Sign in

werdhaihai

@werdhaihai.bsky.social
59 followers 87 following 9 posts

Principal Red Team Operator at Armadin github.com/werdhaihai

PostsRepliesMedia
Reposted by werdhaihai
SpecterOps @specterops.io · 29/09/2025
Lateral movement getting blocked by traditional methods? @werdhaihai.bsky.social just dropped research on a new lateral movement technique using Windows Installer Custom Action Server, complete with working BOF code. ghst.ly/4pN03PG
ghst.ly
DCOM Again: Installing Trouble - SpecterOps
DCOM lateral movement BOF using Windows Installer (MSI) Custom Action Server - install ODBC drivers to load and execute DLLs
093
Reposted by werdhaihai
hotnops @hotnops.bsky.social · 30/07/2025
Finally putting out my research from this spring. "Imitune" coming in soon to support the POC specterops.io/blog/2025/07...
specterops.io
Entra Connect Attacker Tradecraft: Part 3 - SpecterOps
How Entra Connect and Intune can be abused via userCertificate hijacking to bypass conditional access and compromise hybrid domains
011
Reposted by werdhaihai
SpecterOps @specterops.io · 30/07/2025
Entra Connect sync accounts can be exploited to hijack device userCertificate properties, enabling device impersonation and conditional access bypass. @hotnops.bsky.social explores cross-domain compromise tradecraft within the same tenant. Read more: ghst.ly/3ISMGN9
ghst.ly
Entra Connect Attacker Tradecraft: Part 3 - SpecterOps
How Entra Connect and Intune can be abused via userCertificate hijacking to bypass conditional access and compromise hybrid domains
196
Reposted by werdhaihai
Jonas Bülow Knudsen @jonas-bk.bsky.social · 25/06/2025
I publish two blog posts today! 📝🐫 First dives into how we're improving the way BloodHound models attack paths through AD trusts: specterops.io/blog/2025/06... Second covers an attack technique I came across while exploring AD trust abuse: specterops.io/blog/2025/06... Hope you enjoy the read 🥳
specterops.io
Good Fences Make Good Neighbors: New AD Trusts Attack Paths in BloodHound - SpecterOps
The ability of an attacker controlling one domain to compromise another through an Active Directory (AD) trust depends on the trust type and configuration. To better map these relationships and make i...
01811
Reposted by werdhaihai
SpecterOps @specterops.io · 09/04/2025
Think NTLM relay is a solved problem? Think again. Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
12720
Reposted by werdhaihai
Matt Creel @tw1sm.bsky.social · 07/04/2025
Nothing new, but formalized some operator notes on Entra ID/Azure tradecraft I've found to be exceptionally useful on ops. Overlooked this myself for quite some time and thought others in the same boat might find it worth a read! 📖 medium.com/specter-ops-...
medium.com
An Operator’s Guide to Device-Joined Hosts and the PRT Cookie
Introduction
052
werdhaihai @werdhaihai.bsky.social · 22/03/2025
Super excited to be speaking at SO‑CON 2025 on March 31st with my coworker Lance Cain. We’re diving into an example attack path from real-life red team assessments by Lance Cain, Dan Mayer, myself, and the entire @specterops.bsky.social crew. specterops.io/so-con/ #SOCON2025 #redteam
041
Reposted by werdhaihai
its-a-feature.bsky.social @its-a-feature.bsky.social · 12/03/2025
The Mythic family continues to grow! Another cool Windows agent written in C that already has COFF execution! Be sure to check it out and their blog series on it c0rnbread.com/creating-myt... x.com/0xC0rnbread/...
media.tenor.com
a man with a surprised look on his face is standing in front of the word awesome
ALT: a man with a surprised look on his face is standing in front of the word awesome
053
Reposted by werdhaihai
SpecterOps @specterops.io · 06/03/2025
#SCCM forest discovery accounts can be decrypted—even those for untrusted forests. If the site server is a managed client, all creds can be decrypted via Administration Service API. Check out our latest blog post from @unsignedsh0rt.bsky.social to learn more. ghst.ly/4buoISp
ghst.ly
Decrypting the Forest From the Trees - SpecterOps
TL;DR: SCCM forest discovery accounts can be decrypted including accounts used for managing untrusted forests. If the site server is a managed client, service account credentials can be decrypted via ...
