Sign in

Scoubi

@scoubi.bsky.social
400 followers 134 following 83 posts

Infosec, Detection Engineering, Threat Research, Threat Hunting, OffSec, Conference Organizer.

PostsRepliesMedia
Reposted by Scoubi
SpecterOps @specterops.io · 25/09/2026
A #BloodHoundBasics reminder from @scoubi.bsky.social ⤵️ Not into live chat? Join our new SpecterOps & BloodHound Community subreddit! Come for the AMA, stay for the discussions: www.reddit.com/r/SpecterOpsCommunity
031
Reposted by Scoubi
SpecterOps @specterops.io · 24/09/2026
At #OffensiveAICon, @harmj0y.bsky.social & @tifkin.bsky.social will explore optimized evasion attacks & their transferability across EDR products. They’ll share findings from reverse engineering four EDRs and experimenting with LLMs & GEPA to expand the search space for effective obfuscation.
031
Reposted by Scoubi
SpecterOps @specterops.io · 18/09/2026
New #BloodHoundBasics post c/o @scoubi.bsky.social! 🎉 As of v9.7 BH supports multiple destinations in Pathfindings. You can force a path to traverse a specific node. It is also possible to rearrange the order of the nodes a path must traverse. For more info 👉 ghst.ly/4cOBtt9
011
Scoubi @scoubi.bsky.social · 18/09/2026
Only 25 tickets left for #DEATHcon #Montreal! Join us on site for 2 days of hands on workshops on Detection Engineering and Threat Hunting www.eventbrite.ca/e/2026-death...
eventbrite.ca
022
Reposted by Scoubi
Hourly Cosmos @hourlycosmos.bsky.social · 17/09/2026
Cassini WAC Saturn Storm Obs 85155 - From Ian Regan - flic.kr/p/jRD1HW
November 27, 2013
222943
Reposted by Scoubi
5pider @5pider.net · 17/09/2026
New Release Havoc Professional 0.8: Leviathan 🩸 - Introducing Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Refactored port forwarding and sleep masking - Enhanced .NET/PowerSafe execution - In-Memory PE Execution and BOF-PE support Release: www.infinitycurve.org/blog/leviathan
infinitycurve.org
Havoc Professional 0.8: Leviathan
Introducing Kaine User-Defined C2, expanded Linux post-ex capabilities, refactored port forwarding and sleep masking, enhanced .NET/PowerSafe execution, Beacon Object File improvements, In-Memory PE E...
084
Reposted by Scoubi
Ninja Owl @ninjaowl.ai · 18/09/2026
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
022
Reposted by Scoubi
Ninja Owl @ninjaowl.ai · 18/09/2026
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
022
Reposted by Scoubi
Rob Fuller @mubix.com · 07/09/2026
Made a Cybersecurity Resume Reviewer AI skill that I've been using for some mentees, made it public for anyone who is interested in using it as well. Hope others find it useful (also open to feedback or pull requests). github.com/mubix/cyber-...
github.com
GitHub - mubix/cyber-resume-reviewer-skill: A skill to help cybersecurity folks update and tweak their resume
A skill to help cybersecurity folks update and tweak their resume - mubix/cyber-resume-reviewer-skill
094
Scoubi @scoubi.bsky.social · 13/07/2026
🚨 @deathcon.io - Montreal On Site Tickets 🚨 Tickets: eventbrite.ca/e/2026-death... Tickets are selling super fast this year! This is my first post about it and already 30% of the tickets are sold!! #DetectionEngineering and #ThreatHunting buy your tickets now!!
eventbrite.ca
000
Reposted by Scoubi
GreyNoise @greynoise.io · 13/07/2026
NoiseFest is just a few weeks away!🎉 If you're in Las Vegas for #BlackHat or #DEFCON, come join us for a night of cold drinks, good company, and 60s and 70s vibes. 🏵️ 📅Thursday, August 6th | 6–9 PM PT | Las Vegas 🔗RSVP: info.greynoise.io/events/black... #NoiseFest #GreyNoise #cybersecurity
info.greynoise.io
GreyNoise - NoiseFest at BlackHat 2026
Join us for NoiseFest at BlackHat/DEFCON on Thursday, August 6th. Enjoy drinks, snacks, and engaging conversations with your peers. RSVP now!
