Sign in

SpecterOps

@specterops.io
1.2K followers 66 following 742 posts

Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management

PostsRepliesMedia
SpecterOps @specterops.io · 30/09/2026
What do your AWS permissions make possible? @hotnops.bsky.social and Julian Catrambone join our hosts Jared Atkinson and Justin Kohler to discuss bringing AWS attack paths into BloodHound in episode 16 of #KnowYourAdversary. 🎧: ghst.ly/4gS0KFc
010
SpecterOps @specterops.io · 30/09/2026
New from the Tradecraft Academy 👇 Built in partnership w/ OpenAI through OpenAI Daybreak Defense Network, Adversary Intelligence: LLM Tradecraft provides hands-on training to build, evaluate, attack, and defend LLM and agentic systems. More from @harmj0y.bsky.social: ghst.ly/4hw4zim
020
SpecterOps @specterops.io · 28/09/2026
AI may accelerate identity misuse, but paths to critical assets often run through inherited permissions, outdated groups and trust relationships. Hear from our team at #SecTor on October 8 at 1:15 PM ET: ghst.ly/4dRBHjq
100
SpecterOps @specterops.io · 25/09/2026
A #BloodHoundBasics reminder from @scoubi.bsky.social ⤵️ Not into live chat? Join our new SpecterOps & BloodHound Community subreddit! Come for the AMA, stay for the discussions: www.reddit.com/r/SpecterOpsCommunity
031
SpecterOps @specterops.io · 24/09/2026
At #OffensiveAICon, @harmj0y.bsky.social & @tifkin.bsky.social will explore optimized evasion attacks & their transferability across EDR products. They’ll share findings from reverse engineering four EDRs and experimenting with LLMs & GEPA to expand the search space for effective obfuscation.
031
SpecterOps @specterops.io · 22/09/2026
Introducing Ghostwriter Skills 👻 The first release helps with report templates, template QA, report readiness checks and executive summary drafts. Practitioners remain responsible for the final analysis. Explore each skill: ghst.ly/46zigYS
010
SpecterOps @specterops.io · 21/09/2026
✨This is your sign to reserve your spot for Michael Grafnetter's webinar this week!✨ Hear about Pass-the-Passkey, a novel & actively researched category of malware-initiated attack techniques targeting passkey auth that can enable cloud user impersonation. 👉 ghst.ly/4cpVSoa
000
SpecterOps @specterops.io · 18/09/2026
New #BloodHoundBasics post c/o @scoubi.bsky.social! 🎉 As of v9.7 BH supports multiple destinations in Pathfindings. You can force a path to traverse a specific node. It is also possible to rearrange the order of the nodes a path must traverse. For more info 👉 ghst.ly/4cOBtt9
011
SpecterOps @specterops.io · 17/09/2026
Don't miss Justin Kohler's session at Infosec Nashville TOMORROW! Justin will explore why defenders need to shift focus to the identity layer as agents, non-human identities, and hidden trust introduce new risk. ghst.ly/4yCNTg1
000
SpecterOps @specterops.io · 15/09/2026
Identity-driven attacks are among the most critical threat vectors in modern environments. Identity-driven Offensive Tradecraft at #SpecterBash covers the methodology for discovering & exploiting identity attack paths across on-prem & hybrid environments. specterops.io/specter-bash
010
SpecterOps @specterops.io · 14/09/2026
AI is speeding up attacks while expanding the enterprise attack surface. At Infosec Nashville, Justin Kohler will explore why defenders need to shift focus to the identity layer as agents, non-human identities, and hidden trust introduce new risk. ghst.ly/4yCNTg1
000
SpecterOps @specterops.io · 10/09/2026
Adversary simulation tradecraft, live defense data, enterprise-scale labs. Red Team Operations at #SpecterBash doesn't just teach you how to attack. It teaches you how to think, adapt & operate under pressure. The scariest part? How much you didn't know going in. 🎃 ghst.ly/45COqlF
010
SpecterOps @specterops.io · 07/09/2026
This #LaborDay, we’re celebrating the hard work and dedication of people everywhere who help their teams and communities thrive. Wishing everyone a safe and relaxing holiday with family and friends!
010
SpecterOps @specterops.io · 02/09/2026
Introducing SpecterOps Skills: a public repository built to turn practitioner knowledge into reusable, reviewable workflows for AI-assisted security work. John Hopper shares what we're building, why we're building it, and how you can contribute ➡️ ghst.ly/4ybT6ew
021
SpecterOps @specterops.io · 01/09/2026
See Azure & Entra ID the way attackers do. Our Azure course at #SpecterBash teaches you to identify the misconfigs & attack paths that matter, and take your first step in attacking or defending corporate cloud environments. Save your spot ➡️ ghst.ly/45COqlF
020
SpecterOps @specterops.io · 01/09/2026
Passkeys are gaining adoption, and adversaries are exploring how to target them. Join Michael Grafnetter on Sept. 23 for a practical look at Pass-the-Passkey and emerging techniques for attacking passkey authentication. Register 👉 ghst.ly/4cpVSoa
010
SpecterOps @specterops.io · 28/08/2026
In today’s installment of #BloodHoundBasics from Carlo Alcantara, a quick reminder that all pages in BloodHound support keyboard shortcuts. 💡 Use Alt/Option + H to access the shortcut menu to see all available options.
