Sign in

hotnops

@hotnops.bsky.social
166 followers 76 following 13 posts

Does stuff at @specterops Cloud security research

PostsRepliesMedia
Reposted by hotnops
Andy Robbins @andyrobbins.bsky.social · 20/10/2025
Introducing PingOneHound! This OpenGraph extension for BloodHound can help you identify, analyze, execute, and remediate attack paths in PingOne organizations. Read the introductory blog post here: specterops.io/blog/2025/10...
specterops.io
PingOne Attack Paths - SpecterOps
You can use PingOneHound in conjunction with BloodHound Community Edition to discover, analyze, execute, and remediate identity-based attack paths in PingOne instances.
0910
Reposted by hotnops
SpecterOps @specterops.io · 11/08/2025
The AD CS security landscape keeps evolving, and so does our tooling. 🛠️ Valdemar Carøe drops info on Certify 2.0, including a suite of new capabilities and refined usability improvements. ghst.ly/45IrBxI
ghst.ly
Certify 2.0 - SpecterOps
Certify 2.0 features a suite of new capabilities and usability enhancements. This blogpost introduces changes and features additions.
0108
Reposted by hotnops
SpecterOps @specterops.io · 31/07/2025
Red teamers know the drill: endless file churning, hunting for passwords & tokens. 🔍 Meet DeepPass2, our new secret scanning tool that goes beyond structured tokens to catch those tricky free-form passwords too. Read Neeraj Gupta's blog post for more. ghst.ly/40HLNNA
ghst.ly
What’s Your Secret?: Secret Scanning by DeepPass2  - SpecterOps
Discover DeepPass2 - a secret scanning tool combining BERT-based model and LLMs to detect free-form passwords, and other structured tokens and secrets with high accuracy.
0124
hotnops @hotnops.bsky.social · 31/07/2025
The best creds are the ones you simply ask for =) specterops.io/blog/2025/07...
000
hotnops @hotnops.bsky.social · 30/07/2025
Finally putting out my research from this spring. "Imitune" coming in soon to support the POC specterops.io/blog/2025/07...
specterops.io
Entra Connect Attacker Tradecraft: Part 3 - SpecterOps
How Entra Connect and Intune can be abused via userCertificate hijacking to bypass conditional access and compromise hybrid domains
011
hotnops @hotnops.bsky.social · 30/07/2025
If you're a #bloodhound user, JD's bloodhound operator is invaluable. Now with opengraph cmdlets! github.com/SadProcessor...
github.com
GitHub - SadProcessor/BloodHoundOperator: BloodHound PowerShell client
BloodHound PowerShell client. Contribute to SadProcessor/BloodHoundOperator development by creating an account on GitHub.
020
Reposted by hotnops
Nathan McNulty @nathanmcnulty.com · 25/07/2025
Looks like the Entra QR code authentication method is going GA 🥳 They've also added some great guidance on suppressing the camera permission prompt for iOS :) learn.microsoft.com/...
031
Reposted by hotnops
Steve Syfuhs @syfuhs.net · 13/07/2025
Part 8053 of eleventy billion on our path to killing NTLM: way way way way way better auditing. support.microsoft.com/en-us/topic/...
support.microsoft.com
Overview of NTLM auditing enhancements in Windows 11, version 24H2 and Windows Server 2025 - Microsoft Support
Summary of new auditing features and deployment details
34612
Reposted by hotnops
Jonas Bülow Knudsen @jonas-bk.bsky.social · 25/06/2025
I publish two blog posts today! 📝🐫 First dives into how we're improving the way BloodHound models attack paths through AD trusts: specterops.io/blog/2025/06... Second covers an attack technique I came across while exploring AD trust abuse: specterops.io/blog/2025/06... Hope you enjoy the read 🥳
specterops.io
Good Fences Make Good Neighbors: New AD Trusts Attack Paths in BloodHound - SpecterOps
The ability of an attacker controlling one domain to compromise another through an Active Directory (AD) trust depends on the trust type and configuration. To better map these relationships and make i...
