spencer @techspence
🛠️ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack | @SecurIT360 & @CyberThreatPOV spenceralessi.com/adsecuritykit 🏰AD Security Resource Kit ⬇️ Joined November 2010-
Tweets52K
-
Followers16K
-
Following3K
-
Likes129K
@clintgibler @OpenAI @michaelaiello Wicked! Make Active Directory great again!
@awscloud Masterclass in twitter viral marketing
I think this N-day research is potentially the biggest story of AI, vulnerability finding, and exploit development. red.anthropic.com/2026/n-days/ 1/6
@Kipnis_a @anton_chuvakin Totally, this one has sound! 😜
@m19o__ Unfortunately many tasks require elevation
Hardening Active Directory is, forgive me, hard. But it doesn’t make it unnecessary.
@AndyMicone For sure. AD in its default form it’s not desirable
@CreativeWolf @PyroTek3 Some folks believe there will be a resurgence of on-prem. Who knows
How dead is Active Directory? According to NAIC census data as of December 2024, there were about 1.5 million businesses in the US with 10+ employees. Even with conservative estimates, the amount of businesses that STILL have AD is not insignificant. Active Directory is alive and well and continues to be a major infrastructure component for many, many organizations. That means that Active Directory will continue to be attacked. That also means that learning to defend Active Directory will continue to be important.
One of the many reasons to use @magicswordio is to avoid this trade off: “ransomware actors can defeat core components of their defenses without warning and shut down their networks, but preemptively blocking these vulnerable drivers could also cause significant disruptions.”
Our co-founder @M_haggis was quoted in Dark Reading's piece on the BYOVD ecosystem. 430 vulnerable drivers can bypass HVCI. That's 21% of everything LOLDrivers tracks. Most organizations don't block them because they don't understand the risk, and because they fear that blocking
Career update: I’ve joined @OpenAI to lead Cyber with @michaelaiello. Why I joined, and what we’ll be building: It’s clear that AI is fundamentally changing how software is being written and secured. Coding agents are writing the majority of code for many developers, software is getting shipped more quickly, and vulnerabilities that were latent for 20 years are being discovered at a rapid pace. The time to bug discovery, and exploitation once discovered, are trending down (H/T @EppSecurity and @gadievron). I believe we have an unparalleled opportunity to fundamentally 𝘪𝘮𝘱𝘳𝘰𝘷𝘦 cybersecurity in ways that were previously impossible. (H/T @bubblewire’ BSidesSF keynote on reasons for optimism) Over 6 years at @Semgrep, I had the privilege of working with an amazing team building what has become the most popular open source security code scanning tool in the world, that many companies have built their application security program around. Now, at @OpenAI, I’m thrilled to be a part of a company helping shape how software is written, and how security work gets done. It is a massive opportunity, and responsibility, and I don’t take that lightly. Here are my current thoughts about where things are headed: 𝐑𝐞𝐬𝐢𝐥𝐢𝐞𝐧𝐭 𝐛𝐲 𝐝𝐞𝐬𝐢𝐠𝐧. Defenders are not going to win playing bug whack-a-mole. We need to systematically eliminate classes of vulnerabilities, via generating secure code and streamlining the detect → validate → fix process. 𝐀𝐮𝐠𝐦𝐞𝐧𝐭 𝐚𝐧𝐝 𝐞𝐦𝐩𝐨𝐰𝐞𝐫 𝐩𝐞𝐨𝐩𝐥𝐞. We should build models and tools that give defenders “superpowers,” enabling them to be more ambitious in the scope they tackle, shift from being reactive to proactive, and allow them to automate the drudgery so they can focus on the highest leverage work. 𝐒𝐞𝐜𝐮𝐫𝐞 𝐭𝐡𝐞 𝐜𝐨𝐦𝐦𝐨𝐧𝐬. The world runs on open source software. OpenAI has already spent $Ms finding and patching vulnerabilities in the most popular and widely run software, including browsers, operating systems, and core libraries. More on this soon. We’re also working on helping secure critical infrastructure. 𝐂𝐨𝐦𝐦𝐮𝐧𝐢𝐭𝐲 𝐚𝐧𝐝 𝐩𝐚𝐫𝐭𝐧𝐞𝐫𝐬. Securing the world is a community effort. I’m looking forward to partnering with cybersecurity vendors, researchers, practitioners, governments, and more to do together what we can’t do alone. 𝐓𝐢𝐦𝐞 𝐭𝐨 𝐛𝐮𝐢𝐥𝐝. Tactically, here are some domains I’m excited about: - Finding, validating, and reliably patching software vulnerabilities at scale. - Eliminating classes of vulnerabilities and making software resilient by design. - Giving broad access to the best cyber models to empower defenders, not just to a select few. - Creating and sharing Skills and playbooks that help in many security domains. - Building platforms that enable defenders to easily orchestrate security work. - Making enterprise agents safe and reliable. Time to build 😎 — What would help you most? What should we build? Let me know.
