Sign in

XPN

@xpnsec.com
1.7K followers 142 following 220 posts

Hacker for hire at @specterops.bsky.social Blog: blog.xpnsec.com

PostsRepliesMedia
XPN @xpnsec.com · 16/07/2026
An article continuing my preview of Apple's new LLM frameworks in macOS 27. This time I'm using the new Evaluations framework to benchmark the agent's model performance when extracting credentials from images on disk. x.com/_xpn_/status...
x.com
Adam Chester 🏴‍☠️ (@_xpn_) on X
https://t.co/ANq7Q6k5Xd
021
Reposted by XPN
MinuteCon @minutecon.org · 13/07/2026
Our first-ever keynote: Chris Wysopal @weld.bsky.social. Original L0pht vulnerability researcher, Veracode co-founder, and one of the first people to warn the world about insecure software. Boston hacker history, back on a Boston stage at MinuteCon. April 30 – May 1, 2027 minutecon.org
0149
XPN @xpnsec.com · 14/07/2026
If you're at Blackhat USA next month, I'm giving a talk on the Wednesday. Currently working on the presentation and attempting to avoid other rabbit holes until it's done! Excited to talk about this 😈 #BHUSA blackhat.com/us-26/briefi...
060
Reposted by XPN
Double Fine @doublefine.com · 06/07/2026
Once again, Double Fine Productions will be an independent studio.

We're thankful to Xbox for seven great years together, and for working with us to reach an outcome which preserves our history and culture, and returns ownership of our games to us.

To everyone who reached out to us these past few weeks: Thank you for all your kind words, we've been deeply touched by your messages. We will share more soon on what comes next.

