XPN @xpnsec.com · 08/08/2026I wrapped mine around my bag and got asked multiple times “do you have a bad… oh wait I see it” 🤣 020
XPN @xpnsec.com · 16/07/2026An article continuing my preview of Apple's new LLM frameworks in macOS 27. This time I'm using the new Evaluations framework to benchmark the agent's model performance when extracting credentials from images on disk. x.com/_xpn_/status...x.comAdam Chester 🏴☠️ (@_xpn_) on Xhttps://t.co/ANq7Q6k5Xd 021
Reposted by XPNMinuteCon @minutecon.org · 13/07/2026Our first-ever keynote: Chris Wysopal @weld.bsky.social. Original L0pht vulnerability researcher, Veracode co-founder, and one of the first people to warn the world about insecure software. Boston hacker history, back on a Boston stage at MinuteCon. April 30 – May 1, 2027 minutecon.org 0149
XPN @xpnsec.com · 14/07/2026If you're at Blackhat USA next month, I'm giving a talk on the Wednesday. Currently working on the presentation and attempting to avoid other rabbit holes until it's done! Excited to talk about this 😈 #BHUSA blackhat.com/us-26/briefi... 060
Reposted by XPNSpecterOps @specterops.io · 30/06/2026New GhostWorks blog! 👻 @xpnsec.com continues his series, exploring how LLMs are impacting how we approach endpoint security, from EDR analysis to evasion research. ⬇️ Read more ghst.ly/4vFEcfPspecterops.ioAccelerating EDR Evasion with LLM-Driven AnalysisSpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections. 023
XPN @xpnsec.com · 29/06/2026New blog post is up looking at how LLMs are making local EDR rulesets, YARA rules, and behavioral detections trivial to extract. This post focuses on how simple the harness can be. Buckle up h4xx0rs, the next few months are gonna get interesting! specterops.io/blog/2026/06...specterops.ioAccelerating EDR Evasion with LLM-Driven AnalysisSpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections. 0102
Reposted by XPNSpecterOps @specterops.io · 24/06/2026What happens when a new Mythic agent can be generated, tested, and deployed in ~2 hours? @xpnsec.com explores "disposable tooling" and the implications for offensive operations and defenders alike. Check out the latest from GhostWorks ⬇️ ghst.ly/4oMyrdCghst.lyDisposable Tooling: Building LLM-Generated Mythic Agents from Prompt to DeploymentUsing Claude Opus to autonomously generate Mythic C2 agents from prompt to deployment—and what that means for defenders. 052
XPN @xpnsec.com · 24/06/2026First blog post in a mini series where I look at "disposable tooling". This post shares what I have found to be useful when 1-shot'ing LLM generated Stage-0 agents for Mythic. specterops.io/blog/2026/06...specterops.ioDisposable Tooling: Building LLM-Generated Mythic Agents from Prompt to DeploymentUsing Claude Opus to autonomously generate Mythic C2 agents from prompt to deployment—and what that means for defenders. 041
Reposted by XPNSpecterOps @specterops.io · 10/06/2026This work is published as part of GhostWorks, an AI-focused engineering and research initiative at SpecterOps, focused on the disciplined exploration of frontier AI-enabled cybersecurity tooling. Read more: ghst.ly/4otZ1rJghst.lyIntroducing GhostWorks: A Practical AI Initiative from SpecterOpsNo hype. No guessing. SpecterOps built GhostWorks to test frontier AI tools against real identity security problems and document what actually works. 011
Reposted by XPNSpecterOps @specterops.io · 10/06/2026Most prompt engineering still boils down to vibes. @xpnsec.com explores GEPA, a framework for optimizing prompts using eval results, execution traces, & iterative refinement. Read this practical look at bringing measurable engineering practices to AI agents. ghst.ly/4vGffApghst.lyPrompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPAStop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results. 221