@Kipnis_a @anton_chuvakin Haha nice!! Not bad
@Mitchell90 There is that for sure. also many orgs would do well to just clean up some obviously stale or dormant accounts and permissions. It would go a long way
@netumune yeah for real. The worst kind of cleanup
@Mitchell90 That's becoming super common with the orgs I work with
Do this so you are less likely to have to talk to me.
If you're an IT Admin and you follow this list, and you put in the work to fix the findings, your environment will be more secure.
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Dave Kennedy @HackingDave
231K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
mRr3b00t @UK_Daniel_Card
123K Followers 8K Following Department of Cyber WAR. Member of the Counter Spider Collective. Wielder of AI to defend in Cyber Space. Ralph Vibe Specialist. VibeOps Operator!
SwiftOnSecurity @SwiftOnSecurity
410K Followers 9K Following computer security person. former helpdesk.
Jean @Jean_Maes_1994
12K Followers 1K Following @sansoffensive Certified instructor/SEC565 author/SEC699 co author https://t.co/cp5DerI3g4
Grzegorz Tworek @0gtweet
38K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
Mick Douglas 🇺🇦... @bettersafetynet
32K Followers 575 Following Consultant for InfoSec Innovations | @SANSInstitute Principal Instructor | @IANS_Security Faculty | I like information security. How about you?
John Hammond @_JohnHammond
320K Followers 3K Following Cybersecurity Researcher @HuntressLabs Just Hacking Training @JustHackingHQ w/ @ethicalhacker https://t.co/UtsNJiyiEk && https://t.co/narO3syzIy
Florian Roth ⚡️ @cyb3rops
221K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
sn🥶vvcr💥sh @snovvcrash
12K Followers 494 Following Sr. Penetration Tester / Red Team Operator @ptswarm :: Author of the Pentester’s Promiscuous Notebook :: He/him :: Tweets’re my pwn 🐣
n00py @n00py1
14K Followers 966 Following Retweeter of InfoSec/Offsec/Pentest/Red Team. Occasional blogger/Independent security research.
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
mgeeky | Mariusz Bana... @mariuszbit
14K Followers 950 Following 🔴 Offensive Security Developer @ Outflank, Red Team operator, ex-AV dev, ex- malware researcher 🫖 Green tea lover
rootsecdev @rootsecdev
27K Followers 1K Following Senior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.
Bryson 🦄 @brysonbort
20K Followers 496 Following 🦄 @scythe_io @grimmcyber, Sr Advisor @IST_Org & NatSec Sr Fellow, Co-Fdr @ICS_Village, @c2_matrix co-creator, USMA Science Board, Angel Investor, US Army Offcr
EvilMog® @mog.evil.a... @Evil_Mog
18K Followers 2K Following Hacker, Team Hashcat, Bishop of the Church of Wifi, Uber Badge Collector. Views != Employers. Not a Ph.D, Recycled Memes,
an0n @an0n_r0
14K Followers 731 Following CRT(E|O|L) | OSCP | @RingZer0_CTF 1st (for 2yrs) | HackTheBox Top10 | RPISEC MBE | Flare-On completer | GoogleCTF writeup winner | SSD research | Math MSc |🇭🇺
Lisa Forte @LisaForteUK
58K Followers 4K Following Cyber Security - Partner @redgoatcyber - Climber / Caver. she/her
Baron Von Jangles @BaronVonJangles
23 Followers 496 Following Baron of the Blockchain... Stealing Womens Hearts with Crypto Pillow Talk since 2018 #ROSE #AZERO
vinnie✌🏿 @vincentoo_ko
17 Followers 126 Following Security is contextual || ----Techie---✌🏿 Network engineering and Cybersecurity ||
Josh Edwards @JEdwards5
602 Followers 904 Following InfoSec enthusiast. Cybersecurity professional. Nerd. Fitness model for Under Armour.
Horus-labs @_horus_labs
4 Followers 189 Following
Mehmet Sait YILMAZ | ... @yilmazmehmets
448 Followers 1K Following ÇözümPark Bilişim Portalı Haber Editörü / Yazar - Microsoft Technical Evangelist - MVP
Pete Lodge @AmericanPete
15 Followers 90 Following
RnR_Chan @RnR0804
15 Followers 915 Following
Hayk @TheHayk
20 Followers 243 Following Technologist with a passion for system design, and cyber security. I love solving interesting problems.
