The PowerShell Podcast Living Off the Land With Spencer Alessi
Listen to this Episode
Audio available

Andrew welcomes back pen tester and AD security enthusiast Spencer Alessi (Tech Spence) fresh off DEF CON for a wide ranging chat on where PowerShell still fits into offensive security, how AI is changing his workflow, and what makes an environment genuinely painful to attack. Spencer talks through why PowerShell remains a favorite for both attackers and defenders, how he uses LLMs to speed up one off scripting tasks (and where they still fall short), and how he leans on AI tools to obfuscate offensive tooling during engagements. The conversation shifts into real world stories from the field, including a memorable case of exposed domain user hashes sitting on an overly permissive share, before wrapping up with the three controls Spencer sees make the biggest difference for defenders: application control, content filtering, and network segmentation.
KEY TAKEAWAYS:
- PowerShell is still a top tool for both attackers and defenders because it is fast, flexible, and built into every Windows box, which is exactly why locking it down matters.
- AI is great for offloading quick one off scripting tasks, but it often assumes intent incorrectly and can produce messy code, so manual review and hand written scripting still matter.
- Application control, outbound content filtering, and network segmentation are the three controls Spencer sees make attackers’ lives noticeably harder.
GUEST BIO:
Former Sysadmin, now Pentester @SecurIT360 | Microsoft MVP | Helping IT teams make their environment harder to attack | Social Media content & podcast @CyberThreatPOV
RESOURCE LINKS:
Spencer’s website and newsletter: https://spenceralessi.com Spencer’s link hub: https://links.spenceralessi.com
SecurIT360: https://securit360.com The Cyber Threat Perspective podcast: https://offsec.blog PowerSploit (offensive PowerShell framework): https://github.com/PowerShellMafia/PowerSploit Locksmith (AD CS misconfiguration finder, Spencer is a contributor): https://github.com/TrimarcJake/Locksmith ScriptSentry (Spencer’s logon script scanner): https://github.com/techspence/ScriptSentry PowerShell Wednesdays (weekly livestream): https://www.youtube.com/@PDQ
About the Author
Andrew Pla
PowerShell MVP, podcast host, and Community Director of PowerShell Summit
I’m a technical educator and community builder. I’m a Microsoft PowerShell MVP, podcast host, speaker, and Community Director of PowerShell Summit. I also work at PDQ alongside sysadmins and IT pros every day.
Community isn’t just what I do. It’s where I get my energy. I genuinely light up when I see someone land a new job, level up a skill, or show up to their first conference. I love sharing that passion with others.
Every week I host a live podcast and stream on YouTube covering PowerShell, automation, and the humans behind the keyboards.
If you’re on your IT journey and need someone in your corner, you’re in the right place. Find more at andrewpla.tech/links.
