Start with Identity
Identity Security Researcher

Dirk-jan Mollema

Entra ID and Active Directory researcher · Outsider Security · 10+ years in identity
Focus areas
Entra IDActive DirectoryNTLM RelayConditional Access
Notable work
  • Author of ROADtools, mitm6, ldapdomaindump, adidnsdump, krbrelayx, and BloodHound.py
  • Disclosed critical vulnerabilities in Active Directory, Windows, and Entra ID
  • Microsoft Security MVP and Most Valuable Researcher

Bio

Dirk-jan Mollema researches Microsoft identity from the outside and writes the tooling to prove his findings: ROADtools for Entra ID, mitm6 and krbrelayx for relay attacks, adidnsdump and ldapdomaindump for enumeration, and the Python port of BloodHound. He has disclosed critical vulnerabilities across Active Directory, Windows, and Entra ID, and runs Outsider Security.

Profile built from public research, project, and vendor-acknowledgement records.

Where their work shows up

Hybrid identity is where most enterprises are exposed, and it is the seam his research keeps opening: what a synchronization account can actually do, how a foothold on-premises becomes tenant-wide access in the cloud, and which Conditional Access policies do not hold under specific protocol paths. That work turned into real product hardening and into the detection logic ITDR tools now ship. See primary refresh token theft, federation trust abuse and SAML forgery, and cross-tenant token confusion.

Built from public information only. This is an independent profile and is not an endorsement by, or affiliation with, the person listed. Corrections: [email protected].