Sign in

SpecterOps

@specterops.io
1.2K followers 66 following 742 posts

Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management

PostsRepliesMedia
SpecterOps @specterops.io · 2h
What do your AWS permissions make possible? @hotnops.bsky.social and Julian Catrambone join our hosts Jared Atkinson and Justin Kohler to discuss bringing AWS attack paths into BloodHound in episode 16 of #KnowYourAdversary. 🎧: ghst.ly/4gS0KFc
010
SpecterOps @specterops.io · 8h
New from the Tradecraft Academy 👇 Built in partnership w/ OpenAI through OpenAI Daybreak Defense Network, Adversary Intelligence: LLM Tradecraft provides hands-on training to build, evaluate, attack, and defend LLM and agentic systems. More from @harmj0y.bsky.social: ghst.ly/4hw4zim
020
SpecterOps @specterops.io · 28/09/2026
AI may accelerate identity misuse, but paths to critical assets often run through inherited permissions, outdated groups and trust relationships. Hear from our team at #SecTor on October 8 at 1:15 PM ET: ghst.ly/4dRBHjq
100
SpecterOps @specterops.io · 25/09/2026
A #BloodHoundBasics reminder from @scoubi.bsky.social ⤵️ Not into live chat? Join our new SpecterOps & BloodHound Community subreddit! Come for the AMA, stay for the discussions: www.reddit.com/r/SpecterOpsCommunity
031
SpecterOps @specterops.io · 24/09/2026
At #OffensiveAICon, @harmj0y.bsky.social & @tifkin.bsky.social will explore optimized evasion attacks & their transferability across EDR products. They’ll share findings from reverse engineering four EDRs and experimenting with LLMs & GEPA to expand the search space for effective obfuscation.
031
SpecterOps @specterops.io · 22/09/2026
Introducing Ghostwriter Skills 👻 The first release helps with report templates, template QA, report readiness checks and executive summary drafts. Practitioners remain responsible for the final analysis. Explore each skill: ghst.ly/46zigYS
010
SpecterOps @specterops.io · 21/09/2026
✨This is your sign to reserve your spot for Michael Grafnetter's webinar this week!✨ Hear about Pass-the-Passkey, a novel & actively researched category of malware-initiated attack techniques targeting passkey auth that can enable cloud user impersonation. 👉 ghst.ly/4cpVSoa
000
SpecterOps @specterops.io · 18/09/2026
New #BloodHoundBasics post c/o @scoubi.bsky.social! 🎉 As of v9.7 BH supports multiple destinations in Pathfindings. You can force a path to traverse a specific node. It is also possible to rearrange the order of the nodes a path must traverse. For more info 👉 ghst.ly/4cOBtt9
011
SpecterOps @specterops.io · 17/09/2026
Don't miss Justin Kohler's session at Infosec Nashville TOMORROW! Justin will explore why defenders need to shift focus to the identity layer as agents, non-human identities, and hidden trust introduce new risk. ghst.ly/4yCNTg1
000
SpecterOps @specterops.io · 15/09/2026
Identity-driven attacks are among the most critical threat vectors in modern environments. Identity-driven Offensive Tradecraft at #SpecterBash covers the methodology for discovering & exploiting identity attack paths across on-prem & hybrid environments. specterops.io/specter-bash
010
SpecterOps @specterops.io · 14/09/2026
AI is speeding up attacks while expanding the enterprise attack surface. At Infosec Nashville, Justin Kohler will explore why defenders need to shift focus to the identity layer as agents, non-human identities, and hidden trust introduce new risk. ghst.ly/4yCNTg1
000
SpecterOps @specterops.io · 10/09/2026
Adversary simulation tradecraft, live defense data, enterprise-scale labs. Red Team Operations at #SpecterBash doesn't just teach you how to attack. It teaches you how to think, adapt & operate under pressure. The scariest part? How much you didn't know going in. 🎃 ghst.ly/45COqlF
010
SpecterOps @specterops.io · 10/09/2026
Why does SCCM app execution spawn from WmiPrvSE.exe instead of CcmExec.exe? @bouj33boy.bsky.social traced the full chain with ProcMon + Ghidra, from WMI tasking to CreateProcessW, and built a detection strategy around it. Check it out: ghst.ly/4gXzp2Z
ghst.ly
Unmasking SCCM Application Execution
A deep dive into why SCCM application execution spawns via WmiPrvSE.exe instead of CcmExec.exe, and how to detect anomalous SCCM deployments.
