Jonas Bülow Knudsen

@jonas-bk.bsky.social

Manager, Research @ SpecterOps https://github.com/JonasBK/JonasBK/blob/main/README.md

Identity security in restricted environments shouldn’t be limited to periodic reviews. BloodHound Enterprise on-premises enables continuous Identity Attack Path Management without cloud connectivity. Learn more ➡️ ghst.ly/4kadAi0

Bild

DEF CON releases, PDQ SmartDeploy creds (@unsigned_sh0rt), FortiSIEM root command injection (@SinSinology), a cat themed loader (@vxunderground), fine-tune LLMs for offsec (@kyleavery_), juicing NTDS.DIT (@MGrafnetter), and more! blog.badsectorlabs.com/last-week-in...

Last Week in Security (LWiS) - 2025-08-18

DEF CON releases, PDQ SmartDeploy creds (@unsigned_sh0rt), FortiSIEM root command injection (@SinSinology), a cat themed loader (@vxunderground), fine-tune LLMs for offsec (@kyleavery_), juicing NTDS....

blog.badsectorlabs.com

Introducing the BloodHound Query Library! 📚 @martinsohn.dk & @joeydreijer.bsky.social explore the new collection of Cypher queries designed to help BloodHound users to unlock the full potential of the BloodHound platform by creating an open query ecosystem. ghst.ly/4jTgRQQ

Introducing the BloodHound Query Library - SpecterOps

The BloodHound Query Library is a community-driven collection of BloodHound Cypher available at https://queries.specterops.io

ghst.ly

It’s #BloodHoundBasics Day! 🎉 Want to find relationships cross AD domains? Use this Cypher query: MATCH p = (x:Base)-->(y:Base) WHERE x.domain <> y.domain AND NOT COALESCE(x.system_tags, '') CONTAINS 'admin_tier_0' RETURN p LIMIT 100 (1/2)

Bild

The query excludes Tier Zero control to filter out legit permissions granted to groups such as Enterprise Admins. The screenshot is redacted, but can you guess the name of the group in the middle? Hint: It has something to do with emails. s/o @jonas-bk.bsky.social (2/2)

Accurately see what permissions are exploitable in your AD environment. Chris Thompson discusses a recent update in BloodHound that shows fewer false positives for Owns/WriteOwner edges, & introduces the new Owns/WriteOwnerLimitedRights edges. Read more: ghst.ly/3QORQdF

Do You Own Your Permissions, or Do Your Permissions Own You? - SpecterOps

tl;dr: Less FPs for Owns/WriteOwner and new Owns/WriteOwnerLimitedRights edges Before we get started, if you’d prefer to listen to a 10-minute presentation instead of or to supplement reading this pos...

ghst.ly

Happy #BloodHoundBasics day! This week we are looking at how BloodHound classifies Tier Zero. Q: Why is not just the DA group Tier Zero but also all members? A: BloodHound classifies a few default Tier Zero assets, then adds more w/ logic from known attack techniques. 1/8

Part 2 of Nathan Davis' Getting Started with BloodHound Enterprise series just dropped! Check out the latest post on understanding & contextualizing Tier Zero, & ensuring you have an accurate depiction of the Attack Paths that exist in your BHE tenant. ghst.ly/4kEebbK

Getting Started with BHE — Part 2 - SpecterOps

Contextualizing Tier Zero TL;DR An accurately defined Tier Zero provides an accurate depiction of Attack Path Findings in your BHE tenant. Different principals (groups, GPOs, OUs, etc.) have different...

ghst.ly