011
Reposted by Scoubi
Olaf Hartong @olafhartong.nl · 10/06/2026
Next August, we'll host our newly designed advanced defensive engineering training at BlackHat USA in Las Vegas. Next to detection engineering we'll also cover many important defensive security topics like enrichment, lifecycle management and AI. blackhat.com/us-26/traini...
011
Reposted by Scoubi
SpecterOps @specterops.io · 29/05/2026
New #BloodHoundBasics from @scoubi.bsky.social! Waiting on better Cypher parity to switch your BHCE deployment to a PG backend? v9.2.0 brings new Cypher support! UNWIND, RELATIONSHIPS(p), NODES(p), etc & several improvements to existing verbs. Ex: Exclude edge types directly in Cypher!
111
Reposted by Scoubi
DEATHCon @deathcon.io · 30/05/2026
This is it folks! This is the last weekend to submit a DEATHCon workshop CFP proposal if you want to get in the first round of acceptance! We've got a lot of great submissions already but there's room for yours too! deathcon.io Click on CFP. Conf can pay for travel! Or you can teach online remote!
deathcon.io
DEATHCon 2026 - Detection Engineering & Threat Hunting Conference
DEATHCon - Detection Engineering and Threat Hunting Workshops
021
Reposted by Scoubi
Ron Bowes @iagox86.bsky.social · 22/04/2026
My team at @greynoise.io is hiring a Junior Detection Engineer - somebody who understands network traffic and can write detection rules. Hit me up if you have any questions! job-boards.greenhouse.io/greynoiseint...
job-boards.greenhouse.io
Detection Engineer
United States (Remote)
077
Reposted by Scoubi
SpecterOps @specterops.io · 20/02/2026
It’s #BloodHoundBasics day w/ @scoubi.bsky.social! This week: Relationship Shortcuts. Instead of listing all traversable relationships in your Cypher queries, use: [:AD_ATTACK_PATHS] for Active Directory [:AZ_ATTACK_PATHS] for Entra ID [:ALL_ATTACK_PATHS] for AD & Entra
051
Scoubi @scoubi.bsky.social · 07/12/2025
3rd times the charm? My talk about #BloodHound #OpenGraph was accepted at #WWHF Mile High (Denver). That will allow me to realize 2 dreams at the same time. 1- Speak at WWHF live in person 2- Snowboard in that part of the world with good friends (that will also give a talk at WWHF)
110
Scoubi @scoubi.bsky.social · 02/12/2025
I'm happy to share a new #BloodHound #OpenGraph extension with the commnunity!! Here's the link : github.com/Scoubi/Blood... It maps MITRE ATT&CK. #Sigma and #AtomicRedTeam test all in one graph!
github.com
GitHub - Scoubi/BloodSOCer
Contribute to Scoubi/BloodSOCer development by creating an account on GitHub.
031
Reposted by Scoubi
Merill Fernando 💚 @merill.net · 24/10/2025
Dirk-jan Mollema found one of the most severe vulnerabilities ever discovered in Microsoft Entra ID. One that could have compromised every tenant in the cloud. In this episode, we unpack the story, the stress, and the mindset behind responsible disclosure. 🔥
1133
Reposted by Scoubi
Andy Robbins @andyrobbins.bsky.social · 20/10/2025
Introducing PingOneHound! This OpenGraph extension for BloodHound can help you identify, analyze, execute, and remediate attack paths in PingOne organizations. Read the introductory blog post here: specterops.io/blog/2025/10...
specterops.io
PingOne Attack Paths - SpecterOps
You can use PingOneHound in conjunction with BloodHound Community Edition to discover, analyze, execute, and remediate identity-based attack paths in PingOne instances.
0910
Reposted by Scoubi
SpecterOps @specterops.io · 26/09/2025
Happy #BloodHoundBasics Day from @scoubi.bsky.social! By now, you've probably heard about our Query Library. But did you know you can run any query in your own instance of BHE/BHCE and then save the query to your Personal Library? Follow the steps threaded below! 🧵: 1/5
111
Reposted by Scoubi
Ian Coldwater 🧊🚫 @lookitup.baby · 16/09/2025
Today is the 30th anniversary of Hackers
the cast of Hackers (1995) posing in a series of adjacent phone booths
7135761035
Reposted by Scoubi
DEATHCon @deathcon.io · 06/09/2025
The final round of #DEATHCon2025 online tickets will drop on 9/9 at 0900 UTC deathcon.io/tickets.html In-person tickets still available at some sites (1/4)
112
Scoubi @scoubi.bsky.social · 20/08/2025
Interested in hands-on learning of #DetectionEngineering and #ThreatHunting ? We still have a few tickets left for @DEATHCon2025 in #Montreal We are lucky enough to have 4 Workshops Leaders with us that will be able to hosts a Live Play of their workshop and help you complete it!
eventbrite.ca
DEATHcon Montreal - On Site
2 days of hands-on Detection Engineering and Threat Hunting workshops! Join us Live in Montreal.