010
SpecterOps @specterops.io · 09/09/2026
The red team report has landed. What happens next? Russel Van Tuyl breaks down how to turn findings into action by prioritizing remediation, closing detection gaps, and building on what you learned. Read more: ghst.ly/46fFjHW
ghst.ly
From Findings to Fixes: Getting Value from Red Team Results
A red team report is a starting point. Learn how to extract full value from findings: root cause analysis, detection gap mapping, remediation prioritization, and building the improvement habit.
020
SpecterOps @specterops.io · 09/09/2026
Tracking OAuth token exchanges is complicated. TATS can help. @1cemoon.bsky.social introduces the Token Analysis and Tracking System & shares some unexpected findings uncovered along the way. Check it out! ghst.ly/4xMBaYd
ghst.ly
Token Analysis and Tracking System (TATS)
Tracking OAuth tokens is hard, but Token Analysis and Tracking System (TATS) can help. TATS will collect, store, decode, analyze and provide visual tracking for OAuth token exchanges. It was built to ...
021
SpecterOps @specterops.io · 07/09/2026
This #LaborDay, we’re celebrating the hard work and dedication of people everywhere who help their teams and communities thrive. Wishing everyone a safe and relaxing holiday with family and friends!
010
SpecterOps @specterops.io · 02/09/2026
Introducing SpecterOps Skills: a public repository built to turn practitioner knowledge into reusable, reviewable workflows for AI-assisted security work. John Hopper shares what we're building, why we're building it, and how you can contribute ➡️ ghst.ly/4ybT6ew
021
SpecterOps @specterops.io · 01/09/2026
See Azure & Entra ID the way attackers do. Our Azure course at #SpecterBash teaches you to identify the misconfigs & attack paths that matter, and take your first step in attacking or defending corporate cloud environments. Save your spot ➡️ ghst.ly/45COqlF
020
SpecterOps @specterops.io · 01/09/2026
Passkeys are gaining adoption, and adversaries are exploring how to target them. Join Michael Grafnetter on Sept. 23 for a practical look at Pass-the-Passkey and emerging techniques for attacking passkey authentication. Register 👉 ghst.ly/4cpVSoa
010
SpecterOps @specterops.io · 28/08/2026
In today’s installment of #BloodHoundBasics from Carlo Alcantara, a quick reminder that all pages in BloodHound support keyboard shortcuts. 💡 Use Alt/Option + H to access the shortcut menu to see all available options.
000
SpecterOps @specterops.io · 28/08/2026
Did you miss our webinar w/ Kaleb Pomeroy & John Hopper last week? You can watch on demand now & hear their practical tips on designing with MCP, including how security and access boundaries influence agent interactions. 👀: ghst.ly/4y1vPfb
121
SpecterOps @specterops.io · 27/08/2026
AI won't create new weaknesses. It will find the ones already in your environment faster. That's why we're signing OpenAI's cyber defense letter. Read our take on why visibility (not secrecy) wins: ghst.ly/3UHiBpw
000
SpecterOps @specterops.io · 27/08/2026
ServiceNow won't let you query cleartext discovery credentials, not even as admin. @tw1sm.bsky.social found a way to make the server hand them over anyway, no coercion or relay needed. Works on SSH keys, AWS keys, Entra secrets, and LDAP creds. Check it out: ghst.ly/4y37KVo
ghst.ly
Cleartext Credential Recovery in ServiceNow
Discover a technique for retrieving cleartext LDAP credentials from ServiceNow using script includes, and how to defend against it.
011
SpecterOps @specterops.io · 26/08/2026
Happy #InternationalDogDay from some of the VERY good dogs of SpecterOps! 🐶🐾 We're celebrating with a few of our team's canine coworkers. Now we want to see yours! Consider paying the pup tax and sharing a photo of your furry friend in the comments. 👇
010
SpecterOps @specterops.io · 26/08/2026
ICYMI: @andyrobbins.bsky.social, @harmj0y.bsky.social & @cptjesus.bsky.social joined #KnowYourAdversary to take a look back at 10 years of BloodHound! Tune in & hear how BloodHound has evolved in the years since it was first unveiled at #DEFCON in 2016. Parts 1 & 2 ➡️ ghst.ly/3Kkoiob
000
SpecterOps @specterops.io · 24/08/2026
Red teaming should produce findings security leaders can act on. @russelvantuyl.bsky.social , Andrew Chiles & @xpnsec.com will discuss aligning engagements to business risk, the impact of assumed breach & the difference between measuring and building detection & response. ➡️ ghst.ly/4qAYKEj
020
SpecterOps @specterops.io · 19/08/2026
Can this role read that bucket?" and "Can it decrypt that key?" aren't the same question. @n0pe-sled.bsky.social's latest blog post introduces AWSHound, free, self-hosted, turns AWS Orgs into real BloodHound CE attack paths. Check it out: ghst.ly/4g4EJm9
ghst.ly
AWSHound: An OpenSource AWS OpenGraph Collector
See how AWSHound maps AWS attack paths into BloodHound, evaluating IAM policies, SCPs, and boundaries to reveal real privilege escalation.
