes, and your report card shows up on the dashboard. My two nitpicks (and they're mine, not necessarily yours): The download does a full-blown install with an install footprint, and the raw scan data gets shipped back up to Insight Recon so you can view your report. I can't help but compare everything in this space to PingCastle, where you unzip, run the EXE, and your HTML report is sitting right there on the C drive — nothing leaves the building. As someone who tries to be a good data janitor and nuke assessment data after reports go out, cloud storage is just one more place I've got to remember to go scrub. What I really liked: The remediation guidance is legit. I clicked into a few of the critical findings — some ESC/ADCS stuff especially — and it walked me through exactly what to change, why an attacker cares, how to verify the fix afterward, and where to go read more. There's also a "quick wins" view that pares the big list down to the biggest security impact for the least effort. The dashboard and the slide-out detail panes are genuinely pleasant to use. Why this matters even for offense-only folks: We're mostly on the offensive side with a little blue team consulting — we don't do hands-to-keyboard remediation. But I think you become a better pentester when you can speak confidently at delivery time about not just what to fix, but the gotchas that might bite them along the way. Pricing: On the podcast I guessed "a few thousand a year" and admitted that number may have come straight out of my bum cheeks. Turns out I wasn't too far off — there's a free tier to start, and paid runs $3,000/year with founder pricing at $1,500/year locked in for the first 25 customers. See the pricing page for the current details. Verdict so far: A promising first dance. I want to give it a proper workout — run it side by side with PingCastle on a couple of real assessments and see if either one has blind spots the other covers. More on that in a future episode. Part 2: Why I've got the giggidies My son Cam graduated paramedic school! As of tonight he has everything signed off to go take the gargantuan national test. I'm not going to pretend I got through recording this without getting a little watery-eyed. The journey: Senior year of high school, nothing career-wise floated his boat — there were subjects he tolerated and subjects he hated, and that was about it. Then a conversation with a family friend who's a paramedic lit a fire in his belly, and he's been running at it ever since: EMT coursework in high school, then straight into the paramedic program. How he did it: He wrestles with ADHD, so he had to figure out how to hack his own brain to get through a mountain of material. Come home from five or six hours of class, eat dinner, then hit the books again and re-take his own notes. Then he'd sit down with my wife or me and do an Ace Ventura-style verbal dump of everything he'd learned that day — and any time he caught himself glitching on something, he'd write it down, keep going, then go back and shore it up. Every single night. The Mr. Miyagi moment: My wife has been a nurse for 20+ years, and about six months ago she had to tell him she couldn't help anymore because he'd surpassed her in certain areas of healthcare. Yes, AI made a cameo: The night before his final scenario testing, he and I sat down and had Claude generate random practice scenarios so I could prompt him and just watch him talk for two minutes straight about airway management, medication dosing, all of it. The cliffhanger: Four-ish hours of individual scenario testing, an hour-and-a-half drive to the ceremony, and no word either way on if he passed his tests. I hit the front door of the building not knowing whether I was walking into smiles or tears — and right as my hand hit the door handle, a text came in with a giant happy face: I passed. Somebody must have been cutting onions in that parking lot. His people: Cam's the youngest of the bunch — most of his classmates had been working EMTs for years — and from day one they told him "we got you, we'll get through this together." For the group photo on the steps afterward, one of them tried to pick him up solo and just about threw her back out, so it took three of them. That's the little family he's got, and I hope they stay close, because they've all got that beast of a test coming next month. The hard part: If you've listened to the last few episodes, you know my dad passed away at the end of June, and that Cam was the one who found him and sprung into paramedic mode. My dad was a cop and a pilot who had enormous respect for paramedics, EMTs, and nurses, and he was one of Cam's biggest cheerleaders. Whenever I did something my dad was proud of, he'd say, "I'm busting my buttons over here!" That's exactly what he'd have said tonight, and not having him here to say it is a karate kick to the heart. But I'll tell you what — I'm busting my buttons about Cam for the both of us. Thank you: So many of you have reached out with condolences and shared stories of your own losses these past weeks. I'm sorry for every one of them, and I appreciate you more than I can say. Thanks for listening — to the security stuff, the tangents, or both. Come find us at 7MinSec.com, and/or subscribe (free or paid) over at 7MinSec.club, and dig through the our notes at 7MinSec.wiki.
This episode features Philip Keibler, Vice President and CISO at Meijer, one of the nation's largest privately held retailers.With nearly three decades of security leadership, including CISO roles at Bass Pro Shops and Finish Line, Phil brings a rare long-view perspective on what the job actually requires day to day. He also talks about his feature in Semperis' upcoming documentary Midnight in the War Room, premiering at Black Hat on August 5.In this episode, Phil explains why CISOs who struggle to get budget usually have a storytelling problem, how he defines success in a role where stopping every attack is impossible, and what it takes to lead a team through an active incident. He also dives into why fundamentals are what actually address most of an organization's risk.This episode makes the case that the hardest parts of the CISO job are rarely technical, and that mastering the basics matters more than chasing the newest tool.Guest Bio Philip Keibler has spent nearly three decades at the intersection of technology, risk, and business building information security programs that work in the real world.As Vice President and Chief Information Security Officer at Meijer, Phil leads security for one of the nation's largest privately held retailers, overseeing the protection of supply chains, customer data, and critical operations across hundreds of locations in the Midwest.Phil's career spans industries where the stakes are high and the margin for error is low. Before joining Meijer in 2015, he served as CISO at Bass Pro Shops and previously held the CISO role at Finish Line. Earlier in his career he led security at Herff Jones, bringing security discipline to the manufacturing sector. He began his career at EDS and spent years consulting in the Aerospace sector where he got his start in security.What sets Phil apart is not just longevity, it is perspective. He has watched information security evolve from a reactive, audit-driven function into a proactive capability that enables business velocity. His approach centers on integrating security into how organizations operate, not as a checkbox, but as a competitive advantage that lets teams move fast while managing risk in practical ways.Beyond the day-to-day, Phil is a passionate contributor to the broader security community. He has served as a guest lecturer on cybersecurity and data privacy at the University of Chicago Law School, sits on the Institute for Cybersecurity Education and Research Advisory Board at Grand Valley State University, serves on the IT Advisory Committee at Kent County Technical Center, and is a board member the Meijer Credit Union. He is also featured in Midnight in the War Room, a Semperis documentary examining the human reality behind enterprise cyber defense.Phil has held his CISSP certification since 2009, attained his MBA from Davenport University, and a career's worth of operational experience across retail, aerospace, insurance, and manufacturing.Guest Quote “A successful CISO understands that it's not about prevention, it's about resilience, it's about recovery, and it's about identifying those things in your program that you can do incrementally better every single day. We're in the pursuit of perfection, but we understand we'll never get there.”Time stamps 02:46 Meet Philip Keibler: From Sysadmin to Security 04:35 Becoming a CISO 06:20 What CISOs Really Do 08:50 Defining Success and Resilience 10:41 Storytelling to the Board 13:29 Semperis' Midnight in the War Room 17:47 Team Care and Crisis Leadership 21:47 Advice for CISOs 24:24 The Case for Mastering the Fundamentals 31:02 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Phil on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.
Andrew sits down with Evgenij Smirnov, a Berlin-based IT veteran with 30 years of experience in Active Directory and security consulting, to dig into what actually gets organizations popped. Evgenij walks through the most common escalation paths he sees in real-world AD environments, including over-permissioned accounts, exposed certificate authorities, and unencrypted domain controller backups, and explains how attackers chain these together to produce golden tickets and gain god-mode access. The conversation covers why these misconfigurations keep happening (bad defaults, lazy vendors, and a long history of "just click next"), how PowerShell fits into both hardening and attack scenarios, and what proper tier isolation actually looks like when you implement it with both authentication policies and user rights assignments. Evgenij also introduces his book, Building Modern Active Directory, and makes the case for treating security not as a chapter you can skip, but as something baked into the design from day one. Key Takeaways: The most common Active Directory escalation paths are not sophisticated. Over-permissioned accounts with ACL chains to DC sync, exposed certificate authorities, and unencrypted backup tapes are consistently the entry points attackers exploit. If you can find these first, you are already ahead of most threat actors. Tier isolation done right requires both authentication policies and user rights assignment policies working together. Either technique alone leaves a blind spot that a determined attacker can walk through. Cybersecurity is a team sport, and bad cybersecurity is too. Microsoft ships AD with questionable defaults, vendors demand domain admin for service accounts, and administrators make shortcuts under pressure. The fix is not one heroic hardening sprint; it is a culture of least privilege built into every decision from the start. Guest Bio: Evgenij Smirnov is a Principal Solutions Architect at Semperis and a Microsoft MVP in both Security and PowerShell since 2020. Based in Berlin, Germany, he has spent more than 30 years in IT and security consulting, with deep expertise in Active Directory, identity security, and hybrid infrastructure. He is a longtime community leader, running the PowerShell User Group Berlin and the Windows Server User Group Berlin, and a regular speaker at conferences including PSConfEU. He is the author of Building Modern Active Directory, published by Apress in 2024. Resource Links: Building Modern Active Directory (book site): ad2049.com Evgenij's personal blog): it-pro-berlin.de Evgenij on LinkedIn: linkedin.com/in/evgenijsmirnov ADMF (Active Directory Management Framework) on GitHub: github.com/ActiveDirectoryManagementFramework/ADMF ADMF documentation and project site: admf.one Attack Scenario To Go: https://github.com/HerrHoZi/AS2Go The PowerShell Podcast on YouTube: https://youtu.be/EQb7H6vBOtg
Microsoft has put the Active Directory Tier Model on GitHub, MIT-licensed, with a deployment engine, a drift auditor, and around 1,700 tests. This used to be consulting material that Microsoft deployed to you as a paid engagement, so the obvious question is: why now? We start with that question, and also consider whether Active Directory is still worth your attention.(00:00) - Intro and catching up.(03:55) - Show content starts.Show links- Repository- FAQ- What's new in Windows Server 2025 (the AD DS section)- Microsoft Learn - Enterprise access model- Microsoft Digital Defense Report 2025- Give us feedback!
Andrew sits down with Fred Weinmann, one of the most prolific PowerShell module authors in the community, for part one of a multi-episode series covering his projects. This episode focuses on the Active Directory Management Framework, or ADMF, a configuration-driven system Fred originally built while working as a field engineer at Microsoft for a large enterprise customer managing hundreds of Active Directory forests. Fred walks through the problem ADMF was designed to solve: Active Directory is notoriously hard to manage consistently across environments, and most organizations just accept the chaos as the cost of doing business. The old approach at this particular customer involved zipping up scripts, RDPing into domain controllers, and running them manually. ADMF changed that by borrowing the test/apply concept from Desired State Configuration, but making it flexible enough to handle the messiness of real-world AD environments. The conversation covers how ADMF is structured around components (like organizational units) and contexts, why generating a reference configuration from an existing environment is harder than it sounds, the protocol juggling required to handle Group Policy and schema updates, and why Fred would use raw LDAP instead of the built-in AD commands if he were starting from scratch today. Fred also touches on the credential provider plugin system, which lets teams plug in their own password management workflows for things like break-glass accounts. Key Takeaways: ADMF follows a test-before-apply model borrowed from DSC, but trades DSC's all-or-nothing enforcement for a more selective, component-by-component approach that better fits the fluid reality of Active Directory management. Generating a configuration from an existing AD environment is tempting but potentially counterproductive. If you auto-generate your desired state from a domain that's accumulated years of cruft, you're not capturing what you want, you're just freezing what already exists. Performance at scale is a real consideration. The built-in Active Directory PowerShell module uses the AD Web Services protocol, which sends XML over the wire. Raw LDAP is significantly faster, and Fred says switching to it is the one architectural change he'd make if building ADMF over again. Guest Bio: Friedrich "Fred" Weinmann is a Cloud Solution Architect at Microsoft and one of the most recognized PowerShell community contributors working today. He is the creator of PSFramework, which underpins many other modules in the ecosystem, as well as tools like PSModuleDevelopment, PSUtil, and the Active Directory Management Framework. Fred is a frequent conference speaker, a longtime community collaborator, and someone Andrew credits with helping shape his own PowerShell journey. Resource Links: ADMF documentation and getting started guide: admf.one ADMF on GitHub: github.com/ActiveDirectoryManagementFramework/ADMF ADMF on PowerShell Gallery: powershellgallery.com/packages/ADMF PSFramework (Fred's logging, configuration, and scripting infrastructure module): psframework.org Fred Weinmann on GitHub: github.com/FriedrichWeinmann Fred Weinmann on X: x.com/FredWeinmann PDQ Community Discord: discord.gg/pdq The PowerShell Podcast on YouTube: https://youtu.be/8SlIqUKP3hY
Hey friends! Welcome back to another Tales of Pentest Pwnage — my favorite mini-series where I share the good, the bad, and the "why didn't I check THAT first?!" moments from real-world engagements. Today's story has a little bit of everything: a legit path to domain admin, some late-night rabbit holes, a lesson in humility, and a villain you've definitely met before. (Spoiler: it's DNS.) A couple of quick plugs before we dive in: Private GOAD training is going strong! — We just wrapped a 3-day private session (7 students — that's max capacity!) of our Active Directory pentesting class built on the Game of Active Directory (GOAD) framework. Over three days, students enumerate, attack, and fully pwn three separate AD environments. The private format is just *chef's kiss* — when it's a team from the same company, the conversation gets real fast. Like, "hey I just checked Bloodhound on break and Bob from accounting has full rights over the DC" real. If you want to send 3–7 people from your org, hit up 7MinSec.com/training to line up a private session. Support the show over at 7MinSec.club — That's our Substack, where every Tuesday I drop a short TuesdayTOOLSday video about security tools. Free subscriptions are welcome and mean a lot — you'll just get pinged when new content drops. No spam, no blindly-sent Outlook calendar invites. I promise. Pentest tips and scripts live at 7MinSec.wiki — I reference it throughout today's episode, including some step-by-step guidance on the techniques we'll talk about below. Now — onto the pwnage. Fair warning: I've been burning the candle at three ends lately trying to catch up after a tough few weeks of grief (if you want the backstory, the last couple episodes cover my dad passing away). The good news is my head is semi back on straight and I put it to work on a recurring client environment — one that keeps getting better year over year. Machine account quota locked down? Check. No Kerberoastable or AS-REP roastable users? Check. No local admin rights, no web client running? Check and check. All good signs. And then PingCastle smiled right into my eyeballs with a big red finding: The DC's LAN Manager authentication level was weak enough to coerce and capture a downgraded hash — Specifically, an NTLMv1 SSP hash. Using Coercer to nudge the DC into authenticating to my Kali box (with Responder running), I captured the goods. Pretty little hashes all in a row. Cracking that hash: enter Vast.ai — The old go-to for this type of crack used to be crack.sh, but their cracker has been offline for years. What they do still have is a walkthrough pointing to a tool from EvilMog on GitHub that helps you prep the raw hash material and figure out exactly how to crack it with Hashcat. For the GPU horsepower, I rented a beefy multi-GPU instance on Vast.ai — filter for 16+ GPUs, pick a Hashcat Docker image, and SSH in. The whole crack job took about 16 hours at ~$4/hr. Do the math: $64 to reconstruct the DC's NTLM hash. Worth it. Tmux sidebar — seriously just learn it — Vast.ai is actually what finally got me into tmux, because the Hashcat Docker container drops you right into a tmux session. This is clutch: you can kick off a 16-hour crack job, detach, and reattach later without killing anything. On a pentest, my workflow now is SSH in → tmux → name a few session windows for Responder, Exegol, packet captures, etc. I used to fumble around with Linux screen sessions. Not anymore! From hash to DA — the usual playbook — Once you've got the DC's NTLM hash, you can request a Kerberos ticket and load it up, then run a DCSync to pull the KRBTGT hash. From there it's god mode: dump hashes, pass-the-hash as domain admins, and you have yourself a cool privesc POC. Except this time…the POC didn't work. The part where I Jean-Claude Van Damme helicopter kick myself in the face — DCSync failed immediately. Like, suspiciously fast — barely two lines of output and done. I tried every version of every tool I could get my hands on. I tried Windows, I tried Linux. I even asked the client to check if their endpoint protection was blocking me (it wasn't). I touched grass. I played guitar. I played some Splinter Cell Blacklist (old game, highly recommend if you like the Hitman-style vibes). Came back fresh. Rebooted both VMs. Still nothing. It was DNS. It's always DNS. — The thing that finally caught my eye: the commands were failing too fast. Like it wasn't even reaching the DC. I catted the resolv.conf inside my Exegol instance (heads up: Exegol has its own resolv.conf and hosts file, separate from your base Kali system!) and found a stale DNS entry pointing to an old DC that was no longer serving anything. Nuked the bad entry, added static hosts file entries for the live DC, ran the command again, and — hash rain. Pennies from heaven. It was midnight and I literally pushed back from my desk like a baby pushing away from a high chair going "Baby Brian is all done!" The lesson: — I know the meme. "It's always DNS." I just personally hadn't hit it hard in my security life since my sysadmin days back before 2013. Now I have. So going forward I'll check DNS first (and often). Vacation attempt #3 incoming… pray for me — My wife nearly died in Punta Cana earlier this year. Then our summer cabin trip was cold and rainy with zero water time. And now we've got families flying in from multiple states for a lake weekend — except we just found out our reservation through Booking.com was basically vaporized because the resort changed hands and never updated their website. My wife (who is an absolute saint and my better three-quarters) almost had a 360-degree head spin (like in The Exorcist) talking to customer service. But we scrambled, found a last-minute place, and I'm choosing to believe it's not in Jason Voorhees' back yard. Could this be my last episode? Maybe. But hey — it was a good one. Talk to you next week (hopefully).