Atakilti Tigabu @AtakInjector
12 Followers 388 Following
Abbas Muraj @abbasmuraj
4 Followers 249 Following
Sly @arrambide1
555 Followers 5K Following #BTC - cash 💵 is trash 👎🏼. I like long walks on the beach, and my safe word is pancakes 🥞.
Ashish @Ashish09978453
16 Followers 202 Following
zhangling @zhangli47713576
50 Followers 1K Following
Mitch Lantz @lantzops
32 Followers 386 Following RHCSA | DevSecOps | Blue Team Building CI/CD AppSec labs to fight supply chain vulnerabilities. Defending the pipeline against vibe-coded shenanigans.
Marc @Marc_ZADBN
23 Followers 135 Following
beres gitau @manzzlikegitau
29 Followers 311 Following Trying not to think too hard and having fun with this. I guess || Mousepad connoisseur
Elliot Bolour @elliotbol4
1 Followers 61 Following
Jean Weerts | @jweert... @JeanJWeerts
33 Followers 777 Following Technomancer 🇫🇷🇺🇸🇪🇺 Terminally curious. Interested in all things Microsoft, 3D Print/Electronics/Fabrication/Music
Toms I @xtoomsx
25 Followers 473 Following
MuratT @Krakartal_1903
46 Followers 520 Following
GUATETECHLABS @incognit0gt
270 Followers 2K Following Desarrollo de software, y app mobiles para tu negocio.
Aaron Bregg @Tychoash
99 Followers 153 Following I am an information security, outdoors, gaming and technology enthusiast.
MRreviews @m_rreviews
10 Followers 794 Following wine and album reviews simple, easily digestible reviews write drunk, dont edit
dosmic @pkngrsq
2 Followers 392 Following
Nikhil Mittal @nikhil_mitt
20K Followers 439 Following Hacker, Infosec Researcher, Military Affairs & History, PowerShell, AD and Azure pwner, Creator of Nishang and others :) Founder @alteredsecurity
Brad @Showtime_13_
163 Followers 1K Following
Ben Hocking (he/him) @bmwhocking
775 Followers 3K Following Happiest Outdoors, Whitewater, Climbing, Gliding • Occasionally political, dislike accepting inequality as part of life • he/him
Ife_lade @ife_ladee
12 Followers 109 Following
doug @Doug_Alk
740 Followers 265 Following
JBird Cyber @JBirdCyber
151 Followers 49 Following Helping you get that cyber / IT job. CISSP, CISM, CISA, CySA+. No gatekeeping.👇
w @webhoooker
2 Followers 94 Following
Recon @stealthrecon01
159 Followers 1K Following Cybersecurity Engineer Learning in public | figuring life out Never trust, always verify
George Vadasis @GVadasis
99 Followers 930 Following Άνθρωπος, Παναθηναϊκός, προπονητής του καναπέ, αιώνιος φοιτητής, IT specialist, cat person.
LIMITLESS FOREVER @NasirStylin
200 Followers 182 Following Founder @ https://t.co/DQuF25ngP5 Identity Systems Engineer
pat @P4121209
4 Followers 165 Following
Solomon Neas @solomonneas
209 Followers 139 Following dad. retired chef. network & systems engineer. doin' AI stuff. - MS Cyber Intel & Info Security @ USF. https://t.co/3670uzIIOp https://t.co/QWmmvdwYKY https://t.co/rvaZV0iBXU
BlackBoyFly 🇬🇭 @blackboyfly0
883 Followers 3K Following I am Weird, Normal isn’t working for me anymore plus I don’t know what I am doing .👑Die Hard LFC Fan . ManiFan . 💻 Computer Programming Enthusiast .
Sahil Bhatt @Misguidedcoder
6 Followers 162 Following Code ninja by day, web dev & DSA student by night.
cwestpapa.btc🟧 @Cwestpapa
99 Followers 185 Following Web3 enthusiast | Eager to help others navigate the decentralized world | Learning and growing with the community | Photographer
dave @_dave_bull_
551 Followers 3K Following
Yesenia Barajas @CyberChisme
13 Followers 46 Following Busy writing about true crime, mysteries, scientific phenomena, and aliens. You know, normal girl stuff.
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Dave Kennedy @HackingDave
231K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
vx-underground @vxunderground
438K Followers 358 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Mike Felch (Stay Read... @ustayready
17K Followers 2K Following Offensive @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | Fighter for truth | K1HAQ
mRr3b00t @UK_Daniel_Card
123K Followers 8K Following Department of Cyber WAR. Member of the Counter Spider Collective. Wielder of AI to defend in Cyber Space. Ralph Vibe Specialist. VibeOps Operator!
