Skip to Main Content
All Trimarc services are now delivered through TrustedSec! Learn more

Caroline Fenstermacher

Security Consultant

Experience
Prior to joining the TrustedSec Incident Response Team, Caroline gained experience at an open-XDR vendor as a Security Operations Center Analyst, where she then moved into the role of a Threat Hunter and Incident Response Analyst. Her research interests have been focused on cloud security, specifically in AWS environments. Caroline also has the unique experiences of briefly working within law enforcement and the banking industry.

Education & Certifications:

  • Bachelor of Science, Cybersecurity, The University of Tampa
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • AWS Certified Cloud Practitioner

Passion for Security
Caroline’s interest in cybersecurity spawned from constantly wanting to get to the bottom of whatever mystery presented itself to her. Tracking down an attacker’s actions and learning how to proactively look for those actions in the future perfectly satiates her curious nature.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog July 17 2025

Hiding in the Shadows: Covert Tunnels via QEMU Virtualization

Attackers are getting increasingly creative—not just with their payloads, but with how they deliver and operate them. In a recent Incident Response engagement,…

Read about this article
Blog February 25 2025

A Threat Hunter’s Guide to Decoding the Cloud

This blog will guide you through how to be a successful threat hunter in cloud environments, along with some helpful tips and advice.

Read about this article
Webinars December 04 2024

BEC Basics: Your First Step to Thwarting Email Scams

Learn to identify and combat business email compromise (BEC) threats in Microsoft 365 with expert Steven Erwin and Caroline Fenstermacher.

Read about this article
News December 12 2025

Security Advisory: React2Shell (CVE-2025-55182) - Critical RCE Vulnerability

A critical vulnerability affecting React Server Components (RSC) is being actively exploited. Here's what to look for and what to do next.

Read about this article
Blog December 09 2025

Holy Shuck! Weaponizing NTLM Hashes as a Wordlist

Password reuse is common in Active Directory (AD). From an attacker’s perspective, it is a reliable path to lateral movement or privilege escalation. Most IT…

Read about this article
Podcasts December 05 2025

Security Noise - Hacker Family Feud

Our security experts compete to see which team can guess the most popular answers to cybersecurity industry questions on this episode of the TrustedSec…

Read about this article
Events December 04 2025

Research on Windows Accessibility: Narrator.exe

Join us for our next Discord Livestream "Research on Windows Accessibility: Narrator.exe" on December 4 at 11:00AM ET! During this exclusive session, Principal…

Read about this article
Blog December 04 2025

What is a TrustedSec Program Maturity Assessment (PMA)?

The TrustedSec PMA is a tactical approach to evaluating the components, efficiency, and overall maturity of an organization’s Information Security…

Read about this article
Webinars December 03 2025

NIST CSF 2.0 - From Compliance to Confidence

During our next webinar, our experts will cover the latest evolution of the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF),…

Read about this article
News December 01 2025

KTVU Fox 2 San Francisco - Too good to be true? Cyber Monday Warning

Protect your purchases this Cyber Monday! Director of Advisory Services Chris Camejo speaks with KTVU Fox 2 to share essential tips on how to safeguard your…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.