Tim Medin
            
            @timmedin.bsky.social
          
          1.4K followers
          780 following
          280 posts
        
          Kerberoast Guy • RedSiege CEO • Hater of Pants • Former SANS 560 Author, Senior Instructor • Packers owner • Work Req: http://redsiege.com/contact
            
      
        Posts
        Media
        Videos
        Starter Packs
      
    
      Putting a bow on the day at @wildwesthackinfest.bsky.social with CEO @timmedin.bsky.social presenting "Death by Dashboards: Moving the Needle on What Actually Matters"
#hacking #infosec #cybersecurity #wwhf
        #hacking #infosec #cybersecurity #wwhf
        
      Reposted by Tim Medin
    
  
      The booth is buzzin here at @wildwesthackinfest.bsky.social! We've had the chance to meet so many awesome folks already. 
There's still plenty of handshakes, high fives, and killer swag to give out!
#hacking #infosec #cybersecurity #wwhf
        There's still plenty of handshakes, high fives, and killer swag to give out!
#hacking #infosec #cybersecurity #wwhf
          
              Tim Medin
              @timmedin.bsky.social
          
              · Oct 1
        
        
          
      Don't miss out! Tomorrow, @timmedin.bsky.social of @redsiege.com joins us for #ThursDef at 12:30 PM CT to discuss Offensive for Defense.
This 30-minute fireside chat is one you won't want to miss. Register now: thursdef.com
#ThursdayDefensive #cybersecurity #infosec
        This 30-minute fireside chat is one you won't want to miss. Register now: thursdef.com
#ThursdayDefensive #cybersecurity #infosec
          
              Tim Medin
              @timmedin.bsky.social
          
              · Oct 1
        
        
        
            Anti-Cast: Close Security Gaps, Pass Audits, Stay Secure with Kimber Amos - Antisyphon Training
            Join Kimber Amos for a free one-hour training on cutting through compliance theater and running reviews that actually strengthen defenses and keep auditors happy.
          
            
            www.antisyphontraining.com
          
        
      
    
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 30
        
        
      
    
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 30
        
        
          
      My understanding from @timmedin.bsky.social is RC4 risk is mitigable w/ a properly (service account std differs from user account) strong password. If it was never cracked by a pen tester, because their level of effort vs. adversary effort differed--how would Ascension know it wasn't strong enough?
    
  
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 30
        
        
      
    
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 26
        
        
      
    
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 24
        
        
          
      Today's hot take: "Vulnerability" as a term has become meaningless in the industry. 
I propose that at a system level, a vulnerability is not a *vulnerability* if there are other intact, effective compensating controls. Many of the things we call vulns should just be called bugs
  I propose that at a system level, a vulnerability is not a *vulnerability* if there are other intact, effective compensating controls. Many of the things we call vulns should just be called bugs
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 18
        
        
          
      Our CEO @timmedin.bsky.social offers his thoughts on what exactly led to the Ascension breach in this follow-up article from Ars Technica:
arstechnica.com/security/202...
#hacking #infosec #cybersecurity
      
          arstechnica.com/security/202...
#hacking #infosec #cybersecurity
How weak passwords and other failings led to catastrophic breach of Ascension
          A deep-dive into Active Directory and how “Kerberoasting” breaks it wide open.
        
          
          arstechnica.com
        
      
  
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 16
        
        
      
    
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 16
        
        
      
    
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 12
        
        
          
      @timmedin.bsky.social is ridin' into Wild West Hackin' Fest - Deadwood 2025 with his talk "Death by Dashboards: Moving the Needle on What Actually Matters" 
Virtual con and virtual training tickets are still available! wildwesthackinfest.com/register-for...
#WWHF #Deadwood2025 #TheFutureIs
        Virtual con and virtual training tickets are still available! wildwesthackinfest.com/register-for...
#WWHF #Deadwood2025 #TheFutureIs
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 10
        
        
      
    
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 10
        
        
      
    
          
              Tim Medin
              @timmedin.bsky.social
          
              · Sep 10
        
        
      
    
          
              Tim Medin
              @timmedin.bsky.social
          
              · Aug 16