Andy Robbins

@andyrobbins.bsky.social

aka wald0

SCCM attack paths are messy until you can see them. 👀 ConfigManBearPig from Chris Thompson extends BloodHound with SCCM nodes + edges using OpenGraph, plus queries to surface hierarchy takeovers and escalation paths. Check it out: ghst.ly/45FCP5G

Introducing ConfigManBearPig, a BloodHound OpenGraph Collector for SCCM - SpecterOps

ConfigManBearPig is a standalone PowerShell collector that adds new SCCM attack path nodes and edges to BloodHound using OpenGraph.

ghst.ly

Note: Work related I do Active Directory stuff for a living. Security research to be more specific. One of my favorite niche AD topics is AdminSDHolder. It's even my vanity domain. I wrote a 159 pg book about AdminSDHolder. I'm kinda proud of it. specterops.io/resources/ad...

AdminSDHolder Misconceptions & Misconfigurations - SpecterOps

AdminSDHolder is an object and associated process in Active Directory Domain Services (AD DS) that helps protect specific sensitive and highly privileged accounts from being manipulated. This topic is...

specterops.io

See your network shares the way attackers do. 👀 Meet ShareHound, an OpenGraph collector for BloodHound CE & Enterprise that reveals share-level attack paths at scale. @podalirius.bsky.social unpacks all the details in our latest blog post. ghst.ly/4ogiBqt

ShareHound: An OpenGraph Collector for Network Shares - SpecterOps

ShareHound is an OpenGraph collector for BloodHound CE and BloodHound Enterprise helping identify attack paths to network shares automatically.

ghst.ly

A little OpenGraph POC for mapping PE header imports of all .dll and .exe files in a fresh Windows install. These are all the binaries that have some kind of import chain leading to kernel32.dll

Bild

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...

One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens

While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...

dirkjanm.io

Adalanche searches works way better now - it uses BFS rather than DFS which gave unnecessary long paths at times. This is available in the latest commit on GitHub. There might be bugs with the new search - let me know if you see any strangeness. Happy hunting :-)

Bild

From November 2016: This is how I used to design BloodHound's entity panels. Just a text editor to list out what I as a red-teamer wanted to see, with the corresponding (then new) cypher queries listed as well. Simple, VERY low-fidelity mockup, but really helped during the design phase.

Bild

🚨 New #BloodHound shirt alert 🚨 ✅ - Unisex adult/child and ladies sizes available ✅ - Cool design :) ✅ - ALL profits go to charity This time we are supporting Hope for HIE, which supports families suffering the effects of hypoxic ischemic encephalopathy Get your shirt here: ghst.ly/bh8-tshirt

BloodHound 8.0 T-Shirt Fundraiser, Supporting Hope for HIE

Hope for HIE is the global voice for families affected by Hypoxic Ischemic Encephalopathy. As the world’s largest HIE support network, Hope for HIE offers personalized resources, education, and a deep...

ghst.ly

Red teamers know the drill: endless file churning, hunting for passwords & tokens. 🔍 Meet DeepPass2, our new secret scanning tool that goes beyond structured tokens to catch those tricky free-form passwords too. Read Neeraj Gupta's blog post for more. ghst.ly/40HLNNA

What’s Your Secret?: Secret Scanning by DeepPass2  - SpecterOps

Discover DeepPass2 - a secret scanning tool combining BERT-based model and LLMs to detect free-form passwords, and other structured tokens and secrets with high accuracy.

ghst.ly

BloodHound v8.0 is here! 🎉 This update introduces BloodHound OpenGraph, revolutionizing Identity Attack Path Management by exposing attack paths throughout your entire tech stack, not just AD/Entra ID. Read more from Justin Kohler: ghst.ly/bloodhoundv8 🧵: 1/7

Happy Friday! @tifkin.bsky.social and I are happy to announce that we have cut the release for Nemesis 2.0.0 - check out the CHANGELOG for a (brief) summary of changes, and dive into our new docs for more detail! We're extremely proud and excited for this release github.com/SpecterOps/N...

GitHub - SpecterOps/Nemesis: An offensive data enrichment pipeline

An offensive data enrichment pipeline. Contribute to SpecterOps/Nemesis development by creating an account on GitHub.

github.com

So you've compromised a host that isn’t cloud-joined. Antero Guy breaks down how to request OAuth tokens & enumerate an Entra ID tenant by using an SSO cookie from a non cloud-joined device. Read more: ghst.ly/445tQKL

Requesting Entra ID Tokens with Entra ID SSO Cookies - SpecterOps

Learn how to use a browser SSO cookie to request Entra ID OAuth tokens and enumerate a target tenant. This technique is useful when a device is not joined to an Entra ID tenant.

ghst.ly