Your continued support is greatly appreciated,

Tim & Double Fine
486191773591
Reposted by XPN
SpecterOps @specterops.io · 30/06/2026
New GhostWorks blog! 👻 @xpnsec.com continues his series, exploring how LLMs are impacting how we approach endpoint security, from EDR analysis to evasion research. ⬇️ Read more ghst.ly/4vFEcfP
specterops.io
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
023
XPN @xpnsec.com · 29/06/2026
New blog post is up looking at how LLMs are making local EDR rulesets, YARA rules, and behavioral detections trivial to extract. This post focuses on how simple the harness can be. Buckle up h4xx0rs, the next few months are gonna get interesting! specterops.io/blog/2026/06...
specterops.io
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
0102
XPN @xpnsec.com · 27/06/2026
I bet that my day is going better than yours!! 🐣
050
Reposted by XPN
SpecterOps @specterops.io · 24/06/2026
What happens when a new Mythic agent can be generated, tested, and deployed in ~2 hours? @xpnsec.com explores "disposable tooling" and the implications for offensive operations and defenders alike. Check out the latest from GhostWorks ⬇️ ghst.ly/4oMyrdC
ghst.ly
Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment
Using Claude Opus to autonomously generate Mythic C2 agents from prompt to deployment—and what that means for defenders.
052
XPN @xpnsec.com · 24/06/2026
First blog post in a mini series where I look at "disposable tooling". This post shares what I have found to be useful when 1-shot'ing LLM generated Stage-0 agents for Mythic. specterops.io/blog/2026/06...
specterops.io
Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment
Using Claude Opus to autonomously generate Mythic C2 agents from prompt to deployment—and what that means for defenders.
041
XPN @xpnsec.com · 15/06/2026
Lights up in the office 💜
260
Reposted by XPN
SpecterOps @specterops.io · 10/06/2026
This work is published as part of GhostWorks, an AI-focused engineering and research initiative at SpecterOps, focused on the disciplined exploration of frontier AI-enabled cybersecurity tooling. Read more: ghst.ly/4otZ1rJ
ghst.ly
Introducing GhostWorks: A Practical AI Initiative from SpecterOps
No hype. No guessing. SpecterOps built GhostWorks to test frontier AI tools against real identity security problems and document what actually works.
011
Reposted by XPN
SpecterOps @specterops.io · 10/06/2026
Most prompt engineering still boils down to vibes. @xpnsec.com explores GEPA, a framework for optimizing prompts using eval results, execution traces, & iterative refinement. Read this practical look at bringing measurable engineering practices to AI agents. ghst.ly/4vGffAp
ghst.ly
Prompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPA
Stop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results.
221
XPN @xpnsec.com · 10/06/2026
New blog post is up looking at what GEPA is, and how it can be used for refining prompts for security agents. This post was published as part of the @specterops.io GhostWorks initiative. Can't wait to show what we've been working on! specterops.io/blog/2026/06...
specterops.io
Prompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPA
Stop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results.
041
XPN @xpnsec.com · 13/05/2026
My talk has been accepted to Blackhat USA, hyped for this one!!!! 🎉🎉 See y'all there o/ blackhat.com/us-26/briefi...
040
Reposted by XPN
SpecterOps @specterops.io · 06/05/2026
In his latest research, @xpnsec.com tears apart VS Code Dev Tunnels and finds a C2 framework underneath — REST → WebSocket → SSH → MsgPack RPC, remote exec, file ops. Find the Ouroboros tool and protocol breakdown here: ghst.ly/4mZ4arb
specterops.io
The Accidental C2: Exploring Dev Tunnels for Remote Access
Peel back the layers of Microsoft Dev Tunnels and you'll find embedded protocols, RPC message exchanges, and a full command-and-control architecture hiding in plain sight.
0105
XPN @xpnsec.com · 06/05/2026
If you came to SOCON, you may have seen the fireside chat on Ouroboros (if you weren't too busy counting my "urm"s 😝). The blog post is now live, detailing how we can use Dev-Tunnels for lateral movement, and allow pivoting from GitHub/Entra ID access. specterops.io/blog/2026/05...
specterops.io
The Accidental C2: Exploring Dev Tunnels for Remote Access
Peel back the layers of Microsoft Dev Tunnels and you'll find embedded protocols, RPC message exchanges, and a full command-and-control architecture hiding in plain sight.
151
XPN @xpnsec.com · 08/02/2026
010
Reposted by XPN
Dirk-jan @dirkjanm.io · 06/02/2026
Next week at WWHF Mile High I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀
095
Reposted by XPN
Gus Squawks @gussquawks.bsky.social · 01/02/2026
What do you MEAN the president audibly SHIT himself live on camera and they immediately cancelled the press conference and rushed everyone out of the room like it's a fire drill, and it happened two days ago, and I'm just hearing about it NOW?
215122543608
XPN @xpnsec.com · 01/02/2026
Beach walk with the doggos 🐶
050
XPN @xpnsec.com · 25/01/2026
Finally watching Welcome to Derry, took until the final few episodes to see Pennywise but the show stands well on its own 🎈
media.tenor.com
a clown on a stage in front of a banner that says time to dance
ALT: a clown on a stage in front of a banner that says time to dance
000
Reposted by XPN
SpecterOps @specterops.io · 21/11/2025
AI tooling and MCP servers are entering enterprises fast, often faster than security teams can assess the risks. During a recent engagement, @xpnsec.com found a new Claude Code vuln (CVE-2025-64755) while exploring MCP abuse paths. 👀 Read the details: ghst.ly/49ybl4W
ghst.ly
An Evening with Claude (Code) - SpecterOps
This blog post explores a bug, (CVE-2025-64755), I found while trying to find a command execution primitive within Claude Code to demonstrate the risks of web-hosted MCP to a client.
0104
XPN @xpnsec.com · 28/10/2025
Still here.. still lurking
190
XPN @xpnsec.com · 18/06/2025
My second post for the month is now live 🎉