01811
Reposted by hotnops
XPN @xpnsec.com · 18/06/2025
My second post for the month is now live 🎉
2122
hotnops @hotnops.bsky.social · 09/06/2025
New tricks, same impact posts.specterops.io/update-dumpi...
posts.specterops.io
Update: Dumping Entra Connect Sync Credentials
Recently, Microsoft changed the way the Entra Connect Connect Sync agent authenticates to Entra ID. These changes affect attacker tradecraft, as we can no longer export the sync account credentials…
067
Reposted by hotnops
Nick Frichette @frichetten.com · 02/06/2025
A little over a year ago I published research on how you could leverage non-production AWS API endpoints to enumerate permissions without logging to CloudTrail. A year later...I'm still finding them. Red Teamers, these can be super useful and really up your game!
152
Reposted by hotnops
David Fowler @davidfowl.com · 22/05/2025
We’re about to take C# to the next level! #dotnet #csharp
A command line interface Some c# code
2722635
Reposted by hotnops
SpecterOps @specterops.io · 19/05/2025
Did you miss #SOCON2025? Did you have a favorite talk you'd like to rewatch? 🎥 All presentations from SO-CON 2025 are now live at ghst.ly/socon25-talks. 💻 Slides for each talk are available at ghst.ly/socon25-slides.
055
Reposted by hotnops
Fabian Bader @fabian.bader.cloud · 02/05/2025
Application Based Authentication on Microsoft Entra Connect Sync is near. With this change you will be able to use a TPM backed certificate in Entra Connect Sync for authentication. This is a welcome change to prevent the compromise of this high privileged account. #Entra #Certificate
0102
Reposted by hotnops
Anthony J. Fontanez @ajf8729.com · 30/04/2025
Did you know you can send LAPS passwords to Entra on Server OS? Neither did @adamgrosstx.bsky.social or I until yesterday! Just need to hybrid join the server(s) and set the GPO to backup to "AAD"! Neat!
2154
hotnops @hotnops.bsky.social · 25/04/2025
Can you use the on-behalf-of flow to bypass conditional access policies? If the middleware app satisfies conditional access, can it exchange an access token to an otherwise blocked backend resource? It turns out... no. No it can't. The CAP will kick in when the middleware app uses the OBO flow.
000
Reposted by hotnops
Fabian Bader @fabian.bader.cloud · 06/01/2025
A new dedicated resource application to enable Active Directory to Microsoft Entra ID sync using Microsoft Entra Connect Sync or Cloud Sync is coming 😱 In the announcement the mentioned reason is "upcoming security hardening"... 6bf85cfa-ac8a-4be5-b5de-425a0d0dc016 #EntraID
34013
Reposted by hotnops
50501: The People’s Movement ❌👑 @50501movement.bsky.social · 16/04/2025
🚨 Join the #PeoplesMovement this Saturday #April19 for a National Day of Action! Yes, people will be in the streets again. Others will be organizing food drives, volunteering at shelters, hosting teach-ins, and more. Hundreds of events are already listed at www.FiftyFifty.one/events.
611071501
Reposted by hotnops
SpecterOps @specterops.io · 18/04/2025
Understanding Windows access tokens could be your best defense. At @cackalackycon.bsky.social, @atomicchonk.bsky.social will be peeling back the layers on potato exploits that threat actors use for privilege escalation. Check out the schedule to learn more ➡️ ghst.ly/4jzjlnI
063
Reposted by hotnops
Garrett @unsignedsh0rt.bsky.social · 11/04/2025
Had some fun with PDQ deploy/inventory credential decryption and wrote about it here: unsigned-sh0rt.net/posts/pdq_cr... thanks to @dru1d.bsky.social for writing a BOF out of the POC tl;dr get admin on PDQ box, decrypt privileged creds
unsigned-sh0rt.net
Decrypting PDQ credentials | unsigned_sh0rt's blog
Walkthrough of how PDQ credentials encrypts service credentials
096
Reposted by hotnops
Max Andreacchi @atomicchonk.bsky.social · 07/04/2025
Everybody’s using AI assistants and tools these days, but do most of us understand how our text-based input is being interpreted and processed? Check out my latest blog post for a basic intro to text interpretation by AI assistants. www.corgi-Corp.com/post/tokeniz...
