New support for Azure in BloodHound Enterprise per @SpecterOps !
Attack Path Management solution to quickly identify, eliminate & manage attack paths in on-prem Active Directory, Azure tenants & subnoscriptions & attack paths bridging those platforms.
https://posts.specterops.io/announcing-azure-in-bloodhound-enterprise-b1a900557cda
Attack Path Management solution to quickly identify, eliminate & manage attack paths in on-prem Active Directory, Azure tenants & subnoscriptions & attack paths bridging those platforms.
https://posts.specterops.io/announcing-azure-in-bloodhound-enterprise-b1a900557cda
Medium
Announcing Azure in BloodHound Enterprise
In July of 2021, we launched BloodHound Enterprise. Since then, our customers have been using BHE to easily identify and eliminate…
We stand with the brave people of Ukraine defending their homes and freedom against Russia's unprovoked invasion. A message from our CEO:
https://posts.specterops.io/war-in-ukraine-1e77d8024b1a
https://posts.specterops.io/war-in-ukraine-1e77d8024b1a
Medium
War In Ukraine
SpecterOps statement regarding the War in Ukraine.
👍4
Ghostwriter v2.3 RC1 releases: The SpecterOps project management and reporting engine
https://securityonline.info/ghostwriter/
https://securityonline.info/ghostwriter/
securityonline.info
Ghostwriter v4.0.1 releases: The SpecterOps project management and reporting engine
Ghostwriter is a part of your team. It helps you manage clients, projects, reports, and infrastructure in one application.
Coercing NTLM Authentication from SCCM | by Chris Thompson | Apr, 2022 | Posts By SpecterOps Team Members
https://posts.specterops.io/coercing-ntlm-authentication-from-sccm-e6e23ea8260a
https://posts.specterops.io/coercing-ntlm-authentication-from-sccm-e6e23ea8260a
SpecterOps
Coercing NTLM Authentication from SCCM - SpecterOps
SCCM crash course on how to prevent attacks, and invoking Automatic Client Push with SharpSCCM. How to build, test, and contribute to SharpSCCM.
Learning Machine Learning Part 1: Introduction and Revoke-Obfuscation
https://posts.specterops.io/learning-machine-learning-part-1-introduction-and-revoke-obfuscation-c73033184f0
https://posts.specterops.io/learning-machine-learning-part-1-introduction-and-revoke-obfuscation-c73033184f0
Medium
Learning Machine Learning Part 1: Introduction and Revoke-Obfuscation
For the past two years I’ve been trying to get a grasp on the field of machine learning with the hopes of applying it to both offense and…
Learning Machine Learning Part 2: Attacking White Box Models
https://posts.specterops.io/learning-machine-learning-part-2-attacking-white-box-models-1a10bbb4a2ae
https://posts.specterops.io/learning-machine-learning-part-2-attacking-white-box-models-1a10bbb4a2ae
Medium
Learning Machine Learning Part 2: Attacking White Box Models
In the previous post, I went through a very brief overview of some machine learning concepts, talked about the Revoke-Obfuscation project…
Learning Machine Learning Part 3: Attacking Black Box Models
https://posts.specterops.io/learning-machine-learning-part-3-attacking-black-box-models-3efffc256909
https://posts.specterops.io/learning-machine-learning-part-3-attacking-black-box-models-3efffc256909
Medium
Learning Machine Learning Part 3: Attacking Black Box Models
In the first post in this series we covered a brief background on machine learning, the Revoke-Obfuscation approach for detecting…
EntropyCapture: Simple Extraction of DPAPI Optional Entropy
https://posts.specterops.io/entropycapture-simple-extraction-of-dpapi-optional-entropy-6885196d54d0
https://posts.specterops.io/entropycapture-simple-extraction-of-dpapi-optional-entropy-6885196d54d0
Medium
EntropyCapture: Simple Extraction of DPAPI Optional Entropy
EntropyCapture extracts the DPAPI optional entropy using API hooking.
DeepPass — Finding Passwords With Deep Learning
https://posts.specterops.io/deeppass-finding-passwords-with-deep-learning-4d31c534cd00
https://github.com/GhostPack/DeepPass
https://posts.specterops.io/deeppass-finding-passwords-with-deep-learning-4d31c534cd00
https://github.com/GhostPack/DeepPass
Medium
DeepPass — Finding Passwords With Deep Learning
One of the routine tasks operators regularly encounter on most engagements is data mining. While exactly what operators are after varies…
Ghostwriter v2.3 RC2 releases: The SpecterOps project management and reporting engine
https://securityonline.info/ghostwriter/
https://securityonline.info/ghostwriter/
securityonline.info
Ghostwriter v4.0.1 releases: The SpecterOps project management and reporting engine
Ghostwriter is a part of your team. It helps you manage clients, projects, reports, and infrastructure in one application.
Managed Identity Attack Paths, Part 2: Logic Apps
https://posts.specterops.io/managed-identity-attack-paths-part-2-logic-apps-52b29354fc54
https://posts.specterops.io/managed-identity-attack-paths-part-2-logic-apps-52b29354fc54
Medium
Managed Identity Attack Paths, Part 2: Logic Apps
Intro and Prior Work
Establish security boundaries in your on-prem AD and Azure environment
https://posts.specterops.io/establish-security-boundaries-in-your-on-prem-ad-and-azure-environment-dcb44498cfc2?gi=b18c825d4a9a
https://posts.specterops.io/establish-security-boundaries-in-your-on-prem-ad-and-azure-environment-dcb44498cfc2?gi=b18c825d4a9a
Medium
Establish security boundaries in your on-prem AD and Azure environment
Preventing escalation from initial access in your Active Directory (AD) environment to Domain Admins can feel impossible, especially after…
The Phantom Credentials of SCCM: Why the NAA Won’t Die
https://posts.specterops.io/the-phantom-credentials-of-sccm-why-the-naa-wont-die-332ac7aa1ab9
https://posts.specterops.io/the-phantom-credentials-of-sccm-why-the-naa-wont-die-332ac7aa1ab9
SpecterOps
The Phantom Credentials of SCCM: Why the NAA Won’t Die - SpecterOps
Explore the risks lurking within SCCM's Network Access Accounts, why transitioning to Enhanced HTTP isn't enough, and why disabling NAAs from AD is crucial.