techspence Profile Banner
spencer Profile
spencer

@techspence

Followers
14K
Following
114K
Media
3K
Statuses
45K

šŸ› ļø Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack | @SecurIT360 @cyberthreatpov

šŸ°AD Security Resource Kit ā¬‡ļø
Joined November 2010
Don't wanna be here? Send us removal request.
@techspence
spencer
22 days
ps - I created an AD Security resource kit for IT admins. If you want to know where to start & what issues to look for, then this is for you. You can get access to it by signing up for my free email newsletter. If you're already a subscriber, DM me for the link! šŸ‘‡ Access it
3
30
169
@techspence
spencer
2 hours
I scheduled this post to go live on Friday fully betting something spicy would happen...lets see if this pans out šŸ˜…
1
0
4
@premium
Premium
4 months
Why guess when you can know?
0
699
8K
@techspence
spencer
4 hours
What if we just got rid of the security products that were not carrying their weight and put that money into better trained & more knowledgeable people…
2
0
13
@techspence
spencer
6 hours
I’m rooting for you to have a clean pentest report…but honestly, I kind of hope you don’t. You learn way more when we find the dumb stuff like creds dumped on a share or Domain Users with Full Control on the DC OU. What did your last pentest actually teach you, what did you
6
0
12
@techspence
spencer
9 hours
What we need less of: Products that promise to solve ALL your problems (and even some you don’t have) automatically while you sleep except you end up paying money to introduce new problems you also can’t solve What we need more of: products that solve distinct problems that can
0
0
3
@hackswithcoffee
Daniel Karistai
10 hours
@techspence Microsoft Learn has a host of free learning paths for Active Directory, Identity and Access Management, and any cert of theirs one might find useful. https://t.co/bcd9Eyu7XN I'd also recommend getting comfortable with control groups from either MCSB or CIS benchmarks
Tweet card summary image
learn.microsoft.com
Active Directory Domain Services
2
1
7
@Mandiant
Mandiant (part of Google Cloud)
1 day
A strong defense starts long before an incident. We distilled 20+ years of Mandiant breach experience into a practical guide for building an effective #IncidentResponse plan. Stay prepared, not reactive. Read the guide āž”ļø https://t.co/QiIM9E0eRa
2
49
179
@ICEgov
U.S. Immigration and Customs Enforcement
3 months
America needs you! Join U.S. Immigration and Customs Enforcement today.
7K
16K
72K
@techspence
spencer
22 hours
šŸ™ŒšŸ¤˜šŸ’ŖšŸ¤™šŸ™
@I_Am_Jakoby
I am Jakoby
1 day
I got microsoft to change their whole bounty program! they finally listened. critical vulns now count even if they’re ā€œout of scopeā€, as long as they impact microsoft’s ecosystem. Pictured below is the exact post to make it happen. We have been having very respectful
0
0
17
@rez0__
Joseph Thacker
1 day
> Starting today, if aĀ criticalĀ vulnerabilityĀ has a direct andĀ demonstrableĀ impact toĀ ourĀ onlineĀ services, it’s eligible for a bounty award.Ā Regardless of whether the codeĀ is owned and managed byĀ Microsoft, a third-party, orĀ isĀ openĀ source, we willĀ do whatever it takes to
@busf4ctor
Vitor Falcão "busfactor"
1 day
This is very interesting https://t.co/4pJchAVKnq
6
14
121
@techspence
spencer
1 day
Consistency is a funny thing. No one sees it if they are not there along side you. @kamakauzy thanks for being the best co-host and partner in crime with this podcast. I really really appreciate all the support you all have shown for our content and podcast. Literally the only
1
1
9
@techspence
spencer
1 day
What’s working for threat actors once they get inside? Lots of the same things that are still working for us during internal pentests. While we have morals and they don’t… we try our best to use the same/similar TTPs so clients get as close to a taste of what to expect as we
1
2
34
@ChicagoSteakCo
Chicago Steak Company
10 days
This holiday, skip the stress. USDA Prime steaks delivered to their door. They'll thank you later. 8 FREE Steak Burgers + FREE shipping ($145 value) on orders $149+ Use code SANTA149 →
1
4
39
@techspence
spencer
1 day
Stay tuned for more insights from zack. he and I recorded a video the other day. Working on editing and getting it out on the youtubes!
@ZackKorman
Zack Korman
1 day
I like to be transparent, so here’s a thread on some of the biggest misses (false negatives) we’ve had in detecting insider threats with AI. I also talk about false positives and what I think is needed to really unlock the value of AI in cybersecurity (especially detection).
2
0
14
@techspence
spencer
1 day
AD Security resources for defenders...šŸ‘‡
@techspence
spencer
2 days
šŸ§µšŸ’™Active Directory training/resources specifically for IT admins/defenders. Please comment below the resources you know about. I’ll do the same, see my replies…
2
6
63
@techspence
spencer
1 day
What are we all gonna do when AI is doing our jobs for us?
11
0
10
@techspence
spencer
1 day
Internal pentest findings that shouldn’t exist in 2025, part 2 - Domain Users members of Domain Admins - Default new user password that’s never changed - Services with unquoted service paths - Unattend xml files with plaintext creds - Non-unique local admin password, for
8
11
136
@chainlink
Chainlink
9 days
Chainlink: Linking Crypto to Capital Markets.
1
0
10
@techspence
spencer
1 day
Cybersecurity is both easier than we expect and harder than we hope all in one rollercoaster of emotion.
4
0
12
@techspence
spencer
1 day
Please share your favorite AD/AD security training or resources in the thread below šŸ™
@techspence
spencer
2 days
šŸ§µšŸ’™Active Directory training/resources specifically for IT admins/defenders. Please comment below the resources you know about. I’ll do the same, see my replies…
4
5
67
@techspence
spencer
2 days
Some of the best content on hardening AD by Jerry Devore https://t.co/NbMPcJvSO3
Tweet card summary image
techcommunity.microsoft.com
0
1
21
@techspence
spencer
2 days
Another repo that’s not strictly training but is a giant list of resources is by @ThePoolmanjim on the AD subreddit https://t.co/LCtpxZtqIl
Tweet card summary image
reddit.com
Explore this post and more from the activedirectory community
1
2
24
@techspence
spencer
2 days
I’ve never taken any training from this outfit, so I cannot attest to quality, if anyone can please share what they think of the stuff here https://t.co/jXK4YPqfH1
2
0
8
@VISITFLORIDA
VISIT FLORIDA
1 month
Put a calendar hold for a meeting** on Friday. (**Playing pickleball)
1
1
9
@techspence
spencer
2 days
Not formal training courses but one of the best central places for AD Security knowledge by @PyroTek3 https://t.co/K0Sl4fAVyg
1
0
31