This episode features Andre Priebe, Chief Technology Officer at iC Consult Group, the world's largest independent provider of identity security services.Andre has spent more than two decades leading IAM projects for large-scale enterprises across workforce, customer, and device identity domains. As CTO, he steers iC Consult's Centers of Excellence, service portfolio, and vendor strategy, and advises strategic customers on shaping their identity programs.In this episode, Andre explains why the gap between identity security awareness and actual maturity is growing every day, and how AI is making it faster and easier for attackers to find the weaknesses organizations already know they have. He breaks down why recovery is the most underestimated phase of the NIST cybersecurity framework and what it really costs when organizations haven't prepared for it.This episode is a candid look at the state of identity security from someone who sees it across hundreds of organizations every year.Guest Bio Andre Priebe serves as the Chief Technology Officer at iC Consult Group, a vendor-independent system integrator specializing in Identity & Access Management and Identity Security with a global team of over 850 employees. Boasting more than two decades of experience managing IAM projects focused on workforce, customer, and device identities within large-scale enterprises, Andre steers the Centers of Excellence, the service portfolio, and vendor strategy at iC Consult.Andre's role involves a deep focus on emerging approaches, trends, and technologies within the IAM sector, assessing their business value for iC Consult's clientele. He is an innovator with a patent in DevOps-related IAM methodologies, and he holds a B.Sc. and an MBA.Guest Quote “Threat actors, for them, it's easier than ever before, faster, more efficient to identify that kind of technical debt, the weaknesses. They are not going for your latest Entra ID, conditional access, configuration with all the fancy stuff in place to really make sure that nobody else accessing that resource. No. They're going for the old systems, for old protocols, for areas that might be out of control, out of visibility. Third parties, contractors, unmanaged devices.”Time stamps 0:40 Meet Andre Priebe: Veteran IAM Expert 2:43 The State of Identity Security Awareness 4:51 The Reality of Technical Debt 6:16 How AI Is Changing the Attack Landscape 10:37 Zero Trust Is Mandatory but Almost Nobody Has Achieved It 15:06 What Customers Are Actually Asking About Now 19:19 Planning for Identity Recovery 26:08 The Most Underestimated Part of Recovery 29:56 Return to Trustworthiness vs Return to Operations 39:42 AI Agents and Non-Human Identities 44:02 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Andre on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.
Hey friends! Fair warning: today's episode is a bit of an emotional rollercoaster — we've got a big security win, some honest lab feedback, and a very personal share about my dad's funeral. Buckle up. CARTP certified, baby! — I'm officially a Certified Azure Red Team Professional (CARTP), courtesy of the folks at Altered Security. It's been a long time coming (I originally signed up for the live version and fell off after missing a couple Saturdays), but I came back for the self-paced 30-day version and finally finished the job. The lab experience — the good: — ~25 objectives, a solid lab guide, and a really fun variety of attack paths. Highlights include stealing tokens, enumerating Azure tenants, attacking apps and VMs and key vaults, simulated phishing against real tenant email addresses, popping reverse shells, and some clever OneDrive-based follow-on attacks via session hijacking. There's even some web app pen testing (hello, server-side template injection!) sprinkled in. The lab experience — the not-so-good: — The included videos are… not my favorite format. Think notepad-on-screen copy-paste tutorials with zero context. To fill in the gaps, I leaned heavily on Claude — pasting blobs of the lab guide and asking things like "why did stealing this token give me X but not Y?" — and it did a great job standing in where a live instructor would normally add color and context. Exam tips (spoiler-free, I promise): — A few things that helped me: I had Claude build me a CliffsNotes study guide from all our study-session chats — token context, command flags, the works. Before hitting start on the 24-hour clock, I fed Claude a list of all the tools I'd been using in the lab and had it build a one-shot PowerShell script to pull them all down from GitHub onto a fresh Windows VM. If your exam lab environment fails to spin up (as mine did in the US region), just try a different region — UK worked great for me. Enumerate. Enumerate. Enumerate. Know your tools, know which ones cover which areas of an Azure tenancy, and know how to get more verbose/tabular output when you need it. Take screenshots and notes as you go — the lab closes after 24 hours and you've got 48 hours to submit your report, so if you forgot to grab a screenshot of a flag… you are SOL, my friend. The exam itself: — I started around 5:30 p.m., wrapped up around 11 p.m., and had the final flag captured, a full Word report drafted, and was in bed at a reasonable hour. Submitted the report the next morning after the gym and a mint hot cocoa, and had my pass confirmation back well within their 7-business-day window. Private pen test training is happening: — I'm currently running a private 3-day session of our Active Directory pen testing class (version 2.0 — it got a big facelift!). It's built on the Game of Active Directory platform and we fully pwn three separate domains over the course of three days. If you can send 3–7 people, reach out at 7MinSec.com/training to line up a private session. I'm also building an interest list for a public version later this fall (reach out if interested)! Also: check out 7MinSec.club — I dropped a little show-and-tell video over on 7MinSec.club this week giving you a peek at what the training looks like in action. Dad's funeral: — I shared some words at my dad's service this past Saturday and wanted to capture them here while they're fresh, since this podcast is basically my journal at this point. The service was perfect — very "him." He'd actually written funeral instructions (yes, they literally sat in a safety deposit box for years) specifying things like: max 10-minute message from the pastor, specific Bible verses, specific songs, and — my favorite — if the service runs over 45 minutes, someone needs to pull the fire alarm. He came up with that final instruction at his brother's funeral, which ran nearly two hours. He leaned over, squeezed my knee and said, "If my service goes over 45 minutes, pull the fire alarm." The song: — I played and sang at the service. The song was "Jesus Savior Pilot Me" — not a personal favorite of my dad's exactly, but he called it "the one about Jesus flying airplanes" after seeing me perform it years ago at the Minnesota State Fair chapel. I practiced it in the car on the way to Caribou every morning until I could get through it without crying. My guitar teacher's advice: close your eyes, focus on your fingers, and pretend you're just playing a tune in a room. It worked. Mostly. Thank you: — Seriously, so many of you have sent kind messages and I just want you to know it means the world. He taught me a lot about being a good dad, a good husband, and how to live with passion, a good attitude about your work, and a heart for serving others.
570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin. Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPenti for the July 2026 rundown:An Active Directory Federation Services bug (CVE-2026-56155) already exploited in the wild, rated a deceptively low 7.8A 9.8 DHCP client flaw (CVE-2026-49181) that reaches every Windows endpoint on the networkAn RDP bug you can shut down with a single setting, no patch requiredA SharePoint deserialization flaw (CVE-2026-50522) reachable by anyone with site-owner accessA 9.9 Hyper-V escape that lets one compromised VM take the whole hostA BitLocker bypass (6.1) worth knowing if you manage laptops in the fieldPlus why hacker summer camp turns every July into a bug dump, and what a 570-CVE release says about how much AI is really driving vulnerability discovery.
This episode features Tim Wolf, Senior Solutions Architect at Semperis, and Tim Springston, Principal Product Manager for Recovery Solutions at Semperis.Tim Wolf spent years as a Microsoft Premier Field Engineer helping enterprise customers architect identity solutions at scale. Tim Springston brings 25 years in identity and security and served as Microsoft's product manager for Azure AD recoverability, including direct involvement in building the Entra ID shared responsibility model documentation.In this episode, they walk through what the shared responsibility model actually means for Entra tenant data, how token-based attacks sidestep phishing-resistant authentication, and what happens when a threat actor hard-deletes objects and locks you out.They examine where Microsoft's new Entra ID Identity Resilience Recovery feature stops short, and why planning your recovery before anything goes wrong is the only call to action that matters.Guest BiosTim Wolf Tim Wolf is a Senior Solution Architect at Semperis. Tim's mission is protecting identities. Currently at Semperis, Tim ensures the resilience of Active Directory and Entra ID. Their background includes years as a Microsoft PFE, implementing Zero Trust and modern Authentication like Fido at an enterprise scale. Tim is an active speaker at multiple conferences, advocating for secure and automated identity architectures.Tim Springston Tim Springston is Principal Product Manager for recovery solutions at Semperis. He has over 25 years' identity and security experience with education, government, and Fortune 500 organizations from around the world. In his 25 years at Microsoft, he led services and support for Active Directory and later for Microsoft's cloud identity platform as it evolved from Windows Azure AD to Azure AD. At Microsoft, he was a recurring speaker at internal TechReady conferences and external events. Prior to Semperis, Tim was Microsoft's product manager for Azure AD (now Entra ID) recoverability and Sophos' IAM product manager for the Sophos Central cybersecurity platform.Guest Quotes “The first step in resiliency is not just having a backup plan or a backup tool or capabilities to put things back. You need to know what's important to your organization. If you know what's important, you know what to put back, you know when it's broken.” - Tim Springston “If Entra ID is going down... This is business critical today. You're not available to sign in to Teams, to SharePoint, to Salesforce, to your business critical application. So to really understand Entra ID is business critical.” - Tim WolfTime stamps 0:40 Meet Tim Wolf and Tim Springston 2:32 The Microsoft Shared Responsibility Model for Entra ID 6:22 How Entra ID Tenants Are Being Attacked 8:45 Token-Based Attacks Explained 12:26 What Happens When a Threat Actor Takes Over Your Tenant 19:05 Microsoft's New Entra ID Recovery Solution 25:24 The Difference Between Accidents and Adversaries 28:54 Semperis' Disaster Recovery for Entra Tenant 39:27 Hard Delete and Tenant Cloning Limits 45:30 Resiliency Playbooks and Testing 49:58 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Tim Wolf on LinkedInConnect with Tim Springston on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Hey friends! Still your grieving pal over here, but also your happy hacking host — because today we're diving into baby's first Dracarys! (Yes, I'm probably pronouncing that wrong. Yes, I'm going to keep saying it anyway.) Quick housekeeping: A few days ago I published a mini-series episode from our How to Secure Your Family During and After a Disaster series, where I shared the news that my dad passed away last Friday. So many of you reached out with condolences — thank you from the bottom of my heart. I'll share a little life update at the end of this episode. But first — Dracarys! I didn't know it existed until recently. If you knew about it and didn't tell me, I'm mad at you. But we made up. We're friends forever. Here's what we cover: What is Dracarys? It's a smaller, CTF-style Active Directory pentesting lab from the same crew that brought us Game of Active Directory (GOAD), GOAD-SCCM, GOAD-Light, and Ninja Hacker Academy. Where GOAD holds your hand through the vulnerabilities, Dracarys and Ninja Hacker Academy take more of a "here's your starting point, now figure it out" approach — which I love. The lab setup: One Linux VM, a Windows domain controller, and a Windows application server. Your only hint? Start with the Linux box. That's it. Good luck! TuesdayTOOLSday preview: Over on 7MinSec.club, I did a TuesdayTOOLSday episode walking through initial setup — getting your hosts file configured, running a NetExec sweep to map out the attack surface, and doing some light enumeration on that Linux box. No big spoilers, just enough to get your Kali box ready to rock. What I've learned since: After the TuesdayTOOLSday recording, I kept digging. My methodology has been: nmap to identify open ports and service versions, then research whether any of those versions have known exploits. Once I spotted an interesting web service, AI pointed me toward FeroxBuster for directory and file enumeration — a tool I hadn't used before but am now a huge fan of. It's fast, configurable, and once I got my scan tuned properly… I found a jewel. That jewel feels like the next step deeper into this lab. More on that in future TuesdayTOOLSday episodes! Shameless plug: All of this walkthrough content lives at 7MinSec.club. Subscriptions are free, and subscribing just means you get an email when I publish new content. No spam, no sales pitches — just hacking stuff. (And if you want to financially support the show, there's a paid tier too. Just sayin'.) Life update: We've moved into funeral planning mode. My dad, thankfully, had already mapped out his whole service — the pastor, the verses, everything — which has made things a little easier. We're picking photos for a tribute slideshow and I've been asked to share some words and sing a song. The song I chose is "Jesus, Savior, Pilot Me" — which my dad once described as "that song about Jesus flying airplanes." (He wasn't wrong. Sort of.) I've been practicing it all week and can barely make it through verse two. Prayers, good vibes, and a large supply of Kleenex would be appreciated. Again, you can find the Dracarys lab here. And if you're not already on 7MinSec.club, come hang out — that's where the deeper dives live.
