Reposted by Lee Chagolla-ChristensenHex-Rays @hex-rays.bsky.social · 02/08/2026🏠 idalib is now available in IDA Home. Now hobbyists & enthusiasts can call IDA's analysis engine as a library. We're offering 30% off IDA Home until Aug 14.* Use code HOME30 at checkout. 👉 Learn More: hex-rays.com/ida-home *Offer not available for corporations, agencies or resellers. 011
Reposted by Lee Chagolla-ChristensenSpecterOps @specterops.io · 24/06/2026What happens when a new Mythic agent can be generated, tested, and deployed in ~2 hours? @xpnsec.com explores "disposable tooling" and the implications for offensive operations and defenders alike. Check out the latest from GhostWorks ⬇️ ghst.ly/4oMyrdCghst.lyDisposable Tooling: Building LLM-Generated Mythic Agents from Prompt to DeploymentUsing Claude Opus to autonomously generate Mythic C2 agents from prompt to deployment—and what that means for defenders. 052
Reposted by Lee Chagolla-ChristensenSpecterOps @specterops.io · 21/11/2025AI tooling and MCP servers are entering enterprises fast, often faster than security teams can assess the risks. During a recent engagement, @xpnsec.com found a new Claude Code vuln (CVE-2025-64755) while exploring MCP abuse paths. 👀 Read the details: ghst.ly/49ybl4Wghst.lyAn Evening with Claude (Code) - SpecterOpsThis blog post explores a bug, (CVE-2025-64755), I found while trying to find a command execution primitive within Claude Code to demonstrate the risks of web-hosted MCP to a client. 0104
Reposted by Lee Chagolla-ChristensenSpecterOps @specterops.io · 23/10/2025Credential Guard was supposed to end credential dumping. It didn't. Valdemar Carøe just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more: ghst.ly/4qtl2rmghst.lyCatching Credential Guard Off Guard - SpecterOpsUncovering the protection mechanisms provided by modern Windows security features and identifying new methods for credential dumping. 01710
Reposted by Lee Chagolla-Christensenharmj0y @harmj0y.bsky.social · 28/06/2025Happy Friday! @tifkin.bsky.social and I are happy to announce that we have cut the release for Nemesis 2.0.0 - check out the CHANGELOG for a (brief) summary of changes, and dive into our new docs for more detail! We're extremely proud and excited for this release github.com/SpecterOps/N...github.comGitHub - SpecterOps/Nemesis: An offensive data enrichment pipelineAn offensive data enrichment pipeline. Contribute to SpecterOps/Nemesis development by creating an account on GitHub. 0126
Reposted by Lee Chagolla-ChristensenSpecterOps @specterops.io · 05/03/2025BIG NEWS: SpecterOps raises $75M Series B to strengthen identity security! Led by Insight Partners with Ansa Capital, M12, Ballistic Ventures, Decibel, and Cisco Investments. ghst.ly/seriesb #IdentitySecurity #CyberSecurity (1/6) 1159
Lee Chagolla-Christensen @tifkin.bsky.social · 07/02/2025Ghidra 11.3 is out! There's some awesome new features, but I want to highlight how responsive the dev team is to questions, issues, and feature suggestions. They've addressed several issues I've opened, notably a bunch of quality of life UI/UX things I've had while using Ghidra. 182
Reposted by Lee Chagolla-ChristensenPortSwigger Research @portswiggerres.bsky.social · 04/02/2025The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2024! portswigger.net/research/top...portswigger.netTop 10 web hacking techniques of 2024Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year 26636
Lee Chagolla-Christensen @tifkin.bsky.social · 31/01/2025@tiraniddo.dev Did you by chance check if the MUP redirector supports port specification in UNC paths? 120
Reposted by Lee Chagolla-ChristensenSpecterOps @specterops.io · 31/01/2025SlackPirate sets sail again! 🏴☠️ In his latest blog post, Dan Mayer intros his new PR to SlackPirate that lets you loot Slack again out of the box, a BOF to get you all the data you need to do it, & how to bee the most active slacker in your group chat. 🐝 ghst.ly/4hgwMItghst.lySlackPirate Set Sails Again! Or: How to Send the Entire “Bee Movie” Script to Your Friends in SlackTLDR: SlackPirate has been defunct for a few years due to a breaking change in how the Slack client interacts with the Slack API. It has a… 055
Reposted by Lee Chagolla-ChristensenJames Forshaw @tiraniddo.dev · 30/01/2025New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...googleprojectzero.blogspot.comWindows Bug Class: Accessing Trapped COM Objects with IDispatchPosted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ... 26541
Reposted by Lee Chagolla-ChristensenSpecterOps @specterops.io · 16/12/2024The Misconfiguration Manager DETECT section has been updated with fresh guidance to help defensive operators spot the most prolific attack techniques. Check out the blog post from @bouj33boy.bsky.social to learn more. ghst.ly/3VJ5y4Fghst.lyMisconfiguration Manager: Detection UpdatesTL;DR: The Misconfiguration Manager DETECT section has been updated with relevant guidance to help defensive operators identify the most… 054
Reposted by Lee Chagolla-Christensenhotnops @hotnops.bsky.social · 13/12/2024A new fun way to set shadow credentials posts.specterops.io/attacking-en...posts.specterops.ioAttacking Entra Metaverse: Part 1This is part one in a two (maybe three…) part series regarding attacker tradecraft around the syncing mechanics between Active Directory… 096
Reposted by Lee Chagolla-ChristensenDirk-jan @dirkjanm.io · 12/12/2024Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph 😃 34520
Reposted by Lee Chagolla-ChristensenAndrea P @decoder-it.bsky.social · 25/11/2024I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/K... 36343
Reposted by Lee Chagolla-ChristensenSpecterOps @specterops.io · 19/11/2024If you missed Part 4 in our What is Tier Zero webinar series hosted by Jonas Bülow Knudsen, @martinsohn.dk & @tifkin.bsky.social last week, you can watch the full presentation on demand now! 👀: ghst.ly/4eSssxL 022
Reposted by Lee Chagolla-ChristensenBarry Dorrans @blowdart.me · 12/11/2024Tomorrow, 10am, BinaryFormatter dies. 169325
Reposted by Lee Chagolla-ChristensenClément Labro @itm4n.bsky.social · 11/11/2024🆕 New blog post! "Exploiting KsecDD through Server Silos" In my latest mini research project, I've been working with my teammate @PMa1n (X) on extending the work of @floesen_ (X) on the KsecDD driver. I'm thrilled to finally share the results. 👉 blog.scrt.ch/2024/11/11/e...blog.scrt.chExploiting KsecDD through Server Silos – SCRT Team Blog 1117