000
SpecterOps @specterops.io · 28/08/2026
Did you miss our webinar w/ Kaleb Pomeroy & John Hopper last week? You can watch on demand now & hear their practical tips on designing with MCP, including how security and access boundaries influence agent interactions. 👀: ghst.ly/4y1vPfb
121
SpecterOps @specterops.io · 27/08/2026
AI won't create new weaknesses. It will find the ones already in your environment faster. That's why we're signing OpenAI's cyber defense letter. Read our take on why visibility (not secrecy) wins: ghst.ly/3UHiBpw
000
SpecterOps @specterops.io · 26/08/2026
Happy #InternationalDogDay from some of the VERY good dogs of SpecterOps! 🐶🐾 We're celebrating with a few of our team's canine coworkers. Now we want to see yours! Consider paying the pup tax and sharing a photo of your furry friend in the comments. 👇
010
SpecterOps @specterops.io · 26/08/2026
ICYMI: @andyrobbins.bsky.social, @harmj0y.bsky.social & @cptjesus.bsky.social joined #KnowYourAdversary to take a look back at 10 years of BloodHound! Tune in & hear how BloodHound has evolved in the years since it was first unveiled at #DEFCON in 2016. Parts 1 & 2 ➡️ ghst.ly/3Kkoiob
000
SpecterOps @specterops.io · 24/08/2026
Red teaming should produce findings security leaders can act on. @russelvantuyl.bsky.social , Andrew Chiles & @xpnsec.com will discuss aligning engagements to business risk, the impact of assumed breach & the difference between measuring and building detection & response. ➡️ ghst.ly/4qAYKEj
020
SpecterOps @specterops.io · 19/08/2026
#SpecterBash is back! 😎 Join us October 5-8 in Denver, CO for four days of adversary tradecraft courses, evening events, and the most fun you’ll have leveling up your infosec skills. 🎃 Registration is open: ghst.ly/45COqlF
001
SpecterOps @specterops.io · 14/08/2026
Don’t forget to save your spot for our upcoming webinar! Join Jared Atkinson & Justin Kohler to explore Identity Attack Path Management in AWS, Entra Agent ID support, agentic AI security & the growing OpenGraph ecosystem. ➡️ ghst.ly/4h0yWPn
010
SpecterOps @specterops.io · 14/08/2026
We're back with a new #BloodHoundBasics post from @sadprocessor.bsky.social! Ready to take your #BloodHound skills to the next level? Head over to the SpecterOps Tradecraft Academy and dive into our free BloodHound Basics Workshop. (1/4)
120
SpecterOps @specterops.io · 13/08/2026
Happening soon! @martinsohn.dk is joining SagaLabs Community Night to present "How To Think In Graphs," covering the inherent advantages defenders & attackers have in the identity graph space, how to tool for the modern graph, & how to get an entire org thinking in graphs.
000
SpecterOps @specterops.io · 12/08/2026
Mark your calendar! 📆 Join us in the r/SpecterOpsCommunity subreddit next Friday, August 21 for a #RedditAMA with BloodHound community member Tom O'Neill as he takes your questions on DataHound and HoundTrainer. ➡️ ghst.ly/4g8nXkK
110
SpecterOps @specterops.io · 11/08/2026
Don't miss our upcoming webinar feat. Kaleb Pomeroy & John Hopper discussing practical lessons on designing with MCP, including how security and access boundaries influence agent interactions. Save your spot! ghst.ly/4hbh44x
000
SpecterOps @specterops.io · 05/08/2026
Good morning! Today at the Kennel Club! ⤵️ Stop by during #BHUSA to hear from SpecterOps researchers, as well as guests from UK AI Security Institute and OpenAI. Learn more about the sessions: ghst.ly/45owr2t
000
SpecterOps @specterops.io · 04/08/2026
AI agents are expanding the attack surface. Are your defenses evolving too? Join Jared Atkinson and Justin Kohler for our upcoming webinar and learn why Identity Attack Path Management is becoming even more critical. Register: ghst.ly/4h0yWPn
000
SpecterOps @specterops.io · 31/07/2026
🐶 It's #BloodHoundBasics day w/ @Jonas_B_K! Two new edges cover ADCS ESC14 attacks: 🔹 WriteAltSecurityIdentities: write altSecurityIdentities on a user/computer. 🔹 WritePublicInformation: write the Public-Information property set, including altSecurityIdentities. 🧵: 1/3
110
SpecterOps @specterops.io · 30/07/2026
Still haven't joined the #BloodHoundUnleashed Attack Path Championship? Start now, then visit Kennel Club during #BHUSA for bonus codes that could move you up the leaderboard. 🔑 Password: LeadThePack Get started 👉 unleashed.bloodhound.quest
010
SpecterOps @specterops.io · 28/07/2026
An MCP server isn't just a wrapper around your REST API. AI agents explore before they act, so MCP tools should be designed around intent, not implementation. Kaleb Pomeroy explains why that distinction matters for security workflows. ➡️ ghst.ly/4x80M0X
020
SpecterOps @specterops.io · 28/07/2026
Visit us at Kennel Club next week at #BHUSA to see a live demo of these updates! specterops.io/black-hat/
000
SpecterOps @specterops.io · 28/07/2026
Your attack surface doesn't stop at AD. BloodHound Enterprise now supports AWS & Microsoft Entra Agent ID. We're also introducing BloodHound Hunter to bring attack path intel into AI workflows. Learn more ➡️ ghst.ly/4fZQN7W
110
SpecterOps @specterops.io · 24/07/2026
Happy #BloodHoundBasics Friday from @martinsohn.dk! BloodHound's new path highlighting helps you focus on the relationships that matter. Demonstration: run the query "Shortest paths from Domain Users to Tier Zero", click a node to highlight the path(s) from Domain Users to it.