In this episode Spencer and Tyler discuss real life Active Directory attack paths, taken from real internal pentest engagements over the last several years.Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
Red teaming isn't about running tools - it's about thinking and operating like a real adversary. While standard vulnerability assessment tracks focus heavily on scanning known exploits, true offensive simulation demands a deep understanding of attacker psychology and stealth execution. In this comprehensive skills masterclass, InfosecTrain pulls back the curtain on what it truly takes to break into elite corporate adversary emulation roles.The "course titled" Red Team Offensive Security Training provides the tactical foundation necessary to execute advanced, full-scope security assessments without setting off enterprise blue team alarms. We break down the complete operational lifecycle from open-source intelligence gathering to achieving domain controller compromise. Discover how to move beyond static scripts, weaponize initial access vectors, maintain persistence, and leverage automated tools like MITRE Caldera to simulate sophisticated, state-sponsored cyber threats.
Hey friends! This is a tough one to write. My dad passed away on Friday, and instead of the hacker-y tech episode I had planned, I pivoted to something more personal — another installment of our "Securing Your Family During and After a Disaster" series. I talk pretty raw and transparently today about loss, grief, and the practical stuff that makes a hard situation just a little less hard. Fair warning: it's about death and dying, so if that's not where your head is today, it's totally okay to duck out – we'll catch you next week. Here's what I cover: My dad's last day — He spent Thursday doing all his favorite things: chainsaws, ATVs, trap-shooting, mowing, and weed-whipping. Then Chinese food with the family and marveling at modern video games for the first time since the Atari 5200. It was, by all accounts, a perfect day for him. How we found out — My son Cameron, who's finishing up paramedic school, was visiting and sprung into EMT mode when my dad was found unresponsive Friday morning. He did CPR for 10 straight minutes — on his grandpa, who was his favorite person in the world. That's the stuff that's going to stay with Cam (and me) for a long time. Getting some closure — Cameron had the presence of mind to ask the paramedics to leave my dad in place so I could have a few minutes with him when we arrived. That was both devastating and, in its own way, healing. Why pre-planning your funeral is a gift to your family — My parents had nearly everything already picked out: the pastor, Bible verses, music, the military honors ceremony, photos for the display board, and even a time limit on service length (45 minutes and no more!). My dad had pre-written his own obituary. When we sat down with the funeral home, the heavy lifting was already done — and that was a genuine gift to all of us in an incredibly hard moment. Storyworth — seriously, do this — Years ago we signed my dad up for Storyworth, a service that sends your loved one a weekly question via email (things like "What's your earliest childhood memory?" or "Do you have any regrets?") and compiles their answers into a hardcover book. It runs about $100. Reading that book the last few nights has been incredibly comforting — including finding out my dad started smoking at age 8 using used cigarette butts rolled in toilet paper. Gross! Get your end-of-life wishes in writing — My wife's mom had verbally told us she wanted to be cremated, but it wasn't documented, and other family members made a different call. My dad put "cremation" right in his paperwork, no ambiguity. My recommendation: have this conversation with your loved ones, write their wishes down and make them official. Funeral home "upsell" moment — I had no idea there were apparently 627 ways to incorporate your loved one's remains into keepsakes — pendants, rings, necklaces with fingerprints, biodegradable urns for water scattering, etc. Some family members were very into this. I was not quite ready to turn my dad into an Atari cartridge, but your mileage may vary. On grief itself — Everybody handles it differently, at different speeds and intensities. My approach is to head straight into it rather than put on a happy face and deal with unprocessed grief years later. I encourage everyone — especially the kids — to not hold back. Ask the questions. Tell the stories. Cry if you need to. Give each other grace. Coming up next week — Back to pentesting content! I'll share details on a new lab from the folks who brought us Game of Active Directory, and I'm getting back on the CARTP (Certified Azure Red Team Professional) horse. I'm also tentatively eyeing the third Thursday of July for an unedited livestream of owning Ninja Hacker Academy from start to finish — Kali setup, tools, Mythic C2, BallisKit obfuscation, the whole thing. More details to come. If you're the thoughts, prayers, and/or good vibes type, I'd really appreciate you sending some my family's way over the next few weeks.
This episode features Jim Bowie, VP and CISO at Tampa General Hospital, joined by co-host Courtney Guss, Director of Crisis Management at Semperis.Jim began his career in EMS and law enforcement before moving into cybersecurity, giving him a grounded understanding of how operational continuity and human outcomes intersect during a crisis. At Tampa General, he leads teams spanning network security, operations, IAM, and GRC, and has built a training culture centered on adversarial simulation, monthly range of exercises, and regular DR drills.In this episode, Jim argues that rehearsal is the highest-leverage move for resource-constrained security teams and explains why an outage is an outage regardless of cause. He covers why identity is consistently the weak point in every simulation and why the relationships you build before an incident are the ones that matter most.If your organization is still treating recovery as an afterthought, this episode will change how you think about it.Guest BiosJim Bowie Jim Bowie is the Vice President and Chief Information Security Officer (CISO) at Tampa General Hospital (TGH). Jim is an accomplished leader with decades of cybersecurity experience and leadership in threat hunting, incident response, threat intelligence, and security operations. He is a strategist with demonstrated ability to bridge between security, infrastructure, and business needs and has experience leading multiple areas in information technology, including cloud infrastructure and security, with exceptional results in employee engagement and productivity.Courtney Guss Courtney Guss is the Director of Crisis Management at Semperis, with over 20 years of experience spanning cybersecurity, risk management, and crisis response. She specializes in helping organizations navigate high-impact incidents—from ransomware attacks to regulatory reporting—by orchestrating clear, business-aligned response strategies. Courtney is passionate about transforming crisis chaos into operational clarity.Guest Quote "You absolutely need a technology component to your program. But at the end of the day, that tech is surfaced to a person in the chair. And if that person's not up to speed, there's no amount of tech that's going to help them and help you get through a crisis."Time stamps 01:45 Meet Jim Bowie: Veteran Cybersecurity Leader 02:38 Healthcare Crisis Management Challenges 04:18 Training Beats Budget 06:46 Clinician Buy-In 07:00 Community Ripple Effects 10:23 Mutual Aid Agreements 12:45 Hurricane Drills as Cyber Drills 14:39 Adversarial Practice Culture 17:30 Making Training Time Non-Negotiable 20:14 Recovery Focus and Identity 26:35 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Jim on LinkedInConnect with Courtney on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Think Active Directory is dead? Think again. According to Microsoft data, 86% of organizational workloads still touch Active Directory, and nearly 20% of organizations don't expect to reach a hybrid state for 10-20+ years. In this episode, Brad and Spencer break down why AD attack paths remain one of the most critical threats in enterprise environments and what defenders can do about it right now.Spencer also previews his ContinuumCon workshop "Killing AD Attack Paths Once and For All" where he demonstrates how authentication policies and silos can eliminate an entire class of lateral movement attacks built into Windows and Active Directory.In this episode:- Why Active Directory is still alive, well, and heavily targeted- What an Active Directory attack path is and how attackers use them- The four prerequisites attackers need to abuse AD attack paths- Real-world examples: Kerberos ticket theft, SCCM abuse, certificate misconfigurations, and misconfigured permissions- Tools defenders should know: Bloodhound, PingCastle, Purple Knight, Locksmith, and ADelegator- How to prioritize remediations based on ease of exploitation vs. impact- Why retesting is the most overlooked step in any remediation cycleResources mentioned:- Spencer's ContinuumCon Workshop (Fri. June 12, 10:30am PT / 1:30pm ET): https://continuumcon.com/schedule/- Hybrid Identity Protection Podcast (Semperis): https://www.semperis.com/hybrid-identity-protection-podcast/- Bloodhound CE: https://github.com/SpecterOps/BloodHound- PingCastle: https://www.pingcastle.com- Purple Knight: https://www.purple-knight.com- Locksmith: https://github.com/TrimarcJake/Locksmith- offsec.blog | securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
This episode features Geoffrey Mattson, CEO of SecureAuth, joined by co-host Sarah Cicchetti, Director of Product Management at Semperis.Geoffrey has spent decades building and leading companies at the intersection of AI and cybersecurity, including MistNet.ai, an AI-native threat detection platform acquired by LogRhythm, and Xage Security, where he drove zero trust adoption across the U.S. military, global energy firms, and Fortune 500 enterprises. At SecureAuth, he leads a platform built around continuous, real-time identity authority across workforces, APIs, and AI agents.In this episode, Geoffrey argues that agents combine the speed of automation with the unpredictability of humans, making real-time per-action authorization the only viable control model. He discusses why “friendly fire” from well-meaning employees is the biggest threat vector right now, how MCP vendors are ignoring their own OAuth spec, and what a practical agent rollout with real guardrails actually looks like.This episode reframes authorization as the problem the identity industry has been deferring for years and can no longer avoid.Guest Bio Geoffrey Mattson is a serial entrepreneur and globally recognized cybersecurity and AI executive with decades of experience building market-defining companies and technologies that protect the world's most critical systems.He is currently CEO of SecureAuth, a leader in AI-driven identity and access management with its Continuous Authority, ensuring ongoing verification across workforces, customers, APIs, and AI agents. This is enabled through its Private Authority Platform, which puts authentication and authorization under your control through any deployment model (cloud, on prem, hybrid, air-gapped).Prior to SecureAuth, Mattson served as CEO of Xage Security, where he led the company in Zero Trust for critical environments from energy to agentic AI. Under his leadership, Xage achieved rapid adoption across the U.S. military, global energy firms, and Fortune 500 enterprises.Previously, Geoffrey Mattson was co-founder and CEO of MistNet.ai, an AI-native threat detection platform acquired by LogRhythm. He pioneered decentralized analytics and machine learning approaches for real-time cyber defense, and later served as SVP of Product at LogRhythm, driving global expansion and shaping the next generation of SIEM/SOAR solutions.Earlier, he held senior executive roles at Juniper Networks, overseeing a $2B product portfolio and leading major M&A efforts, and at Huawei Technologies as SVP and CTO for networking and data center platforms. His engineering leadership at Corona Networks, Caspian, and Bay Networks helped build foundational technologies in network and security architecture.Guest Quote “With agents, you have the power and the speed of an automated process with the unpredictability of a human. And in fact, we are seeing their behavior and their psychology makes them even perhaps less predictable than a human.”Time stamps 01:45 Meet Geoffrey Mattson: Serial Entrepreneur and Cybersecurity Executive 02:40 Why Identity Is Having a Moment 08:40 Defining Agent Identity 12:15 Behavioral Guardrails for Agents 14:37 Agent Identity Lifecycle 17:36 Just-in-Time vs. Standing Privilege 18:02 C-Suite Pressure and Friendly Fires 21:00 When Agents Live Off the Land 26:12 MCP, OAuth, and Token Pitfalls 28:04 Threat Models and Rollout Strategy 30:13 LLMs and Policy Authoring 31:23 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Geoffrey on LinkedInConnect with Sarah on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Frank Lesniak joins Andrew Pla for a wide-ranging conversation that covers Frank's newly minted Microsoft MVP status, his journey through PowerShell, and what it looks like to build a real presence in the tech community. Frank talks through the pipeline struggles that tripped him up early on, how his VB Script and object-oriented background made the shift to PowerShell's object model feel disorienting, and how AI has quietly changed the way he approaches scripting today. The conversation takes a thoughtful turn as Andrew and Frank dig into impostor syndrome, the value of conference speaking, and how showing up consistently in the community compounds into a career. Frank also shares an update on DuPage Animal Friends, the nonprofit he serves, which supports one of the country's highest-performing open-admission animal shelters. Key Takeaways: The PowerShell pipeline is one of the most commonly cited stumbling blocks for newcomers, especially those coming from text-based scripting backgrounds. Learning to visualize what your objects look like at each stage of the pipeline, using tools like Get-Member, is a skill that pays dividends long term. Showing up at conferences and user groups, even when you feel underprepared, is how you build the reps that eventually make it feel natural. Frank's consulting background gave him a head start on presentation skills, and he's clear that no one is born polished. Community involvement and career growth are more connected than they might look from the outside. Engaging with people on GitHub, at events, and through open source creates a feedback loop that builds confidence and opens doors. Guest Bio: Frank Lesniak returns to The PowerShell Podcast, this time as a Microsoft MVP (Microsoft Azure, PowerShell). Frank is a Sr. Cybersecurity & Enterprise Technology Architect at West Monroe, where PowerShell runs through client work on corporate M&A: carve-outs, tenant-to-tenant migrations, identity consolidation, endpoint moves, and security posture improvement across Microsoft 365, Azure, Entra ID, Active Directory, Intune, Defender, and Windows. Beyond consulting, Frank speaks at technical conferences, mentors first-time speakers, and publishes open-source PowerShell standards and tooling, including PSStyleGuide, GloryRole, and PSConnMon. His public work threads least-privilege identity, cloud role mining, cross-platform observability, and high-quality AI-assisted development through standards, automated tests, and automated code quality reviews. Connect with Frank: https://linktr.ee/franklesniak Connect with Andrew: https://andrewpla.tech/links PSConnMon - PowerShell Network Monitoring - https://github.com/franklesniak/PSConnMon/ GloryRole - Automating Least-Privlege Azure and Entra ID Directory Roles - https://gloryrole.com PowerShell Style Guide - https://github.com/franklesniak/PSStyleGuide PowerShell Style Guide + Coding Agents Lightning Talk - https://github.com/devops-collective-inc/pshsummit26/tree/main/PowerShellStyleGuideForCodingAgentsAndHumans-Lesniak Coding Agent Accelerator Template Repo (Coming Soon!) - https://github.com/franklesniak/copilot-repo-template ProStateKit - the DSC v3-Intune Starter Kit - https://github.com/franklesniak/ProStateKit ProStateKit Promotional Commercial - https://www.youtube.com/watch?v=cA5vMH522F0 macOSLab - Automating Legit macOS VMs - https://github.com/franklesniak/macOSLab DuPage Animal Friends - https://www.dupageanimalfriends.org/ PDQ Discord: https://discord.gg/pdq The PowerShell Podcast: https://www.pdq.com/resources/the-powershell-podcast/ Previous episodes with Frank Lesniak: https://powershellpodcast.podbean.com/?s=Frank+Lesniak The PowerShell Podcast on YouTube: https://youtu.be/Eg-uEGaurmY