212
Reposted by Scoubi
Tib3rius @tib3rius.bsky.social · 17/08/2025
Fucking do it, I dare you.
3181
Reposted by Scoubi
SpecterOps @specterops.io · 12/08/2025
What all do you need to know about BloodHound CE 8.0 & OpenGraph? @scoubi.bsky.social is joining @redsiege.com's Wednesday Offensive tomorrow to dive into the JSON schema for OpenGraph, how to ingest nodes & edges, best practices, & how to create custom icons. Join 👉 ghst.ly/46MNltn
053
Reposted by Scoubi
GreyNoise @greynoise.io · 01/08/2025
This month's NoiseLetter will make the perfect light reading for a trip to say...Vegas? Make sure to check it out (even if you're not headed to BlackHat/DEF CON there is something in it for you). 🤘
greynoise.io
NoiseLetter July 2025
Get GreyNoise updates! Read the July 2025 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.
032
Reposted by Scoubi
Red Siege @redsiege.com · 31/07/2025
The Python Software Foundation warns of phishing emails directing users to a fake PyPI site (pypj. org) to steal credentials. PyPI isn’t hacked, but users are urged to stay alert. www.bleepingcomputer.com/news/securit... Via @bleepingcomputer.com #hacking #infosec #cybersecurity
bleepingcomputer.com
Hackers target Python devs in phishing attacks using fake PyPI site
The Python Software Foundation warned users this week that threat actors are trying to steal their credentials in phishing attacks using a fake Python Package Index (PyPI) website.
032
Reposted by Scoubi
Joe Slowik @pylos.co · 30/07/2025
This is AMAZING
3229
Reposted by Scoubi
SpecterOps @specterops.io · 25/07/2025
Think being compliant = being secure? Think again. 🤔 Hear from @scoubi.bsky.social at #BSidesLV as he exposes the gap between blindly following rules & security posture. Get the info on password security & what to do when "compliant" passwords fail you. ghst.ly/4o66cWk
041
Reposted by Scoubi
SpecterOps @specterops.io · 11/07/2025
Happy #BloodHoundBasics Day from @scoubi.bsky.social! 🎉 Have you ever run a Cypher Query & get so many nodes you couldn't see anything? You Pinch Zoom to get a closer look and it worked fine, but you Pinch Un-zoom & the application resized. 🧵: 1/2
121
Scoubi @scoubi.bsky.social · 11/07/2025
Only 3 Early Bird tickets left!!
010
Scoubi @scoubi.bsky.social · 10/07/2025
Tickets for #DEATHcon in Montreal are on sale now! Book now to secure your place. FYI, Virtual Tickets for round 1 are already Sold Out! eventbrite.ca/e/deathcon-m... Additional info (like workshops) for the con can be found here : deathcon.io Please like & repost for reach
eventbrite.ca
DEATHcon Montreal - On Site
2 days of hands-on Detection Engineering and Threat Hunting workshops! Join us Live in Montreal.
032
Scoubi @scoubi.bsky.social · 28/06/2025
Tickets for "DEATHcon - Montreal On Site" go on sale July 8th at 8am. www.eventbrite.ca/e/deathcon-m... Be with 50 other DE&TH aficionados for a whole weekend Nov 8-9 2025!! #DEATHcon #Workshops #DetectionEngineering #ThreatHunting
eventbrite.ca
DEATHcon Montreal - On Site
2 days of hands-on Detection Engineering and Threat Hunting workshops! Join us Live in Montreal.
020
Reposted by Scoubi
SpecterOps @specterops.io · 26/06/2025
How attackers move between AD domains via trusts depends on trust type & config. We're replacing TrustedBy edge in BloodHound with new trust edges for better attack path mapping. Check out @jonas-bk.bsky.social's blog post to learn more. ghst.ly/4lj9C5T
ghst.ly
Good Fences Make Good Neighbors: New AD Trusts Attack Paths in BloodHound - SpecterOps
The ability of an attacker controlling one domain to compromise another through an Active Directory (AD) trust depends on the trust type and configuration. To better map these relationships and make i...
