XPN
@xpnsec.com
📤 1645
📥 139
📝 213
Hacker for hire at
@specterops.bsky.social
Blog:
https://blog.xpnsec.com
Lights up in the office 💜
5 days ago
2
5
0
reposted by
XPN
SpecterOps
10 days ago
This work is published as part of GhostWorks, an AI-focused engineering and research initiative at SpecterOps, focused on the disciplined exploration of frontier AI-enabled cybersecurity tooling. Read more:
ghst.ly/4otZ1rJ
loading . . .
Introducing GhostWorks: A Practical AI Initiative from SpecterOps
No hype. No guessing. SpecterOps built GhostWorks to test frontier AI tools against real identity security problems and document what actually works.
https://ghst.ly/4otZ1rJ
0
1
1
reposted by
XPN
SpecterOps
10 days ago
Most prompt engineering still boils down to vibes.
@xpnsec.com
explores GEPA, a framework for optimizing prompts using eval results, execution traces, & iterative refinement. Read this practical look at bringing measurable engineering practices to AI agents.
https://ghst.ly/4vGffAp
loading . . .
Prompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPA
Stop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results.
https://ghst.ly/4vGffAp
2
2
1
New blog post is up looking at what GEPA is, and how it can be used for refining prompts for security agents. This post was published as part of the
@specterops.io
GhostWorks initiative. Can't wait to show what we've been working on!
specterops.io/blog/2026/06...
loading . . .
Prompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPA
Stop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results.
https://specterops.io/blog/2026/06/09/prompt-engineering-security-agents-gepa/
10 days ago
0
4
1
My talk has been accepted to Blackhat USA, hyped for this one!!!! 🎉🎉 See y'all there o/
blackhat.com/us-26/briefi...
about 1 month ago
0
4
0
reposted by
XPN
SpecterOps
about 1 month ago
In his latest research,
@xpnsec.com
tears apart VS Code Dev Tunnels and finds a C2 framework underneath — REST → WebSocket → SSH → MsgPack RPC, remote exec, file ops. Find the Ouroboros tool and protocol breakdown here:
https://ghst.ly/4mZ4arb
loading . . .
The Accidental C2: Exploring Dev Tunnels for Remote Access
Peel back the layers of Microsoft Dev Tunnels and you'll find embedded protocols, RPC message exchanges, and a full command-and-control architecture hiding in plain sight.
https://specterops.io/blog/2026/05/06/dev-tunnels-the-accidental-c2/
0
10
5
If you came to SOCON, you may have seen the fireside chat on Ouroboros (if you weren't too busy counting my "urm"s 😝). The blog post is now live, detailing how we can use Dev-Tunnels for lateral movement, and allow pivoting from GitHub/Entra ID access.
specterops.io/blog/2026/05...
loading . . .
The Accidental C2: Exploring Dev Tunnels for Remote Access
Peel back the layers of Microsoft Dev Tunnels and you'll find embedded protocols, RPC message exchanges, and a full command-and-control architecture hiding in plain sight.
https://specterops.io/blog/2026/05/06/dev-tunnels-the-accidental-c2/
about 1 month ago
1
5
1
4 months ago
0
1
0
reposted by
XPN
Dirk-jan
4 months ago
Next week at WWHF Mile High I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀
0
9
5
reposted by
XPN
Gus Squawks
5 months ago
What do you MEAN the president audibly SHIT himself live on camera and they immediately cancelled the press conference and rushed everyone out of the room like it's a fire drill, and it happened two days ago, and I'm just hearing about it NOW?
218
12310
4043
Beach walk with the doggos 🐶
5 months ago
0
5
0
Finally watching Welcome to Derry, took until the final few episodes to see Pennywise but the show stands well on its own 🎈
5 months ago
0
0
0
reposted by
XPN
SpecterOps
7 months ago
AI tooling and MCP servers are entering enterprises fast, often faster than security teams can assess the risks. During a recent engagement,
@xpnsec.com
found a new Claude Code vuln (CVE-2025-64755) while exploring MCP abuse paths. 👀 Read the details:
ghst.ly/49ybl4W
loading . . .
An Evening with Claude (Code) - SpecterOps
This blog post explores a bug, (CVE-2025-64755), I found while trying to find a command execution primitive within Claude Code to demonstrate the risks of web-hosted MCP to a client.
https://ghst.ly/49ybl4W
0
10
4
Still here.. still lurking
8 months ago
1
9
0
My second post for the month is now live 🎉
add a skeleton here at some point
about 1 year ago
2
13
2
Talking Heads released a music video for Psycho Killer and it's fucking awesome :D
www.youtube.com/watch?v=CJ54...
loading . . .