This episode features Mark Diodati, Managing Vice President for Identity and Access Management at Gartner.Mark has spent two decades shaping how the industry thinks about authentication, privileged access, and cloud identity, working with renowned companies like Ping Identity, CA, RSA, and now, Gartner. Today, he leads Gartner's global IAM for Leaders analyst team and sets its research agenda across the full identity stack.In this episode, Mark explains how Gartner's research model works and what his team is prioritizing across identity verification, authorization, ITDR, and decentralized identity. He also breaks down what AI means for identity right now and why securing AI agents is harder than most teams realize.This episode is a deep dive into where identity is heading from someone whose job is to listen to everyone.Guest Bio Mark Diodati is the Managing Vice President for Identity & Access Management at Gartner.Mark is a longtime identity pioneer who helped shape the way the industry thinks about authentication, privileged access management, and cloud identity. He leads a large team of analysts, sets the global IAM research agenda, and rigorously reviews every document to keep the bar high. Before that, he guided Gartner's IAM research for technical professionals, chaired major industry conferences like Catalyst Europe and the Cloud Identity Summit, and drove triple-digit growth in attendance and sponsorships. Earlier in his career, he held key leadership roles at CA, RSA, and Ping Identity, influencing product strategy and partnerships that many identity practitioners rely on today.Guest Quote " One thing we're critically aware of at Gartner is that nobody knows everything. It's impossible.”Time stamps (02:11) Meet Mark Diodati: Identity Analyst and IAM Research Leader (06:00) Inside Gartner: Research, Conferences, and Consulting (09:18) Hiring and Training the Gartner Analyst (15:26) How the Inquiry Process Works (24:07) Gartner Research Products for Identity Professionals (28:02) IAM Research Priorities Right Now (32:31) AI and Identity: Opportunity and Risk (39:35) A Musical Moment with Mark (44:26) Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Mark on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Hello friends! Today's a hybrid episode — some security content up top about a new certification I've kicked off, followed by an aggressively quick trip to Tangent Town. Feel free to bail after the security stuff if tangents aren't your thing! The security part: starting CARTP I've started the Certified Azure Red Team Professional course from Altered Security (enterprisesecurity.io). It's the Azure follow-up to CRTP, which I took a few years back. Quick notes: Why now: Active Directory and internal pentests will always be my first love, but more and more of our customers are shifting to hybrid or full-Azure environments. Time to get some formal training in that lane. Self-paced vs. live: They offer both. I'm past the point of giving up Saturdays to security training, so I went with the ~$500 self-paced 30-day option. You get a portal, a lab manual, and a remote Windows VM with low-priv creds into a target Azure tenancy to attack and enumerate. The catch: The lab manual is thorough on "do this, see this output" steps, but light on "and here's the wow moment hiding in line 47 of the output." With the live class, an instructor would highlight that stuff in real time. In the self-paced version, you're on your own to find the meaning in 200 lines of output. The fix: Started a Claude project that's effectively co-teaching the class with me. I paste command output and ask "what's the important bit here?" — Claude pulls out the line that matters and explains why (e.g., "this user has write access to a key vault, which means…"). Way more efficient than ALT-TABbing alone. Tools I've touched so far: ROADtools, GraphRunner, and Monkey365 (kind of a PingCastle-for-Azure that spits out a health-check report). Where I'm at: Module 4 of 40-something. Course culminates in a 24-hour exam, which I swore I'd never do again after CRTP — but James Bond and Justin Bieber both say "Never say never." Tangent Town: The Shake Shack incident. It's gross and not funny. But kind of funny. Saw (and sort of met) Calum Scott at the Fillmore in Minneapolis. Standing-room-only venue, but my wife found a clutch spot wedged between a security barrier and a support beam, perfect for our family. During an acoustic set, Calum and his band came right past us. My wife (unable to help herself) gave his shoulder a squeezy squeeze. I held out for the fist bump on his return trip to the stage — and we're basically best friends now. I highly recommend his show: very positive guy, family-friendly, genuine. Seven super-fast non-spoilery movie reviews from plane rides and hotel nights: Coherence — for smart people. I am not those people. Probably great if you can follow it. Deadstream (Netflix) — YouTuber live-streams a night in a haunted house. Surprisingly entertaining, a couple of real jump-scares. Get Away — a family vacations on a forbidden island. Goes somewhere unexpected in the third act. Hell House LLC — found-footage haunted house. A couple of genuine flinches; story was just OK. Hokum — Adam Scott as a writer at a hotel with a personal history. Creepy-crawly, goes to some dark places. Loved it. Predator: Badlands — went in expecting mind-numbing action, but I loved it! I'd give it an 8 or 9 out of 10. It had action, LOLs, and even some tender Predator moments. Going to watch it again soon. Obsession — young man buys a wish-granting trinket so a young lady will like him. It works. Then it really works. The movie slowly goes into full-on bonkers sauce mode! Satisfying but uncomfortable to watch at parts. That's it! 7MinSec.com for services, 7MinSec.club for the Substack, 7MinSec.wiki for pentest tips and scripts.
L'intelligence artificielle bouleverse les usages dans les entreprises, mais elle ouvre aussi une nouvelle génération de risques cyber. Entre Shadow AI, fuite de données, agents autonomes et manipulation des chatbots, les organisations découvrent un terrain encore largement incontrôlé.
This episode features Angie Klein, IAM Business Technology Manager at Federated Insurance.Angie brings over a decade of experience spanning systems development and identity security leadership, holding CISSP, CIDPRO, and CISM certifications and working hands-on with CyberArk, SailPoint IDN, and Active Directory in a regulated environment.In this episode, Angie dives into the organizational and cultural work that most identity programs skip. She shares why identity deserves its own program, how to apply OCM to bring resistant stakeholders on board, and why governance must come first. Angie's core argument is that if identity security creates too much friction, people will route around it, and that's where the real risk lives.This episode makes the case that the hardest part of identity security isn't the technology, it's getting people to trust it enough to stop working around it.Guest Bio As the IAM Business Technology Manager at Federated Insurance, Angie is dedicated to advancing our Identity and Access Management program and the industry as a whole. With over 10 years of experience and currently leading a team of Security Engineers and Identity and Access Analysts, Angie is passionate about IAM and love to see "ah ha" moments when colleagues understand that security is everyone's job.Angie bring over a decade of experience as a Systems Developer, providing extensive technical expertise in the Identity Security domain. I hold certifications, including CISSP, CIDPRO, and CISM. Additionally, she has experience working in the insurance industry and am skilled in CyberArk, Active Directory, SailPoint IDN, Analytical Skills, Project Management, and Public Speaking.Guest Quote "Identity security is ultimately about trust. People have to trust that you are doing the things that will help them do their job securely and not stop them from doing their job."Time stamps 01:45 Meet Angie Klein: Expert IAM Practitioner 01:22 Why Identity Needs Its Own Program 04:30 Why Identity Programs Stall 07:27 Organizational Change Management (OCM) Explained 12:51 OCM in Action 17:08 How to Gain Buy-In for an Identity Security Program 25:05 First Steps for Standing Up a Program 30:22 The Core Pillars of Identity Security 35:00 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Angie on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
How secure is your Active Directory infrastructure? While at Zero Trust World in Orlando, Richard chatted with Spencer Alessi about his work helping companies secure Active Directory, making it more difficult for black hats to exploit it for lateral moves during a breach attempt. Spencer talks about the increasing speed of these exploits, making it much harder to block them after the fact, so it's best to make AD too difficult to target. Jake Hildreth's Locksmith tools are a great place to start - free and open source. There are also Microsoft tools and Spencer's own AD Security Resource Kit to help evaluate your AD infrastructure and lock it down! Links Locksmith Enhanced Security Admin Environment Active Directory Security Resource Kit Recorded March 4, 2026
This episode features Sarah Cecchetti, Director of Product Management at Semperis.A veteran identity executive, Sarah co-founded IDPro and co-authored NIST SP 800-63-3C Digital Identity Guidelines. She previously led Amazon Cognito as Head of Product at AWS, where she also open-sourced Cedar, the policy language at the center of this conversation.In this episode, Sarah presents her Bsides Seattle talk "Identity Crisis: IAM's Wild Ride in the AI Jungle" on why the assumptions that shaped modern identity have been overturned by the pace of agentic AI. She covers where authentication and authorization standards currently fall short for non-human identities and walks through the emerging frameworks the industry is building to fill that gap.This episode makes the case that natural language safety instructions are not a substitute for provable, external guardrails.Guest Bio Sarah Cecchetti is a seasoned technology executive driving product management at Semperis. At AWS, she led Amazon Cognito to triple-digit growth as Head of Product and led the open-sourcing of Cedar, a new access management language. She co-founded IDPro and co-authored NIST SP 800-63-3C Digital Identity Guidelines. Sarah has designed secure identity systems for corporate clients as well as US and Canadian governments and is recognized as a top identity professional by Okta Ventures and OWI. She's a keynote speaker at global identity conferences like Identiverse and Authenticate.Guest Quote “[The] average enterprise has 250,000 non-human identities, and 97% of those have excessive privilege. And 68% of organizations lack AI identity controls...The concept of excessive privilege has almost been accepted by the industry at this point. That's just the way it's done.”Time stamps 01:45 Meet Sarah Cecchetti: Seasoned Identity Executive 02:36 Sarah's Bsides Seattle Talk: Identity Crisis: IAM's Wild Ride in the AI Jungle 04:19 How Deepfakes Broke Biometrics 06:37 The Scale of Non-Human Identities 09:34 How NHIs Differ from Human Identities 10:38 Why FIDO Doesn't Work for AI Agents 12:19 Introducing SPIFFE and Workload Identity 15:45 How SPIFFE Works in Practice 17:34 Where AI Protocols Are Falling Short 21:12 The Problem with OAuth Client Credentials 23:18 Dynamic Registration and Database Sprawl 24:38 Client ID Metadata Documents Explained 28:43 Authentication Standards: Who Wins the Client ID Field? 30:21 Cedar: Deterministic Authorization for AI Agents 33:58 Clawdrey Hepburn: Sarah's AI Agent in Practice 40:09 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksOAuth Client ID Metadata DocumentConnect with Sarah on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
In Episode 178 of the Cyber Threat Perspective podcast, hosts Spencer and Tyler take a practitioner-first look at the internal security controls that genuinely make attackers' lives difficult, drawing directly from their experience conducting hundreds of internal penetration tests every year.This isn't a vendor comparison or a theoretical framework. It's an honest account of what works, what gets misconfigured, and what separates organizations that slow attackers down from those that don't.Topics covered include:Application Control — ThreatLocker and Magic Sword — why app control is probably the single most effective endpoint control against attackers, how the learning period works, why jumping straight to enforcement mode is a mistake, and why executive buy-in is as critical as the technical implementationWDAC vs. traditional App Locker — the differences, what closed-book enforcement actually means for attackers, and the two schools of thought on allow-list vs. block-list approachesStrong identity controls — MFA beyond RDP including SMB, WinRM, and HTTP via products like Silverfort, why push notification MFA falls short, and why number matching mattersProtected Users Group — one of the most powerful and underused Active Directory controls, with a real-world story of how it nearly matched a full third-party identity product in effectiveness during a law firm pen testLeast privilege and admin tiering — why Help Desk is one of the most targeted groups for social engineering, how over-permissioned service accounts hand attackers domain admin in minutes, and the real cost of control path vulnerabilitiesNetwork segmentation and zero trust — why domain controllers don't need internet access, how segmentation limits attacker recon, and where products like Zscaler fit inEDR baselining and UEBA — why plugging in an EDR tool and expecting it to work isn't enough, the case for getting back to behavior-based detection, and why catching recon activity matters more than catching executionDeception — honeypots, canaries, and fake assets — why deception is underrated, why high-fidelity low-false-positive alerts change the game, and what it actually feels like as a pen tester to trip on a well-placed decoy without knowing itAlso mentioned: Spencer and Brad's Tools of the Trade workshop at ILTA Evolve — Denver, end of April.Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
This episode features a virtual roundtable hosted by Michele Crockett, Associate VP of Product Marketing at Semperis.The panel brings together five practitioners with deep experience in identity security: Alex Weinert, Chief Product Officer at Semperis; Christopher Brumm, Cyber Security Architect at glueckkanja; Eric Woodruff, Chief Identity Architect at Semperis; Jorge de Almeida Pinto, Senior Incident Response Lead at Semperis; and Michael Van Horenbeeck, CEO and Senior Solution Architect at The Collective Consulting. Collectively, they represent experience across incident response, Microsoft product development, enterprise architecture, and security leadership.In this discussion, the panel addresses how to allocate limited security budgets across prevention and recovery, why the same AD misconfigurations keep appearing in assessments year after year, and what AI means for defenders and attackers alike.This episode is a practical, field-tested conversation about what moves the needle when resources are constrained.Guest Quote "80% of permissions that are out there are users that have access to systems they don't need. Going back to that Tier 0 system, a hundred percent of what's got access to Tier 0, you should know what it is, why it has access, why it needs it, [and] what's going on... Any apps that you can't prove what they're there for, turn them off. See who yells."Time stamps 0:00 Meet the Panelists 00:00 AI in Cybersecurity 02:23 Budgeting for Identity Security 05:08 Field Lessons and AD Misconfigs 08:48 Prioritizing Prevention and Funding 12:59 Current Attacker Trends 14:56 Hybrid and Multi Cloud Risks 17:02 Entra Private Access POC 18:28 Lightning RoundSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Alex on LinkedInConnect with Chris on LinkedInConnect with Eric on LinkedInConnect with Michael on LinkedInConnect with Jorge on LinkedInConnect with Michele on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Thank you ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal // Spencer Alessi's SOCIAL // YouTube: / @techspence Website: https://spenceralessi.com/adsecuritykit/ X: https://x.com/techspence LinkedIn: / spenceralessi Swag: https://www.etsy.com/shop/ethicalthre... // ThreatLocker's SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:54 - Spencer Alessi introduction & background 02:20 - Pentesting demo // Active Directory 03:34 - Control paths // Finding bad permissions with ADeleg 06:04 - Finding bad permissions with NetTools 06:52 - The most common issue 08:15 - Certificate abuse 12:20 - Quick recap 12:30 - Certificate abuse continued 15:10 - Pentesting summary 15:09 - How to become a pentester 18:48 - Recommended certifications 20:54 - Advice for blue teamers 22:15 - Overcoming being an introvert // Soft skills vs tech skills 23:43 - Windows hacking in the real world 24:54 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #microsoft #windows11 #hacker
