Sign in

Andy Robbins

@andyrobbins.bsky.social
676 followers 129 following 27 posts

aka wald0

PostsRepliesMedia
Andy Robbins @andyrobbins.bsky.social · 17/02/2026
10 years ago this week I published this blog post while @cptjesus.bsky.social, @harmj0y.bsky.social and I were working on what eventually became BloodHound: wald0.com?p=14
wald0.com
Automated Derivative Administrator Search
Intro Active Directory Domain escalation is an important part of most penetration tests and red team engagements. While gaining domain/enterprise administrator rights is not the end goal of an as…
052
Reposted by Andy Robbins
Jim Sykora @jimsycurity.adminsdholder.com · 06/02/2026
Next week I'll be speaking at WWHF Mile High in Denver about Abusing Backup Operators with @trustedsec.com's Titanis. web.cvent.com/event/1dbf78...
web.cvent.com
Agenda - Wild West Hackin' Fest @ Mile High 2026
181
Reposted by Andy Robbins
SpecterOps @specterops.io · 13/01/2026
SCCM attack paths are messy until you can see them. 👀 ConfigManBearPig from Chris Thompson extends BloodHound with SCCM nodes + edges using OpenGraph, plus queries to surface hierarchy takeovers and escalation paths. Check it out: ghst.ly/45FCP5G
ghst.ly
Introducing ConfigManBearPig, a BloodHound OpenGraph Collector for SCCM - SpecterOps
ConfigManBearPig is a standalone PowerShell collector that adds new SCCM attack path nodes and edges to BloodHound using OpenGraph.
033
Reposted by Andy Robbins
Jim Sykora @jimsycurity.adminsdholder.com · 31/10/2025
Note: Work related I do Active Directory stuff for a living. Security research to be more specific. One of my favorite niche AD topics is AdminSDHolder. It's even my vanity domain. I wrote a 159 pg book about AdminSDHolder. I'm kinda proud of it. specterops.io/resources/ad...
specterops.io
AdminSDHolder Misconceptions & Misconfigurations - SpecterOps
AdminSDHolder is an object and associated process in Active Directory Domain Services (AD DS) that helps protect specific sensitive and highly privileged accounts from being manipulated. This topic is...
1153
Reposted by Andy Robbins
SpecterOps @specterops.io · 30/10/2025
See your network shares the way attackers do. 👀 Meet ShareHound, an OpenGraph collector for BloodHound CE & Enterprise that reveals share-level attack paths at scale. @podalirius.bsky.social unpacks all the details in our latest blog post. ghst.ly/4ogiBqt
ghst.ly
ShareHound: An OpenGraph Collector for Network Shares - SpecterOps
ShareHound is an OpenGraph collector for BloodHound CE and BloodHound Enterprise helping identify attack paths to network shares automatically.
073
Reposted by Andy Robbins
Jason @jasonjfrank.bsky.social · 27/10/2025
Incredible to see @hdm.io using BloodHound to build the new runZeroHound, connecting asset inventory data from @runzero.com with attack path visualization. Love seeing the community take BloodHound in new directions!
041
Reposted by Andy Robbins
SpecterOps @specterops.io · 23/10/2025
Credential Guard was supposed to end credential dumping. It didn't. Valdemar Carøe just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more: ghst.ly/4qtl2rm
ghst.ly
Catching Credential Guard Off Guard - SpecterOps
Uncovering the protection mechanisms provided by modern Windows security features and identifying new methods for credential dumping.
01710
Andy Robbins @andyrobbins.bsky.social · 20/10/2025
Introducing PingOneHound! This OpenGraph extension for BloodHound can help you identify, analyze, execute, and remediate attack paths in PingOne organizations. Read the introductory blog post here: specterops.io/blog/2025/10...
specterops.io
PingOne Attack Paths - SpecterOps
You can use PingOneHound in conjunction with BloodHound Community Edition to discover, analyze, execute, and remediate identity-based attack paths in PingOne instances.
0910
Reposted by Andy Robbins
Evan McBroom @evanmcbroom.bsky.social · 16/10/2025
@reconmtl.bsky.social has uploaded the majority of the 2025 talks, including my talk on LSA. You can check it out at the below link if you'd like. Thank you again to the organizers and everyone else who helps put on the conference. I look forward to coming back! youtu.be/G2CfMWXLU1U?...
youtu.be
Recon 2025 - The Finer Details of LSA Credential Recovery
YouTube video by Recon Conference
0115
Reposted by Andy Robbins
Hope Walker @1cemoon.bsky.social · 15/10/2025
Check out my new blog diving deeper into BroCI.
