

Mike Manrod
10.4K posts

@CroodSolutions
CISO and faculty by day, adversary emulation/tools by night, bad jokes and memes all the time.









What I learned from 1,000 hours of internal pentesting in 2025. - LAPS is not as common as you’d think - The built-in domain Administrator account is often misused as a service account - Flat, non-segmented networks are the norm - Too much stock is put into EDR alone - File shares are never checked for credentials - Many IT admins don’t know they have ADCS I could go on. On the bright side, I truly believe these are some of the most solvable IT security issues. If we can’t eliminate credentials from shares how do we expect to defend against more serious issues… Curious what else I see during internal pentest? I wrote more about this on my blog. Read more: spenceralessi.com/post/common-ac…

