Good morning! Today at the Kennel Club! ⤵️ Stop by during #BHUSA to hear from SpecterOps researchers, as well as guests from UK AI Security Institute and OpenAI. Learn more about the sessions: https://ghst.ly/45owr2t
SpecterOps
@specterops.io
Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management
AI agents are expanding the attack surface. Are your defenses evolving too? Join Jared Atkinson and Justin Kohler for our upcoming webinar and learn why Identity Attack Path Management is becoming even more critical. Register: https://ghst.ly/4h0yWPn
ConfigManBearPig 2.0 is out, a full Python rewrite built on OpenHound. Faster, runs on Linux, SOCKS proxy support, better BloodHound pathfinding for SCCM attacks. Read more: https://ghst.ly/3RGyETm Catch Chris Thompson demo-ing it live at #BHUSA Arsenal TOMORROW, Tue 8/4, 5:15pm, Station 6.
ConfigManBearPig 2.0 - Things Are Getting Cereal
ConfigManBearPig 2.0 is a Python tool that collects SCCM data for BloodHound to map and fix Configuration Manager attack paths.
ghst.ly
🐶 It's #BloodHoundBasics day w/ @Jonas_B_K! Two new edges cover ADCS ESC14 attacks: 🔹 WriteAltSecurityIdentities: write altSecurityIdentities on a user/computer. 🔹 WritePublicInformation: write the Public-Information property set, including altSecurityIdentities. 🧵: 1/3
Still haven't joined the #BloodHoundUnleashed Attack Path Championship? Start now, then visit Kennel Club during #BHUSA for bonus codes that could move you up the leaderboard. 🔑 Password: LeadThePack Get started 👉 https://unleashed.bloodhound.quest/
Compromise one node in a Windows Server Failover Cluster and you've compromised all of them. Garrett Foster dug into why: shared credentials, forged tickets, and a full attack chain to own the cluster. Check it out! https://ghst.ly/4wSZSoW
Clustered Points of Failure
Windows Server Failover Clusters share credentials across every node: compromise one, and you compromise the entire cluster
ghst.ly
Who can actually assume that role? 🤔 Who can reach your secrets, keys, or data? 🔐 @hotnops.bsky.social explores how BloodHound Enterprise brings the attack path mindset to AWS to answer those questions. https://ghst.ly/3ToU5ZP
Attack Path Management Comes to AWS
AWS IAM attack paths let attackers chain roles and permissions to admin. BloodHound Enterprise maps them as paths defenders can sever.
ghst.ly
An MCP server isn't just a wrapper around your REST API. AI agents explore before they act, so MCP tools should be designed around intent, not implementation. Kaleb Pomeroy explains why that distinction matters for security workflows. ➡️ https://ghst.ly/4x80M0X
Your attack surface doesn't stop at AD. BloodHound Enterprise now supports AWS & Microsoft Entra Agent ID. We're also introducing BloodHound Hunter to bring attack path intel into AI workflows. Learn more ➡️ https://ghst.ly/4fZQN7W
Happy #BloodHoundBasics Friday from @martinsohn.dk! BloodHound's new path highlighting helps you focus on the relationships that matter. Demonstration: run the query "Shortest paths from Domain Users to Tier Zero", click a node to highlight the path(s) from Domain Users to it.
The #BloodHoundUnleashed Attack Path Championship is LIVE! 🔑 Password: LeadThePack Complete the challenge before #BHUSA, then visit Kennel Club for bonus codes to boost your leaderboard score. Get started 👉 https://unleashed.bloodhound.quest/
The hunt returns July 22. Complete the #BloodHoundUnleashed Attack Path Championship before #BHUSA, then visit Kennel Club during the event for bonus codes that can boost your leaderboard score. More soon. 👀
Happy #BloodHoundBasics from Nathan Davis! Did you know that BloodHound supports keyboard shortcuts? A quick ALT/OPT+H (Windows/Mac, respectively) will pull up the list of shortcuts. Want more? Feel free to create a feature request w/ our team here: https://ghst.ly/4viAozU
Need to do an NTLM relay over C2 but local priv-esc isn't possible? @logangoins.bsky.social new post walks through relaying NTLM auth out of a network and back in through red team infra to bypass traditional relay controls, plus how defenders actually stop it. Check it out: https://ghst.ly/4wA3fkg
There and Back Again: An Operators Guide on NTLM Relaying Egress
ghst.ly
This week's #BloodHoundBasics post comes courtesy of @andyrobbins.bsky.social 🙌 BloodHound has been free and open source software for nearly 10 years! Our latest version, BloodHound CE v9.4.0, is free and open source under the Apache 2.0 license: https://ghst.ly/3SR9CRS
Proxied execution leaves almost nothing on disk. No new process, no dropped tool, just a socket doing its job. Brian Reitz & John Wotton break down why that's hard to detect, and introduce Proxywatch, our behavior-based approach to catching it. Read more: https://ghst.ly/44feQcF
Finding SOCKS with Proxywatch
Adversaries use SOCKS proxy tunnels to pivot within environments and to execute code against compromised systems without bringing tools to the system. Defenders often lack reliable guidance to detect ...
