Sign in

Brett Hawkins

@h4wkst3r.bsky.social
157 followers 90 following 11 posts

Adversary Services @xforce h4wkst3r.github.io

PostsRepliesMedia
Brett Hawkins @h4wkst3r.bsky.social · 17/06/2025
New research just dropped I'll be presenting at @wearetroopers.bsky.social next week - Attacking ML Training Infrastructure 💥 Model poisoning for code execution ⚠️ Abusing ML workflows ⚙️ MLOKit updates and new threat hunting rules www.ibm.com/think/x-forc...
ibm.com
Becoming the trainer: Attacking ML training infrastructure
Learn more about machine learning training environments and infrastructure, as well as different attack scenarios against critical components, including cloud compute, model artifact storage and model...
010
Brett Hawkins @h4wkst3r.bsky.social · 02/06/2025
Register while you still can for @retbandit.bsky.social and I's @blackhatevents.bsky.social #BHUSA training, seats are filling up fast!! www.blackhat.com/us-25/traini...
blackhat.com
Black Hat
Black Hat
000
Brett Hawkins @h4wkst3r.bsky.social · 17/04/2025
I am thrilled to be presenting new research on attacking ML training infrastructure at @wearetroopers.bsky.social this summer. Stay tuned for a blog post and lots of updates to MLOKit closer to the conference!
030
Reposted by Brett Hawkins
netbiosX @netbiosx.bsky.social · 09/04/2025
ibm.com
RemoteMonologue: Weaponizing DCOM for NTLM authentication coercions | IBM
The IBM X-Force Red team covers the fundamentals of COM and DCOM, dives into the RunAs setting and why authentication coercions are impactful and introduces a new credential harvesting tool - RemoteMo...
072
Brett Hawkins @h4wkst3r.bsky.social · 07/04/2025
Learn 📝 about this emerging topic in a first-of-its-kind #BHUSA training from @retbandit.bsky.social and I where you will use hands-on labs to perform attacks such as model theft, model poisoning and much more 🤖 blackhat.com/us-25/traini...
blackhat.com
Black Hat
Black Hat
011
Reposted by Brett Hawkins
bohops @bohops.bsky.social · 25/03/2025
[Blog] This ended up being a great applied research project with my co-worker Dylan Tran on weaponizing a technique for fileless DCOM lateral movement based on the original work of James Forshaw. Defensive recommendations provided. - Blog: ibm.com/think/news/f... - PoC: github.com/xforcered/Fo...
ibm.com
Fileless lateral movement with trapped COM objects | IBM
New research from IBM X-Force Red has led to the development of a proof-of-concept fileless lateral movement technique by abusing trapped Component Object Model (COM) objects. Get the details.
01511
Reposted by Brett Hawkins
Chris Thompson @retbandit.bsky.social · 19/03/2025
I am excited to announce the first conference dedicated to the offensive use of AI in security! Request an invite at offensiveaicon.com. Co-organized by RemoteThreat, Dreadnode, & DEVSEC.
173
Reposted by Brett Hawkins
its-a-feature.bsky.social @its-a-feature.bsky.social · 06/03/2025
#MythicTip Want to start automating stuff with Mythic, but not sure where to start? Check out the built-in Jupyter notebooks with Mythic Scripting installed and have fun! Lots of ready to run examples exist already :) Just log in with the Jupyter token from your .env file
092
Reposted by Brett Hawkins
Chris Thompson @retbandit.bsky.social · 04/03/2025
It was an honor to speak at the @780thmibdecyber.bsky.social’s AvengerCon on the use of AI in Offensive Cyber Operations, Vuln Discovery/Weaponization, OST Dev as well as attacking AI systems. Here’s a few slides from the talk… @NSACyber @ARCYBER @CISAgov @US_CYBERCOM
041
Reposted by Brett Hawkins
Dirk-jan @dirkjanm.io · 18/02/2025
Normally you can't auth to Entra ID connected webapps with bearer tokens. But if Teams can open SharePoint/OneDrive with an access token, I guess so can we. roadtx now supports opening SharePoint with access tokens in the embedded browser 😀
1198
Reposted by Brett Hawkins
James Forshaw @tiraniddo.dev · 30/01/2025
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...
googleprojectzero.blogspot.com
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
26541
Brett Hawkins @h4wkst3r.bsky.social · 30/01/2025
