EPISODE · Sep 11, 2026 · 31 MIN
[Replay] Episode 178: Internal Security Controls That Actually Frustrate Attackers
from The Cyber Threat Perspective · host SecurIT360
Replay of Episode 178, originally published April 22, 2026.We are re-running this one because it is the question we get asked moston internal pen test debriefs: of everything on the list, what actuallyslows an attacker down? Spencer and Tyler answer it from the attackerside, using what has and has not stopped them on real engagements.What's covered:- Application control done right, including where ThreatLocker and WDAC actually block a payload and where they get bypassed- MFA, the Protected Users group, and least privilege as attacker-facing controls rather than compliance checkboxes- Why mismanaged admin privileges and service accounts remain the fastest route from foothold to domain admin- Network segmentation and zero trust, and what separates a real implementation from a diagram- Deception techniques and EDR baselining for catching activity that looks legitimateIf you are deciding where the next dollar of your security budget goes,this is the episode that tells you what attackers hope you skip.Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
Embed this episode
What this episode covers
Replay of Episode 178, originally published April 22, 2026. We are re-running this one because it is the question we get asked most on internal pen test debriefs: of everything on the list, what actually slows an attacker down? Spencer and Tyler answer it from the attacker side, using what has and has not stopped them on real engagements. What's covered: - Application control done right, including where ThreatLocker and WDAC actually block a payload and where they get bypassed - MFA...
Ready to play
[Replay] Episode 178: Internal Security Controls That Actually Frustrate Attackers
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.