Talking Heads - Psycho Killer (Official Video)
YouTube video by Talking Heads
https://www.youtube.com/watch?v=CJ54eImz88w
about 1 year ago
0
3
0
reposted by
XPN
SpecterOps
about 1 year ago
🚨 New blog post alert!
@xpnsec.com
drops knowledge on LLM security w/ his latest post showing how attackers can by pass LLM WAFs by confusing the tokenization process to smuggle tokens to back-end LLMs. Read more:
ghst.ly/4koUJiz
loading . . .
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
https://ghst.ly/4koUJiz
0
10
5
New blog post is up! Stepping out of my comfort zone (be kind), looking at Meta's Prompt Guard 2 model, how to misclassify prompts using the Unigram tokenizer and hopefully demonstrate why we should invest time looking beyond the API at how LLMs function.
specterops.io/blog/2025/06...
loading . . .
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
https://specterops.io/blog/2025/06/03/tokenization-confusion/
about 1 year ago
0
5
2
The level of snark in my upcoming blogpost is next level... And I'm not even sorry!
about 1 year ago
0
12
0
reposted by
XPN
Marc Smeets
about 1 year ago
Didn’t know this impressive fact.
@xpnsec.com
did you?
add a skeleton here at some point
1
1
1
reposted by
XPN
SpecterOps
about 1 year ago
You've been prepping for
#OSCP
exam day, and it finally arrives. 🙇 In Part 4 of his blog series,
@anam0x.bsky.social
focuses on the test & how to maximize the educational, financial, & professional value of the exam experience. Read more:
ghst.ly/4lHDw4M
🧵: 1/4
loading . . .
1
7
2
Worked on a simple POC last night for connecting Mythic up to LiteLLM (pointing to Claude) for riding shotgun on a C2 session. Only using shell cmd, but provides oversight and hints to potential paths to explore. Quite happy for a weekend project :D
youtu.be/C9J5okm6cA4
loading . . .
Superintendent POC
YouTube video by Adam Chester
https://youtu.be/C9J5okm6cA4
about 1 year ago
0
15
1
New AI Slop Avatar, who dis?
about 1 year ago
1
7
0
reposted by
XPN
Bad Sector Labs
about 1 year ago
WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more!
blog.badsectorlabs.com/last-week-in...
loading . . .
Last Week in Security (LWiS) - 2025-04-14
WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more!
https://blog.badsectorlabs.com/last-week-in-security-lwis-2025-04-14.html
0
5
2
Slides from my SOCON 2025 presentation are now up on GitHub
github.com/xpn/Presenta...
loading . . .
Presentations/SOCON2025 at main · xpn/Presentations
A collections of presentations. Contribute to xpn/Presentations development by creating an account on GitHub.
https://github.com/xpn/Presentations/tree/main/SOCON2025
about 1 year ago
0
8
0
Awesome post from
@atomicchonk.bsky.social
on NLP Tokenizing. We need more content like this to show the "how" behind the LLM :)
www.corgi-corp.com/post/tokeniz...
loading . . .
Tokenizing the Sandwich Debate: How NLP Models Weigh In on Hot Dogs
Get the gist for Natural Language Processing (NLP) and how tokenization plays a factor
https://www.corgi-corp.com/post/tokenizing-the-sandwich-debate-how-nlp-models-weigh-in-on-hot-dogs
about 1 year ago
0
7
0
reposted by
XPN
SpecterOps
about 1 year ago
Think NTLM relay is a solved problem? Think again. Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound.
ghst.ly/4lv3E31
1
27
22
New blog post 🤗
add a skeleton here at some point
about 1 year ago
0
13
2
Celebrating 1 year at SpecterOps, this was the first project I worked on after starting. Looking at SQL Server Transparent Data Encryption, how to bruteforce weak keys, and how ManageEngine's ADSelfService product uses TDE with a suspect key. Enjoy :)
specterops.io/blog/2025/04...
loading . . .
The SQL Server Crypto Detour - SpecterOps
As part of my role as Service Architect here at SpecterOps, one of the things I’m tasked with is exploring all kinds of technologies to help those on assessments with advancing their engagement. Not l...
https://specterops.io/blog/2025/04/08/the-sql-server-crypto-detour/
about 1 year ago
1
15
3
Love this article. It’s something that I’ve tried to follow throughout my career, having a line of sight to business profit centres. Even more important in the days of tech layoffs
www.seangoedecke.com/where-the-mo...
loading . . .