If you would like to learn how to attack and defend popular platforms that are used to develop and deploy ML models, early sign-up is now available for @retbandit.bsky.social and I's @blackhatevents.bsky.social training course ⬇️ www.blackhat.com/us-25/traini...
blackhat.com
Black Hat USA 2025
Black Hat USA 2025
001
Reposted by Brett Hawkins
Andy Robbins @andyrobbins.bsky.social · 15/01/2025
In Part 1 of my Intune Attack Paths series, I discuss the fundamental components and mechanics of Intune that lead to the emergence of attack paths: posts.specterops.io/intune-attac...
posts.specterops.io
Intune Attack Paths — Part 1
Intune is an attractive system for adversaries to target…
34319
Reposted by Brett Hawkins
Catalin Cimpanu @campuscodi.risky.biz · 15/01/2025
Live streams from the last ShmooCon security conference, which took place last week, are available on YouTube www.youtube.com/playlist?lis...
youtube.com
ShmooCon 2025 - YouTube
You can reach me at https://twitter.com/Strong1Wind
02914
Brett Hawkins @h4wkst3r.bsky.social · 12/01/2025
You can find our @shmoocon.bsky.social presentation slides at the below GitHub repo. Thanks again to all that attended. Also, thank you to the conference organizers for putting on a great con and having us! #shmoocon github.com/h4wkst3r/Con...
github.com
11612
Reposted by Brett Hawkins
Karl Fosaaen @kfosaaen.bsky.social · 08/01/2025
New @netspi.bsky.social blog out today on "Hijacking Azure Machine Learning Notebooks (via Storage Accounts)". This is very similar to Storage Account attacks that have been done against Function/Logic Apps and Cloud Shell - www.netspi.com/blog/technic...
netspi.com
Hijacking Azure Machine Learning Notebooks (via Storage Accounts)
Abusing Storage Account Permissions to attack Azure Machine Learning notebooks
021
Reposted by Brett Hawkins
spencer @bsky.ethicalthreat.com · 07/01/2025
Unequivocally one of the best pieces of writing on Tier 0 there is...
posts.specterops.io
What is Tier Zero — Part 1
Tier Zero is a crucial group of assets in Active Directory (AD) and Azure. Its purpose is to protect the most critical components by…
0133
Brett Hawkins @h4wkst3r.bsky.social · 06/01/2025
MLOps platforms are becoming critical to enterprises. This has caused @retbandit.bsky.social and I to research these platforms and how they can be abused by attackers. Check out our research we will be presenting @shmoocon.bsky.social this week. securityintelligence.com/x-force/abus...
securityintelligence.com
Abusing MLOps platforms to compromise ML models and enterprise data lakes
With the rush to implement AI across organizations came the increase in the use of MLOps platforms and a greater risk of attack. Learn more about MLOps platforms and how threat actors are using them.
120
Reposted by Brett Hawkins
Catalin Cimpanu @campuscodi.risky.biz · 26/12/2024
IBM X-Force's Logan Goins has released Krueger, a .NET tool for remotely killing EDR using the Windows Defender Application Control (WDAC) utility github.com/logangoins/K...
github.com
GitHub - logangoins/Krueger: Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC
Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC - logangoins/Krueger
0247
Reposted by Brett Hawkins
Olaf Hartong @olafhartong.nl · 16/12/2024
Detection Engineering is sometimes hard, and may fail. Still a lot of things can be learned by the process. In this blog I cover a lot. I had a detection, currently it's broken but MS is on it :D medium.com/falconforce/...
medium.com
Detection engineering rabbit holes — parsing ASN.1 packets in KQL
TL;DR: Detection engineering is sometimes hard. Your efforts may seem to have failed, but perseverance can pay off. Or you can still fail…
065
Reposted by Brett Hawkins
Catalin Cimpanu @campuscodi.risky.biz · 14/12/2024
Secureworks Japan has released PyTune, a post-exploitation tool for enrolling fake devices into Microsoft Intune www.blackhat.com/eu-24/briefi... github.com/secureworks/...
blackhat.com
Black Hat Europe 2024
Black Hat Europe 2024
03918
Brett Hawkins @h4wkst3r.bsky.social · 10/12/2024
@retbandit.bsky.social and I are thrilled to be speaking @shmoocon.bsky.social in January on research we have been conducting on attacking and defending popular enterprise Machine Learning Operations (MLOps) platforms we see during adversary simulation engagements. Whitepaper and tool coming soon!
011