corgi-corp.com
Tokenizing the Sandwich Debate: How NLP Models Weigh In on Hot Dogs
Get the gist for Natural Language Processing (NLP) and how tokenization plays a factor
051
Reposted by hotnops
SpecterOps @specterops.io · 09/04/2025
Think NTLM relay is a solved problem? Think again. Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
12720
Reposted by hotnops
Matt Creel @tw1sm.bsky.social · 07/04/2025
Nothing new, but formalized some operator notes on Entra ID/Azure tradecraft I've found to be exceptionally useful on ops. Overlooked this myself for quite some time and thought others in the same boat might find it worth a read! 📖 medium.com/specter-ops-...
medium.com
An Operator’s Guide to Device-Joined Hosts and the PRT Cookie
Introduction
052
Reposted by hotnops
XPN @xpnsec.com · 06/04/2025
1 year anniversary at SpecterOps, so many personal and professional achievements in a short space of time. My advice for anyone getting into this field, try and make sure that you work companies and colleagues that push you beyond your comfort level. \o/
0231
Reposted by hotnops
SpecterOps @specterops.io · 30/03/2025
We are excited to see everyone at #SOCON2025 tomorrow! 🙌 Get the details on everything you need to know before arriving at the conference: specterops.io/so-con
0164
Reposted by hotnops
Max Andreacchi @atomicchonk.bsky.social · 29/03/2025
Spent the evening deep diving into MCPs and started a new project: roadrecon_mcp_server! This #MCP takes the web GUI output from the awesome ROADtools by @dirkjanm.io and offers tools to Claude (or your #AI agent of choice) to interact with the data: github.com/atomicchonk/...
github.com
GitHub - atomicchonk/roadrecon_mcp_server: Claude MCP server to perform analysis on ROADrecon data
Claude MCP server to perform analysis on ROADrecon data - atomicchonk/roadrecon_mcp_server
2115
hotnops @hotnops.bsky.social · 21/03/2025
What's the purpose of the x-ms-DeviceCredential header if the device id claim is already included in the user access token? It seems redundant
011
Reposted by hotnops
Merill Fernando 💚 @merill.net · 10/03/2025
🎙️ BIG NEWS: I'm launching Entra.Chat - the podcast identity pros have been waiting for! After years in the identity trenches, I've seen a lot - the midnight calls, the authentication puzzles, and those "how is this even possible?" moments.
26114
hotnops @hotnops.bsky.social · 06/03/2025
Has anyone heard of anyone actually setting up WHFB certificate trust? it's gotta be a MS troll
011
Reposted by hotnops
CyberScoop @cyberscoop.bsky.social · 05/03/2025
Former top NSA cyber official: Probationary #firings ‘devastating’ to cyber, #nationalsecurity. Rob Joyce emphasized during a House hearing how important probationary employees are to #NSA efforts to counter #China and other threats in #cyberspace. cyberscoop.com/joyce-china-...
cyberscoop.com
Former top NSA cyber official: Probationary firings ‘devastating’ to cyber, national security
Rob Joyce emphasized during a House hearing how important probationary employees are to NSA efforts to counter China and other threats in cyberspace.
22618
Reposted by hotnops
SpecterOps @specterops.io · 05/03/2025
BIG NEWS: SpecterOps raises $75M Series B to strengthen identity security! Led by Insight Partners with Ansa Capital, M12, Ballistic Ventures, Decibel, and Cisco Investments. ghst.ly/seriesb #IdentitySecurity #CyberSecurity (1/6)
1159
Reposted by hotnops
SpecterOps @specterops.io · 05/02/2025
Introducing Forge 🔥 – the first “Command Augmentation” container for Mythic! Check out @its-a-feature.bsky.social's latest blog post to learn how this new add-on offers a more standardized way of executing BOFs and .NET assemblies. ghst.ly/416iKnu
ghst.ly
Forging a Better Operator Quality of Life
A new Mythic add-on for Windows Agents
0105
Reposted by hotnops
Stian A. Strysse 🛡️ @learningbydoing.cloud · 03/02/2025
Woah, this feature totally slipped under my #Entra radar - new protected action capability in #ConditionalAccess for hard-deletion of directory objects. Require e.g. compliant device, phishing-resistant MFA and re-auth before allowing permanent deletion of users, M365 groups and apps in Entra ID!
