Shadow Credentials: Abusing Key Trust Account Mapping for Account Takeover
https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab
https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab
SpecterOps
The Renaissance of NTLM Relay Attacks: Everything You Need to Know - SpecterOps
NTLM relay attacks have been around for a long time. While many security practitioners think NTLM relay is a solved problem, or at least a not-so-severe one, it is, in fact, alive and kicking and arguably worse than ever before. Relay attacks are the easiest…
Learning from our Myths
Cody talks about the direction Mythic is going, and walks us through some of the new features coming out with the Mythic 2.2 release.
https://posts.specterops.io/learning-from-our-myths-45a19ad4d077
Cody talks about the direction Mythic is going, and walks us through some of the new features coming out with the Mythic 2.2 release.
https://posts.specterops.io/learning-from-our-myths-45a19ad4d077
Medium
Learning from our Myths
It’s been almost a year since I published A Change of Mythic Proportions where Apfell was rebranded to Mythic. Since then, a lot has…
Ghostwriter v2.2.2 releases: The SpecterOps project management and reporting engine
https://securityonline.info/ghostwriter/
https://securityonline.info/ghostwriter/
securityonline.info
Ghostwriter v4.0.1 releases: The SpecterOps project management and reporting engine
Ghostwriter is a part of your team. It helps you manage clients, projects, reports, and infrastructure in one application.
Azure Privilege Escalation via Azure API Permissions Abuse | by Andy Robbins | Dec, 2021 | Posts By SpecterOps Team Members
https://posts.specterops.io/azure-privilege-escalation-via-azure-api-permissions-abuse-74aee1006f48
https://posts.specterops.io/azure-privilege-escalation-via-azure-api-permissions-abuse-74aee1006f48
SpecterOps
Blog - SpecterOps
Your new best friend: Introducing BloodHound Community Edition!
Ghostwriter v2.2.3 RC1 releases: The SpecterOps project management and reporting engine
(Updated February 1, 2022)
https://securityonline.info/ghostwriter/
(Updated February 1, 2022)
https://securityonline.info/ghostwriter/
securityonline.info
Ghostwriter v4.0.1 releases: The SpecterOps project management and reporting engine
Ghostwriter is a part of your team. It helps you manage clients, projects, reports, and infrastructure in one application.
Introducing BloodHound 4.1 — The Three Headed Hound
https://posts.specterops.io/introducing-bloodhound-4-1-the-three-headed-hound-be3c4a808146
https://posts.specterops.io/introducing-bloodhound-4-1-the-three-headed-hound-be3c4a808146
Medium
Introducing BloodHound 4.1 — The Three Headed Hound
Prior Work
Fixing Common AD Security Issues With BloodHound FOSS
https://dzone.com/articles/how-to-fix-the-three-most-common-ad-security-issue
https://dzone.com/articles/how-to-fix-the-three-most-common-ad-security-issue
DZone
Fixing Common AD Security Issues With BloodHound FOSS
Learn how to identify AD problems with high-privilege Kerberos users, domain control object ownership, and domain users using BloodHound FOSS.
New support for Azure in BloodHound Enterprise per @SpecterOps !
Attack Path Management solution to quickly identify, eliminate & manage attack paths in on-prem Active Directory, Azure tenants & subnoscriptions & attack paths bridging those platforms.
https://posts.specterops.io/announcing-azure-in-bloodhound-enterprise-b1a900557cda
Attack Path Management solution to quickly identify, eliminate & manage attack paths in on-prem Active Directory, Azure tenants & subnoscriptions & attack paths bridging those platforms.
https://posts.specterops.io/announcing-azure-in-bloodhound-enterprise-b1a900557cda
Medium
Announcing Azure in BloodHound Enterprise
In July of 2021, we launched BloodHound Enterprise. Since then, our customers have been using BHE to easily identify and eliminate…
We stand with the brave people of Ukraine defending their homes and freedom against Russia's unprovoked invasion. A message from our CEO:
https://posts.specterops.io/war-in-ukraine-1e77d8024b1a
https://posts.specterops.io/war-in-ukraine-1e77d8024b1a
Medium
War In Ukraine
SpecterOps statement regarding the War in Ukraine.
👍4
Ghostwriter v2.3 RC1 releases: The SpecterOps project management and reporting engine
https://securityonline.info/ghostwriter/
https://securityonline.info/ghostwriter/
securityonline.info
Ghostwriter v4.0.1 releases: The SpecterOps project management and reporting engine
Ghostwriter is a part of your team. It helps you manage clients, projects, reports, and infrastructure in one application.
Coercing NTLM Authentication from SCCM | by Chris Thompson | Apr, 2022 | Posts By SpecterOps Team Members
https://posts.specterops.io/coercing-ntlm-authentication-from-sccm-e6e23ea8260a
https://posts.specterops.io/coercing-ntlm-authentication-from-sccm-e6e23ea8260a
SpecterOps
Coercing NTLM Authentication from SCCM - SpecterOps
SCCM crash course on how to prevent attacks, and invoking Automatic Client Push with SharpSCCM. How to build, test, and contribute to SharpSCCM.
Learning Machine Learning Part 1: Introduction and Revoke-Obfuscation
https://posts.specterops.io/learning-machine-learning-part-1-introduction-and-revoke-obfuscation-c73033184f0
https://posts.specterops.io/learning-machine-learning-part-1-introduction-and-revoke-obfuscation-c73033184f0
Medium
Learning Machine Learning Part 1: Introduction and Revoke-Obfuscation
For the past two years I’ve been trying to get a grasp on the field of machine learning with the hopes of applying it to both offense and…
Learning Machine Learning Part 2: Attacking White Box Models
https://posts.specterops.io/learning-machine-learning-part-2-attacking-white-box-models-1a10bbb4a2ae
https://posts.specterops.io/learning-machine-learning-part-2-attacking-white-box-models-1a10bbb4a2ae
Medium
Learning Machine Learning Part 2: Attacking White Box Models
In the previous post, I went through a very brief overview of some machine learning concepts, talked about the Revoke-Obfuscation project…
Learning Machine Learning Part 3: Attacking Black Box Models
https://posts.specterops.io/learning-machine-learning-part-3-attacking-black-box-models-3efffc256909
https://posts.specterops.io/learning-machine-learning-part-3-attacking-black-box-models-3efffc256909
Medium
Learning Machine Learning Part 3: Attacking Black Box Models
In the first post in this series we covered a brief background on machine learning, the Revoke-Obfuscation approach for detecting…