011
Andy Robbins @andyrobbins.bsky.social · 02/10/2025
A little OpenGraph POC for mapping PE header imports of all .dll and .exe files in a fresh Windows install. These are all the binaries that have some kind of import chain leading to kernel32.dll
163
Reposted by Andy Robbins
Dirk-jan @dirkjanm.io · 17/09/2025
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...
dirkjanm.io
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
98737
Reposted by Andy Robbins
Lars Karlslund 🇩🇰 @lkarlslund.bsky.social · 08/09/2025
Adalanche searches works way better now - it uses BFS rather than DFS which gave unnecessary long paths at times. This is available in the latest commit on GitHub. There might be bugs with the new search - let me know if you see any strangeness. Happy hunting :-)
031
Reposted by Andy Robbins
SpecterOps @specterops.io · 05/09/2025
We've got a fresh #BloodHoundBasics post from @jonas-bk.bsky.social! Ever wondered about those obscure AD special identity groups that quietly grant permissions to every principal in your environment? With BloodHound, you can uncover compromising permissions tied to these groups. 🧵: 1/2
133
Reposted by Andy Robbins
SpecterOps @specterops.io · 04/09/2025
BloodHound isn't just for Active Directory anymore. 🤯 @sadprocessor.bsky.social dives into the BloodHound OpenGraph functionality & demonstrates the new PowerShell cmdlets added to the BloodHound Operator module to work with the OpenGraph feature. ghst.ly/4peTTrB
ghst.ly
BloodHound Operator: The Six Degrees Of Master Yoda - SpecterOps
A Technical Dive Into BloodHound OpenGraph With BloodHound Operator & Master Yoda… TL;DR: The latest version of BloodHound introduces BloodHound OpenGraph. This new feature allows for ingestion of any...
041
Andy Robbins @andyrobbins.bsky.social · 04/09/2025
From November 2016: This is how I used to design BloodHound's entity panels. Just a text editor to list out what I as a red-teamer wanted to see, with the corresponding (then new) cypher queries listed as well. Simple, VERY low-fidelity mockup, but really helped during the design phase.
060
Andy Robbins @andyrobbins.bsky.social · 27/08/2025
🚨 New #BloodHound shirt alert 🚨 ✅ - Unisex adult/child and ladies sizes available ✅ - Cool design :) ✅ - ALL profits go to charity This time we are supporting Hope for HIE, which supports families suffering the effects of hypoxic ischemic encephalopathy Get your shirt here: ghst.ly/bh8-tshirt
ghst.ly
BloodHound 8.0 T-Shirt Fundraiser, Supporting Hope for HIE
Hope for HIE is the global voice for families affected by Hypoxic Ischemic Encephalopathy. As the world’s largest HIE support network, Hope for HIE offers personalized resources, education, and a deep...
092
Reposted by Andy Robbins
Hope Walker @1cemoon.bsky.social · 13/08/2025
Check out my new blog on nested app authentication.
065
Andy Robbins @andyrobbins.bsky.social · 01/08/2025
In this blog post I explain the fundamental building blocks, vocabulary, and principles of attack graph design for BloodHound: specterops.io/blog/2025/08...
specterops.io
Attack Graph Model Design Requirements and Examples - SpecterOps
TL;DR OpenGraph makes it easy to add new nodes and edges into BloodHound, but doesn’t design your data model for you. This blog post has everything you need to get started with proper attack graph mod...
040
Reposted by Andy Robbins
SpecterOps @specterops.io · 31/07/2025
Red teamers know the drill: endless file churning, hunting for passwords & tokens. 🔍 Meet DeepPass2, our new secret scanning tool that goes beyond structured tokens to catch those tricky free-form passwords too. Read Neeraj Gupta's blog post for more. ghst.ly/40HLNNA
ghst.ly
What’s Your Secret?: Secret Scanning by DeepPass2  - SpecterOps
Discover DeepPass2 - a secret scanning tool combining BERT-based model and LLMs to detect free-form passwords, and other structured tokens and secrets with high accuracy.