Summary On this episode of Chattinn Cyber, Marc is chattin' with Ben Wilcox, Chief Technology Officer and Chief Information Security Officer at ProArch. Their chat opens by focusing on high-impact, practical ways organizations can reduce cyber risk. Ben highlights identity as the top priority: his team moved to passkeys to remove passwords and lower the attack surface. He stresses that threat actors increasingly use man-in-the-middle techniques and that AI has accelerated the automation of credential-theft, which makes strengthening identity controls essential. The chat then moves to AI and data governance. Ben describes rolling out visibility tools to monitor internal AI use — what prompts users run and what data is fed into models — and pairing that with data labeling and classification. He warns organizations to restrict where AI tools are allowed and to implement compensating data controls to prevent accidental or intentional leaks of sensitive information. Ben cautions that AI and cybersecurity must be adopted in parallel, because AI will reveal existing misconfigurations and permission drift. He gives practical examples (like Copilot showing information a user shouldn't see because of incorrect permissions) to illustrate how AI surfaces weaknesses in access controls. The takeaway is that AI can be a force-multiplier but also a magnifier of existing security gaps. On leadership and tradeoffs, Ben explains how combining CTO and CSO responsibilities can be an enabler if balanced correctly. He argues for marrying a product/technology lens with a risk lens, leveraging internal expertise, and making business enablement and security complementary so organizations can move quickly while maintaining the right groundwork. Finally, Ben addresses translating cyber risk into financial terms for CFOs and boards. He recommends business impact analysis—linking key system outages (e.g., Active Directory) to production downtime costs—to quantify risk and justify security investments. He shares real incident cost ranges (low seven figures to tens of millions in some cases), underscores the role of compensating controls, and concludes with a call to monitor industry trends, assess outage and reputational costs, and prioritize risk reduction. Key Points Identity-first approach: move away from passwords (passkeys) and reduce reliance on MFA tokens that can be intercepted or automated by attackers. AI visibility and data controls: monitor internal AI usage, restrict sites/tools, and enforce labeling/classification to prevent data leakage. AI exposes existing weaknesses: adopting AI without fixing permission drift and misconfigurations surfaces risks rather than hiding them. Speed and detection advantage: AI can accelerate detection and response in SOCs—gaining even seconds can materially reduce impact. Translate risk to business terms: use business impact analysis to quantify downtime costs and build the financial case for security investments and insurance. Key Quotes “Last year we took the initiative and we moved to pass keys.” “AI has sped up that weaponization and being able to turn that around and get those tokens automatically.” “AI is going to expose the weaknesses that are inherent within your security controls that you already have in place.” “If we can get even 5 seconds faster or 10 seconds faster or 20 seconds faster, sometimes that makes a difference.” “And that’s why they should have bought cyber insurance.” About Our Guest Ben Wilcox is a seasoned technology leader with over 25 years of experience driving innovation and solving complex business challenges. Serving as both Chief Technology Officer and Chief Information Security Officer at ProArch, Ben combines a forward-looking vision with a hands-on approach to cybersecurity. He is passionate about leveraging technology to accelerate business outcomes while embedding security best practices into organizational culture and operations. Ben's strategic mindset and dedication to excellence have strengthened ProArch's resilience and helped protect clients' data and systems. Outside of work, Ben channels his relentless drive into racing as an instructor and competitor with the Northeast Audi Club, and enjoys gardening, cooking, and spending quality time with his family. As he puts it, “Security isn’t just about defending against threats—it’s about enabling trust, protecting growth, and ensuring every decision we make strengthens the foundation of the business.” Follow Our Guest LinkedIn | Website About Our Host National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums. Follow Our Host Website | LinkedIn
In Episode 175, Spencer and Tyler break down NetTools — a free, self-contained Active Directory management and troubleshooting tool that's become a go-to for their internal penetration testing engagements.They start with the backstory: years of relying on AD Explorer from Microsoft Sysinternals, and the growing need to evade EDR detections. At one point, that meant manually obfuscating binaries with a hex editor. NetTools eliminates that friction entirely — no installation, no dependencies, no signatures to fight.Topics covered include:Why NetTools replaced AD Explorer and how EDR pressure forced the shiftGroup Policy enumeration, including how to spot dangerous GPO permissions like authenticated users with write access to server OUsLDAP Search & Browser for querying AD, identifying risky data (like passwords in descriptions), and exploring object relationshipsAssigned Trustees & Permissions Reporter for fast, visual identification of misconfigurationsHow to run NetTools from non-domain-joined machines using saved credential profilesPassword checker functionality for targeted validation without spraying the environmentFor pentesters, it's a faster way to get visibility into AD risk. For IT admins, it's a practical way to audit and harden your environment.NetTools combines the functionality of multiple tools into one portable utility. Learn more at nettools.net. Credit to creator Gary Reynolds.NetTools | The Swiss army knife of AD troubleshootingBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
The future of secure software is going through a mix of skills expected of humans and skills files created for LLMs. We might even posit that appsec as a discipline will fade (and that might not even be a bad thing!). Keith Hoodlet describes the skills he was looking for in building teams of security researchers and why there's still an emphasis on the ability to learn about and understand how software is built. But figuring out what skills will get you hired and what skills are valuable to invest in still feels daunting to new grads and others entering the security industry. We discuss where the role of appsec seems to be heading and a few of the security and software fundamentals that can help you follow that direction. Segment resources https://bsidessf2026.sched.com/event/2E1h4/we-pwn-the-night-growing-leading-an-31337-security-research-team?iframe=yes&w=100%&sidebar=yes&bg=no https://drive.google.com/file/d/1_zLH8vuHU1XOjEyk85WecQwSByDwxAmQ/view?pli=1 https://securing.dev/posts/if-i-were-eighteen-again/ https://research.nvidia.com/labs/lpr/slm-agents/ Then, we rebroadcast two interviews from RSAC 2026. The Identity Crisis of Agentic AI Identity security is being stretched between legacy infrastructure that was never built to be secure and rapidly emerging AI agents and non-human identities that organizations are quickly adopting. As AI accelerates, identity risk grows alongside it, making agentic security fundamentally an identity challenge—because the more access AI has, the greater both its power and potential risk. In this session, Ron Rasin explores how past gaps in areas like Active Directory and machine identities created today's blind spots, and why identity must now act as the control plane for AI-driven enterprises, with real-time enforcement before access is granted. He also highlights new innovations and partnerships enabling embedded identity controls across human, non-human, and AI identities, emphasizing that at machine speed, reactive security is no longer enough. To learn more about Silverfort and their AI Agent product, visit https://securityweekly.com/silverfortrsac. Privileged by Design: AI Agents and the New Identity Risk to Production Systems At RSAC this year, the AI conversation is getting more practical. Less “look what agents can do” and more “who's actually in control when an autonomous system can take real actions across business apps and infrastructure.” The Moltbook breach and the growing attention on OpenClaw-style agent vulnerabilities put real weight behind that question because they show how quickly agent ecosystems can scale past oversight. Today we're talking with Shashwath, CEO of P0 Security, about why identity and authorization are the quiet enablers of modern AI, where teams are losing control as non-human identities explode and what security leaders can do to keep innovation moving without turning access sprawl into enterprise risk. To learn more about P0 Security, visit: https://securityweekly.com/p0rsac. Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-376
The future of secure software is going through a mix of skills expected of humans and skills files created for LLMs. We might even posit that appsec as a discipline will fade (and that might not even be a bad thing!). Keith Hoodlet describes the skills he was looking for in building teams of security researchers and why there's still an emphasis on the ability to learn about and understand how software is built. But figuring out what skills will get you hired and what skills are valuable to invest in still feels daunting to new grads and others entering the security industry. We discuss where the role of appsec seems to be heading and a few of the security and software fundamentals that can help you follow that direction. Segment resources https://bsidessf2026.sched.com/event/2E1h4/we-pwn-the-night-growing-leading-an-31337-security-research-team?iframe=yes&w=100%&sidebar=yes&bg=no https://drive.google.com/file/d/1_zLH8vuHU1XOjEyk85WecQwSByDwxAmQ/view?pli=1 https://securing.dev/posts/if-i-were-eighteen-again/ https://research.nvidia.com/labs/lpr/slm-agents/ Then, we rebroadcast two interviews from RSAC 2026. The Identity Crisis of Agentic AI Identity security is being stretched between legacy infrastructure that was never built to be secure and rapidly emerging AI agents and non-human identities that organizations are quickly adopting. As AI accelerates, identity risk grows alongside it, making agentic security fundamentally an identity challenge—because the more access AI has, the greater both its power and potential risk. In this session, Ron Rasin explores how past gaps in areas like Active Directory and machine identities created today's blind spots, and why identity must now act as the control plane for AI-driven enterprises, with real-time enforcement before access is granted. He also highlights new innovations and partnerships enabling embedded identity controls across human, non-human, and AI identities, emphasizing that at machine speed, reactive security is no longer enough. To learn more about Silverfort and their AI Agent product, visit https://securityweekly.com/silverfortrsac. Privileged by Design: AI Agents and the New Identity Risk to Production Systems At RSAC this year, the AI conversation is getting more practical. Less "look what agents can do" and more "who's actually in control when an autonomous system can take real actions across business apps and infrastructure." The Moltbook breach and the growing attention on OpenClaw-style agent vulnerabilities put real weight behind that question because they show how quickly agent ecosystems can scale past oversight. Today we're talking with Shashwath, CEO of P0 Security, about why identity and authorization are the quiet enablers of modern AI, where teams are losing control as non-human identities explode and what security leaders can do to keep innovation moving without turning access sprawl into enterprise risk. To learn more about P0 Security, visit: https://securityweekly.com/p0rsac. Show Notes: https://securityweekly.com/asw-376
The future of secure software is going through a mix of skills expected of humans and skills files created for LLMs. We might even posit that appsec as a discipline will fade (and that might not even be a bad thing!). Keith Hoodlet describes the skills he was looking for in building teams of security researchers and why there's still an emphasis on the ability to learn about and understand how software is built. But figuring out what skills will get you hired and what skills are valuable to invest in still feels daunting to new grads and others entering the security industry. We discuss where the role of appsec seems to be heading and a few of the security and software fundamentals that can help you follow that direction. Segment resources https://bsidessf2026.sched.com/event/2E1h4/we-pwn-the-night-growing-leading-an-31337-security-research-team?iframe=yes&w=100%&sidebar=yes&bg=no https://drive.google.com/file/d/1_zLH8vuHU1XOjEyk85WecQwSByDwxAmQ/view?pli=1 https://securing.dev/posts/if-i-were-eighteen-again/ https://research.nvidia.com/labs/lpr/slm-agents/ Then, we rebroadcast two interviews from RSAC 2026. The Identity Crisis of Agentic AI Identity security is being stretched between legacy infrastructure that was never built to be secure and rapidly emerging AI agents and non-human identities that organizations are quickly adopting. As AI accelerates, identity risk grows alongside it, making agentic security fundamentally an identity challenge—because the more access AI has, the greater both its power and potential risk. In this session, Ron Rasin explores how past gaps in areas like Active Directory and machine identities created today's blind spots, and why identity must now act as the control plane for AI-driven enterprises, with real-time enforcement before access is granted. He also highlights new innovations and partnerships enabling embedded identity controls across human, non-human, and AI identities, emphasizing that at machine speed, reactive security is no longer enough. To learn more about Silverfort and their AI Agent product, visit https://securityweekly.com/silverfortrsac. Privileged by Design: AI Agents and the New Identity Risk to Production Systems At RSAC this year, the AI conversation is getting more practical. Less "look what agents can do" and more "who's actually in control when an autonomous system can take real actions across business apps and infrastructure." The Moltbook breach and the growing attention on OpenClaw-style agent vulnerabilities put real weight behind that question because they show how quickly agent ecosystems can scale past oversight. Today we're talking with Shashwath, CEO of P0 Security, about why identity and authorization are the quiet enablers of modern AI, where teams are losing control as non-human identities explode and what security leaders can do to keep innovation moving without turning access sprawl into enterprise risk. To learn more about P0 Security, visit: https://securityweekly.com/p0rsac. Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-376