SwiftOnSecurity @SwiftOnSecurity
410K Followers 9K Following computer security person. former helpdesk.
Jean @Jean_Maes_1994
12K Followers 1K Following @sansoffensive Certified instructor/SEC565 author/SEC699 co author https://t.co/cp5DerI3g4
Grzegorz Tworek @0gtweet
38K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
Mick Douglas 🇺🇦... @bettersafetynet
32K Followers 575 Following Consultant for InfoSec Innovations | @SANSInstitute Principal Instructor | @IANS_Security Faculty | I like information security. How about you?
John Hammond @_JohnHammond
320K Followers 3K Following Cybersecurity Researcher @HuntressLabs Just Hacking Training @JustHackingHQ w/ @ethicalhacker https://t.co/UtsNJiyiEk && https://t.co/narO3syzIy
Florian Roth ⚡️ @cyb3rops
221K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
sn🥶vvcr💥sh @snovvcrash
12K Followers 494 Following Sr. Penetration Tester / Red Team Operator @ptswarm :: Author of the Pentester’s Promiscuous Notebook :: He/him :: Tweets’re my pwn 🐣
n00py @n00py1
14K Followers 966 Following Retweeter of InfoSec/Offsec/Pentest/Red Team. Occasional blogger/Independent security research.
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
mgeeky | Mariusz Bana... @mariuszbit
14K Followers 950 Following 🔴 Offensive Security Developer @ Outflank, Red Team operator, ex-AV dev, ex- malware researcher 🫖 Green tea lover
Adam Chester 🏴�... @_xpn_
38K Followers 538 Following Hacker for Hire at @SpecterOps | Blog at https://t.co/tjfTOlmau2 | Insta at https://t.co/PqR6CZQ48T
Marcello @byt3bl33d3r
30K Followers 819 Following CyBeRsEcUrItY | Not afraid to put down with some THICC malware on disk | AI Research @PaloAltoNtwks | former purple team | Ex @spacex
Charlie Bromberg « ... @_nwodtuhs
16K Followers 660 Following Trying to hack the way we hack things 🏴☠️
James Hooker @g0blinResearch
6K Followers 2K Following Developer, turned security advocate - OSCP, BRDY, GNGR. Co-founder of @hackthebox_eu. My thoughts are my own.
Paula Januszkiewicz @PaulaCqure
14K Followers 515 Following Security Expert | Penetration Tester | CQURE Owner | @CQUREAcademy
CQURE Academy @CQUREAcademy
4K Followers 79 Following Welcome to CQURE Academy - Where Windows Security Experts Level Up. #CQUREAcademy
Robin Granberg @ipcdollar1
377 Followers 298 Following Works @ Semperis, Tweets are my own. Blog: https://t.co/XdICuDKHxR Project: https://t.co/Z7OT8sQOep
Nicolas Bustamante @nicbstme
25K Followers 566 Following AI for knowledge workers at @Microsoft. Prev: CEO @fintoolx (acq. Microsoft), CEO @doctrine (Acq. Summit Partners)
Techmeme @Techmeme
423K Followers 990 Following Top news and commentary for technology's leaders, from all around the web. This account shares top-level Techmeme headlines. Visit our site for full context.
Jordi Ribas @JordiRib1
9K Followers 182 Following @Microsoft President, Head of Search at Microsoft. Empowering people to achieve more with Search and AI.
Omar Shahine @OmarShahine
12K Followers 798 Following 🦞 Microsoft Scout (OpenClaw + Microsoft 365), Corporate Vice President @ Microsoft. I write a newsletter on products https://t.co/yMgREYoPcG & https://t.co/fXWpvLkJ4q
Windows Developer @windowsdev
513K Followers 5K Following Everything you need to know to develop great apps, games and other experiences for and on Windows.
Microsoft Developer @msdev
522K Followers 45 Following Dive into the biggest news from Microsoft Build and learn how to start building with it today 👇
Ivan @Ivanklydz
471 Followers 73 Following Security researcher with deep focus on vulnerability detection. 2 google bug bounty awards.
Guinness Chen @guinnesschen
4K Followers 751 Following Building codex at @openai, prev @stanford, @imbue_ai
GenXFatBastard 🏴�... @GenXFatBastard
1K Followers 2K Following Survived the 80's Sex Drugs and Rock and Roll! I am just here for the memes!
💻 Sherrod @sherrod_im
37K Followers 7K Following Difficult mystery girl connected to the divine forces of the universe.
