Security Researcher @ Netwrix. Spec Ops Army Vet, Ham Extra (satellites, sdr, dmr), Team Purple, Wireless Wizard, Creator of Identity Security Village

Joined May 2020
64 Photos and videos
I break Windows.... retweeted
May 22
A proud moment for the Netwrix team. Netwrix PingCastle has been referenced in a recently published joint Five Eyes cybersecurity advisory on detecting and mitigating Active Directory compromises — recognized as a tool defenders can use to assess and strengthen their AD security posture. Active Directory remains one of the most targeted parts of enterprise infrastructure, and we’re honored to see PingCastle acknowledged as part of the broader defensive toolkit available to organizations worldwide. A huge thank you to the cybersecurity community and to every defender who has trusted Newtrix PingCastle over the years. We’ll keep building tools that help blue teams stay ahead. Learn more about PingCastle: netwrix.com/en/products/ping… #CyberSecurity #ActiveDirectory #PingCastle #InfoSec #BlueTeam
2
2
87
I break Windows.... retweeted
I'm so excited to @hthackers 2026 and the Spaceballs theme! Ticket up today and I'll see you there! ❤️🤘
Hackers Teaching Hackers Conference 2026 June 3-5 | Columbus, OH Tickets On Sale: $275 Villages. Talks. Networking. Hacking. 2026.hthackers.com/ #HTH2026
3
8
198
🎉 !TOOL DROP! 🎉 VEXED - vSphere EXploitation & Extraction Dumper It enumerates users, Kerberos credentials, scans process memory, and tests for known misconfigurations. Check it out and let me know what you think! github.com/dfirdeferred/VEXE…
3
80
Check out my new whitepaper covering vSphere's Active Directory authentication flow! I asked one question: when vSphere integrates with Active Directory, where do the credentials actually go? netwrix.com/en/resources/gui…
2
47
I break Windows.... retweeted
Remember your roots.
166
184
2,620
57,976
I break Windows.... retweeted
⚠️ Hackers Can Attack Active Directory Sites to Escalate Privileges and Domain Compromise | Read more: cybersecuritynews.com/active… Active Directory sites are designed to optimize network performance across geographically separated organizations by managing replication and authentication across multiple locations. The vulnerability emerges because Active Directory sites can be linked to Group Policy Objects (GPOs), which control system configurations across an organization. When attackers gain write permissions to sites or their associated GPOs, they can inject malicious configurations that compromise all computers connected to those sites, including domain controllers. #cybersecuritynews #windows
8
140
547
31,642
Super stoked to share that @JimSycurity and I will be leading an Active Directory Security course at BSides Charm 2025! We will cover Active Directory infrastructure, common misconfigurations, vulnerabilities and mitigations, and hands-on labs!
4
155
I break Windows.... retweeted
New #AADInternals version is finally out now: ▪ Moved endpoint related stuff to new module: AADInternals-Endpoints ▪ Added blue team stuff: Get app consent info, find backdoors, convert SID<>Entra ID Object ID, find abusable dynamic groups ▪ Added red team stuff: Get ESTSAUTH cookies, export Intune certificate, invoke PS scripts as system or other users See full change log at: aadinternals.com/aadinternal…
7
117
410
27,172
Make sure you stop by the @TrimarcSecurity ISV (Active Directory Hacking) today at @hthackers Hackers Teaching Hackers. There might even be a second CTF flag there if you know where to look.....
2
2
356
I break Windows.... retweeted
Do you allow your high privileged users in Entra ID (e.g. Global Admin) to register authentication methods themselves after initial setup? Do you, to detect malicious actions, monitor the addition of e.g. passkeys and follow up with the user?
9
6
69
11,744
I break Windows.... retweeted
When it comes to Active Directory Security Descriptors, ignorance is NOT bliss... it can be a full-on SLASHER FLICK of misconfigurations 🔪 This Thursday, @JimSycurity shares insights we've learned across thousands of AD & Entra ID security assessments -- Tips that can arm you to be the "sole survivor" archetype in the horror movie of securing Active Directory environments. (After all, nobody wants to be that sacrificial lamb who yells, "I'll be right back!" before heading into the wine cellar) 🎃 The Gooey Guts of Security Descriptors: Securable Objects, All the Way Down Thursday, October 24th @ 11 am PT / 2 pm ET Register at bit.ly/DescriptorInnards
1
6
18
2,092
New project: FlameScale OS. An operating system aimed at Active Directory/Windows security research. I will be adding more functionality weekly on Sundays. Get your hands dirty with it at the @TrimarcISV (AD Hacking Village) at @hthackers Nov 13th-15th. github.com/dfirdeferred/Flam…
2
5
399
I created a wrapper/menu to make downloading and opening all of the @TrimarcSecurity tools on github easier and in one place. Just run the script and select which tool you want to download/open. github.com/dfirdeferred/Trim… #trimarc #activedirectory
2
9
666
Im stoked to be presenting my new tool! See you all this week!
2 Trimarc team members will be speaking at @WWHackinFest about tools they've developed for the #infosec community! @DFIRdeferred will be presenting his new Purple Team/Adversarial tool, "ADAM and EVE," & @dotdotdotHorse will be speaking about "PowerPUG" 🐾 hubs.ly/Q02R8l7w0
2
67
Wild Wild West Hackin Fest is right around the corner! Im so ready for some good ol' "Break and Make!"
🗓️ One week until we get to see everyone in Deadwood for @WWHackinFest! We're packing up our Backdoors & Breaches decks, shiny new stickers, & a flight of Ignis the Dragon squishies. 🐉 Save room in your bag so you can give a dragon a new, loving home! hubs.li/Q02RqT9X0
56
Make sure you stop by the @TrimarcSecurity table at @GrrCON to start getting directly active with your Active Directory security! #grrcon
1
7
789
GrrCON is right around the corner! See you there!
Heading to @GrrCON? 🌤️ Pack layers (high 79° low 54°), a refillable bottle, comfy shoes, a notepad/pen, your power bank, & STICKERS. Visit our booth to chat w/ the Trimarc crew & pick up an Ignis the Dragon squishy and Backdoors & Breaches expansion pack. hubs.li/Q02QJCWl0
1
95
I had a blast speaking at @bsidesct last weekend. What an awesome conference! I cant wait to see whats in store for next year.
59
I break Windows.... retweeted
18 Sep 2024
Slides from my @MCTTP_Con talk "A Decade of Active Directory Attacks - What We've Learned & What's Next" are now posted: trimarc.co/SeanTalkMCTTP2024
4
96
238
18,920