The #SOCON2026 agenda is live! ๐
Explore talks, topics, & speakers across the Tradecraft, OpenGraph, & new Practice Track, focused on turning Attack Path Management into an operational discipline.
Check out the agenda & plan your experience: ghst.ly/socon26-tw
๐งต: 1/4
27.01.2026 22:35
๐ 3
๐ 2
๐ฌ 1
๐ 0
BloodHound's OpenGraph is ๐ฅ๐
This is how we rapidly developed a customer specific attack primitive for BloodHound that we call "ManagerOf" ๐
19.09.2025 19:05
๐ 0
๐ 0
๐ฌ 0
๐ 0
Easily find and share BloodHound Cyphers on queries.specterops.io
Released with ~90 new Cypher queries, go check them out!
@joeydreijer.bsky.social and I spent many hours creating it and we hope you find it useful. All feedback is appreciated :)
17.06.2025 19:57
๐ 1
๐ 1
๐ฌ 0
๐ 0
Cool! Is there a way to enum Symantec assets via LPDAP? E.g. does the server/service acc have a specific SPN?
16.06.2025 08:41
๐ 0
๐ 0
๐ฌ 0
๐ 0
**Every** BloodHound Enterprise tenant I've checked has multiple Non Tier Zero principals with the rights required for BadSuccessor. Luckily a 2025 DC is still rare.
Often helpdesk has GenericAll, misconfig'ed to apply on the OU itself, instead of only inheriting to principals within.
24.05.2025 05:01
๐ 1
๐ 0
๐ฌ 0
๐ 0
Shout out (skud ud) to @embar.io
Best CTF DJ. #tdcnetctf
26.04.2025 16:01
๐ 1
๐ 0
๐ฌ 0
๐ 0
BloodHound has 4 new edges: ๐๐ผ๐ฒ๐ฟ๐ฐ๐ฒ๐๐ป๐ฑ๐ฅ๐ฒ๐น๐ฎ๐๐ก๐ง๐๐ ๐ง๐ผ๐ฆ๐ ๐, ...๐ง๐ผ๐๐๐๐ฃ, ...๐ง๐ผ๐๐๐๐ฃ๐ฆ, ...๐ง๐ผ๐๐๐๐ฆ [ESC8]
They combine ๐ฐ๐ผ๐ฒ๐ฟ๐ฐ๐ถ๐ผ๐ป and ๐ฟ๐ฒ๐น๐ฎ๐๐ถ๐ป๐ด, allowing Auth. Users to compromise computers. Read this excellent post by Elad Shamir if you are unfamiliar with those terms or want to know how to mitigate.
09.04.2025 06:46
๐ 4
๐ 0
๐ฌ 0
๐ 0
Butthole*... Excellent typo
07.02.2025 10:58
๐ 0
๐ 0
๐ฌ 0
๐ 0
07.02.2025 10:08
๐ 3
๐ 0
๐ฌ 1
๐ 0
Intune Attack PathsโโโPart 1
Intune is an attractive system for adversaries to targetโฆ
In Part 1 of my Intune Attack Paths series, I discuss the fundamental components and mechanics of Intune that lead to the emergence of attack paths: posts.specterops.io/intune-attac...
15.01.2025 17:33
๐ 42
๐ 19
๐ฌ 2
๐ 0
Screenshot of trending topics launched on Christmas 2025. Topics trending include: Virat Kohli, Red Panda, Porzingis, Post Malone, Beyoncรฉ, Gavin and Stacey Finale, Sixers, A Complete Unknown, King Henry, Joel Embiid, Pentatonix
Merry Christmas from us to you ๐๐๐ We launched Trending Topics today, and you can find it by tapping the search icon on the bottom bar of the app or the right sidebar on desktop.
26.12.2024 01:09
๐ 46809
๐ 5278
๐ฌ 1521
๐ 972
Misconfiguration Manager: Detection Updates
TL;DR: The Misconfiguration Manager DETECT section has been updated with relevant guidance to help defensive operators identify the mostโฆ
The Misconfiguration Manager DETECT section has been updated with fresh guidance to help defensive operators spot the most prolific attack techniques.
Check out the blog post from @bouj33boy.bsky.social to learn more. ghst.ly/3VJ5y4F
16.12.2024 16:08
๐ 6
๐ 4
๐ฌ 0
๐ 0
a woman wearing glasses says please with her hand up
ALT: a woman wearing glasses says please with her hand up
It's that time of year again everybody! I want to know YOUR thoughts on Mythic! What did you like? What could be improved? What would you like to see next? Why do you or don't you use it? If you could change something, what would it be? www.surveymonkey.com/r/MythicPlan... I'm all ears :)
25.11.2024 17:35
๐ 10
๐ 5
๐ฌ 0
๐ 2
Other than securing DNS, what could prevent this technique?
Require SMB client signing? Some Kerberos hardening setting? Or only tiering (eg. Auth. Policy Silo)?
25.11.2024 20:33
๐ 0
๐ 0
๐ฌ 1
๐ 0
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx
A Kerberos relay & forwarder for MiTM attacks!
>Relays Kerberos AP-REQ tickets
>Manages multiple SMB consoles
>Works on Win& Linux with .NET 8.0
>...
GitHub: github.com/decoder-it/K...
25.11.2024 17:31
๐ 63
๐ 43
๐ฌ 3
๐ 0
Meme template "they don't know".
*infosec bsky users*
me: they don't know that I had 395 followers on X
355 to go!
21.11.2024 21:05
๐ 3
๐ 0
๐ฌ 0
๐ 0
Relaying Kerberos over SMB using krbrelayx
Awesome new addition to krbrelayx by Hugow from Synacktiv: www.synacktiv.com/publications...
20.11.2024 16:02
๐ 29
๐ 14
๐ฌ 0
๐ 0
DEATHcon 2024: Prevention Engineering via the RPC and LDAP Firewalls
YouTube video by Zero Networks
RCP Firewall and LDAP Firewall workshop by Sagie Dulce and Dekel Paz.
youtube.com/watch?v=hJyI...
19.11.2024 17:30
๐ 1
๐ 0
๐ฌ 0
๐ 0
Windows ships with insecure defaults for network shares, granting Read access to Everyone. But you can change that with "SrvsvcDefaultShareInfo" in the registry.
I made a post about it: blog.improsec.com/tech-blog/ne...
15.11.2024 08:49
๐ 0
๐ 0
๐ฌ 0
๐ 0
SO-CON CFP submitted! Get yours in before tomorrow's deadline.
specterops.io/so-con/
14.11.2024 14:21
๐ 3
๐ 0
๐ฌ 0
๐ 0
Tier list of AD tiers
13.11.2024 11:11
๐ 1
๐ 1
๐ฌ 0
๐ 0
>an explicit Deny overrules an explicit Allow.
If Deny is closer to the secureable object than the Allow, ie. explicit Allow takes precedence over inherited Deny, and parent inherited Allow > grandparent Deny.
08.11.2024 08:33
๐ 0
๐ 0
๐ฌ 1
๐ 0