learn.microsoft.com
What are protected actions in Microsoft Entra ID? - Microsoft Entra ID
Learn about protected actions in Microsoft Entra ID.
1144
hotnops @hotnops.bsky.social · 22/01/2025
This post goes more into Entra Connect tradecraft and how partially synced objects can be hijacked for cross domain attacks. posts.specterops.io/entra-connec...
posts.specterops.io
Entra Connect Attacker Tradecraft: Part 2
Now that we know how to add credentials to an on-premises user, lets pose a question:
051
Reposted by hotnops
Russel Van Tuyl @russelvantuyl.bsky.social · 16/01/2025
Come join us, there isn’t a better place to work and show your technical excellence surrounded by the industry’s best if you ask me!
011
Reposted by hotnops
XPN @xpnsec.com · 07/01/2025
Achievement unlocked, my first blog with SpecterOps 🤗 This post looks at ADFS OAuth2 support, Device Registration, Enterprise PRT, and a brain dump of things that I didn’t want to leave sat on Notion. buff.ly/4j41VQU
buff.ly
ADFS — Living in the Legacy of DRS
It’s no secret that Microsoft have been trying to move customers away from ADFS for a while. Short of slapping a “deprecated” label on it…
23618
Reposted by hotnops
Thomas Seigneuret @zblurx.bsky.social · 18/12/2024
New module on #NetExec : wam Dump #Entra access tokens from Windows Token Broker Cache, and make your way to Entra 🚀 Thanks @xpnsec.com for the technique! More info on his blog : blog.xpnsec.com/wam-bam/
02012
hotnops @hotnops.bsky.social · 13/12/2024
i'm on the internet this week. head over to advent.cloudsecuritypodcast.tv to hear me talk about tokens and conditional access
advent.cloudsecuritypodcast.tv
Advent of Cloud Security
Presented by Cloud Security Podcast, Advent of Cloud Security is a 24 day event where we drop new video every single day.
000
hotnops @hotnops.bsky.social · 13/12/2024
A new fun way to set shadow credentials posts.specterops.io/attacking-en...
posts.specterops.io
Attacking Entra Metaverse: Part 1
This is part one in a two (maybe three…) part series regarding attacker tradecraft around the syncing mechanics between Active Directory…
096
Reposted by hotnops
Steve Syfuhs @syfuhs.net · 06/12/2024
Oh by the way
NTLM v1 is removed from the latest version of Windows
910035
hotnops @hotnops.bsky.social · 05/12/2024
Anyone know anything about the ms graph permission "userauthmethod-passkey.readwrite.all"? i might need it for stuff
011
hotnops @hotnops.bsky.social · 22/11/2024
I love hearing myself talk and so should you!
151
Reposted by hotnops
SpecterOps @specterops.io · 20/11/2024
Learn how BARK's latest functions enhance adversarial tradecraft research relevant to Azure Key Vault. In his blog post, @andyrobbins.bsky.social shares an example of how a #redteam operator may use these commands over the course of an assessment. Read more 👉 ghst.ly/3CEtXSo
042
Reposted by hotnops
Andy Robbins @andyrobbins.bsky.social · 19/11/2024
I couldn't find any PowerShell examples of encrypting/decrypting data w/ Azure Key Vault keys, so I made some: Protect-StringWithAzureKeyVaultKey Unprotect-StringWithAzureKeyVaultKey github.com/BloodHoundAD... Explanatory blog post coming soon.
github.com
Add key vault cryptographic op funcs · BloodHoundAD/BARK@e1c82a1
1166