Skip to Main Content

Caroline Fenstermacher

Security Consultant

Experience
Prior to joining the TrustedSec Incident Response Team, Caroline gained experience at an open-XDR vendor as a Security Operations Center Analyst, where she then moved into the role of a Threat Hunter and Incident Response Analyst. Her research interests have been focused on cloud security, specifically in AWS environments. Caroline also has the unique experiences of briefly working within law enforcement and the banking industry.

Education & Certifications:

  • Bachelor of Science, Cybersecurity, The University of Tampa
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • AWS Certified Cloud Practitioner

Passion for Security
Caroline’s interest in cybersecurity spawned from constantly wanting to get to the bottom of whatever mystery presented itself to her. Tracking down an attacker’s actions and learning how to proactively look for those actions in the future perfectly satiates her curious nature.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog July 17 2025

Hiding in the Shadows: Covert Tunnels via QEMU Virtualization

Attackers are getting increasingly creative—not just with their payloads, but with how they deliver and operate them. In a recent Incident Response engagement,…

Read about this article
Blog February 25 2025

A Threat Hunter’s Guide to Decoding the Cloud

This blog will guide you through how to be a successful threat hunter in cloud environments, along with some helpful tips and advice.

Read about this article
Webinars December 04 2024

BEC Basics: Your First Step to Thwarting Email Scams

Learn to identify and combat business email compromise (BEC) threats in Microsoft 365 with expert Steven Erwin and Caroline Fenstermacher.

Read about this article
Blog April 16 2026

Dungeons and Daemons

Play Roll for Initiative. Hack the Planet.Dungeons & Daemons is a cybersecurity RPG that drops you into the boots of a Red Team operator on a live…

Read about this article
Webinars April 15 2026

You Had Us at the First Alert: A Guide to Finding Frequently Missed Detections

Join us for this webinar to get a clearer picture of where your detection coverage has blind spots and a practical roadmap for closing them before a real…

Read about this article
Blog April 14 2026

Benchmarking Self-Hosted LLMs for Offensive Security

We put LLMs to the test—let's find out how good AI is at hacking! We walk through six simple challenges with intentionally naïve setups to test how capable…

Read about this article
Events April 09 2026

TrustedSec Livestream - AMA: Detection Engineering in 2026 and Beyond with John Dwyer

Come prepared with your questions and walk away with actionable knowledge to sharpen your detection capabilities.

Read about this article
Blog April 09 2026

IAM the Captain Now – Hijacking Azure Identity Access

I decided to spend some research time diving in depth into Identity and Access Management (IAM) within Microsoft Azure. I am going to show you within this blog…

Read about this article
Blog April 07 2026

Building a Detection Foundation: Part 5 - Correlation in Practice

From Data Sources to DetectionWe've covered a lot of ground in this series: Windows Security events for logon tracking and process execution; PowerShell…

Read about this article
Podcasts April 06 2026

Security Noise - A Goblin, a Ghost, and a Ninja Walk into the Azure Bar

On this episode, Geoff and Skyler are joined by NyxGeek to discuss his suite of Azure bypass techniques. Since these techniques leave no trace, what does it…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.