[Replay] Episode 178: Internal Security Controls That Actually Frustrate Attackers
Show notes
Replay of Episode 178, originally published April 22, 2026.
We are re-running this one because it is the question we get asked most
on internal pen test debriefs: of everything on the list, what actually
slows an attacker down? Spencer and Tyler answer it from the attacker
side, using what has and has not stopped them on real engagements.
What's covered:
- Application control done right, including where ThreatLocker and WDAC
actually block a payload and where they get bypassed
- MFA, the Protected Users group, and least privilege as attacker-facing
controls rather than compliance checkboxes
- Why mismanaged admin privileges and service accounts remain the fastest
route from foothold to domain admin
- Network segmentation and zero trust, and what separates a real
implementation from a diagram
- Deception techniques and EDR baselining for catching activity that
looks legitimate
If you are deciding where the next dollar of your security budget goes,
this is the episode that tells you what attackers hope you skip.
Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov
Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com
Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.