SpecterOps
@specterops
Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management
The hunt returns July 22. Complete the #BloodHoundUnleashed Attack Path Championship before #BHUSA, then visit Kennel Club during the event for bonus codes that can boost your leaderboard score. More soon. 👀
Happy #BloodHoundBasics from Nathan Davis! Did you know that BloodHound supports keyboard shortcuts? A quick ALT/OPT+H (Windows/Mac, respectively) will pull up the list of shortcuts. Want more? Feel free to create a feature request w/ our team here: https://ghst.ly/4viAozU
This week's #BloodHoundBasics post comes courtesy of @andyrobbins.bsky.social 🙌 BloodHound has been free and open source software for nearly 10 years! Our latest version, BloodHound CE v9.4.0, is free and open source under the Apache 2.0 license: https://ghst.ly/3SR9CRS
Wishing everyone a safe and happy #FourthofJuly! 🇺🇸 Whether you're spending the day with family, friends, or simply enjoying some well-earned downtime, we hope you have a wonderful #IndependenceDay.
We're back w/ another #BloodHoundBasics from Jacob Jackson! ⤵️ One of my favorite parts of BloodHound Enterprise is the Hygiene findings. Not every security issue shows up as an attack path but that doesn't make it any less important. 🧵: 1/3
The #BHUSA show floor is a busy place. Take a break from the hustle and join our team for bowling, food, drinks, and good company. No presentations. No pitches. Just a fun night with the security community. 🎳 See you there! https://ghst.ly/4wkHkxC
Visibility for a configured user is limited in the graph and will only show nodes and edges for environments they are permitted to view. In the example image, nodes an edges are obfuscated in environments that our user is not permitted access to. 2/2
In today’s #BloodHoundBasics from Carlo Alcantara, we cover Environment Targeted Access Control (ETAC) for Enterprise users. Read-Only & User roles now support environment-based visibility via the “Manage Users” page. Simply select which environments each user can access. 1/2
Looking for more opportunities to sharpen your skills at #BHUSA? Join us at the Kennel Club for hands-on workshops covering AI, red teaming for AWS, and building your own OpenGraph collector. Learn more & sign up 👉 https://specterops.io/black-hat/
The best way to test enterprise defenses is to emulate real adversaries. Join Adversary Tactics: Red Team Operations at #BHUSA and learn how to execute advanced offensive operations against live defenders in a simulated enterprise environment. ➡️ https://ghst.ly/4uKAWyU
Today we celebrate #Juneteenth, honoring freedom, resilience, and the enduring pursuit of equality. We reflect on the past, recognize the progress made, and reaffirm our commitment to building a more inclusive future for all.
Our team will be all over #BHUSA! 🎓 4 hands-on trainings 🎤 3 technical briefings 🛠️ 5 Arsenal sessions Stay in the loop on all we have going on that week. ➡️ https://specterops.io/black-hat/
Most orgs think of GitHub as a code platform. Attackers increasingly see it as a gateway to everything connected to it. Jared Atkinson joined Risky Business to discuss CI/CD attack paths and why GitHub is often a pivot point into the enterprise. 🎧: https://ghst.ly/4ezC0zf
Happy #BloodHoundBasics Friday from @jonas-bk.bsky.social! 🎉 Did you know BloodHound now shows Eligible Roles in the Entity Panel? For Azure users and groups, you can quickly see who can activate privileged roles or approve role activation requests.
📃 The update also added a one-page Cypher cheat sheet for quick lookups, plus a bundle of new queries that increase mapping coverage to security assessment tools. Check it out: queries.specterops.io 6/6
❤️ Favorite queries! Log in, heart the queries you use most, sort for Most Favorites, and use Show Favorites to filter your list. For now, this applies to the BloodHound Query Library source. 5/6
🤹 Multi-server management lets you add, edit, and switch BloodHound targets before running a query. The run action reuses the same tab per server, which helps when you work across staging, production, or multiple engagement instances. 4/6
🔗 Sharing custom-source queries now carries BYOL source context. If a recipient has not added that source, the library will prompt them to import it before loading the query. 3/6
📚 BYOL = Bring Your Own Library The Query Library can now load multiple sources: the default library, built-in JamfHound/GitHound/OktaHound OpenGraph queries, and custom JSON endpoints that follow the query schema. 2/6
Happy #BloodHoundBasics Day! This week, @martinsohn.dk walks through: queries.specterops.io helps you find & run the queries you need. Caught up on the latest features? - Multi-source loading - Multi-server management - Favorites - Cypher cheat sheet Quick glance in 🧵 1/6
And the winner is... 🥁 foobar! At the close of #InfoSecEurope, foobar was crowned the #BloodHoundUnleashed Attack Path Champion! 👑 Thank you to all of our competitors for your enthusiasm and participation throughout the challenge. We will see you for the next one...
#BHUSA will be here before we know it. This year our team will share the tradecraft, research, & attack path insights shaping modern offensive & defensive security. 🎓 5 hands-on trainings 🎤 3 technical briefings 🛠️ 5 Arsenal sessions Learn more: https://specterops.io/black-hat/
#BHUSA is right around the corner! Save your spot in our Detection course while you can. It's designed for defenders looking to improve threat hunting, strengthen detection coverage, & create analytics that remain effective as attacker tradecraft evolves. https://ghst.ly/4e2C22g
Happening soon at #InfoSecEurope: Stop by the Securing the Microsoft Ecosystem Theatre to hear from Mark Wilson on how hidden attack paths in AD & Entra ID enable enterprise-wide compromise and how defenders can eliminate them.
Don't miss Adversary Tactics: Tradecraft Analysis at #BHUSA! This course is great for anyone looking to better understand Windows attack techniques, telemetry, and detection opportunities from both red and blue team perspectives. Reserve your spot! https://ghst.ly/43eLw5s
British summer can't stop us: we are finally underway at #InfoSecEurope & the BloodHound Unleashed Attack Path Championship real-time leaderboard is live. Our top scorers are already on the board — come to the Kennel Club right outside the Excel London, & see where you rank or sign up to play today!
Now underway at #CiscoLive: Jared Atkinson is speaking during the security walkthrough on how signals across identity, SaaS, device, and network environments can be transformed into coordinated security actions.
Happening now! Jared Atkinson & Cisco’s Aaron Woland are speaking at #CiscoLive on how BloodHound Enterprise, Cisco Duo, and Splunk help defenders uncover & reduce identity risk.
To defend Azure & Entra ID, you first need to understand how attackers see them. Join our Azure training at #BHUSA & learn the misconfigurations adversaries look for through hands-on labs built around real-world attack paths. ➡️ https://ghst.ly/4uii3Ua
New #BloodHoundBasics from @scoubi.bsky.social! Waiting on better Cypher parity to switch your BHCE deployment to a PG backend? v9.2.0 brings new Cypher support! UNWIND, RELATIONSHIPS(p), NODES(p), etc & several improvements to existing verbs. Ex: Exclude edge types directly in Cypher!