RID-500 is AD's best break-glass account... and you should disable it!🙃 Jorge de Almeida Pinto shared counterintuitive wisdom at #TROOPERS26 - All-powerful and cannot get locked out. - Disabled = more secure. - Disabled bypassed when booting in Safe Mode With Networking. Sources in🧵
Martin Sohn Christensen
@martinsohn.dk
Security Researcher @ SpecterOps https://martinsohn.dk
#TROOPERS26 afterglow: Andrew Schwartz on building a solid LDAP detection stack - why signature-based detection is failing and volume-based detection generally wins. Lots of tips for detecting SharpHound, ldapnomnom, SOAPy & more.
Timeline of AD CS attack research & Microsoft patches since the AD CS paradigm shift: Certifried Pre-Owned whitepaper by @harmj0y.bsky.social and @tifkin.bsky.social
Speaking at #TROOPERS26 next week and I can't wait. Joining @martinsohn.dk to talk about attack paths to #PAW and real-world risks of tiered admin models with #IntuneRBAC. Plus something we've been working on for months... See you in Heidelberg! www.troopers.de #EntraOps #Bloodhound
I wrote about a recent research task of mine -
AzureHound now has least-privilege permission documentation & @martinsohn.dk shows the internal research that made it. TL;DR of changes: Directory.Read.All → 8 MS Graph permissions Reader role → 16 ARM actions Directory Readers → not required Check it out: https://ghst.ly/4vzI8yk
My SO-CON talk about mapping RBAC in BloodHound is posted now. Fair warning for those who don't know me, I do have a personality and started by yelling at the crowd. 👑 Check out how we are mapping RBAC in BloodHound moving forward. youtu.be/1KDcK9PjnhU?...
Mapping RBAC in BloodHound | SO-CON 26
YouTube video by SpecterOps
youtu.be
This sounds awesome for no money. Unfortunately I'll be between BSides & Troopers those days :/
Next month we perform at ROMA.EXE the first demo party in Rome. On stage with arottenbit and Gom Jabbar (Kenobit + Stormo). Location: Casilino Sky Park Tickets on DICE 10€ (Show only on 20 June) 25€ concert + demoparty access (20/21 june) MBRSERVER.COM / ROMA-EXE.COM SPREAD THE CODE
The BSides Aarhus agenda is now live, and I am giving a talk on my "bad-documentation" research there on June 20. Agenda 👉 bsidesaarhus.dk/agenda/
BloodHound users: your query workflow just got better. With this latest update, @martinsohn.dk and @joeydreijer.bsky.social introduce multi-source loading, multi-server support, and dozens of new queries, now live in the Query Library. Check it out: https://ghst.ly/4vBic6c
What's New in the BloodHound Query Library: BYOL, OpenGraph, Multi-Server, and More - SpecterOps
BloodHound Query Library now supports custom query sources, OpenGraph extensions, and multi-server environments.
specterops.io
I've put up the slides from my Zer0Con 2026 presentation on Administrator Protection. github.com/tyranid/info...
github.com
Time is running out ⏳ Grab your spot in our Detection course at #SOCON2026 happening next week! In-person attendees receive a free pass to the conference days. Save your seat before registration closes TOMORROW! http://ghst.ly/socon26-regbsky
My responsible disclosure covering 16 vendors whose documentation was steering customers into critical misconfigs. More details will be shared at my talk @ BSides Prague on April 24! www.bsidesprg.cz#program:~:te...
Security B-Sides Prague
BSides Prague provides a platform for the information security community to present their work in a friendly and welcoming environment.
bsidesprg.cz
The origin of critical misconfigurations may be a trusted vendor of yours. @martinsohn.dk’s latest research found official documentation across 16 vendors introducing critical attack paths, often through AD CS misconfigurations. Check it out: https://ghst.ly/4bwYiBe
The #SOCON2026 agenda is live! 🎉 Explore talks, topics, & speakers across the Tradecraft, OpenGraph, & new Practice Track, focused on turning Attack Path Management into an operational discipline. Check out the agenda & plan your experience: ghst.ly/socon26-tw 🧵: 1/4
BloodHound's OpenGraph is 🔥🚀 This is how we rapidly developed a customer specific attack primitive for BloodHound that we call "ManagerOf" 👇
New #BloodHoundBasics post from @martinsohn.dk ‼️ Today is a demo of how BloodHound's #OpenGraph helped a customer build ManagerOfHound.ps1 - going from attack path concept to a custom "ManagerOf" edge in BloodHound. Can it fit in a thread? Let's see... 🧵 1/6
I publish two blog posts today! 📝🐫 First dives into how we're improving the way BloodHound models attack paths through AD trusts: specterops.io/blog/2025/06... Second covers an attack technique I came across while exploring AD trust abuse: specterops.io/blog/2025/06... Hope you enjoy the read 🥳
Good Fences Make Good Neighbors: New AD Trusts Attack Paths in BloodHound - SpecterOps
The ability of an attacker controlling one domain to compromise another through an Active Directory (AD) trust depends on the trust type and configuration. To better map these relationships and make i...