12215
Reposted by werdhaihai
SpecterOps @specterops.io · 05/03/2025
BIG NEWS: SpecterOps raises $75M Series B to strengthen identity security! Led by Insight Partners with Ansa Capital, M12, Ballistic Ventures, Decibel, and Cisco Investments. ghst.ly/seriesb #IdentitySecurity #CyberSecurity (1/6)
1159
Reposted by werdhaihai
its-a-feature.bsky.social @its-a-feature.bsky.social · 05/02/2025
Many in the Mythic Community have asked for a way to standardize BOF/.NET execution within Mythic Agents. Today I'm releasing Forge, a new Mythic container to do just that: posts.specterops.io/forging-a-be... We're starting off with default support for Apollo and Athena. Check it out! :)
media.tenor.com
dwight schrute from the office is holding a business card in his hand .
ALT: dwight schrute from the office is holding a business card in his hand .
0114
Reposted by werdhaihai
hotnops @hotnops.bsky.social · 22/01/2025
This post goes more into Entra Connect tradecraft and how partially synced objects can be hijacked for cross domain attacks. posts.specterops.io/entra-connec...
posts.specterops.io
Entra Connect Attacker Tradecraft: Part 2
Now that we know how to add credentials to an on-premises user, lets pose a question:
051
Reposted by werdhaihai
SpecterOps @specterops.io · 21/01/2025
What does the road to becoming a Specter look like? In his latest blog post, @subat0mik.bsky.social provides a high level overview of how we approach recruiting consultants, demystifying the process along the way from application review through interviews. ghst.ly/3PQeuSh
ghst.ly
Life at SpecterOps Part II: From Dream to Reality
We’re hiring consultants; Check out this overview of our recruiting process!
141
werdhaihai @werdhaihai.bsky.social · 08/12/2024
snovvcrash.rocks/2024/12/08/a...
snovvcrash.rocks
On the Applicability of the Timeroasting Attack
Lately I’ve had an opportunity to experiment with the Timeroasting on an engagement, so here are my thoughts on the applicability of the attack in real life conditions with some examples along the way...
000
Reposted by werdhaihai
Andrea P @decoder-it.bsky.social · 20/11/2024
Following my prev tweet, my Kerberos MITM relay/forwarder is almost finished! It targets for example insecure DNS updates in AD, allowing DNS name forgery. It intercepts, relays, and forwards traffic, with the client unaware. Currently supporting smb->smb and smb->http (adcs)
13614
werdhaihai @werdhaihai.bsky.social · 16/11/2024
040
Reposted by werdhaihai
Garrett @unsignedsh0rt.bsky.social · 15/11/2024
Was doing some digging "What's New" in Server2025 learn.microsoft.com/en-us/window... specifically the changes to pre-2k machines. Oddvar and I had spoken previously about the changes being solid and demonstrated pre-created machines in ADUC could no longer be set with a default password.
1105
Reposted by werdhaihai
SpecterOps @specterops.io · 14/11/2024
The CFP for #SOCON2025 closes TOMORROW! We are accepting talks focused on identity-based security and Attack Paths. Submit yours today! ➡️ ghst.ly/cfp-socon25
SO-CON 2025 Call for Presenters Closes November 15
001
werdhaihai @werdhaihai.bsky.social · 12/11/2024
Python implementation of some remote modules from Seatbelt by @0xthirteen github.com/0xthirteen/C...
github.com
GitHub - 0xthirteen/Carseat: Python implementation of GhostPack's Seatbelt situational awareness tool
Python implementation of GhostPack's Seatbelt situational awareness tool - 0xthirteen/Carseat
010
werdhaihai @werdhaihai.bsky.social · 12/11/2024
README for this is great github.com/0xHossam/Ker...
github.com
GitHub - 0xHossam/KernelCallbackTable-Injection-PoC: Proof of Concept for manipulating the Kernel Callback Table in the Process Environment Block (PEB) to perform process injection and hijack executio...
Proof of Concept for manipulating the Kernel Callback Table in the Process Environment Block (PEB) to perform process injection and hijack execution flow - 0xHossam/KernelCallbackTable-Injection-PoC
000
werdhaihai @werdhaihai.bsky.social · 07/11/2024
Anyone read Cory Doctorow's Red Team Blues yet? Curious to hear thoughts and opinions on it.
020