Sign in

Martin Sohn Christensen

@martinsohn.dk
98 followers 56 following 31 posts

Security Researcher @ SpecterOps martinsohn.dk

PostsRepliesMedia
Martin Sohn Christensen @martinsohn.dk · 07/07/2026
RID-500 is AD's best break-glass account... and you should disable it!🙃 Jorge de Almeida Pinto shared counterintuitive wisdom at #TROOPERS26 - All-powerful and cannot get locked out. - Disabled = more secure. - Disabled bypassed when booting in Safe Mode With Networking. Sources in🧵
100
Martin Sohn Christensen @martinsohn.dk · 02/07/2026
#TROOPERS26 afterglow: Andrew Schwartz on building a solid LDAP detection stack - why signature-based detection is failing and volume-based detection generally wins. Lots of tips for detecting SharpHound, ldapnomnom, SOAPy & more.
300
Martin Sohn Christensen @martinsohn.dk · 24/06/2026
Live at TROOPERS: @drazuread.com presenting how Windows users TPM to protect PRTs.
020
Martin Sohn Christensen @martinsohn.dk · 16/06/2026
Timeline of AD CS attack research & Microsoft patches since the AD CS paradigm shift: Certifried Pre-Owned whitepaper by @harmj0y.bsky.social and @tifkin.bsky.social
032
Reposted by Martin Sohn Christensen
Thomas Naunheim @naunheim.cloud · 15/06/2026
Speaking at #TROOPERS26 next week and I can't wait. Joining @martinsohn.dk to talk about attack paths to #PAW and real-world risks of tiered admin models with #IntuneRBAC. Plus something we've been working on for months... See you in Heidelberg! www.troopers.de #EntraOps #Bloodhound
001
Martin Sohn Christensen @martinsohn.dk · 11/06/2026
I wrote about a recent research task of mine -
020
Reposted by Martin Sohn Christensen
Hope Walker @1cemoon.bsky.social · 05/06/2026
My SO-CON talk about mapping RBAC in BloodHound is posted now. Fair warning for those who don't know me, I do have a personality and started by yelling at the crowd. 👑 Check out how we are mapping RBAC in BloodHound moving forward. youtu.be/1KDcK9PjnhU?...
youtu.be
Mapping RBAC in BloodHound | SO-CON 26
YouTube video by SpecterOps
011
Martin Sohn Christensen @martinsohn.dk · 29/05/2026
This sounds awesome for no money. Unfortunately I'll be between BSides & Troopers those days :/
000
Martin Sohn Christensen @martinsohn.dk · 08/05/2026
The BSides Aarhus agenda is now live, and I am giving a talk on my "bad-documentation" research there on June 20. Agenda 👉 bsidesaarhus.dk/agenda/
020
Reposted by Martin Sohn Christensen
SpecterOps @specterops.io · 15/04/2026
BloodHound users: your query workflow just got better. With this latest update, @martinsohn.dk and @joeydreijer.bsky.social introduce multi-source loading, multi-server support, and dozens of new queries, now live in the Query Library. Check it out: ghst.ly/4vBic6c
specterops.io
What's New in the BloodHound Query Library: BYOL, OpenGraph, Multi-Server, and More - SpecterOps
BloodHound Query Library now supports custom query sources, OpenGraph extensions, and multi-server environments.
041
Reposted by Martin Sohn Christensen
James Forshaw @tiraniddo.dev · 07/04/2026
I've put up the slides from my Zer0Con 2026 presentation on Administrator Protection. github.com/tyranid/info...
github.com
064
Reposted by Martin Sohn Christensen
SpecterOps @specterops.io · 08/04/2026
Time is running out ⏳ Grab your spot in our Detection course at #SOCON2026 happening next week! In-person attendees receive a free pass to the conference days. Save your seat before registration closes TOMORROW! ghst.ly/socon26-regbsky
001
Martin Sohn Christensen @martinsohn.dk · 25/03/2026
My responsible disclosure covering 16 vendors whose documentation was steering customers into critical misconfigs. More details will be shared at my talk @ BSides Prague on April 24! www.bsidesprg.cz#program:~:te...
bsidesprg.cz
Security B-Sides Prague
BSides Prague provides a platform for the information security community to present their work in a friendly and welcoming environment.
