werdhaihai
@werdhaihai.bsky.social
📤 51
📥 84
📝 9
Adversary Simulation Consultant @SpecterOps
https://github.com/werdhaihai
reposted by
werdhaihai
SpecterOps
about 2 months ago
Lateral movement getting blocked by traditional methods?
@werdhaihai.bsky.social
just dropped research on a new lateral movement technique using Windows Installer Custom Action Server, complete with working BOF code.
ghst.ly/4pN03PG
loading . . .
DCOM Again: Installing Trouble - SpecterOps
DCOM lateral movement BOF using Windows Installer (MSI) Custom Action Server - install ODBC drivers to load and execute DLLs
https://ghst.ly/4pN03PG
0
9
3
reposted by
werdhaihai
hotnops
4 months ago
Finally putting out my research from this spring. "Imitune" coming in soon to support the POC
specterops.io/blog/2025/07...
loading . . .
Entra Connect Attacker Tradecraft: Part 3 - SpecterOps
How Entra Connect and Intune can be abused via userCertificate hijacking to bypass conditional access and compromise hybrid domains
https://specterops.io/blog/2025/07/30/entra-connect-attacker-tradecraft-part-3/
0
1
1
reposted by
werdhaihai
SpecterOps
4 months ago
Entra Connect sync accounts can be exploited to hijack device userCertificate properties, enabling device impersonation and conditional access bypass.
@hotnops.bsky.social
explores cross-domain compromise tradecraft within the same tenant. Read more:
ghst.ly/3ISMGN9
loading . . .
Entra Connect Attacker Tradecraft: Part 3 - SpecterOps
How Entra Connect and Intune can be abused via userCertificate hijacking to bypass conditional access and compromise hybrid domains
https://ghst.ly/3ISMGN9
1
9
6
reposted by
werdhaihai
Jonas Bülow Knudsen
5 months ago
I publish two blog posts today! 📝🐫 First dives into how we're improving the way BloodHound models attack paths through AD trusts:
specterops.io/blog/2025/06...
Second covers an attack technique I came across while exploring AD trust abuse:
specterops.io/blog/2025/06...
Hope you enjoy the read 🥳
loading . . .
Good Fences Make Good Neighbors: New AD Trusts Attack Paths in BloodHound - SpecterOps
The ability of an attacker controlling one domain to compromise another through an Active Directory (AD) trust depends on the trust type and configuration. To better map these relationships and make i...
https://specterops.io/blog/2025/06/25/good-fences-make-good-neighbors-new-ad-trusts-attack-paths-in-bloodhound/
0
18
12
reposted by
werdhaihai
SpecterOps
8 months ago
Think NTLM relay is a solved problem? Think again. Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound.
ghst.ly/4lv3E31
1
27
22
reposted by
werdhaihai
Matt Creel
8 months ago
Nothing new, but formalized some operator notes on Entra ID/Azure tradecraft I've found to be exceptionally useful on ops. Overlooked this myself for quite some time and thought others in the same boat might find it worth a read! 📖
medium.com/specter-ops-...
loading . . .
An Operator’s Guide to Device-Joined Hosts and the PRT Cookie
Introduction
https://medium.com/specter-ops-posts/an-operators-guide-to-device-joined-hosts-and-the-prt-cookie-bcd0db2812c4
0
5
2
Super excited to be speaking at SO‑CON 2025 on March 31st with my coworker Lance Cain. We’re diving into an example attack path from real-life red team assessments by Lance Cain, Dan Mayer, myself, and the entire
@specterops.bsky.social
crew.
specterops.io/so-con/
#SOCON2025
#redteam
8 months ago
0
4
1
reposted by
werdhaihai
9 months ago
The Mythic family continues to grow! Another cool Windows agent written in C that already has COFF execution! Be sure to check it out and their blog series on it
c0rnbread.com/creating-myt...
x.com/0xC0rnbread/...
0
5
3
reposted by
werdhaihai
SpecterOps
9 months ago
#SCCM
forest discovery accounts can be decrypted—even those for untrusted forests. If the site server is a managed client, all creds can be decrypted via Administration Service API. Check out our latest blog post from
@unsignedsh0rt.bsky.social
to learn more.
ghst.ly/4buoISp
loading . . .