ContinuumCon @_ContinuumCon_
266 Followers 7 Following Official account for ContinuumCon - the Cybersecurity training conference that never ends.
Ekoparty | Hacking ev... @ekoparty
25K Followers 160 Following The coolest #hacking conference and meeting point in LATAM since 2001 🏴☠️
Abdul Mhanni @abdo_mhanni
206 Followers 819 Following Part Time Penetration tester, Full Time Script Kiddie
Anthony Bendas @AnthonyBendas
127 Followers 189 Following Meaning-Finder Futurist, Cybersecurity Educator Building @Level_Effect 日本文化, Gaming
Juan B @juanbqtech
47 Followers 178 Following Networks, SysAdmin, +Cyber | Former NetEng/NetOps Verizon Enterprise, BT Global | Certs: CCNA, CCNP SP, CCST Cyber, CCNA Cyber *Use 2FA everywhere!
Cerebras @cerebras
56K Followers 260 Following The world's fastest AI inference and training. Try the latest open models at: https://t.co/jREGhLI2nj
box turtle @xploitrsturtle2
2K Followers 15 Following I follow ToS Box turtle / canisterturtle / shai huturtle email service is down - uwu underground / icesolst has a safeword with me mum look Im on the news.
❄️ winter ❄️ @_winter_wonders
3K Followers 794 Following security researcher \ rust realist \ @ghostlifae got root on my heart \ @uwu_underground got root on my brain
Boaz Barak @boazbaraktcs
33K Followers 812 Following Computer Scientist. See also https://t.co/EXWR5k634w . @harvard @openai opinions my own.
Atredis Partners @Atredis
3K Followers 1K Following Atredis is a 100% worker-owned team of world-class security researchers and consultants. We do risk-centric, research-driven security testing and consulting.
Mark Sewell @MarkSewe
253 Followers 1K Following I work as an InfoSec and Infrastructure specialist living in the U.K. In my spare time, I enjoy football and boxing! All views expressed here are my own.
Spencer Heckathorn @mrhobbeys
288 Followers 392 Following Christian. Ex-poker player. In IT and AI since the 2000s. Runs several businesses. Posts stopping points, not highlight reels.
IPNetGeek @IPNetGeek
139 Followers 647 Following Server/Network Geek, Azure Admin, Foodie, Traveler, ❤️ both Windows+Mac, Software Development Manager, CLI nerd, Retro Gamer, I❤️C64, WDW DVC+AP. #RetroTech
Oliphant @imoliphant
12 Followers 173 Following Security through Obscurity | Cyber Security Analyst | CySa+ | CCDL2
ANY.RUN @anyrun_app
33K Followers 191 Following Empowering businesses with proactive security solutions: Interactive Sandbox, TI Lookup and Feeds. Sign up: https://t.co/8hIX0Qh5ME
eden @edendotso
26K Followers 3 Following The top creators research before they post. Eden is where they find outlier content across all platforms.
Chris Theisen @crtheisen
248 Followers 351 Following PhD from NCSU in computer science and infosec. Ex-MSFT security architect. Love bunnies. My friend Bonzi Buddy tells me what my opinions are.
Assaf Kipnis @Kipnis_a
116 Followers 301 Following Threat intel @ LinkedIn → Google → Meta → ElevenLabs Building KTLYST Labs: Security org's nervous system AuDHD + AI is my superpower Founder @KTLYSTlabs
michael @mkultraWasHere
14 Followers 165 Following AI Research Engineer @dreadnode offensive cyber evals/benchmarks, agent tooling & harnesses, training datasets (opinions are my own)
Luiz Macedo @OLuizMacedo
576 Followers 413 Following Senior Product Manager @Microsoft | Cloud, Security & AI. Father, husband, and tech professional. Opinions are my own.
clem 🤗 @ClementDelangue
375K Followers 5K Following Co-founder & CEO @HuggingFace 🤗, the open and collaborative platform for AI builders
sshell @sshell_
10K Followers 1K Following AI offensive security at @RunSybil (prev. @BishopFox). security research. ccdc red team. tummy ache survivor.
EntreLeadership @EntreLeadership
227K Followers 11 Following 🎙️ Leadership principles proven by @daveramsey 📈 Scale your business with proven principles and coaches 👇 Join us at EntreLeadership Summit 2025 in Colorado
Dave Ramsey @DaveRamsey
1.0M Followers 59 Following Author: 9 National Bestsellers Host: @RamseyShow & @EntreLeadership Podcast Follow my team: @RachelCruze @KenColeman @JohnDelony @GeorgeKamel @JadeWarshaw


























