The PowerShell Podcast

Living Off the Land With Spencer Alessi

September 21, 2026·45 min
Episode Description from the Publisher

Andrew welcomes back pen tester and AD security enthusiast Spencer Alessi (Tech Spence) fresh off DEF CON for a wide ranging chat on where PowerShell still fits into offensive security, how AI is changing his workflow, and what makes an environment genuinely painful to attack. Spencer talks through why PowerShell remains a favorite for both attackers and defenders, how he uses LLMs to speed up one off scripting tasks (and where they still fall short), and how he leans on AI tools to obfuscate offensive tooling during engagements. The conversation shifts into real world stories from the field, including a memorable case of exposed domain user hashes sitting on an overly permissive share, before wrapping up with the three controls Spencer sees make the biggest difference for defenders: application control, content filtering, and network segmentation. KEY TAKEAWAYS: PowerShell is still a top tool for both attackers and defenders because it is fast, flexible, and built into every Windows box, which is exactly why locking it down matters. AI is great for offloading quick one off scripting tasks, but it often assumes intent incorrectly and can produce messy code, so manual review and hand written scripting still matter. Application control, outbound content filtering, and network segmentation are the three controls Spencer sees make attackers' lives noticeably harder. GUEST BIO: Former Sysadmin, now Pentester @SecurIT360 | Microsoft MVP | Helping IT teams make their environment harder to attack | Social Media content & podcast @CyberThreatPOV RESOURCE LINKS: Spencer's website and newsletter: https://spenceralessi.com  Spencer's link hub: https://links.spenceralessi.com  Andrew's link hub: https://andrewpla.tech/links  SecurIT360: https://securit360.com  The Cyber Threat Perspective podcast: https://offsec.blog  PowerSploit (offensive PowerShell framework): https://github.com/PowerShellMafia/PowerSploit  Locksmith (AD CS misconfiguration finder, Spencer is a contributor): https://github.com/TrimarcJake/Locksmith  ScriptSentry (Spencer's logon script scanner): https://github.com/techspence/ScriptSentry  PDQ Discord community (PowerShell scripting channel): https://discord.gg/pdq  PowerShell Wednesdays (weekly livestream): https://www.youtube.com/@PDQ The PowerShell Podcast on YouTube: https://youtu.be/DDbBZqEJkSI

Podzilla Summary coming soon

Sign up to get notified when the full AI-powered summary is ready.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.

Get summaries like this every morning.

Free AI-powered recaps of The PowerShell Podcast and your other favorite podcasts, delivered to your inbox.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.