XPN @xpnsec.com · 10/06/2026New blog post is up looking at what GEPA is, and how it can be used for refining prompts for security agents. This post was published as part of the @specterops.io GhostWorks initiative. Can't wait to show what we've been working on! specterops.io/blog/2026/06...specterops.ioPrompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPAStop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results. 041
XPN @xpnsec.com · 13/05/2026My talk has been accepted to Blackhat USA, hyped for this one!!!! 🎉🎉 See y'all there o/ blackhat.com/us-26/briefi... 040
Reposted by XPNSpecterOps @specterops.io · 06/05/2026In his latest research, @xpnsec.com tears apart VS Code Dev Tunnels and finds a C2 framework underneath — REST → WebSocket → SSH → MsgPack RPC, remote exec, file ops. Find the Ouroboros tool and protocol breakdown here: ghst.ly/4mZ4arb specterops.ioThe Accidental C2: Exploring Dev Tunnels for Remote AccessPeel back the layers of Microsoft Dev Tunnels and you'll find embedded protocols, RPC message exchanges, and a full command-and-control architecture hiding in plain sight. 0105
XPN @xpnsec.com · 06/05/2026Ah no video for this one, just a random chat in a dark room of a hotel 🤣 020
XPN @xpnsec.com · 06/05/2026If you came to SOCON, you may have seen the fireside chat on Ouroboros (if you weren't too busy counting my "urm"s 😝). The blog post is now live, detailing how we can use Dev-Tunnels for lateral movement, and allow pivoting from GitHub/Entra ID access. specterops.io/blog/2026/05...specterops.ioThe Accidental C2: Exploring Dev Tunnels for Remote AccessPeel back the layers of Microsoft Dev Tunnels and you'll find embedded protocols, RPC message exchanges, and a full command-and-control architecture hiding in plain sight. 151
Reposted by XPNDirk-jan @dirkjanm.io · 06/02/2026Next week at WWHF Mile High I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀 095
Reposted by XPNGus Squawks @gussquawks.bsky.social · 01/02/2026What do you MEAN the president audibly SHIT himself live on camera and they immediately cancelled the press conference and rushed everyone out of the room like it's a fire drill, and it happened two days ago, and I'm just hearing about it NOW? 215122533608
XPN @xpnsec.com · 25/01/2026Finally watching Welcome to Derry, took until the final few episodes to see Pennywise but the show stands well on its own 🎈media.tenor.coma clown on a stage in front of a banner that says time to danceALT: a clown on a stage in front of a banner that says time to dance 000
Reposted by XPNSpecterOps @specterops.io · 21/11/2025AI tooling and MCP servers are entering enterprises fast, often faster than security teams can assess the risks. During a recent engagement, @xpnsec.com found a new Claude Code vuln (CVE-2025-64755) while exploring MCP abuse paths. 👀 Read the details: ghst.ly/49ybl4Wghst.lyAn Evening with Claude (Code) - SpecterOpsThis blog post explores a bug, (CVE-2025-64755), I found while trying to find a command execution primitive within Claude Code to demonstrate the risks of web-hosted MCP to a client. 0104
XPN @xpnsec.com · 13/06/2025Talking Heads released a music video for Psycho Killer and it's fucking awesome :D www.youtube.com/watch?v=CJ54...youtube.comTalking Heads - Psycho Killer (Official Video)YouTube video by Talking Heads 020
XPN @xpnsec.com · 09/06/2025Please say we're getting another PsychOdyssey to go with Keeper dev!!!media.tenor.coma man in a suit and tie is standing in front of a microphone and saying `` please be true '' .ALT: a man in a suit and tie is standing in front of a microphone and saying `` please be true '' . 000
Reposted by XPNSpecterOps @specterops.io · 03/06/2025🚨 New blog post alert! @xpnsec.com drops knowledge on LLM security w/ his latest post showing how attackers can by pass LLM WAFs by confusing the tokenization process to smuggle tokens to back-end LLMs. Read more: ghst.ly/4koUJizghst.lyTokenization Confusion - SpecterOpsMeta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs. 095