084
Reposted by Scoubi
SpecterOps @specterops.io · 18/06/2025
Ghostwriter v6's new collaborative editing feature is 🔥 Alex Parrill & @printingprops.com discuss the new real-time collaborative editing for observations, findings, & report fields, enabling multiple users to edit simultaneously without overwriting each other. ghst.ly/4jVqdvG
ghst.ly
Ghostwriter v6: Introducing Collaborative Editing - SpecterOps
Ghostwriter now supports real-time collaborative editing for observations, findings, and report fields using the YJS framework, Tiptap editor, and Hocuspocus server, enabling multiple users to edit si...
072
Reposted by Scoubi
Wietze @wietzebeukema.nl · 11/06/2025
#HuntingTipOfTheDay: a personal favourite, command-line obfuscation. Substituting or inserting special Unicode characters might allow attackers to bypass string-based detections. Look for command lines with unusual Unicode characters. Checkout ArgFuscator.net for more fun!
031
Reposted by Scoubi
Wietze @wietzebeukema.nl · 10/06/2025
#HuntingTipOfTheDay: macOS has a built-in SSH mechanism that is disabled by default. Would you detect it if someone enables it and logs in remotely? Look for remote login events, and investigate the associated session.
031
Scoubi @scoubi.bsky.social · 07/06/2025
Personalized my work laptop a bit
130
Reposted by Scoubi
netbiosX @netbiosx.bsky.social · 31/05/2025
darkrelay.com
Stealth Syscall Execution: Bypassing ETW, Sysmon, and EDR Detection
"Stealth syscalls: Because life's too short to argue with an angry EDR!" Discover how Stealth Syscall Execution bypasses ETW, Sysmon, and EDR detection. Learn advanced stealth techniques for red teami...
062
Reposted by Scoubi
SpecterOps @specterops.io · 30/05/2025
🚨 New #BloodHoundBasics courtesy of @scoubi.bsky.social! You've successfully compromised Bob in marketing's account in an engagement. Mark it as Owned by right-clicking ➡️ "Add to Owned" ➡️ run the query "Shortest Paths from Owned objects to Tier Zero" & see your new attack paths! (1/2)
142
Reposted by Scoubi
BSides Las Vegas @bsideslv.org · 23/05/2025
Local to Las Vegas? Looking to mingle with and learn from some of the best people you'll ever meet? Locals and students can get a BSidesLV badge for $35. More information is available online in the FAQ: bsideslv.org/registr...
031
Scoubi @scoubi.bsky.social · 15/05/2025
Waiting for the bus to go to #NorthSec2025 That’s what ne thing I do not miss from the pre covid era! (Waiting for the bus. Not going to NSec!!) If you want to talk all things #BloodHound (BHE & BHCE) let me know. I may or may not have something in return ☺️ #NSEC2025
031
Reposted by Scoubi
SpecterOps @specterops.io · 09/05/2025
It's #BloodHoundBasics day! 🙌 The docs got a fresh new look and live at bloodhound.specterops.io — now back in the GitHub repo too, so PRs are welcome! s/o @jonas-bk.bsky.social
042
Scoubi @scoubi.bsky.social · 09/05/2025
That’s the swag I got from my new employer. I think I got more in two weeks than from all my former employers combined!!
030
Scoubi @scoubi.bsky.social · 13/04/2025
I proud of this shot.
030
Reposted by Scoubi
BSides Las Vegas @bsideslv.org · 11/04/2025
Down the rabbit hole we go! The @SecurityBSides Las Vegas #CFP is still open through April 21. Submit your talk & join Alice (& Bob) in Wonderland for #SecuritySummerCamp bsideslv.org/cfp
White Rabbit, wearing a hoodie and carrying a laptop and pocketwatch, panicking, captioned “I’m late!  I’m late!  For a Very Important Date!”
068
Reposted by Scoubi
SpecterOps @specterops.io · 11/04/2025
We are BACK with another #BloodHoundBasics post, this week courtesy of @andyrobbins.bsky.social. ICYMI: The BloodHound BACK button is BACK. Just use your browser's BACK button to go BACK. 🔙
1102