0124
Reposted by Andy Robbins
SpecterOps @specterops.io · 30/07/2025
Entra Connect sync accounts can be exploited to hijack device userCertificate properties, enabling device impersonation and conditional access bypass. @hotnops.bsky.social explores cross-domain compromise tradecraft within the same tenant. Read more: ghst.ly/3ISMGN9
ghst.ly
Entra Connect Attacker Tradecraft: Part 3 - SpecterOps
How Entra Connect and Intune can be abused via userCertificate hijacking to bypass conditional access and compromise hybrid domains
196
Andy Robbins @andyrobbins.bsky.social · 30/07/2025
@egyp7.bsky.social Hey dude ✌️
100
Reposted by Andy Robbins
SpecterOps @specterops.io · 29/07/2025
BloodHound v8.0 is here! 🎉 This update introduces BloodHound OpenGraph, revolutionizing Identity Attack Path Management by exposing attack paths throughout your entire tech stack, not just AD/Entra ID. Read more from Justin Kohler: ghst.ly/bloodhoundv8 🧵: 1/7
1139
Reposted by Andy Robbins
harmj0y @harmj0y.bsky.social · 28/06/2025
Happy Friday! @tifkin.bsky.social and I are happy to announce that we have cut the release for Nemesis 2.0.0 - check out the CHANGELOG for a (brief) summary of changes, and dive into our new docs for more detail! We're extremely proud and excited for this release github.com/SpecterOps/N...
github.com
GitHub - SpecterOps/Nemesis: An offensive data enrichment pipeline
An offensive data enrichment pipeline. Contribute to SpecterOps/Nemesis development by creating an account on GitHub.
0126
Reposted by Andy Robbins
SpecterOps @specterops.io · 27/06/2025
So you've compromised a host that isn’t cloud-joined. Antero Guy breaks down how to request OAuth tokens & enumerate an Entra ID tenant by using an SSO cookie from a non cloud-joined device. Read more: ghst.ly/445tQKL
ghst.ly
Requesting Entra ID Tokens with Entra ID SSO Cookies - SpecterOps
Learn how to use a browser SSO cookie to request Entra ID OAuth tokens and enumerate a target tenant. This technique is useful when a device is not joined to an Entra ID tenant.
051
Reposted by Andy Robbins
Jonas Bülow Knudsen @jonas-bk.bsky.social · 25/06/2025
I publish two blog posts today! 📝🐫 First dives into how we're improving the way BloodHound models attack paths through AD trusts: specterops.io/blog/2025/06... Second covers an attack technique I came across while exploring AD trust abuse: specterops.io/blog/2025/06... Hope you enjoy the read 🥳
specterops.io
Good Fences Make Good Neighbors: New AD Trusts Attack Paths in BloodHound - SpecterOps
The ability of an attacker controlling one domain to compromise another through an Active Directory (AD) trust depends on the trust type and configuration. To better map these relationships and make i...
01811
Reposted by Andy Robbins
Katie Knowles @siigil.bsky.social · 17/06/2025
🕵️‍♀️ I'll be presenting "I SPy: Rethinking Entra ID research for new paths to Global Admin” at fwd:cloudsec June 30-July 1, alongside some fantastic other speakers: fwdcloudsec.org/conference/n... If you can’t make it, talks are streamed at: www.youtube.com/@fwdcloudsec
fwdcloudsec.org
fwd:cloudsec 2025 Speaker Bios & Abstracts | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
051
Reposted by Andy Robbins
hotnops @hotnops.bsky.social · 09/06/2025
New tricks, same impact posts.specterops.io/update-dumpi...
posts.specterops.io
Update: Dumping Entra Connect Sync Credentials
Recently, Microsoft changed the way the Entra Connect Connect Sync agent authenticates to Entra ID. These changes affect attacker tradecraft, as we can no longer export the sync account credentials…
067
Reposted by Andy Robbins
SpecterOps @specterops.io · 10/06/2025
Recently, Microsoft changed the way the Entra Connect Sync agent authenticates to Entra ID. Check out our latest blog post from @hotnops.bsky.social to learn how the agent works now & how these changes affect attacker tradecraft. ghst.ly/3ZpMc6y
ghst.ly
Update: Dumping Entra Connect Sync Credentials - SpecterOps
Recently, Microsoft changed the way the Entra Connect Connect Sync agent authenticates to Entra ID. These changes affect attacker tradecraft, as we can no longer export the sync account credentials; h...
