Sign in

Logan Goins

@logangoins.bsky.social
25 followers 29 following 1 posts

Adversary Simulation @specterops.io

PostsRepliesMedia
Reposted by Logan Goins
SpecterOps @specterops.io · 15/07/2026
Need to do an NTLM relay over C2 but local priv-esc isn't possible? @logangoins.bsky.social new post walks through relaying NTLM auth out of a network and back in through red team infra to bypass traditional relay controls, plus how defenders actually stop it. Check it out: ghst.ly/4wA3fkg
ghst.ly
There and Back Again: An Operators Guide on NTLM Relaying Egress
012
Reposted by Logan Goins
SpecterOps @specterops.io · 14/01/2026
SCCM client push strikes again for hierarchy takeover! @logangoins.bsky.social just dropped a new blog showing how WebClient doesn't need to be already running on site servers to coerce HTTP (WebDav) auth & enable NTLM relay to LDAP for SCCM takeover Read more: ghst.ly/3Z9Gbu6
ghst.ly
Wait, Why is my WebClient Started?: SCCM Hierarchy Takeover via NTLM Relay to LDAP - SpecterOps
During automatic client push installation, an SCCM site server automatically attempts to map WebDav shares on clients, starting WebClient when installed.
043
Logan Goins @logangoins.bsky.social · 14/01/2026
Just released a new @specterops.io blog! I discovered that during client push in SCCM env's it's possible to remotely start WebClient and coerce HTTP from site servers for a relay to LDAP resulting in hierarchy takeover when WebClient is installed! 🫠 specterops.io/blog/2026/01...
specterops.io
Wait, Why is my WebClient Started?: SCCM Hierarchy Takeover via NTLM Relay to LDAP - SpecterOps
During automatic client push installation, an SCCM site server automatically attempts to map WebDav shares on clients, starting WebClient when installed.
031
Reposted by Logan Goins
SpecterOps @specterops.io · 23/10/2025
Credential Guard was supposed to end credential dumping. It didn't. Valdemar Carøe just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more: ghst.ly/4qtl2rm
ghst.ly
Catching Credential Guard Off Guard - SpecterOps
Uncovering the protection mechanisms provided by modern Windows security features and identifying new methods for credential dumping.
01710
Reposted by Logan Goins
SpecterOps @specterops.io · 20/10/2025
Patching one technique doesn't close the entire attack vector. dMSA abuse is still a problem, and @logangoins.bsky.social just dropped a reality check with new tooling to prove it. Learn more about the issue & the new BadTakeover BOF. ghst.ly/42POg9L
ghst.ly
The (Near) Return of the King: Account Takeover Using the BadSuccessor Technique - SpecterOps
After Microsoft patched Yuval Gordon’s BadSuccessor privilege escalation technique, BadSuccessor returned with another blog from Yuval, briefly mentioning to the community that attackers can still abu...
033
Reposted by Logan Goins
SpecterOps @specterops.io · 22/08/2025
Trying to fly under EDR's radar? @logangoins.bsky.social explains how to use HTTP-to-LDAP relay attacks to execute tooling completely off-host through the C2 payload context. Perfect for when you need LDAP access but want to avoid being caught stealing creds. ghst.ly/41mjMv7
ghst.ly
Operating Outside the Box: NTLM Relaying Low-Privilege HTTP Auth to LDAP - SpecterOps
TL;DR When operating out of a ceded access or phishing payload with no credential material, you can use low-privilege HTTP authentication from the current user context to perform a proxied relay to LD...
052