infosec_mike's profile picture. Avid Indoorsman, Blue team, W605, and Octothorpe enthusiast.

Michael ⛰️🌲

@infosec_mike

Avid Indoorsman, Blue team, W605, and Octothorpe enthusiast.

Michael ⛰️🌲 reposted

The next free one-hour @Antisy_Training Anticast is on -- Getting Started in iOS Mobile Application Testing w/ Cameron C. & Dave Wed, OCT 29, 2025 12:00 PM EDT Register -- events.zoom.us/ev/AhuYC0jYtKM… Join us for a free one-hour training session with Cameron Cartier and Dave…

BHinfoSecurity's tweet image. The next free one-hour @Antisy_Training  Anticast is on -- Getting Started in iOS Mobile Application Testing w/ Cameron C. & Dave Wed, OCT 29, 2025 12:00 PM EDT

Register -- events.zoom.us/ev/AhuYC0jYtKM…

Join us for a free one-hour training session with Cameron Cartier and Dave…

Michael ⛰️🌲 reposted

The next free one-hour Black Hills Information Security webcast is on -- AI Agents and MCP Security Risks w/ @joff_thyer Thu, Oct 30, 2025 1:00 PM EDT. Register (Zoom) -- events.zoom.us/ev/Ahn_6DM5Iey… Do you know what MCP stands for? Agentic AI implementations are being used to…

BHinfoSecurity's tweet image. The next free one-hour Black Hills Information Security webcast is on -- AI Agents and MCP Security Risks w/ @joff_thyer Thu, Oct 30, 2025 1:00 PM EDT. Register (Zoom) -- events.zoom.us/ev/Ahn_6DM5Iey…

Do you know what MCP stands for?

Agentic AI implementations are being used to…

Michael ⛰️🌲 reposted

Due to the shutdown, I've had multiple reach out to me... What are the private sector cyber jobs a Fed worker could shift to? (maybe short time?) RT this far and wide. Those folks deserve a break!


Michael ⛰️🌲 reposted

If you take over a bankrupt startup’s domain, you can access okta, gsuite, adp, all sorts of pii. Don’t think there’s any cleanup.


Michael ⛰️🌲 reposted

Learn how to wield Proxifier like a pro in Senior Security Consultant Justin Palk's guide "How to Set Up Proxifier for Penetration Testing" 🔗 redsiege.com/proxifier #hacking #infosec #cybersecurity

RedSiege's tweet image. Learn how to wield Proxifier like a pro in Senior Security Consultant Justin Palk's guide "How to Set Up Proxifier for Penetration Testing" 🔗 redsiege.com/proxifier

#hacking #infosec #cybersecurity

Michael ⛰️🌲 reposted

Decisions decisions.....thoughts?

BHinfoSecurity's tweet image. Decisions decisions.....thoughts?

Michael ⛰️🌲 reposted

Don't forget! Call for Papers for Wild West Hackin' Fest @ Mile High 2026 is open until Nov. 3! Submit yours now! -- wkf.ms/45fLrjH

WWHackinFest's tweet image. Don't forget! Call for Papers for Wild West Hackin' Fest @ Mile High 2026 is open until Nov. 3! Submit yours now! -- wkf.ms/45fLrjH

Michael ⛰️🌲 reposted

Save the date for Deadwood 2026! Pre-con training: Oct. 6-7, 2026; Conference: Oct. 7-9, 2026

WWHackinFest's tweet image. Save the date for Deadwood 2026! Pre-con training: Oct. 6-7, 2026; Conference: Oct. 7-9, 2026

Michael ⛰️🌲 reposted

Don't forget! Call for Volunteers for Wild West Hackin' Fest @ Mile High 2026 ends this Friday, Oct. 17! Submit your application here: forms.monday.com/forms/da56e10f…

WWHackinFest's tweet image. Don't forget! Call for Volunteers for Wild West Hackin' Fest @ Mile High  2026 ends this Friday, Oct. 17! Submit your application here: forms.monday.com/forms/da56e10f…

Michael ⛰️🌲 reposted

Dear M365 admins: ALL OF YOU Are you using Power Platform? If you can't answer that, KEEP READING. There are still things you need to do. Here are some absolute basics that most organizations miss. You license comes with Power Apps and Power Automate functionality and a…

IAMERICAbooted's tweet image. Dear M365 admins: ALL OF YOU

Are you using Power Platform?  If you can't answer that, KEEP READING.  There are still things you need to do.

Here are some absolute basics that most organizations miss.

You license comes with Power Apps and Power Automate functionality and a…
IAMERICAbooted's tweet image. Dear M365 admins: ALL OF YOU

Are you using Power Platform?  If you can't answer that, KEEP READING.  There are still things you need to do.