XPN @xpnsec.com · 03/06/2025New blog post is up! Stepping out of my comfort zone (be kind), looking at Meta's Prompt Guard 2 model, how to misclassify prompts using the Unigram tokenizer and hopefully demonstrate why we should invest time looking beyond the API at how LLMs function. specterops.io/blog/2025/06...specterops.ioTokenization Confusion - SpecterOpsMeta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs. 051
XPN @xpnsec.com · 21/05/2025The level of snark in my upcoming blogpost is next level... And I'm not even sorry!media.tenor.comtaylor swift is wearing a black off the shoulder top .ALT: taylor swift is wearing a black off the shoulder top . 0120
Reposted by XPNMarc Smeets @marcoverip.bsky.social · 13/05/2025Didn’t know this impressive fact. @xpnsec.com did you? 111
Reposted by XPNSpecterOps @specterops.io · 22/04/2025You've been prepping for #OSCP exam day, and it finally arrives. 🙇 In Part 4 of his blog series, @anam0x.bsky.social focuses on the test & how to maximize the educational, financial, & professional value of the exam experience. Read more: ghst.ly/4lHDw4M 🧵: 1/4 162
XPN @xpnsec.com · 20/04/2025Worked on a simple POC last night for connecting Mythic up to LiteLLM (pointing to Claude) for riding shotgun on a C2 session. Only using shell cmd, but provides oversight and hints to potential paths to explore. Quite happy for a weekend project :D youtu.be/C9J5okm6cA4youtu.beSuperintendent POCYouTube video by Adam Chester 0141
Reposted by XPNBad Sector Labs @badsectorlabs.com · 15/04/2025WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more! blog.badsectorlabs.com/last-week-in...blog.badsectorlabs.comLast Week in Security (LWiS) - 2025-04-14WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more! 052
XPN @xpnsec.com · 15/04/2025Slides from my SOCON 2025 presentation are now up on GitHub github.com/xpn/Presenta...github.comPresentations/SOCON2025 at main · xpn/PresentationsA collections of presentations. Contribute to xpn/Presentations development by creating an account on GitHub. 080
XPN @xpnsec.com · 11/04/2025Awesome post from @atomicchonk.bsky.social on NLP Tokenizing. We need more content like this to show the "how" behind the LLM :) www.corgi-corp.com/post/tokeniz...corgi-corp.comTokenizing the Sandwich Debate: How NLP Models Weigh In on Hot DogsGet the gist for Natural Language Processing (NLP) and how tokenization plays a factor 070
Reposted by XPNSpecterOps @specterops.io · 09/04/2025Think NTLM relay is a solved problem? Think again. Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31 12720
XPN @xpnsec.com · 08/04/2025No idea why my first thought to a problem is a heavy RE session, something for therapy I think 🤣 110
XPN @xpnsec.com · 08/04/2025Celebrating 1 year at SpecterOps, this was the first project I worked on after starting. Looking at SQL Server Transparent Data Encryption, how to bruteforce weak keys, and how ManageEngine's ADSelfService product uses TDE with a suspect key. Enjoy :) specterops.io/blog/2025/04...specterops.ioThe SQL Server Crypto Detour - SpecterOpsAs part of my role as Service Architect here at SpecterOps, one of the things I’m tasked with is exploring all kinds of technologies to help those on assessments with advancing their engagement. Not l... 1153
XPN @xpnsec.com · 08/04/2025Love this article. It’s something that I’ve tried to follow throughout my career, having a line of sight to business profit centres. Even more important in the days of tech layoffs www.seangoedecke.com/where-the-mo...seangoedecke.comKnowing where your engineer salary comes fromHow tech companies make money and why it's important 050
XPN @xpnsec.com · 06/04/20251 year anniversary at SpecterOps, so many personal and professional achievements in a short space of time. My advice for anyone getting into this field, try and make sure that you work companies and colleagues that push you beyond your comfort level. \o/ 0231
Reposted by XPNKatie Knowles @siigil.bsky.social · 31/03/2025Excited to be at @specterops.bsky.social SO-CON this week!! If you're around, I'll be presenting "Abusing AUs, Confusing the SOC" tomorrow bright & early: 1157