Principal Purple Team Lead at Microsoft: I design and run adversary-emulation campaigns against the Microsoft Defender and Sentinel stack, turning real attacker tradecraft into stronger detections. Previously Principal Red Team Manager (internal and Federal red teams, as a founding member) and senior penetration tester.
- 🔴 Red teaming · 🟣 purple teaming · penetration testing · detection engineering · cloud/Azure security
- 📚 Two-time No Starch Press author: Pentesting Azure Applications & Locksport
- 🛠️ Contributor to the MITRE ATT&CK framework; named inventor on multiple patents
- 🎤 Speaker at DEF CON, BlueHat, and the SANS Cloud Security Summit
- 🤖 Currently exploring generative AI / LLMs for attacker simulation and detection
- 🔐 Competitive lockpicker & impressioner; co-organizer, Seattle Locksport
- Pentesting Azure Applications (No Starch, 2018). Scripts
- Locksport: A Hacker's Guide to Lock Picking, Impressioning, & Safe Cracking (No Starch, 2024)
- Blog: https://burrough.org
- LinkedIn: https://www.linkedin.com/in/mburrough/
- Mastodon: https://infosec.exchange/@mb
- Bluesky: https://bsky.app/profile/mattburrough.bsky.social
Certifications: CISM, GXPN, GCPN, GPEN, GWAPT, OSCP, eCRE, CCSK, MCT. Projects here are my own and not affiliated with my employer.


