Episode Details:

In this episode of the Hack Responsibly podcast, NetSPI VP of Research Karl Fosaaen connects with Giles Inkson, Director of Red Team Operations at NetSPI. They discuss getting started in security, exploring AI use cases for red teaming, and navigating an industry that's shifted dramatically from stronger EDR, federated identity, SaaS sprawl, to a security culture that's finally starting to catch up.

What You’ll Hack Away With 

  • Why built-in OS tools are still some of the most effective weapons in a red teamer’s kit 
  • How AI is changing detection and triage (including the false positives it’s quietly creating) 
  • What stronger EDR, SaaS adoption, and federated identity have done to the red team playbook 
  • How a leaked YouTube onboarding video became the first link in a chain to domain admin 
  • Why passion and sleep are both non-negotiable for anyone serious about a career in offensive security 

About the Speakers 

Host: Karl Fosaaen | VP, Research 

As a VP of Research, Karl is part of a team developing new services and product offerings at NetSPI. Karl previously oversaw the Cloud Penetration Testing service lines at NetSPI and is one of the founding members of NetSPI’s Portland, OR team. Karl has a Bachelors of Computer Science from the University of Minnesota and has been in the security consulting industry for over 15 years. Karl spends most of his research time focusing on Azure security and contributing to the NetSPI blog. As part of this research, Karl created the MicroBurst toolkit (https://github.com/NetSPI/Microburst) to house many of the PowerShell tools that he uses for testing Azure. In 2021, Karl co-authored the book “Penetration Testing Azure for Ethical Hackers” with David Okeyode. 

Guest: Giles Inkson | Director of Red Team Operations
As a Director, Giles is responsible for performing Red Team Operations assessments, and internal network assessments on client assets and identifying vulnerabilities that could be exploited by attackers. Giles also provides oversight and guidance for in-progress engagements, in addition to managing security projects from scoping to delivery. In his 15-year career in cybersecurity Giles’ experience is in Red Team Operations and Breach and Attack Simulation (BAS) along with experience in performing cloud assessments. Certifications earned CSTL, CTL infrastructure, CISSP, CCSP, AZ-500, MS-500, CCNP, MCSE. 

Empower your strategic decisions with these additional resources: 

Find more episodes on YouTube or wherever you listen to podcasts.