Decrypting the Forest From the Trees - SpecterOps
TL;DR: SCCM forest discovery accounts can be decrypted including accounts used for managing untrusted forests. If the site server is a managed client, service account credentials can be decrypted via ...
https://ghst.ly/4buoISp
1
22
15
reposted by
werdhaihai
SpecterOps
9 months ago
BIG NEWS: SpecterOps raises $75M Series B to strengthen identity security! Led by Insight Partners with Ansa Capital, M12, Ballistic Ventures, Decibel, and Cisco Investments.
ghst.ly/seriesb
#IdentitySecurity
#CyberSecurity
(1/6)
1
16
10
reposted by
werdhaihai
10 months ago
Many in the Mythic Community have asked for a way to standardize BOF/.NET execution within Mythic Agents. Today I'm releasing Forge, a new Mythic container to do just that:
posts.specterops.io/forging-a-be...
We're starting off with default support for Apollo and Athena. Check it out! :)
0
11
5
reposted by
werdhaihai
hotnops
10 months ago
This post goes more into Entra Connect tradecraft and how partially synced objects can be hijacked for cross domain attacks.
posts.specterops.io/entra-connec...
loading . . .
Entra Connect Attacker Tradecraft: Part 2
Now that we know how to add credentials to an on-premises user, lets pose a question:
https://posts.specterops.io/entra-connect-attacker-tradecraft-part-2-672df0147abc
0
5
1
reposted by
werdhaihai
SpecterOps
10 months ago
What does the road to becoming a Specter look like? In his latest blog post,
@subat0mik.bsky.social
provides a high level overview of how we approach recruiting consultants, demystifying the process along the way from application review through interviews.
ghst.ly/3PQeuSh
loading . . .
Life at SpecterOps Part II: From Dream to Reality
We’re hiring consultants; Check out this overview of our recruiting process!
https://ghst.ly/3PQeuSh
1
4
1
snovvcrash.rocks/2024/12/08/a...
loading . . .
On the Applicability of the Timeroasting Attack
Lately I’ve had an opportunity to experiment with the Timeroasting on an engagement, so here are my thoughts on the applicability of the attack in real life conditions with some examples along the way...
https://snovvcrash.rocks/2024/12/08/applicability-of-the-timeroasting-attack.html
12 months ago
0
0
0
reposted by
werdhaihai
Andrea P
about 1 year ago
Following my prev tweet, my Kerberos MITM relay/forwarder is almost finished! It targets for example insecure DNS updates in AD, allowing DNS name forgery. It intercepts, relays, and forwards traffic, with the client unaware. Currently supporting smb->smb and smb->http (adcs)
1
36
14
about 1 year ago
0
4
0
reposted by
werdhaihai
Garrett
about 1 year ago
Was doing some digging "What's New" in Server2025
learn.microsoft.com/en-us/window...
specifically the changes to pre-2k machines. Oddvar and I had spoken previously about the changes being solid and demonstrated pre-created machines in ADUC could no longer be set with a default password.
1
10
5
reposted by
werdhaihai
SpecterOps
about 1 year ago
The CFP for
#SOCON2025
closes TOMORROW! We are accepting talks focused on identity-based security and Attack Paths. Submit yours today! ➡️
ghst.ly/cfp-socon25
0
0
1
Python implementation of some remote modules from Seatbelt by @0xthirteen
github.com/0xthirteen/C...
loading . . .
GitHub - 0xthirteen/Carseat: Python implementation of GhostPack's Seatbelt situational awareness tool
Python implementation of GhostPack's Seatbelt situational awareness tool - 0xthirteen/Carseat
https://github.com/0xthirteen/Carseat
about 1 year ago
0
1
0
README for this is great
github.com/0xHossam/Ker...
loading . . .
GitHub - 0xHossam/KernelCallbackTable-Injection-PoC: Proof of Concept for manipulating the Kernel Callback Table in the Process Environment Block (PEB) to perform process injection and hijack executio...
Proof of Concept for manipulating the Kernel Callback Table in the Process Environment Block (PEB) to perform process injection and hijack execution flow - 0xHossam/KernelCallbackTable-Injection-PoC
https://github.com/0xHossam/KernelCallbackTable-Injection-PoC
about 1 year ago
0
0
0
Anyone read Cory Doctorow's Red Team Blues yet? Curious to hear thoughts and opinions on it.
about 1 year ago
0
2
0
you reached the end!!
feeds!
log in