This episode features Sander Berkouwer and Raymond Comvalius, two longtime identity security experts and Microsoft Most Valuable Professionals (MVPs).Sander is an independent identity architect and author of the Active Directory Cookbooks. Raymond is an IT specialist and senior technical consultant specializing in hybrid identity, Microsoft Entra ID, and identity lifecycle automation.In this episode, they explore a growing blind spot in cloud security: application governance. As organizations adopt more cloud apps and integrations, identity platforms like Microsoft Entra ID often accumulate hundreds of application registrations with little oversight.They explain why governance so often falls behind adoption, share practical steps organizations can take to regain control, and discuss the next frontier of identity.Guest BiosSander Berkouwer DirTeam Sander Berkouwer works as an independent identity architect in the Netherlands, where he helps organizations make the most out of Microsoft products, services, strategies, and technologies. Sander blogs on DirTeam.com. He regularly gets invited as speaker for his enthusiastic approach, his in-depth real-world knowledge and as the author of the much-appraised Active Directory Cookbooks. Sander has been awarded the Microsoft Most Valuable Professional (MVP) award (for the last 17 years), Veeam Vanguard award (for the last 8 years) and VMware vExpert (for 3 years).Raymond Comvalius Raymond Comvalius is an IT specialist and senior technical consultant with more than two decades of experience delivering enterprise infrastructure, identity, and security improvements. His work centers on hybrid identity and Microsoft ecosystems, including Microsoft Entra ID, Conditional Access, and identity lifecycle automation with Microsoft Graph and scripting. Raymond advises teams on pragmatic roadmaps for strengthening authentication (MFA, passkeys/FIDO2, Windows Hello), improving governance, and operationalizing secure access at scale across cloud and on-prem environments. Beyond consulting, he serves as a board member and co-hosts the IT Bro's Podcast, sharing news and insights for identity and security professionals.Guest Quotes “In your tenant, you want to know what objects are in there, and it doesn't matter if those are users or groups or applications. You want to know what's in there so that you can keep track of what's going on.” - Raymond Comvalius“There's a difference between an application and an agent. An agent is far more ephemeral. It does a job that requires some sort of permission. It spins up, it does its thing, and it spins down.” - Sander BerkouwerTime stamps 00:45 Meet Sander Berkouwer and Raymond Comvalius: Microsoft Most Valuable Professionals (MVPs) 02:32 Importance of Entra Application Governance 12:29 How to Get Started with Application Governance 20:18 Understanding Entra Agent ID 26:59 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Sander on LinkedInConnect with Raymond on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Jim McDonald sits down with Greg Handrick, Director of IAM at Best Buy, for a wide-ranging conversation on running enterprise identity at one of America's largest consumer electronics retailers. Greg traces a nonlinear career path from Oracle DBA and Novell administrator to IAM director. The discussion covers Best Buy's CIO-reporting structure for IAM, how their steering committee evolved from status meetings into a strategic body, and managing identity across workforce, vendors, marketplace sellers, and non-human identities. Greg and Jim also dig into communicating identity value in business language, making the investment case without FUD, identity and cyber convergence, AI adoption, and psychological safety on a well-run IAM team. The Lighter Note wraps with Greg's YouTube-powered DIY hobby life.Connect with Greg: https://www.linkedin.com/in/greghandrick/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps00:00:00 Intro and upcoming event announcements00:03:00 Meet Greg Handrick, Director of IAM at Best Buy00:04:00 What is Best Buy?00:05:00 Greg's career path from Oracle DBA to IAM Director00:12:00 IAM reporting to the CIO vs. the CISO00:17:00 How Best Buy's IAM steering committee evolved00:22:00 Third-party and non-human identities at scale00:24:00 Identity as a team sport and imposter syndrome00:27:00 Communicating identity value in business language00:28:00 Making the investment case for IAM without FUD00:32:00 Identity and cybersecurity convergence at Best Buy00:35:00 Balancing technical depth with business acumen00:38:00 AI in identity programs today00:39:00 Leadership philosophy and psychological safety00:43:00 Will AI replace identity practitioners?00:46:00 Ledger Note: DIY projects and the power of YouTubeKeywords: IDAC, Identity at the Center, Jim McDonald, Jeff Steadman, Greg Handrick, Best Buy, IAM, identity and access management, identity security, CIO, CISO, steering committee, SailPoint, Ping Identity, Active Directory, third-party identity, non-human identity, identity governance, PAM, privileged access management, zero trust, AI in identity, leadership, retail IAM, imposter syndrome, psychological safety
professorjrod@gmail.comIn this episode of Technology Tap: CompTIA Study Guide, we dive deep into Windows security at scale, focusing on critical points where security measures impact real network environments. Learn how small misconfigurations, like one wrong checkbox, can expose significant data risks. Whether you are part of a study group, preparing for the CompTIA exam, or aiming to develop your IT skills, this episode covers practical Windows security architecture relevant to system administration, IT support, and tech exam prep. We discuss strategies for managing shared resources, centralized identity, and enforceable policies that you'll encounter in both real-world technology education settings and certification environments. Tune in to enhance your understanding and get tips that will aid you in your IT certification journey.I walk through modern Windows authentication, including what Windows Hello is designed to fix, why passwords keep failing in the real world, and how device bound PINs, biometrics, and phishing resistant security keys change the security model. From there, we talk about reducing login chaos with single sign-on and how SAML authentication helps systems trust an identity provider without making users juggle endless credentials.Then we move into the enterprise core: Windows domains, Active Directory, and how domain controllers, organizational units, and security groups keep management scalable. I also cover Group Policy as the tool that enforces consistent security settings across hundreds or thousands of PCs, plus the commands that matter when you need to verify and refresh policy like GPUpdate and GPResult.Finally, we dig into the breach magnet: Windows shares and permissions. You'll learn the difference between share permissions and NTFS permissions, why “most restrictive wins,” how deny rules and inheritance can save you or sink you, and why least privilege is the habit that keeps sensitive data out of the wrong hands. If this helps you, subscribe, share it with a friend in IT, and leave a review with the topic you want next.Support the showArt By Sarah/DesmondMusic by Joakim KarudLittle chacha ProductionsJuan Rodriguez can be reached atTikTok @ProfessorJrodProfessorJRod@gmail.com@Prof_JRodInstagram ProfessorJRod
How do you find insecure permissions in Active Directory before they turn into attack paths?In this episode, we take a practical look at how to identify insecure Active Directory permissions using ADeleg, a free security tool trusted by penetration testers.Misconfigured delegation and overly permissive access rights are a common source of risk in Active Directory environments. These gaps can create hidden attack paths—but many teams don't know where to look or how to interpret what they're seeing.In this episode, we cover:How to identify insecure permissions in Active DirectoryWhat to look for in high-risk users and groups like Domain Users, Everyone, and Authenticated UsersHow these misconfigurations translate into real-world attack pathsHow to use ADeleg to analyze delegated permissions and uncover hidden riskWe also include a reference to ADeleginator, a related tool that can help automate parts of this process using PowerShell. While this episode focuses on hands-on analysis with ADeleg, ADeleginator is a useful companion for scaling this work.Tools referenced:ADeleg: https://github.com/mtth-bfft/adelegBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
This episode features Krista Arndt, Associate CISO at St. Luke's University Health Network.With a career spanning healthcare, finance, crypto, and the Department of Defense, Krista brings a uniquely nontraditional path into cybersecurity, one shaped by mission-driven leadership, authenticity, and a commitment to mentorship.In this episode, Krista explains why identity sits at the center of nearly every major cyber incident and shares lessons from real-world response work. She also draws a striking parallel between incident response and her life as a national drag racing competitor, where staying calm under pressure and building in fail-safes can mean the difference between disaster and resilience.This episode is a powerful look at what it means to lead in cybersecurity.Guest Bio Krista Arndt is the Associate CISO SLUHN. As the Associate CISO, Krista is responsible for managing the security program's day-to-day operational effectiveness. In her previous roles, Krista assisted with developing and leading security programs in crypto, finance, and the Department of Defense. Krista earned her Bachelor's Degree in Biology from Felician College in NJ where she was a scholarship athlete, serving as the women's basketball team captain. She also holds her CISM and CRISC certifications and NHRA competition driver's license.Krista is an active member of ISACA, serves as InfraGard Philadelphia Chapter's Healthcare Sector Chief, serves on Neumann University's Business Advisory Council and is Marketing Committee chair for Women in Cybersecurity-Delaware Valley Affiliate. Krista is also a published author, detailing her journey to embracing her unique authenticity in her book, “Permission to be Real; How to Lead, Influence, and Thrive Without Fitting the Mold". Through this service and her writing, Krista's mission is to give back to her community by providing mentorship and support for aspiring cybersecurity professionals, especially for women who wish to enter the field. When off the clock, Krista takes her affinity for overcoming challenges to the garage and the race track, where she enjoys building and improving her own race car, competing as a driver in national drag racing events with her family, and using her racing as a forum to advocate for neurodiversity awareness and inclusion.Guest Quote “In the incidents that I've been involved in, major or not, I'll tell you—identity is at the crux of that... They're trying to get unfettered access… How do they get unfettered access? Through an identity that isn't secured correctly.”Time stamps 00:45 Meet Krista Arndt: Veteran CSO 06:17 Writing Permission to Be Real 10:43 Speaking the Business Language: Why Security Translation Matters 12:49 Lessons from Real-World Incidents 15:43 AI Agents and the Next Wave of Identity Risk 16:55 What Drag Racing Teaches About Incident Response 23:28 Surviving the CISO Seat 26:44 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Krista on LinkedInCheck out Krista's book: Permission to be RealLearn more about St. Luke's University Health NetworkConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Welcome to Episode 423 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben is live from Workplace Ninjas, joined by Eric Woodruff, Chief Identity Architect at Semperis and Microsoft MVP in Security focused on identity, and Chris Brumm, Cyber Security Architect at glueckkanja and Microsoft MVP in Security with over 16 years of experience in cybersecurity. Together they dig into the often-overlooked world of non-human identities in Microsoft Entra ID. They cover what service principals are, why they tend to fly under the radar compared to user accounts, and how attackers actively exploit that gap. The conversation spans credential management best practices, the risks of improper owner assignments, the challenges of multi-tenant app configurations, and why managed identities should be your go-to wherever possible. They also discuss the growing challenge of AI agent identities and what IT pros need to start thinking about now before that surface area explodes. Show Notes Eric Woodruff on LinkedIn Eric Woodruff on X (@ericanidentity) Eric on Identity Chris Brum on LinkedIn Chris Brumm on X (@cbrhh) Chris Brumm’s Blog Application and service principal objects in Microsoft Entra ID Workload Identities Securing service principals in Microsoft Entra ID Securing managed identities in Microsoft Entra ID Conditional Access for Workload Identities Microsoft Entra Audit Logs Microsoft Sentinel Detection Templates Eric Woodruff Eric Woodruff is the Chief Identity Architect at Semperis and a Microsoft MVP in Security with a focus on identity. He specializes in all things Microsoft Entra and Active Directory, with a passion for helping organizations understand and secure both human and non-human identities. You can find Eric on social media as @ericanidentity. Chris Brumm Chris Brumm is a Cyber Security Architect at glueckkanja based in Germany, with over 16 years of experience across virtually every corner of cybersecurity. He is a Microsoft MVP in Security with a primary focus on identity security. His team operates SOC services and he brings a detection and response perspective to identity risk, helping organizations build lifecycle processes and monitoring strategies for non-human identities in Microsoft Entra. About the sponsors TrustedTech is a leading Microsoft Cloud Solution Provider (CSP) specializing in Microsoft Cloud services, Microsoft perpetual licensing, and Microsoft Support Services for medium and enterprise-sized businesses. Our robust team of in-house, U.S-based Microsoft architects and engineers are certified in all 6/6 Microsoft Solutions Partner Designations in the Microsoft Cloud Partner Program. M365 Licensing Consultation M365 Tenant Assessment Copilot Readiness Assessment At Intelligink, our focus is singular: the Microsoft cloud. Our Microsoft 365 and Azure experts help you work securely and efficiently by unlocking the full value of what you’re already paying for, so you can focus on running your business.
This episode features Drew Russell, Identity Resilience Platform Owner at Rubrik. Jim McDonald and Jeff Steadman explore the intersection of backup, recovery, and identity security. Drew explains how Rubrik evolved from data backup into a cyber resilience platform with identity as a core pillar. Topics include recovering Active Directory, Okta, and Entra ID after ransomware, Rubrik's "bunker in a box" appliance for immutable air-gapped recovery, proactive posture management, CrowdStrike and Defender integrations, and where AI and non-human identities fit into Rubrik's roadmap. The episode wraps with measuring success for a product you hope to never use, and a detour into watch collecting.This episode was made possible by the support of Rubrik. Learn more at rubrik.com/idacConnect with Drew: https://www.linkedin.com/in/drew-russell-3762411b/Learn more about Rubrik: https://www.rubrik.com/idacConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at idacpodcast.comTIMESTAMPS00:00:00 - Welcome and Introduction00:01:19 - Introducing Drew Russell00:01:36 - How Drew Got Into Identity00:02:43 - What Is Rubrik and What Sets It Apart00:03:38 - From Backup to Cyber Resilience00:05:31 - Where Rubrik Fits in the IAM Landscape00:07:08 - Rubrik's Scale: Clients and Growth00:07:51 - Primary Use Cases: Post-Incident Recovery and AD00:09:09 - Kicking Out Compromised Accounts and ADR00:10:11 - Proactive Threat Detection and Mandiant Integration00:11:28 - Scanning Backups to Find the Clean Recovery Point00:12:14 - The Bunker in a Box Explained00:13:18 - Posture Management and Upstream Tool Integration00:14:19 - AI Agent Swarms and the Future Attack Surface00:15:37 - The Taiwan Bank Case Study: Six Weeks to Rebuild AD00:17:16 - The State of Nevada Incident: $400K and 30 Days00:17:56 - What Recovery Covers: AD, Okta, and Entra ID00:19:26 - Post-Restore Change Management and Whitelisting00:20:08 - How Long Should You Store Backups?00:21:19 - Indexing Identity for Intelligent Recovery Points00:22:29 - Excluding Malicious Actions During Restore00:24:41 - Zero Trust for Rubrik's Own Backups00:26:21 - No Windows, No Virtualization Architecture00:27:49 - Proactive Posture Management00:29:00 - CrowdStrike and Defender Real-Time Integration00:30:48 - Why Tabletop Exercises Often Fall Short00:31:53 - AI Roadmap and Non-Human Identities00:34:22 - The Three Pillars: Data, Identity, and AI00:35:29 - Deployment: SaaS vs. On-Prem00:38:37 - Appliance Sizing and Redundancy00:42:23 - Measuring Success for a Product You Hope to Never Use00:43:46 - The Ludacris Rubrik Commercial00:45:31 - Watch Collecting and the Omega Speedmaster00:53:39 - Drew's Closing WordsKEYWORDSIdentity at the Center, IDAC, Jeff Steadman, Jim McDonald, Rubrik, Drew Russell, identity resilience, cyber resilience, Active Directory recovery, AD backup, Okta recovery, Entra ID recovery, identity backup, ITDR, ISPM, non-human identity, NHI, agentic AI, ransomware recovery, bunker in a box, immutable backup, CrowdStrike integration, Microsoft Defender integration, Mandiant integration, identity disaster recovery, ADR, zero trust, tabletop exercises, posture management, IAM, identity security podcast, cybersecurity podcast
AI is reshaping both sides of the cybersecurity battlefield — and fast. In this episode, we break down five stories that prove it: the first Chrome zero-day of 2026 (CVE-2026-2441), a near-perfect CVSS 9.9 in Microsoft's Semantic Kernel SDK (CVE-2026-26030), a supply chain attack on AI coding assistant Cline that silently installed autonomous agents on thousands of developer machines, the first-ever Android malware using Google's Gemini AI at runtime (PromptSpy), and a Russian-speaking threat actor who used commercial AI tools to breach over 600 FortiGate firewalls across 55 countries in just five weeks. Whether you're a developer, security professional, or just someone who uses a browser — this one's worth your time.