Here are some absolute basics that most organizations miss.

You license comes with Power Apps and Power Automate functionality and a…

Safe travels from @WWHackinFest another excellent experience thank you to all the staff and volunteers. Glad I was able to see and visit with so many.


Michael ⛰️🌲 reposted

"[...] the Microsoft Store is likely to allow users to install dual use applications that can be used to bypass security controls or access sensitive information in the environment." Read more: blackhillsinfosec.com/microsoft-stor… Microsoft Store and WinGet: Security Risks for Corporate…

BHinfoSecurity's tweet image. "[...] the Microsoft Store is likely to allow users to install dual use applications that can be used to bypass security controls or access sensitive information in the environment."
Read more: blackhillsinfosec.com/microsoft-stor…

Microsoft Store and WinGet: Security Risks for Corporate…

Michael ⛰️🌲 reposted

What risks arise from adding Domain Users to a template’s Enroll ACL? Share your top 3! 🔥 Last chance to join us on Oct 15 @ 12:00 pm ET! events.zoom.us/ev/AsbybLz-COO…

Antisy_Training's tweet image. What risks arise from adding Domain Users to a template’s Enroll ACL? Share your top 3! 🔥 Last chance to join us on Oct 15 @ 12:00 pm ET! events.zoom.us/ev/AsbybLz-COO…

Michael ⛰️🌲 reposted

👀An attacker requests a cert, uses it for lateral movement, deletes logs... Where else can you see evidence? Join us Oct 15 @ 12 PM ET for Anti-Cast with Alyssa Snow & Kaitlyn Wimberley. events.zoom.us/ev/AsbybLz-COO…

Antisy_Training's tweet image. 👀An attacker requests a cert, uses it for lateral movement, deletes logs... Where else can you see evidence? Join us Oct 15 @ 12 PM ET for Anti-Cast with Alyssa Snow & Kaitlyn Wimberley. events.zoom.us/ev/AsbybLz-COO…

Michael ⛰️🌲 reposted

Join @Carlos_Perez for our next webinar on October 15 at 1:00PM. We'll draw from recent, anonymized investigations to expose the most devastating failure patterns our Incident Response team has encountered in the field. Secure your spot now! trustedsec.zoom.us/webinar/regist…

TrustedSec's tweet image. Join @Carlos_Perez for our next webinar on October 15 at 1:00PM. We'll draw from recent, anonymized investigations to expose the most devastating failure patterns our Incident Response team has encountered in the field. Secure your spot now!
trustedsec.zoom.us/webinar/regist…

Michael ⛰️🌲 reposted

If posture reviews had a boss battle, what would yours be? 🎮 Stay equipped for the fight and join Kimber Amos for free: antisyphontraining.com/event/anti-cas…

Antisy_Training's tweet image. If posture reviews had a boss battle, what would yours be? 🎮

Stay equipped for the fight and join Kimber Amos for free: antisyphontraining.com/event/anti-cas…

Michael ⛰️🌲 reposted

"Who knows what vulnerabilities are hiding just waiting to be found?" Security Consultant Stuart Rorer discusses how to up your recon game during web app penetration tests in this blog post 🔗 redsiege.com/eagleeye #hacking #infosec #cybersecurity

RedSiege's tweet image. "Who knows what vulnerabilities are hiding just waiting to be found?"

Security Consultant Stuart Rorer discusses how to up your recon game during web app penetration tests in this blog post 🔗 redsiege.com/eagleeye

#hacking #infosec #cybersecurity

Michael ⛰️🌲 reposted

Check out Titanis, my new C#-based protocol library! It features implementations of SMB and various Windows RPC protocols along with Kerberos and NTLM. github.com/trustedsec/Tit…


Michael ⛰️🌲 reposted

Active Directory hardening is free…outside of your time. Overall - PingCastle Passwords - FGPP, LAPS, Lithnet Permissions - ADeleg/ADeleginator Applocker - Applocker Inspector/Applocker gen ADCS - Locksmith Logon scripts - ScriptSentry GPO - GPOZaurr Baselines - CIS/Microsoft…


Michael ⛰️🌲 reposted

Dumping LSASS is old school. If an admin is connected on a server you are local admin on, just create a scheduled task asking for a certificate on his behalf, get the cert, get its privs. All automatized in the schtask_as module for NetExec 🥳🥳🥳

Defte_'s tweet image. Dumping LSASS is old school. If an admin is connected on a server you are local admin on, just create a scheduled task asking for a certificate on his behalf, get the cert, get its privs. All automatized in the schtask_as module for NetExec 🥳🥳🥳

Loading...

Something went wrong.


Something went wrong.