<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Trimarc Security]]></title><description><![CDATA[Trimarc provides leading expertise in security solutions including security reviews, strategy, architecture, and implementation.]]></description><link>https://www.hub.trimarcsecurity.com/posts</link><generator>RSS for Node</generator><lastBuildDate>Tue, 10 Mar 2026 19:05:49 GMT</lastBuildDate><atom:link href="https://www.hub.trimarcsecurity.com/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[Hybrid Identity Conference 2024 Slides]]></title><description><![CDATA[Trimarc Founder and CTO recently presented his talk "Lessons Learned from a Decade of Attacks Against Microsoft Identity Systems" at...]]></description><link>https://www.hub.trimarcsecurity.com/post/hybrid-identity-conference-2024-slides</link><guid isPermaLink="false">6734df8f33f336791ac2395b</guid><pubDate>Thu, 14 Nov 2024 21:07:57 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_11418d6fdf754abd9f0a9dd678548308~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Danny Akacki</dc:creator></item><item><title><![CDATA[Limiting Domain Controller Attack Surface: Why less services, less software, less agents = less exposure.]]></title><description><![CDATA[This article is a guide to making the best-informed decisions by companies asking the right questions. ]]></description><link>https://www.hub.trimarcsecurity.com/post/limiting-domain-controller-attack-surface-why-less-services-less-software-less-agents-less-expo</link><guid isPermaLink="false">670537efa9837b0b5d0337a0</guid><pubDate>Tue, 08 Oct 2024 14:09:02 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_bed7622d5c014e3cab5ec6e1680de819~mv2.png/v1/fit/w_242,h_233,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Scott Blake</dc:creator></item><item><title><![CDATA[Tutorial - Throwing Windows Through an Apple. - Virtualizing Windows Server 2025 on Apple Silicon]]></title><description><![CDATA[This is where some people will try to dazzle and impress you with pontification and prose. I’m not those people. ]]></description><link>https://www.hub.trimarcsecurity.com/post/tutorial-throwing-windows-through-an-apple-virtualizing-windows-server-2025-on-apple-silicon</link><guid isPermaLink="false">66cf6f023abd577fc0ae928a</guid><pubDate>Wed, 28 Aug 2024 18:49:33 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_308c56765c284a25835f5c95210a7183~mv2.png/v1/fit/w_874,h_864,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Jake Hildreth</dc:creator></item><item><title><![CDATA[Securing The Chink in Kerberos’ Armor,  FAST! Understanding The Need For Kerberos Armoring]]></title><description><![CDATA[35 years after the first public version of Kerberos, attacks on it are still coming fast and furious. Time to armor up. ]]></description><link>https://www.hub.trimarcsecurity.com/post/securing-the-chink-in-kerberos-armor-fast-understanding-the-need-for-kerberos-armoring</link><guid isPermaLink="false">669696fd030ee47be15cea72</guid><pubDate>Tue, 16 Jul 2024 16:44:33 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_e1c015d2ebc841138d6d78ecf0320633~mv2.png/v1/fit/w_975,h_896,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Darryl Baker</dc:creator></item><item><title><![CDATA[Active Directory Security Risk #101: Kerberos Unconstrained Delegation (or How Compromise of a Single Server Can Compromise the Domain)]]></title><description><![CDATA[Editor's Note: Nearly a decade ago, Sean Metcalf made this post on ADSecurity.org and we're reposting it here in its original form because, ]]></description><link>https://www.hub.trimarcsecurity.com/post/active-directory-security-risk-101-kerberos-unconstrained-delegation-or-how-compromise-of-a-singl</link><guid isPermaLink="false">6682d602fd4a7fb236c0f92c</guid><pubDate>Mon, 01 Jul 2024 16:28:59 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_46b086be9f5246c9bc91ff1bc1e13bf3~mv2.png/v1/fit/w_557,h_403,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Sean Metcalf</dc:creator></item><item><title><![CDATA[BSides Dublin - The Current State of Microsoft Identity Security: Common Security Issues and Misconfigurations]]></title><description><![CDATA[We have an Identity problem and not the kind you think of when you look in the mirror. Attacks have shifted from the perimeter to the...]]