specterops.io
How do you make sense of a Kubernetes environment that's constantly changing? Hector Riestra explores how Codex helped shape a reusable framework for reasoning about AKS identity, trust relationships, and attack surface. Read more ⤵️ https://ghst.ly/4h1DWTF
Building a Mental Model for Kubernetes Security Research
A first-principles taxonomy for AKS identity and access, turned into a YAML and Terraform framework for building security research scenarios.
ghst.ly
Most red team scope gets written the same way: "find what you can." Russel Van Tuyl breaks down why that approach leaves the most important questions unanswered and what to do instead. Check it out: https://ghst.ly/4wsMQOO
How to Set Red Team Objectives that Produce Value
Red team engagements produce better findings when objectives are specific, answerable, actionable, and tied to the decisions security leaders need to make
specterops.io
Wishing everyone a safe and happy #FourthofJuly! 🇺🇸 Whether you're spending the day with family, friends, or simply enjoying some well-earned downtime, we hope you have a wonderful #IndependenceDay.
We're back w/ another #BloodHoundBasics from Jacob Jackson! ⤵️ One of my favorite parts of BloodHound Enterprise is the Hygiene findings. Not every security issue shows up as an attack path but that doesn't make it any less important. 🧵: 1/3
New GhostWorks blog! 👻 @xpnsec.com continues his series, exploring how LLMs are impacting how we approach endpoint security, from EDR analysis to evasion research. ⬇️ Read more https://ghst.ly/4vFEcfP
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
specterops.io
Testing an LLM once is easy. Testing it consistently is harder. Neeraj Gupta's latest GhostWorks research introduces Jailbreaker, an open-source platform built to make jailbreak, prompt injection, & agent behavior testing repeatable and easier to manage. https://ghst.ly/4gdCHk1
Jailbreaker: LLM Jailbreak Testing You Can Actually Repeat
Learnings with Jailbreaker, an open-source LLM jailbreak testing platform for prompt-injection and agent-behavior tests.
ghst.ly
The #BHUSA show floor is a busy place. Take a break from the hustle and join our team for bowling, food, drinks, and good company. No presentations. No pitches. Just a fun night with the security community. 🎳 See you there! https://ghst.ly/4wkHkxC
In today’s #BloodHoundBasics from Carlo Alcantara, we cover Environment Targeted Access Control (ETAC) for Enterprise users. Read-Only & User roles now support environment-based visibility via the “Manage Users” page. Simply select which environments each user can access. 1/2
Looking for more opportunities to sharpen your skills at #BHUSA? Join us at the Kennel Club for hands-on workshops covering AI, red teaming for AWS, and building your own OpenGraph collector. Learn more & sign up 👉 https://specterops.io/black-hat/
What happens when a new Mythic agent can be generated, tested, and deployed in ~2 hours? @xpnsec.com explores "disposable tooling" and the implications for offensive operations and defenders alike. Check out the latest from GhostWorks ⬇️ https://ghst.ly/4oMyrdC
Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment
Using Claude Opus to autonomously generate Mythic C2 agents from prompt to deployment—and what that means for defenders.
ghst.ly
The best way to test enterprise defenses is to emulate real adversaries. Join Adversary Tactics: Red Team Operations at #BHUSA and learn how to execute advanced offensive operations against live defenders in a simulated enterprise environment. ➡️ https://ghst.ly/4uKAWyU
We're excited to partner with OpenAI through the Daybreak Cyber Partner Program to help defenders solve one of cybersecurity's toughest challenges: attack path triage. The challenge isn't finding risk. It's knowing which attack paths matter most. https://ghst.ly/4xKhwMP
SpecterOps and OpenAI: Helping to Build a New Security Frontier with Daybreak
SpecterOps joins OpenAI's Trusted Access for Cyber program to bring Daybreak AI capabilities to BloodHound Enterprise and GhostWorks, advancing AI-powered attack path management.
ghst.ly
Today we celebrate #Juneteenth, honoring freedom, resilience, and the enduring pursuit of equality. We reflect on the past, recognize the progress made, and reaffirm our commitment to building a more inclusive future for all.
The first version of BloodHound MCP proved an LLM could talk to BloodHound. The next version taught a more important lesson: MCP design is context design. @turbo-sec.bsky.social breaks down what changed, what didn't, and why smaller tools beat larger API surfaces. https://ghst.ly/4exgf2O
BloodHound MCP, One Year Later: What I Learned About MCPs, Models, and Context
The first version of BloodHound MCP proved that an LLM could converse with BloodHound. The current version drove home the lesson that MCP design is context design. The most useful changes were smaller...
ghst.ly