Dirk-jan Mollema
- Author of ROADtools, mitm6, ldapdomaindump, adidnsdump, krbrelayx, and BloodHound.py
- Disclosed critical vulnerabilities in Active Directory, Windows, and Entra ID
- Microsoft Security MVP and Most Valuable Researcher
Bio
Dirk-jan Mollema researches Microsoft identity from the outside and writes the tooling to prove his findings: ROADtools for Entra ID, mitm6 and krbrelayx for relay attacks, adidnsdump and ldapdomaindump for enumeration, and the Python port of BloodHound. He has disclosed critical vulnerabilities across Active Directory, Windows, and Entra ID, and runs Outsider Security.
Profile built from public research, project, and vendor-acknowledgement records.
Where their work shows up
Hybrid identity is where most enterprises are exposed, and it is the seam his research keeps opening: what a synchronization account can actually do, how a foothold on-premises becomes tenant-wide access in the cloud, and which Conditional Access policies do not hold under specific protocol paths. That work turned into real product hardening and into the detection logic ITDR tools now ship. See primary refresh token theft, federation trust abuse and SAML forgery, and cross-tenant token confusion.
Related on Start with Identity
- GlossaryAdaptive Authentication
Authentication flows that change based on risk signals. Low-risk sign-ins may complete with one factor; high-risk sign-ins escalate to step-up MFA or are blocke
- GlossaryDevice Posture
The state of a device at the time of access: OS patch level, disk encryption status, EDR presence, jailbreak detection, certificate enrollment. Posture is an in
- GlossaryIdentity Resilience
The ability to keep authenticating and authorising legitimate users, and to recover the identity system itself, when the identity provider or directory is degra
- ExpertCo-creator of BloodHound
Andy Robbins co-created BloodHound with Will Schroeder and Rohan Vazarkar, released at DEF CON 24, and led its extension from on-premises Active Directory into
- ExpertCo-creator of BloodHound, AD CS attack research
Will Schroeder co-created BloodHound and has published a long run of Active Directory research, including the Certified Pre-Owned work on Active Directory Certi
- ExpertCreator of mimikatz
Benjamin Delpy, who publishes as gentilkiwi, wrote mimikatz in 2011 after finding that Windows held both an encrypted copy of a password and the key to decrypt