Identity Security Architect @ TrustedSec. Microsoft Certified Master #ActiveDirectory & former Microsoft MVP. Co-Host @ Enterprise Security Weekly. He/Him. #BLM

Joined August 2014
1,673 Photos and videos
Pinned Tweet
3 Jun 2020
To my black family, friends, and people seeing this: I love you You matter I'm here for you #BlackLivesMatter
4
4
139
Sean Metcalf retweeted
Jun 12
I cannot overstate how powerful codex is for cybersecurity work. I'd encourage all defenders to sign up for Trusted Access for Cyber (chatgpt.com/cyber) and give it a shot for their workflows. If orgs are slow to get TAC approvals, please reach out to me.

56
65
624
51,588
Sean Metcalf retweeted
Probably shouldn’t have hyped the hype machine of world catastrophe which mythos is not.
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
22
21
200
17,683
Sean Metcalf retweeted
Checkout all the great talks from this year's event. I'm obviously quite fond of my talk with @PyroTek3 but @rootsecdev also does a fantastic job walking though some modern token attacks.
Wait a minute, Doc 👀 Are you telling me this year's #SmileyCon sessions are available for everyone? Check out the latest #cybersecurity insights and expert perspectives from the Doc Browns of TrustedSec—watch now! hubs.la/Q04l5H5L0
1
3
779
Sean Metcalf retweeted
Huge! Some amazing talks here !! Check them out
Wait a minute, Doc 👀 Are you telling me this year's #SmileyCon sessions are available for everyone? Check out the latest #cybersecurity insights and expert perspectives from the Doc Browns of TrustedSec—watch now! hubs.la/Q04l5H5L0
8
50
4,728
Talks from @TrustedSec's invite-only conference #SmileyCon are now available on YouTube. Enjoy!
Wait a minute, Doc 👀 Are you telling me this year's #SmileyCon sessions are available for everyone? Check out the latest #cybersecurity insights and expert perspectives from the Doc Browns of TrustedSec—watch now! hubs.la/Q04l5H5L0
4
928
Sean Metcalf retweeted
Bitkocker exploits go brrrr Nothing is safe, everything is vulnerable ;) (that’s not true but it sounds like a cool marketing line) Not tested this but I’m sure many will. Just woke up! Need tea 🫖 #bitlocker #microsoft #windows #exploits github.com/MSNightmare/Great…
11
18
173
10,855
Sean Metcalf retweeted
want to see how much HTTPS is in use? transparencyreport.google.co…

4
4
39
6,061
Sean Metcalf retweeted
🔥 The InfoSec World 2026 agenda is live! Explore the sessions, discover the speakers, and build a schedule tailored to your goals. ⏰ Register now to save: bit.ly/4cXS9yK #InfoSecWorld #CRAevents
1
1
431
Sean Metcalf retweeted
x% of y = y% of x So, in order to calculate a percentage in your head, it might be easier to turn it around. What is 4% of 50? It's the same as 50% of 4.
12
80
652
19,821
Sean Metcalf retweeted
Now that we've identified the blind spot, here's how to fix it. In Part 2 of our two-part series, @Carlos_Perez delivers a phase-based implementation guide to hardening Microsoft #Intune across 11 critical controls. Read it now! hubs.la/Q04l3yQk0
1
13
29
4,197
Sean Metcalf retweeted
Attackers were able to query customer tables 😳 As a reminder, these tables can contain, employee information, asset information, vulnerability asset information, HR cases, security operations, vendor information.
ServiceNow discloses security incident exposing customer data bleepingcomputer.com/news/se… bleepingcomputer.com/news/se…
3
13
37
7,712
Sean Metcalf retweeted
I'm seeing from virtually every enterprise customer that they are being tasked with two things: 1. All in on AI - every aspect of the business, right now every organization, every team, every function of the business. 2. How they will reduce 20-30% in their budgets using AI. 3. Build enterprise solutions that solve business problems without relying on SaaS providers. How little do they know that this increases demand, work, and complexity as well as adding substantial cost for AI token usage. Someone flagged me where I was speaking (non cybersecurity) and said "How do I reduce 20% of my budget, while adding monumental complexity, workload, and unproven technologies that aren't defined on what they would accomplish at the same time?" Welcome to our lives in cybersecurity the past 20 years.

ALT Hang First Time GIF

31
33
205
9,331
Sean Metcalf retweeted
I tire of this. The word is "users". Normal end-users. And I don't blame them for doing so. If orgs want to improve security: block browser password storage at the policy level, invest in a password manager, and train end users how to use it. People don't respond well to shame (even if implicit), but they do to knowledge and encouragement. Dumb take, Proton.
We need a word for people who store their passwords in their browser.
10
13
120
9,225
Sean Metcalf retweeted
Keep going family!!
As a bit of a Google Trends nerd 😂 If Stargate were a dead franchise and aimed at a “small dedicated fanbase” you wouldn’t expect worldwide search spikes for “Stargate SG-1 Netflix” ( 800%), “Stargate Netflix,” and “Stargate new series.” The datas suggestion is there is still a strong meaningful audience demand whenever the franchise becomes visible on a major streaming platform for example. (There’s numerous examples of this kind’ve trend) So if little old me with a PC and a pretty ok understanding of how social media ticks can see the missed goal here. How is it the executive at Amazon MGM getting paid what I’m sure is top money get to the decision they did from a strategic standpoint? I feel there’s a missing piece here because it makes no sense. lol. #stargate
67
426
3,080
33,108
Sean Metcalf retweeted
If you have the ability, Mike and Angela are amazing humans going through a very difficult time and could use your help. Praying for their family during this difficult time ❤️🙏
As yall may have realized, I disappeared from the community for a little while we fight the most difficult fight of our life. My wife Angela was diagnosed with stage 3 cancer. We need all the help we can get, please consider supporting our fight. givesendgo.com/anchors-for-a…
3
8
55
7,206
Sean Metcalf retweeted
How dead is Active Directory? According to NAIC census data as of December 2024, there were about 1.5 million businesses in the US with 10 employees. Even with conservative estimates, the amount of businesses that STILL have AD is not insignificant. Active Directory is alive and well and continues to be a major infrastructure component for many, many organizations. That means that Active Directory will continue to be attacked. That also means that learning to defend Active Directory will continue to be important.
13
23
151
21,124
Sean Metcalf retweeted
According to naic census data as of December 2024 there’s ~1.5M businesses of 10 employees in the US. 86% of businesses (surveyed by Microsoft) have some form of workload that depends on AD. Long live Active Directory ✌️
Wait, people still use AD?
4
5
40
8,046
Sean Metcalf retweeted
‼️🚨 BREAKING: ServiceNow has been breached. Customers are reporting unauthorised access to their instances. One customer states their security team reported this vulnerability to them, and they closed the case twice, saying they had already known since the 7th of April.
93
731
3,855
872,163