This episode features Cliff Fisher, Senior Solutions Architect at Semperis and former Senior Technical Program Manager on Microsoft's Active Directory product group.With over a decade spent inside Microsoft supporting enterprise customers and helping guide Active Directory's security and roadmap, Cliff brings a rare insider perspective on what's actually happening behind the scenes of one of the world's most widely deployed identity platforms.In this episode, Cliff tackles the question many organizations are still asking: Is Active Directory really going away? He explains why the shift to cloud identity has moved far slower than expected, shares polling data that confirms hybrid environments are here for the long term, and breaks down how Microsoft is still investing in AD through security hardening, supportability improvements, and features like Windows LAPS.This episode offers a clearer look at why Active Directory remains central to enterprise identity and what defenders need to prepare for as hybrid becomes the default reality.Guest Bio With nearly 20 years of Active Directory experience across varied roles in system administration, support, debugging, and program management, Cliff spent over a decade at Microsoft supporting Premier and Unified customers and, most recently, managing the releases of Windows LAPS, new features for Server 2025, and monthly security and quality updates. In January of 2026, he joined Semperis, bringing his unique blend of skills, perspectives, and passion to their stacked roster of established identity experts.Guest Quote “The easiest way to get everyone secure is to get people all to the cloud. What [Microsoft] didn't realize... is that customers just aren't going to be able to absorb change at that rate, and especially at that cost. Shifting to the cloud is not cheap.”Time stamps 01:45 Meet Cliff Fisher: Identity security expert 04:24 Microsoft's Vision for Active Directory 07:58 Challenges and Future of Active Directory 23:12 The Complexity of AD Code and Security Vulnerabilities 24:39 Understanding Fuzzing and Its Importance 27:28 Domain Join Hardening and Its Challenges 36:28 Windows LAPS and Future Security Measures 41:39 Why is RC4 Going Away? 45:14 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Cliff on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisSubmit your proposal to speak at HIP Conf 26: HIP Conf 26 Call for Papers Submission
Long-time Microsoft MVP and consultant Richard Hicks joins The PowerShell Podcast to talk about ADCS security, PKI misconfigurations, and why PowerShell is a consultant's ultimate force multiplier. Richard shares real-world stories from auditing enterprise certificate environments, explains how simple template mistakes can lead to full domain compromise, and walks through tools like Locksmith that help administrators quickly identify dangerous configurations. The conversation also explores Richard's open-source PowerShell work, including his widely downloaded Get-UEFICertificate script for Secure Boot certificate expiration issues and his new ADPrincipalCertificate module for cleaning up unnecessary certificates published in Active Directory. Along the way, Richard reflects on career growth, publishing, consulting, and why sharing knowledge openly has been one of the biggest drivers of his long-term success. Key Takeaways: • ADCS is easy to deploy but difficult to secure — Misconfigured certificate templates, especially ESC1 scenarios, can allow instant privilege escalation and domain compromise. • PowerShell turns repetitive work into reusable tools — From UEFI certificate auditing to Active Directory cleanup, scripting creates consistency and prevents human error. • Sharing expertise compounds over time — Blogging, publishing modules, and speaking at conferences builds credibility, community, and long-term career momentum. Guest Bio: Richard Hicks is the founder and principal consultant of Richard M. Hicks Consulting, Inc. A Microsoft MVP with over 30 years of experience, he specializes in secure remote access and PKI, helping organizations deliver secure, high-performing access for today's mobile workforce. Resource Links: Richard Hicks Website – https://richardhicks.com Connect with Richard – https://richardhicks.com/connect Connect with Andrew: https://andrewpla.tech/links Get-UEFICertificate Script – https://www.powershellgallery.com/packages/Get-UEFICertificate ADPrincipalCertificate Module – https://www.powershellgallery.com/packages/ADPrincipalCertificate Locksmith ADCS Audit Tool – https://github.com/jakehildreth/Locksmith PDQ Discord – https://discord.gg/PDQ PowerShell Wednesdays – https://www.youtube.com/watch?v=Oa0GYX9_vj8&list=PL1mL90yFExsix-L0havb8SbZXoYRPol0B&pp=sAgC The PowerShell Podcast on YouTube: https://youtu.be/4HYCAjQS2W8
In this episode, we're digging into malicious browser extensions...the quiet, often overlooked attack vector living inside nearly every organization. While we focus on patching servers, hardening Active Directory, and deploying EDR, attackers are increasingly abusing the browser as their initial foothold. We'll break down how these extensions work, why they're so dangerous, and what IT leaders can realistically do about it.Check out these resources:Annex - Enterprise Software Extension Security & Managementhttps://crxaminer.tech/https://x.com/tucknerhttps://x.com/IceSolstBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
Welcome to Episode 421 of the Microsoft Cloud IT Pro Podcast. In this episode Ben sits down for a conversation with Frank Lesniak, the lead of the Microsoft 365 team at West Monroe. In this episode, they dive into the intricacies of mergers and divestitures within Microsoft 365 environments. They discuss the initial due diligence phase, planning and approach, building and configuring new environments, and the final migration and cutover phase. Frank shares insights on common challenges such as integration of different licensing models, the handling of workstations and applications, and the importance of security assessments. The episode provides a detailed look at the methodology and tools used by Frank’s team to streamline these complex processes. Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options. Show Notes Frank Lesniak on LinkedIn West Monroe Frank Lesniak Github Microsoft 365 tenant-to-tenant migrations Microsoft 365 inter-tenant collaboration Tenant life cycle considerations in multitenant solutions Frank Lesniak Frank Lesniak is a Sr. Cybersecurity & Enterprise Technology Architect at West Monroe with nearly 20 years of experience leading consulting engagements involving Microsoft infrastructure technology. His expertise spans modern cloud systems like Azure, Microsoft 365, and Entra ID to classic platforms like Windows Server, Active Directory, and SQL Server. His recent focus has been on Microsoft platform cybersecurity and automating technical processes using PowerShell. In his role, Frank establishes technical project methodologies, leads teams, automates associated processes, and creates internal software products at West Monroe and in the open-source community. About the sponsors Would you like to become the irreplaceable Microsoft 365 resource for your organization? Let us know!
You're using Active Directory Certificate Services - but is it configured securely? Richard talks to Ron Arestia about his work with organizations implementing their own Public Key Infrastructure (PKI) with ADCS. Ron explains how poorly configured ADCS enables lateral attacks within an organization once an initial breach occurs, allowing black hats to move throughout your network. A well-designed PKI system has tiers of protection, with the top level completely disconnected from the network. Or do you really need your own PKI system? The conversation digs into the various scenarios, including third-party options. Certificates are the top level of security for your organization - you need to get it right!LinksActive Directory Certificate ServicesWindows Hello for BusinessCertified Pre-OwnedMicrosoft Defender for IdentitySecure Privileged AccessPass the HashMicrosoft Cloud PKI for Microsoft IntuneMicrosoft Entra Conditional AccessMicrosoft AutopilotRon's BlogRecorded February 6, 2026
Principal Security Consultant and community favorite Jake Hildreth returns to The PowerShell Podcast to talk about building smarter automation, leveling up through community, and creating tools that solve real problems. Andrew shares his “stop trying so hard” theme for the year, how working smarter applies directly to scripting and security, and why getting involved with others is one of the fastest ways to grow in your career. The conversation dives into Jake's recent projects including Deck, a Markdown-to-terminal presentation tool built on Spectre.Console, and Stepper, a resumable scripting framework designed for long-running workflows that can't be fully automated end-to-end. They also explore presentation skills, avoiding “death by PowerPoint,” and why security work requires constantly re-checking assumptions as threats evolve. Key Takeaways: • Work smarter, not harder — Whether you're scripting or building a career, small sustainable improvements beat grinding yourself into a corner. • Resumable automation is a game changer — Stepper helps scripts safely pause and resume, making real-world workflows more reliable when humans or flaky APIs are part of the loop. • Community turns into real momentum — Contributing, asking questions, and sharing feedback builds skills, friendships, and opportunities faster than trying to learn alone. Guest Bio: Jake Hildreth is a Principal Security Consultant at Semperis, Microsoft MVP, and longtime builder of tools that make identity security suck a little less. With nearly 25 years in IT (and the battle scars to prove it), he specializes in helping orgs secure Active Directory and survive the baroque disaster that is Active Directory Certificate Services. He's the creator of Locksmith, Stepper, Deck, BlueTuxedo, and PowerPUG!, open-source tools built to make life easier for overworked identity admins. When he's not untangling Kerberos or wrangling DNS, he's usually hanging out with his favorite people and most grounding reality check: his wife and daughter. Resource Links: • Jake Hildreth's Website – https://jakehildreth.com • Jake's GitHub - https://github.com/jakehildreth Andrew's Links - https://andrewpla.tech/links • PowerShell Spectre Console – https://pwshspectreconsole.com/ • PDQ Discord – https://discord.gg/PDQ • PowerShell Conference Europe – https://psconf.eu • PowerShell + DevOps Global Summit – https://powershellsummit.org • Jake's PowerShell Wednesday – https://www.youtube.com/watch?v=YdV6Qecn9v0 The PowerShell Podcast on YouTube: https://youtu.be/rFeoTKLerkA
Today we're thrilled to announce the launch of LPLITE:GOAD (Light Pentest Live Interactive Training Experience: Game of Active Directory). The first class is coming up Tuesday, January 27 – Thursday, January 29 (9:00 a.m. – 1:00 p.m. CST each day). More information, pricing information and more can be found at training.7minsec.com. Today I talk about who should sign up for the course, what you should bring, and some of the awesome things you'll be doing should you choose to join me on this hacking adventure!