094
Reposted by Andy Robbins
SpecterOps @specterops.io · 30/05/2025
🚨 New #BloodHoundBasics courtesy of @scoubi.bsky.social! You've successfully compromised Bob in marketing's account in an engagement. Mark it as Owned by right-clicking ➡️ "Add to Owned" ➡️ run the query "Shortest Paths from Owned objects to Tier Zero" & see your new attack paths! (1/2)
142
Reposted by Andy Robbins
Phillip Wylie @phillipwylie.bsky.social · 28/05/2025
Andy Robbins: The Evolution of Bloodhound podcasters.spotify.c...
podcasters.spotify.com
Andy Robbins: The Evolution of Bloodhound by Phillip Wylie Show
About The Guest:Andy Robbins is the Principal Product Architect at SpecterOps and one of the original 13 founding members of the company. He has a background in pen testing and red teaming and is the co-creator of Bloodhound, a popular open-source tool for attack path mapping in Active Directory environments. Summary:Andy Robbins, the Principal Product Architect at SpecterOps, joins host Phillip Wylie to discuss the evolution of Bloodhound, a tool for attack path mapping in Active Directory environments. Andy shares the origin story of Bloodhound and how it was developed to solve the problem of finding attack paths in complex environments. He explains the graph theory behind Bloodhound and how it visualizes data to help practitioners and defenders understand and mitigate security risks. Andy also discusses the recent release of Bloodhound Community Edition (CE) and the improvements it brings, including faster data ingest, query times, and a friendlier user experience. He highlights the focus on practical attack primitives and abuse primitives in Bloodhound and the goal of making attack paths a non-issue for organizations. Andy concludes by sharing valuable advice for those looking to advance in the industry, emphasizing the importance of understanding and solving real problems and being loyal to people rather than companies. Key Takeaways: Bloodhound is a tool for attack path mapping in Active Directory environments, using graph theory to visualize data and identify security risks. Bloodhound Community Edition (CE) brings improvements such as faster data ingest, query times, and a friendlier user experience. Bloodhound focuses on practical attack primitives and abuse primitives to solve real security problems and make attack paths a non-issue for organizations. Quotes: "If we give people an excellent experience for free, then enough of those people will choose to become paying customers that we have a viable business." - Andy Robbins "The industry as a whole is very young, but the capability of visualizing data problems and data security problems in this way is also relatively brand new." - Andy Robbins "We focus on attack paths or risk that emerges out of a combination of the mechanics of a system, the configurations of that system, and the behaviors of users or identities in that system." - Andy Robbins Socials and Resources: https://twitter.com/_wald0 https://twitter.com/SpecterOps https://specterops.io/ https://bloodhoundenterprise.io/ https://github.com/SpecterOps/BloodHound
073
Reposted by Andy Robbins
Bad Sector Labs @badsectorlabs.com · 21/05/2025
MATCH (c1:Computer)-[:MemberOf*1..]->(g:Group) WHERE g.objectsid ENDS WITH '-516' WITH COLLECT(c1[.]name) AS dcs MATCH (c2:Computer) WHERE c2.enabled = true AND (c2.operatingsystem contains '2025') AND (c2[.]name IN dcs) RETURN c2[.]name If this query hits, you're DA: www.akamai.com/blog/securit...
akamai.com
042
Reposted by Andy Robbins
SpecterOps @specterops.io · 18/04/2025
It's #BloodHoundBasics day! Let's talk Tier 0 inheritance. If you're trying to unravel why some of the objects in your environment show up as Tier 0, this query will demonstrate the nuances of inheritance in 2 ways: inheritance up w/ OUs, & inheritance down w/ Groups. 🧵 1/3
152
Reposted by Andy Robbins
SpecterOps @specterops.io · 11/04/2025
We are BACK with another #BloodHoundBasics post, this week courtesy of @andyrobbins.bsky.social. ICYMI: The BloodHound BACK button is BACK. Just use your browser's BACK button to go BACK. 🔙
1102
Reposted by Andy Robbins
Governor JB Pritzker @govpritzker.illinois.gov · 31/03/2025
There are trans Americans right now looking out at this world and wondering if anyone is going to stand up for them and for their simple right to exist. Well, I am. We are. We will.
