Skip to content
PodcastsTechnologyThe Cyber Threat Perspective

The Cyber Threat Perspective

SecurIT360
The Cyber Threat Perspective
Latest episode

233 episodes

  • The Cyber Threat Perspective

    Every IT Team Has a Joe | Ep 195

    04/09/2026 | 27 mins.
    Interested in a pen test? Visit securit360.com.
    Every organization has a Joe. He is the long tenured engineer or admin who built half the environment, maintains the other half, and keeps most of it in his head. Everybody depends on him and nobody wants to challenge him.
    Spencer and Tyler break down key man risk in IT, drawing on hundreds of internal pen tests across law firms, banks, credit unions, manufacturing, municipalities, and SaaS organizations.
    In this episode:
    Why tribal knowledge is a security risk, not just an operations problem
    How word of mouth process handoffs turn into a game of telephone
    The reason remediations stall for an extra 30 days
    Shadow IT that originates inside the IT team
    Privilege creep and the single account that owns the environment
    When Joe's resistance to change is the correct call
    Cross training that does not add more work to Joe's plate
    Incentives, clear ownership, and update deadlines that actually stick
    Separating fact gathering from decision making so seniority does not win by default
    This is not a knock on senior admins. It is a look at the risk that accumulates when one person carries everything, and what IT leaders can do about it.
    All of our content can be found at Offsec.blog. Interested in a pen test? Visit securit360.com.
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
  • The Cyber Threat Perspective

    Service Accounts: The Shortest Path to Domain Admin | Ep 194

    27/08/2026 | 32 mins.
    Service accounts are one of the easiest paths to domain admin on an internal
    pen test, and one of the most neglected accounts in Active Directory.

    In this episode, Spencer and Tyler break down why service accounts keep
    falling: Kerberoasting every service account (not just the privileged ones),
    cracking the hashes offline, and spraying what cracks across the environment.
    Tyler shares a recent engagement where a non-administrative service account
    shared its password with a domain admin. Same password, one "SVC_" prefix
    apart. That spray handed over the domain. He's also seen the built-in RID 500
    administrator account used as a service account on three separate engagements
    this year.

    They also get into where these credentials actually live: web.config files on
    open file shares, plaintext password files (present on roughly 90% of their
    pen tests), and one .eml attachment with the credentials sitting inside a
    screenshot.

    Then the fix list, in the order they'd actually do it:

    - Inventory the accounts and document where each one is used, before you touch a password
    - Delete the service accounts that don't need to exist
    - Strip privileges and restrict interactive logon rights
    - Get a password vault or PAM solution, and make every password long and unique
    - Alert on service accounts logging on interactively
    - Move to group managed service accounts (gMSA) where you can
    - Enforce 20-25 character minimums in the meantime. They've cracked 20+ character passphrases with a gaming rig, a 180 GB wordlist, and mutation rules producing roughly four quadrillion permutations

    Plus the three cleanup mistakes that cause the most damage, including the story
    of a $70 billion enterprise where one undocumented password reset turned into a
    10-hour troubleshooting call.
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
  • The Cyber Threat Perspective

