Sign in

Hope Walker

@1cemoon.bsky.social
96 followers 59 following 4 posts

Principal Consultant at SpecterOps. All opinions are my own.

PostsRepliesMedia
Reposted by Hope Walker
SpecterOps @specterops.io · 09/09/2026
Tracking OAuth token exchanges is complicated. TATS can help. @1cemoon.bsky.social introduces the Token Analysis and Tracking System & shares some unexpected findings uncovered along the way. Check it out! ghst.ly/4xMBaYd
ghst.ly
Token Analysis and Tracking System (TATS)
Tracking OAuth tokens is hard, but Token Analysis and Tracking System (TATS) can help. TATS will collect, store, decode, analyze and provide visual tracking for OAuth token exchanges. It was built to ...
021
Hope Walker @1cemoon.bsky.social · 05/06/2026
My SO-CON talk about mapping RBAC in BloodHound is posted now. Fair warning for those who don't know me, I do have a personality and started by yelling at the crowd. 👑 Check out how we are mapping RBAC in BloodHound moving forward. youtu.be/1KDcK9PjnhU?...
youtu.be
Mapping RBAC in BloodHound | SO-CON 26
YouTube video by SpecterOps
011
Reposted by Hope Walker
SpecterOps @specterops.io · 01/06/2026
During an assessment, our team discovered that StrongDM auth state files containing JWTs & key material could be reused across hosts to obtain authenticated sessions & access infrastructure resources (CVE-2026-4387). Read more from @1cemoon.bsky.social: ghst.ly/4egbgVd
ghst.ly
CVE-2026-4387: StrongDM State File Reuse
Public disclosure for CVE-2026-4387. State file could be transferred and used on other hosts without restriction
022
Hope Walker @1cemoon.bsky.social · 01/06/2026
I'm excited to be able to finally publish the public disclosure for CVE-2026-4387. Check out my blog on discovering the reuse of the state.kv file to get authenticated sessions with StrongDM (now fixed). specterops.io/blog/2026/06...
specterops.io
CVE-2026-4387: StrongDM State File Reuse
Public disclosure for CVE-2026-4387. State file could be transferred and used on other hosts without restriction
001
Reposted by Hope Walker
SpecterOps @specterops.io · 14/04/2026
How do you really model RBAC in attack paths? 🤔 @1cemoon.bsky.social breaks down the limitations of role-based mapping in BloodHound, and shows how to move to permission-level edges for clearer, more accurate graphs. #SOCON2026
011
Reposted by Hope Walker
SpecterOps @specterops.io · 27/03/2026
Don’t miss @1cemoon.bsky.social at #BSidesSD 🔥 Deep dive into NAA, brokered client IDs, and how token flows behave (and break) in Microsoft environments. Learn more: www.bsidessd.org
011
Hope Walker @1cemoon.bsky.social · 15/10/2025
Check out my new blog diving deeper into BroCI.
011
Hope Walker @1cemoon.bsky.social · 13/08/2025
Check out my new blog on nested app authentication.
065
Reposted by Hope Walker
SpecterOps @specterops.io · 11/12/2024
What can you expect to learn in our Azure Security Fundamentals training at #SOCON2025? Course architect @1cemoon.bsky.social shares that students will dive into: ➡️ Azure Resource Manager ➡️ Common security misconfigurations ➡️ Entra ID authentication Register today: ghst.ly/reg-socon25-...
022