specterops.io
Easily find and share BloodHound Cyphers on queries.specterops.io Released with ~90 new Cypher queries, go check them out! @joeydreijer.bsky.social and I spent many hours creating it and we hope you find it useful. All feedback is appreciated :)
queries.specterops.io
Introducing the BloodHound Query Library! 📚 @martinsohn.dk & @joeydreijer.bsky.social explore the new collection of Cypher queries designed to help BloodHound users to unlock the full potential of the BloodHound platform by creating an open query ecosystem. ghst.ly/4jTgRQQ
**Every** BloodHound Enterprise tenant I've checked has multiple Non Tier Zero principals with the rights required for BadSuccessor. Luckily a 2025 DC is still rare. Often helpdesk has GenericAll, misconfig'ed to apply on the OU itself, instead of only inheriting to principals within.
Happy #BloodHoundBasics Day! This week's 🔥 topic from @martinsohn.dk: the Microsoft-wont-fix-yet "BadSuccessor" attack that abuses Server 2025's dMSA feature for domain takeover. This 🧵 shows how you can use BloodHound to find BadSuccessor risk. (1/9)
Shout out (skud ud) to @embar.io Best CTF DJ. #tdcnetctf
BloodHound has 4 new edges: 𝗖𝗼𝗲𝗿𝗰𝗲𝗔𝗻𝗱𝗥𝗲𝗹𝗮𝘆𝗡𝗧𝗟𝗠𝗧𝗼𝗦𝗠𝗕, ...𝗧𝗼𝗟𝗗𝗔𝗣, ...𝗧𝗼𝗟𝗗𝗔𝗣𝗦, ...𝗧𝗼𝗔𝗗𝗖𝗦 [ESC8] They combine 𝗰𝗼𝗲𝗿𝗰𝗶𝗼𝗻 and 𝗿𝗲𝗹𝗮𝘆𝗶𝗻𝗴, allowing Auth. Users to compromise computers. Read this excellent post by Elad Shamir if you are unfamiliar with those terms or want to know how to mitigate.
Think NTLM relay is a solved problem? Think again. Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
I had a great time at @specterops.bsky.social #SOCON2025 in Arlington/DC! I'm grateful I get to meet all you awesome people; community members and Specters. Huge thanks to the many speakers and trainers 💙 See you next year!
In Part 1 of my Intune Attack Paths series, I discuss the fundamental components and mechanics of Intune that lead to the emergence of attack paths: posts.specterops.io/intune-attac...
Intune Attack Paths — Part 1
Intune is an attractive system for adversaries to target…
posts.specterops.io
Merry Christmas from us to you 🎄🎁💙 We launched Trending Topics today, and you can find it by tapping the search icon on the bottom bar of the app or the right sidebar on desktop.
The Misconfiguration Manager DETECT section has been updated with fresh guidance to help defensive operators spot the most prolific attack techniques. Check out the blog post from @bouj33boy.bsky.social to learn more. ghst.ly/3VJ5y4F
Misconfiguration Manager: Detection Updates
TL;DR: The Misconfiguration Manager DETECT section has been updated with relevant guidance to help defensive operators identify the most…
ghst.ly
It's that time of year again everybody! I want to know YOUR thoughts on Mythic! What did you like? What could be improved? What would you like to see next? Why do you or don't you use it? If you could change something, what would it be? www.surveymonkey.com/r/MythicPlan... I'm all ears :)
a woman wearing glasses says please with her hand up
ALT: a woman wearing glasses says please with her hand up
media.tenor.com
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/K...
ShadowHound - brand new .ps1 SharpHound alternative that supports LDAP and ADWS Outputs data in ldapsearch format that can be converted to BH JSON with BOFHound. blog.fndsec.net/2024/11/25/s...
ShadowHound: A SharpHound Alternative Using Native PowerShell
ShadowHound is a PowerShell tool designed for mapping Active Directory environments without using known malicious binaries. It utilizes legitimate PowerShell modules for data collection through two…
blog.fndsec.net
Awesome new addition to krbrelayx by Hugow from Synacktiv: www.synacktiv.com/publications...
Relaying Kerberos over SMB using krbrelayx
synacktiv.com