032
SpecterOps @specterops.io · 19/08/2026
#SpecterBash is back! 😎 Join us October 5-8 in Denver, CO for four days of adversary tradecraft courses, evening events, and the most fun you’ll have leveling up your infosec skills. 🎃 Registration is open: ghst.ly/45COqlF
001
SpecterOps @specterops.io · 17/08/2026
Frontier AI is changing cyber defense. Dave Bittner talks with Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, our Chief Services Officer, about where it delivers the most value and why human judgment still matters. ghst.ly/4cuiSSP
ghst.ly
- YouTube
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
010
SpecterOps @specterops.io · 14/08/2026
Don’t forget to save your spot for our upcoming webinar! Join Jared Atkinson & Justin Kohler to explore Identity Attack Path Management in AWS, Entra Agent ID support, agentic AI security & the growing OpenGraph ecosystem. ➡️ ghst.ly/4h0yWPn
010
SpecterOps @specterops.io · 14/08/2026
We're back with a new #BloodHoundBasics post from @sadprocessor.bsky.social! Ready to take your #BloodHound skills to the next level? Head over to the SpecterOps Tradecraft Academy and dive into our free BloodHound Basics Workshop. (1/4)
120
SpecterOps @specterops.io · 13/08/2026
Your browser is a C2 agent waiting to happen. Andrew Gomez shows how to silently sideload a Chromium extension, no prompts or GUI, and turn Chrome/Edge into a persistent implant with SOCKS, cookie theft, and OS access. Check it out: ghst.ly/4g8AZif
specterops.io
Attack of The Extensions
Learn how Chromium browser extensions can be silently sideloaded to establish persistent C2 access and how to detect it with Sysmon.
031
SpecterOps @specterops.io · 13/08/2026
Cookie theft got harder. Browser hijacking didn't. Andrew Gomez shows how enabling the Chrome DevTools Protocol inside a live Chrome/Edge process can bypass modern cookie protections, plus how to detect it with Sysmon. Explore more: ghst.ly/461sfpi
specterops.io
Return of the Cookie Monster
Chrome DevTools Protocol cookie theft: how CDP can be enabled inside a live browser to steal cookies, passwords, and sessions.
010
SpecterOps @specterops.io · 13/08/2026
Happening soon! @martinsohn.dk is joining SagaLabs Community Night to present "How To Think In Graphs," covering the inherent advantages defenders & attackers have in the identity graph space, how to tool for the modern graph, & how to get an entire org thinking in graphs.
000
SpecterOps @specterops.io · 12/08/2026
AI coding agents leave a lot behind on endpoints. Consulting Services intern Gavin Kramer built Blacklight to show defenders exactly what's exposed and how to monitor it. Covering Claude Code, Codex, Cursor, and Gemini CLI. Check it out! ghst.ly/4g03vT8
specterops.io
Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders
AI agent endpoint artifacts expose credentials, sessions, and configs. Blacklight helps security teams assess and reduce this surface.
140
SpecterOps @specterops.io · 12/08/2026
Mark your calendar! 📆 Join us in the r/SpecterOpsCommunity subreddit next Friday, August 21 for a #RedditAMA with BloodHound community member Tom O'Neill as he takes your questions on DataHound and HoundTrainer. ➡️ ghst.ly/4g8nXkK
110
SpecterOps @specterops.io · 11/08/2026
Don't miss our upcoming webinar feat. Kaleb Pomeroy & John Hopper discussing practical lessons on designing with MCP, including how security and access boundaries influence agent interactions. Save your spot! ghst.ly/4hbh44x
000
SpecterOps @specterops.io · 05/08/2026
If you're at #BHUSA you can get a look at Mythic 4 during Russel Van Tuyl's Arsenal talk TOMORROW at 12:30PM New in v4: AI chat containers, scoped API tokens, operation chat, and resumable file transfers. Check it out: ghst.ly/4xpPplg
ghst.ly
Mythic 4 Public Beta: More Than a New Coat of Paint
Mythic 4 is now in public beta, adding AI chat containers, operation chat, scoped API tokens, and resumable file transfers.