Imagine your work day starting off like any other only to find you've been laid off. What would you do next? Dave Stevens lived this reality a couple of years ago and joins us this week in episode 354 to share the lessons from that experience. We'll take you through how Dave processed the news of being laid off, the warning signs he missed, when he knew it was time to begin searching for a new role, how he thought about what to do next, and the critical importance of his personal and professional network throughout this process. Regardless of your age or the size of your professional network, Dave shares actionable suggestions for building professional connections that we all may be overlooking. Original Recording Date: 10-28-2025 Topics – Background and the Impact of a Layoff Event, Initial Forward Progress and Reliance on a Professional Network, Skills Gaps and Unexpected Positives, Elements of the Personal and Professional Network, Reaching Closure and Reflecting Back on the Lessons 2:27 – Background and the Impact of a Layoff Event Dave Stevens is a Field Solutions Architect at Pure Storage. In this role, Dave is a technical overlay for pre-sales technical personnel at Pure across North America. This is the role Dave took after he was impacted by a layoff. What was Dave's role before he was impacted by a layoff event? For context, the layoff event we discuss in this episode took place around 2.5 years before this recording. Dave was classified as a systems engineer or pre-sales technical resource at his employer supporting multiple account reps. It was more of a solutions architect type of role, and Dave highlights his entry into this organization and role was via acquisition. Was there an element of technical marketing to the role? Nick mentions that Dave often had to attend trade shows in this role. Dave had a virtualization background and went to a lot of events to discuss how his company's products integrated with those different technology ecosystems. The day Dave was laid off started as a normal day at his home office. His boss was based in Europe, so most 1-1 calls were usually late in the day his boss's time (early afternoon for Dave). A meeting popped up that was earlier than usual, but Dave didn't think anything of it. Right after Dave joined the remote session for the meeting, someone from HR joined followed by Dave's boss. Dave wasn't quite sure what to expect and didn't know what was happening. He didn't know if it was a layoff coming or some other kind of situation happening at his company. When Dave was laid off, they told him it was not for performance reasons, but there weren't really any other details provided on why he was being laid off. “So, at that point it was just like, ‘what do I do?'” – Dave Stevens, on receiving layoff news After receiving the news, Dave's access to company systems like e-mail was quickly cut off. He went downstairs and spent the rest of his day relaxing. Dave did not want to talk about what happened any further that first day. Did Dave struggle with separating his identity from his employer or the job he held at all when this happened? Dave says he did, at least a little bit. Dave wanted to be successful in whatever role he found himself, and the reason he was in the systems engineering role at the time of the layoff event is a result of his drive to be successful in the years leading up to that role. “I also wanted to make sure that…the people that I worked with that I enjoyed working with. If I didn't enjoy working with them, then there was no reason to continue staying there. So that's part of my identity on how I interact with work.” – Dave Stevens In the early days of Twitter (now X), Dave defined an identity there. He also created a personal blog. Dave says his identity was often tied to where he worked. “Once this all happened, I just kind of cut that off. And I needed some time to really digest what I just went through that day.” – Dave Stevens Is there something Dave wishes people had done for him when this first happened? Dave says he wishes he would have listened to his wife. Before experiencing the layoff event, a number of colleagues who had entered the company through acquisition like Dave were either leaving or had been laid off (including his boss being laid off). At the time, Dave didn't think much about these events. Dave's wife had encouraged him to look for other jobs before the layoff happened, and he feels he should have listened. “It's much easier finding a job when you have a job. There's not as much pressure on you. You can take your time and really find the job that you want. That's the one thing that kind of took me by surprise….” – Dave Stevens Did Dave's wife also point him in a direction or provide feedback on the type of work he should pursue? We've spoken to previous guests who had spouses that provided insight into the type of work that made them happy. Dave feels like there has been an element of this in place since he and his wife got married. When Dave got a job opportunity to relocate to the New Hampshire area, his wife had some interesting feedback. “It's great that you're going to make more than you're making at the job you are currently, but I don't want you to take a job just because of money. I want you to take a job because it's something you're interested in doing and you're going to be happy at. So, I've always kept that in the back of my mind every time I go and look for a job….” – Dave Stevens, quoting his wife's advice Dave considered this same advice when pursuing his current role at Pure. Because he enjoyed meeting and speaking with people during the interview process, the decision to accept the role was easy. Liking the people he would be working with was more important than a pay increase. 10:53 – Initial Forward Progress and Reliance on a Professional Network How long did Dave need to process before taking the first actions toward a new role? For the first 3 weeks or so, Dave relaxed a little bit. There were a number of projects at home that he needed to do and some that he wanted to do. Working on the projects helped take his mind off what had happened. Dave mentions he was given a severance for about 3 months and wanted to find a new role within that time period if possible. But if he could not find something in that time period, it would not be the end of the world. Dave tells us it was easier to find work when he was laid off than it is currently. Close to the time of this recording, AWS announced job cuts for up to 30,000 people. He made the conscious decision after those first few weeks to spend the first part of the day searching for new jobs and then continued working on different projects in the afternoons. How did Dave know who to reach out to first? Nick argues that most of us likely don't have a list of who we would call if something like this happened. When Dave came to the New England area, he started working for Dell in tech marketing. Through his work, Dave built a tight bond with many of his co-workers. Dave remembers sending a text message to many of his former co-workers (none of which were still at Dell) asking if they knew of any open opportunities. Dave wanted to understand what former colleagues were working on now and what the culture of their company was like. He started by seeking out people he already enjoyed working with and analyzed whether it made sense to go and work with them again. Was Dave open to different types of roles in his job search, or did that not matter? It had to be interesting work and involve people he wanted to work with or enjoyed working with. Dave says as long as it was something in the tech field, it didn't matter too much. Dave began his career in systems administration and tech support and had experience in the storage industry, with backups, and with Active Directory to name a few areas. He had also done technical marketing and was open to returning to it. Dave also looked at pre-sales systems engineering or solution architect roles. What about taking roles that moved him deeper into a business unit like product management? Dave says product management is interesting work, but depending on the company, the work may not always have the technical aspects he likes. Many of the product managers at Pure are quite technical, but most of the product management roles he observed at other companies were not as technical as he would like. “It just didn't interest me. It wasn't technical enough in nature for me.” – Dave Stevens, on moving into product management It sounds like Dave had done a good job of keeping in touch with people in his professional network over time. “I have always made sure to have a small group of folks that I can just reach out to at any time and…chat about anything…. I've always made sure to have that…. I didn't talk to them all the time, but we all interacted in some way, shape, or form whether it was an e-mail or text messaging…even some stuff on LinkedIn. We all kind of kept in touch…. I had people that I could fall back on and reach out to and get advice from if I needed to. This is the time where I really needed some advice on where to go to next.” – Dave Stevens Dave says he was lucky enough to find a new job before the end of his 3 months of severance pay. Dave's wife commented that she wasn't too worried about him. She knew he had a strong professional network. Did anyone in Dave's professional network ask him what he wanted to do next, or did they just start making recommendations based on what they knew about him? Dave says it was a little bit of both. Some people pointed Dave to specific open roles in the same group where they worked (still in tech, of course), while others directed him to the company job site and offered to act as a referral for him. Dave tells us he's very willing to give others a referral. “I want to make sure that people that I know and I like to work with come to work with me.” – Dave Stevens Dave says he also turned on the Open to Work banner on LinkedIn. While this did result in many recruiters reaching out to Dave, many of the opportunities they contacted him about were not interesting. Dave is hearing from many in our industry that bots are reaching out to people and trying to take advantage of them. His advice is that we need to be guarded in our interactions on LinkedIn as a result to avoid scams. 19:10 – Skills Gaps and Unexpected Positives What kinds of skills gaps did Dave see when seeking new opportunities? For context, this was roughly 2.5 years ago. Dave says at that time, AI wasn't as helpful as it is today and was not something that was interesting to him. Dave tells us he uses AI heavily today compared to back then. Dave felt confident in the knowledge and skillset he had built through years of industry experience. Ideally, he would land a new role that overlapped those areas, but if a new role required coming up to speed quickly, he would do what was needed. Dave started looking at public cloud and certifications related to Azure and AWS. “Although it was interesting, it wasn't really what I wanted to do.” – Dave Stevens, on public cloud technologies compared to the technologies with which he was familiar What were some of the unexpected positive outcomes of getting laid off even though it was difficult in the beginning? One positive, according to Dave, is the amount of people in his network he was able to reach out to on LinkedIn. So many people were open to helping. The only negative Dave thinks is maybe not acting quickly enough in starting his job search. “It's really about building not only your personal network but your professional network. And my professional network really came to my rescue and helped me understand that…it's not the end of the world. You're going to make it. You're going to do fine. But let me know if there's any way that I can help you in that journey that you're on right now.” – Dave Stevens Were there any things Dave and his wife had done (conscious or unconscious) to prepare for the layoff event based on market trends? Dave says his wife is very good at managing their home budget, and since they got married, they intentionally build a financial nest egg they could lean on in the event Dave was out of a job. 22:27 – Elements of the Personal and Professional Network What are some of the things Dave is even more intentional about now with his professional network than he was in the past? Dave received some great advice from a co-worker to reach out to one person in his professional network each week. Many times, Dave will do this on LinkedIn or even via text if he has the person's number. “Keep that personal connection going. As much as AI is taking over, as much as we do a lot of things on Zoom, I've learned over my years of working in the industry that there's nothing better than the face-to-face interaction…. It's so much more fun and relaxing to just get out of the office or home office…and just sit down with people and keep that personal connection going.” – Dave Stevens Dave mentions he likes to get together with co-workers in the area every now and then, even if they have the same conversation in person that they would have had on Zoom. It's different and more relaxing. How can younger listeners who may be trying to break into the industry build a professional network when they might not have a deep contact list or large network like someone in the industry for a long time? Nick and Dave talked about this before hitting record and thought it could be helpful to share during our discussion. Dave has a newfound perspective on this from being around his nephews and nieces. The job market is very different today than when Dave first began his career. “Nowadays, resumes just go into a black hole, and you don't necessarily know if you're still in the mix for a current job.” – Dave Stevens Dave has encouraged his nephews and nieces to leverage their personal network to build a professional network. He may know someone who knows someone in the field they want to pursue, for example. “There's no shame or harm in utilizing all your resources…. Utilize your personal network because you don't have the professional network built up yet to help you get that foot in the door.” – Dave Stevens Young people could even use their parents as a way to broaden their own network. It's an opportunity to get introduced to others. Dave uses the example of a chance meeting at a concert that could result in a new connection for someone. Nick would encourage younger listeners to get out to in-person meetup groups on any interesting topic. Go ask people what they are learning, why they work where they work, how they got there, and see if they have advice for you. Dave agrees and has leveraged both local professional groups and meetup groups in the New Hampshire area to meet new people. This is expanding your local professional network as Dave calls it (not to be confused with your global professional network) and is a great thing to do when you move to a new place. You never know when a conversation at a local meetup might help you get a warm lead on a job that will be posted soon. Did the layoff come up in interviews at all? How did Dave handle that? Dave says some people brought it up. In other cases, he brought it up in conversation, wanting people to know he was not let go for doing something wrong. 28:22 – Reaching Closure and Reflecting Back on the Lessons How did Dave know he had reached closure on the layoff situation? Dave thinks he was motivated to take action toward finding a job due to a fear of boredom. He had been working on various projects but knew he would run out of them at some point. Dave had enough time to adjust to not having a job, and he was ready to begin doing some kind of work again. “I didn't want to get bored. I hate being bored. I hate being bored at work. I hate being bored in general. That's really what the impetus was for me to go out and start looking…that fear of relaxing for too long and being bored.” – Dave Stevens At this point Dave reached further into his professional network beyond that first group of friends and former colleagues he mentioned earlier. Does taking action in a direction mean we're ready to move on from what happened? Is it when we have to discuss what happened in an interview, or is it something else? How do we measure this? Dave says it was easier to accept and felt mostly behind him when he was actively looking for a new position. He knew only he could take the actions to move forward. The feeling of what happened before went completely away when Dave accepted a new job at Pure. Dave feels he was very lucky to find a role. Lining up multiple interviews gave Dave momentum and a feeling of positivity. “I feel that people understand that I have the skills for these jobs. Otherwise, I wouldn't have gotten 5 job interviews as quickly after I really started taking action to look for a job. So, I got lucky.” – Dave Stevens If Dave had to do it all again, what would he do differently? Dave feels he has about 10 more years left working in the tech industry. For now, Dave enjoys the job he has, wants to excel doing it, and wants to continue growing. Dave currently works for the best boss he's had to date. “He not only pushes me, but he pushes our entire team to just get better….” – Dave Stevens, on his current manager Dave tells us he does not want to be a people manager or a product manager. “I want to continue to excel and expand my depth of knowledge across the virtualization industry and the storage industry.” – Dave Stevens The work at Pure is very interesting to Dave, which is also motivating him to continue learning and excelling. Part of this is using more AI-focused tooling as it becomes available to use. What does Dave think the role of AI tools is in helping with one's job search? There are a number of tools out there we can leverage to analyze our resume. Dave suggests keeping track of which tool we've used to analyze our resume because that could be used to train a model. In addition to this, use AI to research companies. Use them to help you understand what companies are like and what their culture is like. Many people in a sales role within Pure, for example, use an AI tool of some kind to learn more about their customers. Nick reiterates the nuances of acquisitions. Dave worked for a company that was acquired by another company. Over time there was a pattern of people from the company which was acquired being laid off. Perhaps this is a sign we should watch for and prepare. Dave says we need to be looking at and listening for the signs coming toward us. He listens to his wife more intently when she makes a suggestion. Dave continues to check in with people in his professional network and offers advice when they need it. Dave would encourage all of us to use our personal and professional network if we end up in the situation he was in (experiencing a layoff). “Not everybody is going to be able to help you or is willing to reach out and help you, but when someone does…don't just brush it aside as they want something out of this. They probably genuinely want to help you. So, take advantage….” – Dave Stevens If you want to follow up with Dave on this conversation, Connect with Dave on LinkedIn Check out Dave's blog site Mentioned in the Outro The three week period Dave took to work on projects may have been what gave him the clarity on the type of work he did and did not want to do once he began his search. Dave mentions getting some great advice from his wife and her emphasis on him pursuing roles that would make him happy and be enjoyable work. This echoes something similar to what Brad Christian shared in Episode 264 – Back to Basics: Technology Bets and Industry Relationships with Brad Christian (2/2) when it came to choosing what to do next after a layoff. If you enjoyed this format and want to hear other stories of people recounting their layoff experience, check out these episodes featuring Jason Gass. He talks about the lost art of supporting others in episode 343, which aligns very well with Dave's advice on building our personal and professional network. Episode 342 – Planting Seeds: Networking and Maneuvering Unexpected Job Loss with Jason Gass (1/2) Episode 343 – The Lost Art: Marketplace Heartbeat and Finding Closure after a Layoff with Jason Gass (2/2) Contact the Hosts The hosts of Nerd Journey are John White and Nick Korte. E-mail: nerdjourneypodcast@gmail.com DM us on Twitter/X @NerdJourney Connect with John on LinkedIn or DM him on Twitter/X @vJourneyman Connect with Nick on LinkedIn or DM him on Twitter/X @NetworkNerd_ Leave a Comment on Your Favorite Episode on YouTube If you've been impacted by a layoff or need advice, check out our Layoff Resources Page. If uncertainty is getting to you, check out or Career Uncertainty Action Guide with a checklist of actions to take control during uncertain periods and AI prompts to help you think through topics like navigating a recent layoff, financial planning, or managing your mindset and being overwhelmed.
Think your cloud backups will save you from a ransomware attack? Think again. In this episode, Matt Castriotta (Field CTO at Rubrik) explains why the traditional "I have backups" mindset is dangerous. He distinguishes between Disaster Recovery (business continuity for operational errors) and Cyber Resilience (recovering from a malicious attack where data and identity are untrusted) .Matt speaks about the "dirty secrets" of cloud-native recovery, explaining why S3 versioning and replication are not valid cyber recovery strategies . The conversation shifts to the critical, often overlooked aspect of Identity Recovery. If your Active Directory or Entra ID is compromised, it's "ground zero” and you can't access anything. Matt argues that identity must be treated as the new perimeter and backed up just like any other critical data source .We also explore the impact of AI agents on data integrity, how do you "rewind" an AI agent that hallucinated and corrupted your data? Plus, practical advice on DORA compliance, multi-cloud resiliency, and the "people and process" side of surviving a breach.Guest Socials - Matt's LinkedinPodcast Twitter - @CloudSecPod If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-Cloud Security Podcast- Youtube- Cloud Security Newsletter If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Security PodcastQuestions:(00:00) Introduction(02:20) Who is Matt Castriotta?(03:20) Defining Cyber Resilience: The Ability to Say "No" to Ransomware(05:00) Why "I Have Backups" is Not Enough(06:45) The Difference Between Disaster Recovery and Cyber Recovery(10:20) Cloud Native Risks: Versioning and Replication Are Not Backups(12:50) DORA Compliance: Multi-Cloud Resiliency & Egress Costs(15:10) The "Shared Responsibility Model" Trap in Cloud(17:45) Identity is the New Perimeter: Why You Must Back It Up(22:30) Identity Recovery: Can You Restore Your Active Directory in Minutes?(25:40) AI and Data: The New "Oil" and "Crown Jewels"(27:20) Rubrik Agent Cloud: Rewinding AI Agent Actions(29:40) Top 3 Priorities for a 2026 Resiliency Program(33:10) Fun Questions: Guitar, Family, and Italian Food