
Patrick Laverty 🎱
11.6K posts

Patrick Laverty 🎱
@plaverty9
Organizer https://t.co/koddp3Iu9y, Host #Layer8Podcast




Still the greatest champions dinner menu of all time


What I learned from 1,000 hours of internal pentesting in 2025. - LAPS is not as common as you’d think - The built-in domain Administrator account is often misused as a service account - Flat, non-segmented networks are the norm - Too much stock is put into EDR alone - File shares are never checked for credentials - Many IT admins don’t know they have ADCS I could go on. On the bright side, I truly believe these are some of the most solvable IT security issues. If we can’t eliminate credentials from shares how do we expect to defend against more serious issues… Curious what else I see during internal pentest? I wrote more about this on my blog. Read more: spenceralessi.com/post/common-ac…




