010
SpecterOps @specterops.io · 05/08/2026
Good morning! Today at the Kennel Club! ⤵️ Stop by during #BHUSA to hear from SpecterOps researchers, as well as guests from UK AI Security Institute and OpenAI. Learn more about the sessions: ghst.ly/45owr2t
000
SpecterOps @specterops.io · 04/08/2026
AI agents are expanding the attack surface. Are your defenses evolving too? Join Jared Atkinson and Justin Kohler for our upcoming webinar and learn why Identity Attack Path Management is becoming even more critical. Register: ghst.ly/4h0yWPn
000
SpecterOps @specterops.io · 03/08/2026
ConfigManBearPig 2.0 is out, a full Python rewrite built on OpenHound. Faster, runs on Linux, SOCKS proxy support, better BloodHound pathfinding for SCCM attacks. Read more: ghst.ly/3RGyETm Catch Chris Thompson demo-ing it live at #BHUSA Arsenal TOMORROW, Tue 8/4, 5:15pm, Station 6.
ghst.ly
ConfigManBearPig 2.0 - Things Are Getting Cereal
ConfigManBearPig 2.0 is a Python tool that collects SCCM data for BloodHound to map and fix Configuration Manager attack paths.
010
SpecterOps @specterops.io · 31/07/2026
🐶 It's #BloodHoundBasics day w/ @Jonas_B_K! Two new edges cover ADCS ESC14 attacks: 🔹 WriteAltSecurityIdentities: write altSecurityIdentities on a user/computer. 🔹 WritePublicInformation: write the Public-Information property set, including altSecurityIdentities. 🧵: 1/3
110
SpecterOps @specterops.io · 30/07/2026
Still haven't joined the #BloodHoundUnleashed Attack Path Championship? Start now, then visit Kennel Club during #BHUSA for bonus codes that could move you up the leaderboard. 🔑 Password: LeadThePack Get started 👉 unleashed.bloodhound.quest
010
SpecterOps @specterops.io · 29/07/2026
Compromise one node in a Windows Server Failover Cluster and you've compromised all of them. Garrett Foster dug into why: shared credentials, forged tickets, and a full attack chain to own the cluster. Check it out! ghst.ly/4wSZSoW
ghst.ly
Clustered Points of Failure
Windows Server Failover Clusters share credentials across every node: compromise one, and you compromise the entire cluster
021
SpecterOps @specterops.io · 29/07/2026
Who can actually assume that role? 🤔 Who can reach your secrets, keys, or data? 🔐 @hotnops.bsky.social explores how BloodHound Enterprise brings the attack path mindset to AWS to answer those questions. ghst.ly/3ToU5ZP
ghst.ly
Attack Path Management Comes to AWS
AWS IAM attack paths let attackers chain roles and permissions to admin. BloodHound Enterprise maps them as paths defenders can sever.
011
SpecterOps @specterops.io · 28/07/2026
An MCP server isn't just a wrapper around your REST API. AI agents explore before they act, so MCP tools should be designed around intent, not implementation. Kaleb Pomeroy explains why that distinction matters for security workflows. ➡️ ghst.ly/4x80M0X
020
SpecterOps @specterops.io · 28/07/2026
Your attack surface doesn't stop at AD. BloodHound Enterprise now supports AWS & Microsoft Entra Agent ID. We're also introducing BloodHound Hunter to bring attack path intel into AI workflows. Learn more ➡️ ghst.ly/4fZQN7W
110
SpecterOps @specterops.io · 24/07/2026
Happy #BloodHoundBasics Friday from @martinsohn.dk! BloodHound's new path highlighting helps you focus on the relationships that matter. Demonstration: run the query "Shortest paths from Domain Users to Tier Zero", click a node to highlight the path(s) from Domain Users to it.
001
SpecterOps @specterops.io · 22/07/2026
The #BloodHoundUnleashed Attack Path Championship is LIVE! 🔑 Password: LeadThePack Complete the challenge before #BHUSA, then visit Kennel Club for bonus codes to boost your leaderboard score. Get started 👉 unleashed.bloodhound.quest
001
SpecterOps @specterops.io · 20/07/2026
The hunt returns July 22. Complete the #BloodHoundUnleashed Attack Path Championship before #BHUSA, then visit Kennel Club during the event for bonus codes that can boost your leaderboard score. More soon. 👀
010