Knowing where your engineer salary comes from
How tech companies make money and why it's important
http://www.seangoedecke.com/where-the-money-comes-from/
about 1 year ago
0
5
0
1 year anniversary at SpecterOps, so many personal and professional achievements in a short space of time. My advice for anyone getting into this field, try and make sure that you work companies and colleagues that push you beyond your comfort level. \o/
about 1 year ago
0
23
1
I did a talk!!
#socon2025
about 1 year ago
1
20
0
reposted by
XPN
Katie Knowles
about 1 year ago
Excited to be at
@specterops.bsky.social
SO-CON this week!! If you're around, I'll be presenting "Abusing AUs, Confusing the SOC" tomorrow bright & early:
1
15
7
Talking tomorrow so can just enjoy today before the nerves kick in 🤣
#socon2025
about 1 year ago
3
18
0
#SOCON2025
Time \o/
about 1 year ago
0
5
0
reposted by
XPN
SpecterOps
about 1 year ago
We are excited to see everyone at
#SOCON2025
tomorrow! 🙌 Get the details on everything you need to know before arriving at the conference:
specterops.io/so-con
0
16
4
reposted by
XPN
Gynvael Coldwind
about 1 year ago
Paged Out! #6 is out!
pagedout.institute
Totally free, 80 pages, best issue so far! 'nuff said, enjoy! (please repost to help spread out the news!)
0
25
19
Too true! xD
about 1 year ago
0
4
0
reposted by
XPN
Max Andreacchi
about 1 year ago
Spent the evening deep diving into MCPs and started a new project: roadrecon_mcp_server! This
#MCP
takes the web GUI output from the awesome ROADtools by
@dirkjanm.io
and offers tools to Claude (or your
#AI
agent of choice) to interact with the data:
github.com/atomicchonk/...
loading . . .
GitHub - atomicchonk/roadrecon_mcp_server: Claude MCP server to perform analysis on ROADrecon data
Claude MCP server to perform analysis on ROADrecon data - atomicchonk/roadrecon_mcp_server
https://github.com/atomicchonk/roadrecon_mcp_server
2
11
5
Slides ported to SO-CON deck, time to work my presenting skillz \o/
about 1 year ago
1
13
0
Prepping slides for SO CON 2025... meme time ;)
about 1 year ago
1
14
0
First time for me :D Not just a hacker.. but a mother fuckin' muffin maker!! (only when on PTO, when bored and cba h4xx0ring).
about 1 year ago
2
16
0
On PTO and bored, so playing around with MCP by exposing Mythic APIs to Claude and seeing what the result. Attempting to have it emulate threat actors while operating Apollo in a lab... would make a good sparring partner :D
www.youtube.com/watch?v=ZooT...
loading . . .
Mythic MCP - Claude Sonnet driving Mythic (Apollo)
YouTube video by Adam Chester
https://www.youtube.com/watch?v=ZooTlwajQT4
about 1 year ago
1
20
6
Brilliant talk from
@scott.hanselman.com
on the realities on LLMs. The temperature demo is such a good way to explain the "magic" behind text generation.
www.youtube.com/watch?v=kYUi...
loading . . .
Keynote: AI without the BS, for humans - Scott Hanselman - NDC London 2025
YouTube video by NDC Conferences
https://www.youtube.com/watch?v=kYUicaho5k8
over 1 year ago
1
46
16
reposted by
XPN
SpecterOps
over 1 year ago
#SCCM
forest discovery accounts can be decrypted—even those for untrusted forests. If the site server is a managed client, all creds can be decrypted via Administration Service API. Check out our latest blog post from
@unsignedsh0rt.bsky.social
to learn more.
ghst.ly/4buoISp
loading . . .
Decrypting the Forest From the Trees - SpecterOps
TL;DR: SCCM forest discovery accounts can be decrypted including accounts used for managing untrusted forests. If the site server is a managed client, service account credentials can be decrypted via ...
https://ghst.ly/4buoISp
1
22
15
A nice reminder that everyone underrates their skills and talent
www.youtube.com/watch?v=dZCr...
loading . . .
Dave Grohl Inspired By Disco Drum Beats
YouTube video by Vocal Vibes
https://www.youtube.com/watch?v=dZCrdSC2-1I
over 1 year ago
0
4
1
over 1 year ago
0
2
0
Just arrived 🍏
over 1 year ago
0
20
1
When the senior takes over the assessment
youtube.com/clip/UgkxQcl...
loading . . .
YouTube
Share your videos with friends, family, and the world
https://youtube.com/clip/UgkxQclAJi-6veP4PqwWdv9Hb-oM3kdCCJLp?si=EE0ufKqdbsWHtVVP
over 1 year ago
0
1
0
Time to start selling “mishing” engagements 🤑💰💸
over 1 year ago
0
3
0
Load more
feeds!
log in