></description><link>https://www.hub.trimarcsecurity.com/post/bsides-dublin-the-current-state-of-microsoft-identity-security-common-security-issues-and-misconf</link><guid isPermaLink="false">666081ddf575ae933c92422c</guid><pubDate>Wed, 05 Jun 2024 15:22:04 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_de0bdbf9dad14879998d791461656ddd~mv2.png/v1/fit/w_1000,h_716,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Sean Metcalf</dc:creator></item><item><title><![CDATA[Demystifying Privileged Identity Management - Part 1]]></title><description><![CDATA[This article series attempts to dissect the terms we throw around when talking about PIM.]]></description><link>https://www.hub.trimarcsecurity.com/post/demystifying-privileged-identity-management-part-1</link><guid isPermaLink="false">665f73fdf6dafa2b174dfe98</guid><pubDate>Wed, 05 Jun 2024 14:18:56 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_c0b61013c53b4970a378366bb73ff495~mv2.png/v1/fit/w_656,h_438,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Brandon Colley</dc:creator></item><item><title><![CDATA[The Current State of Microsoft Identity Security: Common Security Issues and Misconfigurations - BSides Dublin 2024]]></title><description><![CDATA["We have an Identity problem and not the kind you think of when you look in the mirror. Attacks have shifted from the perimeter to the...]]></description><link>https://www.hub.trimarcsecurity.com/post/the-current-state-of-microsoft-identity-security-common-security-issues-and-misconfigurations-bsi</link><guid isPermaLink="false">664b507df7baef87efde8e1d</guid><pubDate>Mon, 20 May 2024 13:33:51 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_de0bdbf9dad14879998d791461656ddd~mv2.png/v1/fit/w_1000,h_716,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Sean Metcalf</dc:creator></item><item><title><![CDATA[BSides Charm - 2024]]></title><description><![CDATA[Trimarc CTO Sean Metcalf and Active Directory Security Assessment Lead Jake Hildreth presented at the 2024 BSides Charm. Their slides are...]]></description><link>https://www.hub.trimarcsecurity.com/post/bsides-charm-2024</link><guid isPermaLink="false">6627da91ddebbc0939f11119</guid><pubDate>Tue, 23 Apr 2024 16:08:07 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_0b20e0a9ffdb4f3283af04db98a222f3~mv2.png/v1/fit/w_444,h_444,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Danny Akacki</dc:creator></item><item><title><![CDATA[Nesting Is For The Birds: The Problem with Nested Groups]]></title><description><![CDATA[Discussing a common High Priority issue: excessive membership in AD Admin groups due to Nested Groups.]]></description><link>https://www.hub.trimarcsecurity.com/post/let-s-talk-about-nested-groups</link><guid isPermaLink="false">65ef32880e474f8e2ccf59ac</guid><pubDate>Mon, 11 Mar 2024 17:02:49 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_6bf2298cded94ab8bf23e0715fee951c~mv2.png/v1/fit/w_969,h_298,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Jake Hildreth</dc:creator></item><item><title><![CDATA[Trimarc January Newsletter]]></title><description><![CDATA[Happy New Year, Trimarc Subscribers! We realize the time normal people say that was about 2.5 weeks ago but, in our defense, it’s cold in...]]></description><link>https://www.hub.trimarcsecurity.com/post/trimarc-january-newsletter</link><guid isPermaLink="false">65bab820d2a2f606cd07145b</guid><pubDate>Wed, 31 Jan 2024 21:41:48 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_1fcf22f37b6a487f81bee7272e2d6044~mv2.png/v1/fit/w_652,h_339,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Danny Akacki</dc:creator></item><item><title><![CDATA[CEO Livestream: Dave Kennedy &#38; Sean Metcalf]]></title><link>https://www.hub.trimarcsecurity.com/post/ceo-livestream-dave-kennedy-sean-metcalf</link><guid isPermaLink="false">6568e3c9be915f7856b4834b</guid><pubDate>Thu, 30 Nov 2023 19:34:40 GMT</pubDate><enclosure url="http://youtu.be/vvY48T55m4g" length="0" type="video"/><dc:creator>Danny Akacki</dc:creator></item><item><title><![CDATA[Once Upon a Console: vCenter Console Coercion]]></title><description><![CDATA[The best way to combat creative attackers is to become more creative ourselves. ]]></description><link>https://www.hub.trimarcsecurity.com/post/once-upon-a-console</link><guid isPermaLink="false">655685b289cc014595f9e5b1</guid><pubDate>Thu, 16 Nov 2023 21:12:25 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_32008363bfd04d7c8d1a27ee023445a3~mv2.png/v1/fit/w_380,h_528,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Brandon Colley</dc:creator></item><item><title><![CDATA[The Crypt O Plague]]></title><description><![CDATA[Spooky scary skeletons that send shivers down your spine, are nothing compared to users clicking links that will seal your doom tonight.]]