spencer

@bsky.ethicalthreat.com

🛠️ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack Pentesting -> SecurIT360 Podcast -> CyberThreatPOV Active Directory Security Resources for IT Admins 👇 https://go.spenceralessi.com/adsecurity

Yes, you should lock your computer when you get up and walk away while at the office. No, you're not gonna get hacked in the 3 minutes that you're gone from your desk getting some water. YMMV

You should speak to your AI so it can understand the intent and inflection in your voice. You really want it to know when you're ticked off because it's creating bugs in your code.

Y’all are focusing on the wrong thing. organizations don’t get better by automating pentesting and eliminating pentesting jobs. Organizations get better by making their systems more secure and resilient. Great, you found 4000 vulnerabilities in half the time, IT admin still need to fix that stuff

While no AI isn’t replacing pentesters just yet, I do believe it’s changing the game drastically. It’s forcing low quality pentesting to raise the bar. It’s also a signal of what’s to come. But also, I think in many ways the “market” will decide if these ai pentesting platforms have value or not.

As a defender, I want the advantage. I want my environment to be hostile territory to adversaries. I want them to know… that I know that they know I see them. Get wrecked.

How to get people to talk about your stuff. Make something that intersects with what people want and something that solves a deeply painful problem. Then make it really really good.

If you’re an IT admin and you want upward career progression and you have any length of time left in your career, beginning to poke at these AI platforms and becoming comfortable with them is crucial. Not to be an expert but so you know what’s coming.

Pentesting findings don’t get fixed for a number of reasons. Some of which are out of the IT teams control. But also, many IT teams are burnt out putting out fires and working on other “more important” projects handed down to them by management that they don’t have time to fix security issues.

The infosec/cybersecurity space is funny because on social media, AI is taking over the world. Then I go to conferences and meet people who are primarily defenders and they haven’t heard of OpenClaw, which is probably the biggest phenomenon since OpenAI launched ChatGPT. Social media is a bubble.

I’m currently a pentester, but I’m also a former sysadmin. Something that’s not lost on me is that it doesn’t matter how good you think your security is, if your backups and recovery processes haven’t been tested, you’re rolling the dice.

Sure Pentest one a year, but also, don’t wait until your next pentest to: Run Locksmith Run ADeleginator Run PingCastle/PurpleKnight Check shares, sharepoint, wikis for creds