2122
XPN @xpnsec.com · 13/06/2025
Talking Heads released a music video for Psycho Killer and it's fucking awesome :D www.youtube.com/watch?v=CJ54...
youtube.com
Talking Heads - Psycho Killer (Official Video)
YouTube video by Talking Heads
020
Reposted by XPN
SpecterOps @specterops.io · 03/06/2025
🚨 New blog post alert! @xpnsec.com drops knowledge on LLM security w/ his latest post showing how attackers can by pass LLM WAFs by confusing the tokenization process to smuggle tokens to back-end LLMs. Read more: ghst.ly/4koUJiz
ghst.ly
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
095
XPN @xpnsec.com · 03/06/2025
New blog post is up! Stepping out of my comfort zone (be kind), looking at Meta's Prompt Guard 2 model, how to misclassify prompts using the Unigram tokenizer and hopefully demonstrate why we should invest time looking beyond the API at how LLMs function. specterops.io/blog/2025/06...
specterops.io
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
051
XPN @xpnsec.com · 21/05/2025
The level of snark in my upcoming blogpost is next level... And I'm not even sorry!
media.tenor.com
taylor swift is wearing a black off the shoulder top .
ALT: taylor swift is wearing a black off the shoulder top .
0120
Reposted by XPN
Marc Smeets @marcoverip.bsky.social · 13/05/2025
Didn’t know this impressive fact. @xpnsec.com did you?
111
Reposted by XPN
SpecterOps @specterops.io · 22/04/2025
You've been prepping for #OSCP exam day, and it finally arrives. 🙇 In Part 4 of his blog series, @anam0x.bsky.social focuses on the test & how to maximize the educational, financial, & professional value of the exam experience. Read more: ghst.ly/4lHDw4M 🧵: 1/4
162
XPN @xpnsec.com · 20/04/2025
Worked on a simple POC last night for connecting Mythic up to LiteLLM (pointing to Claude) for riding shotgun on a C2 session. Only using shell cmd, but provides oversight and hints to potential paths to explore. Quite happy for a weekend project :D youtu.be/C9J5okm6cA4
youtu.be
Superintendent POC
YouTube video by Adam Chester
0141
XPN @xpnsec.com · 18/04/2025
New AI Slop Avatar, who dis?
160
Reposted by XPN
Bad Sector Labs @badsectorlabs.com · 15/04/2025
WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-04-14
WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more!
052
XPN @xpnsec.com · 15/04/2025
Slides from my SOCON 2025 presentation are now up on GitHub github.com/xpn/Presenta...
github.com
Presentations/SOCON2025 at main · xpn/Presentations
A collections of presentations. Contribute to xpn/Presentations development by creating an account on GitHub.
080
XPN @xpnsec.com · 11/04/2025
Awesome post from @atomicchonk.bsky.social on NLP Tokenizing. We need more content like this to show the "how" behind the LLM :) www.corgi-corp.com/post/tokeniz...
corgi-corp.com
Tokenizing the Sandwich Debate: How NLP Models Weigh In on Hot Dogs
Get the gist for Natural Language Processing (NLP) and how tokenization plays a factor
070
Reposted by XPN
SpecterOps @specterops.io · 09/04/2025
Think NTLM relay is a solved problem? Think again. Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
12720
XPN @xpnsec.com · 08/04/2025
New blog post 🤗
0132
XPN @xpnsec.com · 08/04/2025
Celebrating 1 year at SpecterOps, this was the first project I worked on after starting. Looking at SQL Server Transparent Data Encryption, how to bruteforce weak keys, and how ManageEngine's ADSelfService product uses TDE with a suspect key. Enjoy :) specterops.io/blog/2025/04...
specterops.io
The SQL Server Crypto Detour - SpecterOps
As part of my role as Service Architect here at SpecterOps, one of the things I’m tasked with is exploring all kinds of technologies to help those on assessments with advancing their engagement. Not l...
1153
XPN @xpnsec.com · 08/04/2025
Love this article. It’s something that I’ve tried to follow throughout my career, having a line of sight to business profit centres. Even more important in the days of tech layoffs www.seangoedecke.com/where-the-mo...
seangoedecke.com
Knowing where your engineer salary comes from
How tech companies make money and why it's important
050
XPN @xpnsec.com · 06/04/2025
1 year anniversary at SpecterOps, so many personal and professional achievements in a short space of time. My advice for anyone getting into this field, try and make sure that you work companies and colleagues that push you beyond your comfort level. \o/
0231
XPN @xpnsec.com · 01/04/2025
I did a talk!! #socon2025
1200
Reposted by XPN
Katie Knowles @siigil.bsky.social · 31/03/2025
Excited to be at @specterops.bsky.social SO-CON this week!! If you're around, I'll be presenting "Abusing AUs, Confusing the SOC" tomorrow bright & early:
1157
XPN @xpnsec.com · 31/03/2025
Talking tomorrow so can just enjoy today before the nerves kick in 🤣 #socon2025
3180
XPN @xpnsec.com · 31/03/2025
#SOCON2025 Time \o/
050
Reposted by XPN
SpecterOps @specterops.io · 30/03/2025
We are excited to see everyone at #SOCON2025 tomorrow! 🙌 Get the details on everything you need to know before arriving at the conference: specterops.io/so-con
0164
Reposted by XPN
Gynvael Coldwind @gynvael.bsky.social · 29/03/2025
Paged Out! #6 is out! pagedout.institute Totally free, 80 pages, best issue so far! 'nuff said, enjoy! (please repost to help spread out the news!)
02419
XPN @xpnsec.com · 29/03/2025
Too true! xD
040
Reposted by XPN
Max Andreacchi @atomicchonk.bsky.social · 29/03/2025
Spent the evening deep diving into MCPs and started a new project: roadrecon_mcp_server! This #MCP takes the web GUI output from the awesome ROADtools by @dirkjanm.io and offers tools to Claude (or your #AI agent of choice) to interact with the data: github.com/atomicchonk/...
github.com
GitHub - atomicchonk/roadrecon_mcp_server: Claude MCP server to perform analysis on ROADrecon data
Claude MCP server to perform analysis on ROADrecon data - atomicchonk/roadrecon_mcp_server
2115
XPN @xpnsec.com · 24/03/2025
Slides ported to SO-CON deck, time to work my presenting skillz \o/
1130
XPN @xpnsec.com · 24/03/2025
Prepping slides for SO CON 2025... meme time ;)
1140