></description><link>https://www.hub.trimarcsecurity.com/post/the-crypt-o-plague</link><guid isPermaLink="false">65413a7fc99267798874e399</guid><pubDate>Tue, 31 Oct 2023 17:44:18 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_882d69c67c704ea5a2e96e8d453e4515~mv2.png/v1/fit/w_464,h_464,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Sean Burgess</dc:creator></item><item><title><![CDATA[Enumerating Entra ID Anonymously]]></title><description><![CDATA[While your on-prem AD home isn’t the same as your vacation Entra ID home, Attackers are still peeking through your Windows.]]></description><link>https://www.hub.trimarcsecurity.com/post/enumerating-entra-id-anonymously</link><guid isPermaLink="false">653fe090727d2c060e6819d3</guid><pubDate>Mon, 30 Oct 2023 17:08:55 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_173586e8a78d4dc080024d5e323a2dac~mv2.png/v1/fit/w_975,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Brandon Colley</dc:creator></item><item><title><![CDATA[Return of The LDAP Channel Binding and LDAP Signing ]]></title><description><![CDATA[Author: Scott Blake / Director of Trimarc Services The Saga Continues It has been over two and a half years since we first touched on the...]]></description><link>https://www.hub.trimarcsecurity.com/post/return-of-the-ldap-channel-binding-and-ldap-signing</link><guid isPermaLink="false">652eeb7132473d12b88623f4</guid><pubDate>Tue, 17 Oct 2023 20:22:17 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_74cf1fbafe694ab0bc5fc30e2bbd405b~mv2.jpg/v1/fit/w_1000,h_720,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Scott Blake</dc:creator></item><item><title><![CDATA[Hardening Azure AD in the Face of Emerging Threats]]></title><description><![CDATA[Overview: In September of 2021, Trimarc Founder &#38; CTO Sean Metcalf presented at Quest's The Experts Conference. "This presentation covers...]]></description><link>https://www.hub.trimarcsecurity.com/post/hardening-azure-ad-in-the-face-of-emerging-threats</link><guid isPermaLink="false">651c7b6498758a311f809ef3</guid><pubDate>Tue, 03 Oct 2023 20:41:47 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_c947110d06e1423ab31c70389f26e2f0~mv2.png/v1/fit/w_699,h_386,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Sean Metcalf</dc:creator></item><item><title><![CDATA[The Current State of Microsoft Identity Security: Common Security Issues and Misconfigurations]]></title><description><![CDATA[In September of 2023, Trimarc founder and CTO Sean Metcalf spoke at The Experts Conference in Atlanta, GA on common mistakes people make...]]></description><link>https://www.hub.trimarcsecurity.com/post/the-current-state-of-microsoft-identity-security-common-security-issues-and-misconfigurations</link><guid isPermaLink="false">650dc0569d6bcedf92037091</guid><pubDate>Fri, 22 Sep 2023 16:32:47 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_688f05dce36d465fbaa84a2b8aa0c354~mv2.png/v1/fit/w_953,h_528,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Sean Metcalf</dc:creator></item><item><title><![CDATA[Defending The Identity Nexus]]></title><description><![CDATA[In October of 2022, Founder and CTO of Trimarc Security Sean Metcalf gave a talk The Experts Conference on defending the Identity Nexus. ...]]></description><link>https://www.hub.trimarcsecurity.com/post/defending-the-identity-nexus</link><guid isPermaLink="false">6504cadc0caa92b860160a90</guid><pubDate>Tue, 19 Sep 2023 16:02:17 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_ee31044879f7498abf7c3c43abe62d12~mv2.png/v1/fit/w_948,h_530,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Sean Metcalf</dc:creator></item><item><title><![CDATA[Protecting Virtual Machines in vSphere: A Comprehensive Guide]]></title><description><![CDATA[Introduction Virtual machines (VMs) play a central role in modern data centers by offering unparalleled flexibility and resource...]]></description><link>https://www.hub.trimarcsecurity.com/post/protecting-virtual-machines-in-vsphere-a-comprehensive-guide</link><guid isPermaLink="false">64f88ec8db274627f47c16c5</guid><pubDate>Wed, 06 Sep 2023 14:45:22 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/27c3eb_19e8038fa9714709ada1dc9b658698f1~mv2.jpg/v1/fit/w_409,h_123,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Demetrios Mustakas</dc:creator></item></channel></rss>