Skip to Main Content
All Trimarc services are now delivered through TrustedSec! Learn more

Oddvar Moe

Principal Security Consultant

EXPERIENCE
Oddvar Moe has worked in the IT industry since 1999. Initially, he began as a Microsoft consultant, helping a variety of public and private clients to implement Microsoft technology, before he sharpened his focused on security in 2012 as a malware reverser at a Security Operations Center. Since 2013, Oddvar has worked dedicatedly with offensive security either doing penetration tests or red teams. 

Oddvar has also taught many different courses and has been an active Microsoft Certified Trainer for many years. Within the setup of Microsoft technologies, Oddvar has expertise in products such as Advanced Threat Analytics, Windows Defender Advanced Threat Protection, AppLocker, System Center Configuration Manager, Deployment Toolkit, Active Directory, Group Policy, Exchange, Windows operating systems, and Remote Desktop Services. Oddvar currently works as a red teamer in the Targeted Operations Group at TrustedSec. While red teaming for Fortune 100 companies, Oddvar has gained a lot of experience from some of the most secure customers in the world. In total, he has more than 20 years of working experience in the IT industry and is passionate about Windows Security—so passionate, in fact, that Microsoft has awarded him the Most Valuable Professional Award for eight (8) years in row.

EDUCATION & CERTIFICATIONS

  • Microsoft MVP
  • GIAC Penetration Tester (GPEN)
  • Microsoft Certified Professional (MSCP)
  • Microsoft Certified Technology Specialist (MCTS)
  • Microsoft Certified Solutions Associate (MCSA)
  • Microsoft Certified Systems Engineer (MCSE)
  • Microsoft Certified Systems Administrator (MCSA)

INDUSTRY CONTRIBUTIONS
As a speaker, Oddvar has delivered top-notch sessions at conferences such as DerbyCon, IT Dev Connections, Paranoia, MVP Day, HackCon, Microsoft Security Week, and the Nordic Infrastructure Conference.

Oddvar actively contributes to the security community and is most known for his contributions around the LOLBins/LOLBAS and the Ultimate AppLocker Bypasslist. He also loves to research stuff and has uncovered many different persistence and code execution techniques, UAC bypasses, and AWL bypasses over the years that have since been used by APT groups. Oddvar also has a few CVEs to his record, such as CVE-2017-8625 and CVE-2022-24696.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog September 05 2023

Creative Process Enumeration

Differentiate process architecture using virtual memory size in 64-bit and 32-bit processes.

Read about this article
Blog March 17 2023

Critical Outlook Vulnerability: In-Depth Technical Analysis and Recommendations (CVE-2023-23397)

Protect your organization from the Microsoft Outlook CVE-2023-23397 vulnerability with expert guidance and a simple remediation script.

Read about this article
Blog May 10 2022

Diving into Pre-Created Computer Accounts

Discover how to find a valid, unused computer account password using a vulnerable certificate template and a pre-created computer account, leveraging…

Read about this article
Blog March 11 2022

CVE-2022-24696 - Glance by Mirametrix Privilege Escalation

Lenovo ThinkPad X1 Extreme Gen 1 users, beware: a vulnerability in Glance software can be exploited to gain SYSTEM privileges, allowing malicious actions to…

Read about this article
Webinars February 12 2020

Unleashing the Power of AppLocker: How to Get Started and Go Beyond the Basics

Learn how to build a powerful AppLocker policy, stopping ransomware and automated attacks, and identify weaknesses in your configuration with expert guidance.

Read about this article
Webinars January 14 2026

Tips for Incident Response Planning: Prepare Before Crisis Strikes

During our next webinar, our Incident Response experts will cover what organizations should do to prepare so they can respond quickly and be on the way to…

Read about this article
Business Resources December 30 2025

Inside the Modern Red Team: How Attackers Think, and What Defenders Miss

Discover how modern Red Teams think like attackers, what defenders often miss, and how to strengthen your cybersecurity posture.

Read about this article
Blog December 18 2025

Limiting Domain Controller Attack Surface: Why Less Services, Less Software, Less Agents = Less Exposure

Before we dive in, let’s get all the TrustedSec Certified Absolutes out of the way:All software presents some level of inherent risk.Only required software…

Read about this article
News December 17 2025

News 5 Cleveland - Elyria Police responded to a reported restaurant robbery. But it was actually an AI prank.

AI quality is evolving rapidly, making it easier than ever to create convincing fakes from a phone. Advisory Solutions Director Alex Hamerstone spoke with News…

Read about this article
Blog December 16 2025

Top 10 Blogs of 2025

Everyone has a year-end list, and this is ours. See what our top-performing cybersecurity blogs were in 2025, there could be some you might have missed!

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.