001
SpecterOps @specterops.io · 22/07/2026
The #BloodHoundUnleashed Attack Path Championship is LIVE! 🔑 Password: LeadThePack Complete the challenge before #BHUSA, then visit Kennel Club for bonus codes to boost your leaderboard score. Get started 👉 unleashed.bloodhound.quest
001
SpecterOps @specterops.io · 20/07/2026
The hunt returns July 22. Complete the #BloodHoundUnleashed Attack Path Championship before #BHUSA, then visit Kennel Club during the event for bonus codes that can boost your leaderboard score. More soon. 👀
010
SpecterOps @specterops.io · 17/07/2026
Happy #BloodHoundBasics from Nathan Davis! Did you know that BloodHound supports keyboard shortcuts? A quick ALT/OPT+H (Windows/Mac, respectively) will pull up the list of shortcuts. Want more? Feel free to create a feature request w/ our team here: ghst.ly/4viAozU
000
SpecterOps @specterops.io · 10/07/2026
This week's #BloodHoundBasics post comes courtesy of @andyrobbins.bsky.social 🙌 BloodHound has been free and open source software for nearly 10 years! Our latest version, BloodHound CE v9.4.0, is free and open source under the Apache 2.0 license: ghst.ly/3SR9CRS
001
SpecterOps @specterops.io · 04/07/2026
Wishing everyone a safe and happy #FourthofJuly! 🇺🇸 Whether you're spending the day with family, friends, or simply enjoying some well-earned downtime, we hope you have a wonderful #IndependenceDay.
000
SpecterOps @specterops.io · 03/07/2026
We're back w/ another #BloodHoundBasics from Jacob Jackson! ⤵️ One of my favorite parts of BloodHound Enterprise is the Hygiene findings. Not every security issue shows up as an attack path but that doesn't make it any less important. 🧵: 1/3
100
SpecterOps @specterops.io · 29/06/2026
The #BHUSA show floor is a busy place. Take a break from the hustle and join our team for bowling, food, drinks, and good company. No presentations. No pitches. Just a fun night with the security community. 🎳 See you there! ghst.ly/4wkHkxC
000
SpecterOps @specterops.io · 26/06/2026
Visibility for a configured user is limited in the graph and will only show nodes and edges for environments they are permitted to view. In the example image, nodes an edges are obfuscated in environments that our user is not permitted access to. 2/2
001
SpecterOps @specterops.io · 26/06/2026
In today’s #BloodHoundBasics from Carlo Alcantara, we cover Environment Targeted Access Control (ETAC) for Enterprise users. Read-Only & User roles now support environment-based visibility via the “Manage Users” page. Simply select which environments each user can access. 1/2
110
SpecterOps @specterops.io · 26/06/2026
Looking for more opportunities to sharpen your skills at #BHUSA? Join us at the Kennel Club for hands-on workshops covering AI, red teaming for AWS, and building your own OpenGraph collector. Learn more & sign up 👉 specterops.io/black-hat
000
SpecterOps @specterops.io · 23/06/2026
The best way to test enterprise defenses is to emulate real adversaries. Join Adversary Tactics: Red Team Operations at #BHUSA and learn how to execute advanced offensive operations against live defenders in a simulated enterprise environment. ➡️ ghst.ly/4uKAWyU
010
SpecterOps @specterops.io · 19/06/2026
Today we celebrate #Juneteenth, honoring freedom, resilience, and the enduring pursuit of equality. We reflect on the past, recognize the progress made, and reaffirm our commitment to building a more inclusive future for all.
030
SpecterOps @specterops.io · 17/06/2026
Our team will be all over #BHUSA! 🎓 4 hands-on trainings 🎤 3 technical briefings 🛠️ 5 Arsenal sessions Stay in the loop on all we have going on that week. ➡️ specterops.io/black-hat
000
SpecterOps @specterops.io · 17/06/2026
Most orgs think of GitHub as a code platform. Attackers increasingly see it as a gateway to everything connected to it. Jared Atkinson joined Risky Business to discuss CI/CD attack paths and why GitHub is often a pivot point into the enterprise. 🎧: ghst.ly/4ezC0zf
010