270166123420
Reposted by Andy Robbins
Katie Knowles @siigil.bsky.social · 31/03/2025
Excited to be at @specterops.bsky.social SO-CON this week!! If you're around, I'll be presenting "Abusing AUs, Confusing the SOC" tomorrow bright & early:
1157
Reposted by Andy Robbins
SpecterOps @specterops.io · 17/01/2025
Introducing a new tool designed to help you install & manage BloodHound instances...🥁 BloodHound CLI! Check out @printingprops.com's blog post to learn how this tool dramatically simplifies installation and server management. ghst.ly/40zXAxI
ghst.ly
Introducing BloodHound CLI
We created a new tool to help you install and manage BloodHound instances, BloodHound CLI!
0124
Andy Robbins @andyrobbins.bsky.social · 15/01/2025
In Part 1 of my Intune Attack Paths series, I discuss the fundamental components and mechanics of Intune that lead to the emergence of attack paths: posts.specterops.io/intune-attac...
posts.specterops.io
Intune Attack Paths — Part 1
Intune is an attractive system for adversaries to target…
34319
Reposted by Andy Robbins
Dirk-jan @dirkjanm.io · 02/01/2025
Few BloodHound python updates: LDAP channel binding is now supported with Kerberos auth (native) or with NTLM (custom ldap3 version). Furthermore, the BH CE collector now has its own pypi package and command. You can have both on the same system with pipx. github.com/dirkjanm/Blo...
github.com
GitHub - dirkjanm/BloodHound.py: A Python based ingestor for BloodHound
A Python based ingestor for BloodHound. Contribute to dirkjanm/BloodHound.py development by creating an account on GitHub.
22914
Reposted by Andy Robbins
SpecterOps @specterops.io · 20/12/2024
Santa's early w/ a new #BloodHoundBasics post!🎅 Looking for new Attack Paths to the domain? 🔎 BH v6.3 introduces CoerceToTGT. The edge connects principals w/ unconstrained delegation to the domain, as attackers can use those to coerce privileged computers & retrieve their TGT.
162
Reposted by Andy Robbins
hotnops @hotnops.bsky.social · 13/12/2024
A new fun way to set shadow credentials posts.specterops.io/attacking-en...
posts.specterops.io
Attacking Entra Metaverse: Part 1
This is part one in a two (maybe three…) part series regarding attacker tradecraft around the syncing mechanics between Active Directory…
096
Reposted by Andy Robbins
SpecterOps @specterops.io · 10/12/2024
New blog post alert! 🚨 Lance Cain shares insights from a recent security assessment about the attack surface of Single-Page Applications integrated w/ Azure and how to aid technology professionals in securing their Azure environment. ghst.ly/4gq8E5y
ghst.ly
SPA is for Single-Page Abuse! - Using Single-Page Application Tokens to Enumerate Azure
Author: Lance B. Cain
1173
Reposted by Andy Robbins
Dirk-jan @dirkjanm.io · 10/12/2024
Awesome work by Lance, clear write-up on the issue, the solution, a PR to ROADtools and more tradecraft!
0164
Reposted by Andy Robbins
Dr Nestori Syynimaa @drazuread.com · 10/12/2024
New #AADInternals version is finally out now: ▪ Moved endpoint related stuff to new module: AADInternals-Endpoints ▪ Added blue team stuff ▪ Added red team stuff See full change log at: aadinternals.com/aadinternals...
14321
Andy Robbins @andyrobbins.bsky.social · 20/11/2024
A quick tour of new functions in BARK that support Azure Key Vault tradecraft research, including a walk-through of how an adversary may chain these functions together as part of an attack path: posts.specterops.io/azure-key-va...
0178
Andy Robbins @andyrobbins.bsky.social · 19/11/2024
I couldn't find any PowerShell examples of encrypting/decrypting data w/ Azure Key Vault keys, so I made some: Protect-StringWithAzureKeyVaultKey Unprotect-StringWithAzureKeyVaultKey github.com/BloodHoundAD... Explanatory blog post coming soon.
github.com
Add key vault cryptographic op funcs · BloodHoundAD/BARK@e1c82a1
1166
Andy Robbins @andyrobbins.bsky.social · 18/11/2024
Hello :)
150