011
Reposted by Martin Sohn Christensen
SpecterOps @specterops.io · 27/01/2026
The #SOCON2026 agenda is live! 🎉 Explore talks, topics, & speakers across the Tradecraft, OpenGraph, & new Practice Track, focused on turning Attack Path Management into an operational discipline. Check out the agenda & plan your experience: ghst.ly/socon26-tw 🧵: 1/4
132
Martin Sohn Christensen @martinsohn.dk · 19/09/2025
BloodHound's OpenGraph is 🔥🚀 This is how we rapidly developed a customer specific attack primitive for BloodHound that we call "ManagerOf" 👇
000
Reposted by Martin Sohn Christensen
Jonas Bülow Knudsen @jonas-bk.bsky.social · 25/06/2025
I publish two blog posts today! 📝🐫 First dives into how we're improving the way BloodHound models attack paths through AD trusts: specterops.io/blog/2025/06... Second covers an attack technique I came across while exploring AD trust abuse: specterops.io/blog/2025/06... Hope you enjoy the read 🥳
specterops.io
Good Fences Make Good Neighbors: New AD Trusts Attack Paths in BloodHound - SpecterOps
The ability of an attacker controlling one domain to compromise another through an Active Directory (AD) trust depends on the trust type and configuration. To better map these relationships and make i...
01811
Martin Sohn Christensen @martinsohn.dk · 17/06/2025
Easily find and share BloodHound Cyphers on queries.specterops.io Released with ~90 new Cypher queries, go check them out! @joeydreijer.bsky.social and I spent many hours creating it and we hope you find it useful. All feedback is appreciated :)
queries.specterops.io
011
Martin Sohn Christensen @martinsohn.dk · 24/05/2025
**Every** BloodHound Enterprise tenant I've checked has multiple Non Tier Zero principals with the rights required for BadSuccessor. Luckily a 2025 DC is still rare. Often helpdesk has GenericAll, misconfig'ed to apply on the OU itself, instead of only inheriting to principals within.
010
Martin Sohn Christensen @martinsohn.dk · 26/04/2025
Shout out (skud ud) to @embar.io Best CTF DJ. #tdcnetctf
010
Martin Sohn Christensen @martinsohn.dk · 09/04/2025
BloodHound has 4 new edges: 𝗖𝗼𝗲𝗿𝗰𝗲𝗔𝗻𝗱𝗥𝗲𝗹𝗮𝘆𝗡𝗧𝗟𝗠𝗧𝗼𝗦𝗠𝗕, ...𝗧𝗼𝗟𝗗𝗔𝗣, ...𝗧𝗼𝗟𝗗𝗔𝗣𝗦, ...𝗧𝗼𝗔𝗗𝗖𝗦 [ESC8] They combine 𝗰𝗼𝗲𝗿𝗰𝗶𝗼𝗻 and 𝗿𝗲𝗹𝗮𝘆𝗶𝗻𝗴, allowing Auth. Users to compromise computers. Read this excellent post by Elad Shamir if you are unfamiliar with those terms or want to know how to mitigate.
040
Martin Sohn Christensen @martinsohn.dk · 08/04/2025
I had a great time at @specterops.bsky.social #SOCON2025 in Arlington/DC! I'm grateful I get to meet all you awesome people; community members and Specters. Huge thanks to the many speakers and trainers 💙 See you next year!
070
Martin Sohn Christensen @martinsohn.dk · 07/02/2025
130
Reposted by Martin Sohn Christensen
Andy Robbins @andyrobbins.bsky.social · 15/01/2025
In Part 1 of my Intune Attack Paths series, I discuss the fundamental components and mechanics of Intune that lead to the emergence of attack paths: posts.specterops.io/intune-attac...
posts.specterops.io
Intune Attack Paths — Part 1
Intune is an attractive system for adversaries to target…
34319
Reposted by Martin Sohn Christensen
Bluesky @bsky.app · 26/12/2024
Merry Christmas from us to you 🎄🎁💙 We launched Trending Topics today, and you can find it by tapping the search icon on the bottom bar of the app or the right sidebar on desktop.