    Your IT Job Doubled. Nobody Told Your Boss. | Ep 193

    20/08/2026 | 39 mins.
    In July 2026, Microsoft alone released 622 CVEs. In the 2010s, the monthly average was about a dozen. Nobody handed IT teams more time, budget, or headcount to match, and that gap is what burnout is actually made of.
    Somewhere in the last five to ten years, "keeping the lights on" became "and also prevent cyberattacks." Spencer Alessi and Brad Causey talk through how security landed on IT's plate, why capable admins end up feeling like they're failing, and what to do about it when hiring a dedicated security person isn't on the table.
    The core of the episode is a four-question framework for prioritizing when you can't do everything:
    - Harm: what would cause the greatest damage to the business?
    - Likelihood: what is most likely to actually be attacked?
    - Improve: what can you realistically fix with the people and tools you have today?
    - Accept: what risk must leadership explicitly own because your team can't address it?
    Brad's addition: don't start from the scan report, start from the crown jewels. Client matters if you're a law firm, financial data if you're a bank. From there, draw lines outward to whatever touches them. And executives need to get comfortable accepting risk, because zero risk tolerance isn't a strategy, it's a phrase.
    We also get into the language that works with leadership. "You gave me four things and I have time for two" is adversarial and doesn't give anyone enough to decide with. "I recommend A and C, here's why, and here's when B and D land if nothing else gets added" is managing up. Same for new projects: price the work honestly, including cost, timeline, and tradeoffs, then hand the decision back to the people with full business context.
    We close with the four things IT teams need to succeed: authority, budget, team, and support, including a trusted outside partner for the specialized work you shouldn't be doing yourself.
    Planning your next penetration test? Book a call with us at https://securit360.com
    If you enjoyed this episode, please share it with your network. See you next week.
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
  • The Cyber Threat Perspective

    Subtractive Security: Stop Adding Tools and Start Deleting Attack Paths | Ep 192

    14/08/2026 | 38 mins.
    Work with us --> https://www.securit360.com/#contact-anchor
    The OWASP Subtractive Security Top 10 Project --> https://github.com/OWASP/OWASP-Subtractive-Hardening-Top-10
    The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber risk through the elimination of attack paths.
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
  • The Cyber Threat Perspective

    The CrowdStrike Settings That Actually Stop Us | Ep 191

    06/08/2026 | 38 mins.
    Two pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned.

    In this episode, Spencer and Tyler open up the CrowdStrike Falcon console and walk through the specific settings that decide whether your team catches an attack or never sees it. They start with the story that kicked the whole thing off: Tyler running a pen test where every AMSI bypass gets blocked and detections fire left and right, while Spencer runs nearly identical tooling against the same product at another client and the SOC sees nothing all week. Same CrowdStrike. Same version. Different checkboxes.

    From there it's a tactical walkthrough of Endpoint Security → Prevention Policies and the settings worth your attention: Enhanced Exploitation Visibility, which unlocks command-line and PowerShell telemetry that Microsoft disables by default; Enhanced DLL Load Visibility for side-loading attacks; WSL2 Visibility, which closes a sandbox threat actors have been using to run Kali tooling under the radar; memory scanning for in-memory C# tradecraft; Office malicious macro removal; file system containment for ransomware over SMB; vulnerable driver protection, the direct mitigation for BYOVD attacks and EDR killers; and cloud-based anomalous process execution for living-off-the-land binaries.

    They also cover custom IOA rule groups for blocking unauthorized RMM tools, centralized firewall policy management, device policies for USB control, and a warning on exclusions — especially wildcard paths, which Tyler calls a threat actor's best dream.

    The takeaway is simple: you're paying real money for EDR, and default configurations aren't giving you what you paid for. Open your console, work through the settings, test them against an IT pilot group, and enable what fits your environment.

    TOPICS COVERED

    - Why EDR vendors ship deficient defaults on purpose
    - Enhanced Exploitation Visibility and the telemetry gap in PowerShell attacks
    - DLL side-loading, WSL2 abuse, and vulnerable driver attacks
    - Memory scanning and in-memory tooling detection
    - Blocking RMM tools with custom IOA rule groups
    - Exclusion hygiene and the wildcard path problem
    - Device policies, USB blocking, and insider threat

    Sentinel One and Defender for Endpoint are next — let us know what else you want covered.

    Blog: https://offsec.blog
    Work with us on an internal pen test: https://securit360.com
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
More Technology podcasts
About The Cyber Threat Perspective
Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. We’re bringing you fresh content from our journeys into penetration testing, threat research and various other interesting topics.brad@securit360.com
Podcast website

Listen to The Cyber Threat Perspective, The AI Daily Brief: Artificial Intelligence News and Analysis and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features