Matt Burrough is a Principal Purple Team Lead at Microsoft, where he designs and runs adversary-emulation campaigns against the Microsoft Defender and Sentinel product suite, translating real attacker tradecraft into stronger detections. He previously served as a Principal Red Team Manager, leading Microsoft’s enterprise and Federal red teams, and before that as a senior penetration tester. Earlier in his career, he spent five years debugging, code-reviewing, and reverse engineering Windows at Microsoft, and created new digital-radio technology at NPR, including the first closed-captioned radio broadcasting system.
Matt is the author of two No Starch Press books, Pentesting Azure Applications (2018) and Locksport (2024), a contributor to the MITRE ATT&CK framework, a named inventor on multiple patents, and a frequent speaker at conferences including DEF CON, BlueHat, and the SANS Cloud Security Summit. He holds a Master’s degree in Computer Science and a graduate certificate in Computer Security from the University of Illinois at Urbana-Champaign, and a Bachelor of Science in Applied Networking and System Administration from the Rochester Institute of Technology. Outside of work he’s an avid competitive lockpicker and co-organizes Seattle Locksport.