Screenshot of trending topics launched on Christmas 2025. Topics trending include: Virat Kohli, Red Panda, Porzingis, Post Malone, Beyoncé, Gavin and Stacey Finale, Sixers, A Complete Unknown, King Henry, Joel Embiid, Pentatonix
1507464125226
Reposted by Martin Sohn Christensen
SpecterOps @specterops.io · 16/12/2024
The Misconfiguration Manager DETECT section has been updated with fresh guidance to help defensive operators spot the most prolific attack techniques. Check out the blog post from @bouj33boy.bsky.social to learn more. ghst.ly/3VJ5y4F
ghst.ly
Misconfiguration Manager: Detection Updates
TL;DR: The Misconfiguration Manager DETECT section has been updated with relevant guidance to help defensive operators identify the most…
054
Reposted by Martin Sohn Christensen
its-a-feature.bsky.social @its-a-feature.bsky.social · 25/11/2024
It's that time of year again everybody! I want to know YOUR thoughts on Mythic! What did you like? What could be improved? What would you like to see next? Why do you or don't you use it? If you could change something, what would it be? www.surveymonkey.com/r/MythicPlan... I'm all ears :)
media.tenor.com
a woman wearing glasses says please with her hand up
ALT: a woman wearing glasses says please with her hand up
0105
Reposted by Martin Sohn Christensen
Andrea P @decoder-it.bsky.social · 25/11/2024
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/K...
36343
Martin Sohn Christensen @martinsohn.dk · 25/11/2024
ShadowHound - brand new .ps1 SharpHound alternative that supports LDAP and ADWS Outputs data in ldapsearch format that can be converted to BH JSON with BOFHound. blog.fndsec.net/2024/11/25/s...
blog.fndsec.net
ShadowHound: A SharpHound Alternative Using Native PowerShell
ShadowHound is a PowerShell tool designed for mapping Active Directory environments without using known malicious binaries. It utilizes legitimate PowerShell modules for data collection through two…
000
Martin Sohn Christensen @martinsohn.dk · 21/11/2024
355 to go!
Meme template "they don't know".
*infosec bsky users*
me: they don't know that I had 395 followers on X
030
Reposted by Martin Sohn Christensen
Dirk-jan @dirkjanm.io · 20/11/2024
Awesome new addition to krbrelayx by Hugow from Synacktiv: www.synacktiv.com/publications...
synacktiv.com
Relaying Kerberos over SMB using krbrelayx
02914
Martin Sohn Christensen @martinsohn.dk · 19/11/2024
RCP Firewall and LDAP Firewall workshop by Sagie Dulce and Dekel Paz. youtube.com/watch?v=hJyI...
m.youtube.com
DEATHcon 2024: Prevention Engineering via the RPC and LDAP Firewalls
YouTube video by Zero Networks
010
Martin Sohn Christensen @martinsohn.dk · 15/11/2024
PowerHuntShares is a useful tool by Scott Sutherland (_nullbind), and the v2 looks amazing. I gotta test the experimental "Share Graph". www.netspi.com/blog/technic...
netspi.com
Hunting SMB Shares, Again! Charts, Graphs, Passwords & LLM Magic for PowerHuntShares 2.0
Learn how to identify, understand, attack, and remediate SMB shares configured with excessive privilege in active directory environments with the help of new charts, graphs, and LLM capabilities.
110
Martin Sohn Christensen @martinsohn.dk · 14/11/2024
SO-CON CFP submitted! Get yours in before tomorrow's deadline. specterops.io/so-con/
030
Martin Sohn Christensen @martinsohn.dk · 13/11/2024
Tier list of AD tiers
011
Martin Sohn Christensen @martinsohn.dk · 11/11/2024
Join our webinar on Thurs when Jonas Knudsen, Lee Christensen, and I will present pt. 4 of "What Is Tier Zero", covering: - MS Exchange On-Premises - ADCS - Insights from isolating Tier Zero with BloodHound Enterprise customers Watch live or register for on-demand at ghst.ly/4eSssxL
ghst.ly
Welcome! You are invited to join a webinar: Defining the Undefined: What is Tier Zero, Part 4. After registering, you will receive a confirmation email about joining the webinar.
In this webinar we continue to define Tier Zero with another deep dive into the intricate world of critical identities and resources across Active Directory and Azure. This discussion covers: - Insig...
010