About What I Do Newsletter Sponsor Tools CVEs
Microsoft MVP

😈 Spirit of a hacker 💙 Heart of a defender

Former sysadmin, now pentester, content creator. Helping IT teams make their environment harder to attack.

Follow Me →
Work With Me → SecurIT360 SecurIT360
Watch/Listen → Cyber Threat POV Cyber Threat POV
Spencer Alessi

Spencer Alessi

Spencer Alessi

Recovering Sysadmin Turned Pentester

Spencer Alessi is a Senior Penetration Tester at SecurIT360 and Microsoft MVP (Security – Identity & Access). A former sysadmin turned pentester. He focuses on the intersection of offense and defense: how internal attackers move, how Active Directory and Windows misconfigurations create "free" attack paths, and how admins can harden environments without breaking production.

He's known for practical demos, concrete remediation steps, and a style that keeps serious topics engaging. Spencer has delivered keynotes, conference sessions and webinars on topics like dangerous logon scripts, insecure Active Directory permissions, and real-world Active Directory/Windows misconfigurations.

Penetration Testing Active Directory Microsoft MVP PowerShell Open Source Podcast Host Assume Breach Windows

Offensive Security, Defensive Impact

I break things so they can be built back stronger. From penetration testing to open-source tooling, everything I do is about making defenders more effective.

Penetration Testing

Internal network and Active Directory penetration testing. Finding misconfigurations, vulnerabilities, and attack paths before the real attackers do.

Open Source Tools

Building PowerShell-based security tools like ScriptSentry that help sysadmins and defenders audit and harden their Active Directory environments.

Newsletter

Writing about pentesting insights, security tips, Active Directory hardening, and lessons learned from real-world engagements.

Podcast

Hosting The Cyber Threat Perspective podcast, sharing conversations about offensive security, career development, and the cybersecurity industry.

Security Tools & Projects

PowerShell tools built for penetration testers and sysadmins to audit and secure Active Directory environments.

Discovered CVEs

Responsible disclosure of security vulnerabilities found through independent research.

1,075+
GitHub Stars
2
CVEs Discovered
5+
Open Source Tools
MVP
Microsoft Award

Latest from the Newsletter

Pentesting insights, security tips, and lessons from the field. Subscribe to the newsletter for exclusive content.

Stay Ahead of the Threats

Get pentesting insights, Active Directory security tips, and tool updates delivered straight to your inbox.

Follow me →

Don't miss what's next

Pentest breakdowns, hardening playbooks, and security tips that help IT teams make their environments harder to attack.