The Security Blog
Get up-to-date security insights, tips, and tricks from our amazing team sent to your inbox.

Browse our blogs
We cover it all in The Security Blog. Discover what you’ve been looking for.

LDAP Channel Binding and LDAP Signing
Want stronger LDAP security without breaking production? In this blog, we cover LDAP Signing and Channel Binding, what Server 2025 changes, and why you should…

Adventures in Primary Group Behavior, Reporting, and Exploitation
Not all AD group membership is created equal. In this blog, we explore how the primaryGroupID attribute can be abused to hide privileges as well as how teams…

Colonel Clustered: Finding Outliers in Burp Intruder
Because 'stare at Burp responses until something looks weird' isn't a strategy 👀 In this blog, we introduce Colonel Clustered, a new Burp Suite extension that…

CMMC Scope – Understanding the Sprawl
CMMC scoping can be confusing, even for organizations that already meet contract requirements. In this blog, we explain what’s in scope and what’s changed.

Updating the Sysmon Community Guide: Lessons Learned from the Front Lines
ICYMI 👀 We’ve updated the Sysmon Community Guide! In this blog, we walk through what changed, why it matters, and how real-world incident response shaped the…

Limiting Domain Controller Attack Surface: Why Less Services, Less Software, Less Agents = Less Exposure
Before we dive in, let’s get all the TrustedSec Certified Absolutes out of the way:All software presents some level of inherent risk.Only required software…

Top 10 Blogs of 2025
Everyone has a year-end list, and this is ours. See what our top-performing cybersecurity blogs were in 2025, there could be some you might have missed!

Holy Shuck! Weaponizing NTLM Hashes as a Wordlist
Password reuse is common in Active Directory (AD). From an attacker’s perspective, it is a reliable path to lateral movement or privilege escalation. Most IT…

What is a TrustedSec Program Maturity Assessment (PMA)?
The TrustedSec PMA is a tactical approach to evaluating the components, efficiency, and overall maturity of an organization’s Information Security…

Managing Privileged Roles in Microsoft Entra ID: A Pragmatic Approach
Introducing a custom model for understanding privileged roles in Microsoft Entra ID, developed by TrustedSecWhenever our team conducts a Hardening Review of…

Helpful Hints for Writing (and Editing) Cybersecurity Reports
When it comes to reading (and editing) (and proofreading) technical documents, it's important to remember that the details are key, and can make all the…

CMMC Subcontractors and Service Providers
Defense contractors are preparing their systems for the start of the upcoming CMMC rollout but what they may not have considered is how their relationship with…
Loading...