SpecterOps

@specterops.io

Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management

ConfigManBearPig 2.0 is out, a full Python rewrite built on OpenHound. Faster, runs on Linux, SOCKS proxy support, better BloodHound pathfinding for SCCM attacks. Read more: https://ghst.ly/3RGyETm Catch Chris Thompson demo-ing it live at #BHUSA Arsenal TOMORROW, Tue 8/4, 5:15pm, Station 6.

ConfigManBearPig 2.0 - Things Are Getting Cereal

ConfigManBearPig 2.0 is a Python tool that collects SCCM data for BloodHound to map and fix Configuration Manager attack paths.

ghst.ly

🐶 It's #BloodHoundBasics day w/ @Jonas_B_K! Two new edges cover ADCS ESC14 attacks: 🔹 WriteAltSecurityIdentities: write altSecurityIdentities on a user/computer. 🔹 WritePublicInformation: write the Public-Information property set, including altSecurityIdentities. 🧵: 1/3

Bild

An MCP server isn't just a wrapper around your REST API. AI agents explore before they act, so MCP tools should be designed around intent, not implementation. Kaleb Pomeroy explains why that distinction matters for security workflows. ➡️ https://ghst.ly/4x80M0X

Proxied execution leaves almost nothing on disk. No new process, no dropped tool, just a socket doing its job. Brian Reitz & John Wotton break down why that's hard to detect, and introduce Proxywatch, our behavior-based approach to catching it. Read more: https://ghst.ly/44feQcF

Finding SOCKS with Proxywatch

Adversaries use SOCKS proxy tunnels to pivot within environments and to execute code against compromised systems without bringing tools to the system. Defenders often lack reliable guidance to detect ...

specterops.io

How do you make sense of a Kubernetes environment that's constantly changing? Hector Riestra explores how Codex helped shape a reusable framework for reasoning about AKS identity, trust relationships, and attack surface. Read more ⤵️ https://ghst.ly/4h1DWTF

Building a Mental Model for Kubernetes Security Research

A first-principles taxonomy for AKS identity and access, turned into a YAML and Terraform framework for building security research scenarios.

ghst.ly

We're back w/ another #BloodHoundBasics from Jacob Jackson! ⤵️ One of my favorite parts of BloodHound Enterprise is the Hygiene findings. Not every security issue shows up as an attack path but that doesn't make it any less important. 🧵: 1/3

Bild

Testing an LLM once is easy. Testing it consistently is harder. Neeraj Gupta's latest GhostWorks research introduces Jailbreaker, an open-source platform built to make jailbreak, prompt injection, & agent behavior testing repeatable and easier to manage. https://ghst.ly/4gdCHk1

Jailbreaker: LLM Jailbreak Testing You Can Actually Repeat

Learnings with Jailbreaker, an open-source LLM jailbreak testing platform for prompt-injection and agent-behavior tests.

ghst.ly

In today’s #BloodHoundBasics from Carlo Alcantara, we cover Environment Targeted Access Control (ETAC) for Enterprise users. Read-Only & User roles now support environment-based visibility via the “Manage Users” page. Simply select which environments each user can access. 1/2

Bild

What happens when a new Mythic agent can be generated, tested, and deployed in ~2 hours? @xpnsec.com explores "disposable tooling" and the implications for offensive operations and defenders alike. Check out the latest from GhostWorks ⬇️ https://ghst.ly/4oMyrdC

Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment

Using Claude Opus to autonomously generate Mythic C2 agents from prompt to deployment—and what that means for defenders.

ghst.ly

We're excited to partner with OpenAI through the Daybreak Cyber Partner Program to help defenders solve one of cybersecurity's toughest challenges: attack path triage. The challenge isn't finding risk. It's knowing which attack paths matter most. https://ghst.ly/4xKhwMP

SpecterOps and OpenAI: Helping to Build a New Security Frontier with Daybreak

SpecterOps joins OpenAI's Trusted Access for Cyber program to bring Daybreak AI capabilities to BloodHound Enterprise and GhostWorks, advancing AI-powered attack path management.

ghst.ly

Today we celebrate #Juneteenth, honoring freedom, resilience, and the enduring pursuit of equality. We reflect on the past, recognize the progress made, and reaffirm our commitment to building a more inclusive future for all.

Bild

The first version of BloodHound MCP proved an LLM could talk to BloodHound. The next version taught a more important lesson: MCP design is context design. @turbo-sec.bsky.social breaks down what changed, what didn't, and why smaller tools beat larger API surfaces. https://ghst.ly/4exgf2O

BloodHound MCP, One Year Later: What I Learned About MCPs, Models, and Context

The first version of BloodHound MCP proved that an LLM could converse with BloodHound. The current version drove home the lesson that MCP design is context design. The most useful changes were smaller...

ghst.ly