The Exploit We Chose Not to Run
We found an EternalBlue-vulnerable host and a path to the plant floor, and stopped. Why restraint is the point when testing near production and OT systems.
Director of Red Team Operations
Mike has worked in IT and security since 2007, pivoting to focus exclusively on security in 2014 when he joined Computer Sciences Corporation (now DXC Technology) managing security infrastructure for large Fortune 500 companies. In 2018 he moved into red teaming at Converge Technology Solutions (now Pellera), where he spent years running adversary simulations against mature enterprise environments. He joined Breach Craft in 2025 to lead red team operations. Mike holds the OSCP and focuses on streamlining operations, building internal tooling, and innovating the tactics, techniques, and procedures that keep Breach Craft on the forefront of offensive security.
4 articles published
We found an EternalBlue-vulnerable host and a path to the plant floor, and stopped. Why restraint is the point when testing near production and OT systems.
"Who's in Domain Admins?" is the wrong question. How nested groups, service accounts, and DCSync rights create Tier-0 access your membership audit never sees.
Deleting a password from a repo doesn't remove it. How attackers pull secrets from git history, self-hosted servers, and reused vault keys, and how to stop it.
AI governance frameworks like the NIST AI RMF and ISO 42001 set the rules. They can't prove your AI resists attack. Why fast-moving, nondeterministic AI also needs adversarial testing.