PingOne Attack Paths - SpecterOps
You can use PingOneHound in conjunction with BloodHound Community Edition to discover, analyze, execute, and remediate identity-based attack paths in PingOne instances.
Introducing PingOneHound! This OpenGraph extension for BloodHound can help you identify, analyze, execute, and remediate attack paths in PingOne organizations. Read the introductory blog post here: specterops.io/blog/2025/10...
20.10.2025 17:43 β π 9 π 10 π¬ 0 π 0
Certify 2.0 - SpecterOps
Certify 2.0 features a suite of new capabilities and usability enhancements. This blogpost introduces changes and features additions.
The AD CS security landscape keeps evolving, and so does our tooling. π οΈ
Valdemar CarΓΈe drops info on Certify 2.0, including a suite of new capabilities and refined usability improvements. ghst.ly/45IrBxI
11.08.2025 20:38 β π 11 π 8 π¬ 0 π 0
Whatβs Your Secret?: Secret Scanning by DeepPass2Β - SpecterOps
Discover DeepPass2 - a secret scanning tool combining BERT-based model and LLMs to detect free-form passwords, and other structured tokens and secrets with high accuracy.
Red teamers know the drill: endless file churning, hunting for passwords & tokens. π
Meet DeepPass2, our new secret scanning tool that goes beyond structured tokens to catch those tricky free-form passwords too. Read Neeraj Gupta's blog post for more. ghst.ly/40HLNNA
31.07.2025 17:36 β π 12 π 4 π¬ 0 π 1
The best creds are the ones you simply ask for =)
specterops.io/blog/2025/07...
31.07.2025 16:02 β π 0 π 0 π¬ 0 π 0
Looks like the Entra QR code authentication method is going GA π₯³
They've also added some great guidance on suppressing the camera permission prompt for iOS :)
learn.microsoft.com/...
24.07.2025 23:30 β π 3 π 1 π¬ 0 π 0
My second post for the month is now live π
18.06.2025 18:54 β π 13 π 2 π¬ 2 π 0
A little over a year ago I published research on how you could leverage non-production AWS API endpoints to enumerate permissions without logging to CloudTrail. A year later...I'm still finding them. Red Teamers, these can be super useful and really up your game!
02.06.2025 13:35 β π 5 π 2 π¬ 1 π 0
A command line interface
Some c# code
Weβre about to take C# to the next level!
#dotnet #csharp
22.05.2025 00:31 β π 228 π 35 π¬ 27 π 13
Did you miss #SOCON2025? Did you have a favorite talk you'd like to rewatch?
π₯ All presentations from SO-CON 2025 are now live at ghst.ly/socon25-talks.
π» Slides for each talk are available at ghst.ly/socon25-slides.
19.05.2025 16:34 β π 5 π 5 π¬ 0 π 0
Application Based Authentication on Microsoft Entra Connect Sync is near. With this change you will be able to use a TPM backed certificate in Entra Connect Sync for authentication.
This is a welcome change to prevent the compromise of this high privileged account.
#Entra #Certificate
02.05.2025 06:52 β π 10 π 2 π¬ 0 π 1
Did you know you can send LAPS passwords to Entra on Server OS? Neither did @adamgrosstx.bsky.social or I until yesterday! Just need to hybrid join the server(s) and set the GPO to backup to "AAD"! Neat!
30.04.2025 00:33 β π 15 π 4 π¬ 2 π 1
Can you use the on-behalf-of flow to bypass conditional access policies? If the middleware app satisfies conditional access, can it exchange an access token to an otherwise blocked backend resource? It turns out... no. No it can't. The CAP will kick in when the middleware app uses the OBO flow.
25.04.2025 04:08 β π 0 π 0 π¬ 0 π 0
A new dedicated resource application to enable Active Directory to Microsoft Entra ID sync using Microsoft Entra Connect Sync or Cloud Sync is coming π±
In the announcement the mentioned reason is "upcoming security hardening"...
6bf85cfa-ac8a-4be5-b5de-425a0d0dc016
#EntraID
06.01.2025 18:29 β π 40 π 13 π¬ 3 π 0
π¨ Join the #PeoplesMovement this Saturday #April19 for a National Day of Action!
Yes, people will be in the streets again. Others will be organizing food drives, volunteering at shelters, hosting teach-ins, and more.
Hundreds of events are already listed at www.FiftyFifty.one/events.
16.04.2025 16:56 β π 1087 π 508 π¬ 60 π 89
Understanding Windows access tokens could be your best defense. At @cackalackycon.bsky.social, @atomicchonk.bsky.social will be peeling back the layers on potato exploits that threat actors use for privilege escalation.
Check out the schedule to learn more β‘οΈ ghst.ly/4jzjlnI
18.04.2025 16:33 β π 6 π 3 π¬ 0 π 0
Decrypting PDQ credentials | unsigned_sh0rt's blog
Walkthrough of how PDQ credentials encrypts service credentials
Had some fun with PDQ deploy/inventory credential decryption and wrote about it here: unsigned-sh0rt.net/posts/pdq_cr... thanks to
@dru1d.bsky.social for writing a BOF out of the POC
tl;dr get admin on PDQ box, decrypt privileged creds
11.04.2025 21:09 β π 9 π 6 π¬ 0 π 0
Tokenizing the Sandwich Debate: How NLP Models Weigh In on Hot Dogs
Get the gist for Natural Language Processing (NLP) and how tokenization plays a factor
Everybodyβs using AI assistants and tools these days, but do most of us understand how our text-based input is being interpreted and processed? Check out my latest blog post for a basic intro to text interpretation by AI assistants. www.corgi-Corp.com/post/tokeniz...
07.04.2025 15:04 β π 5 π 1 π¬ 0 π 0
Think NTLM relay is a solved problem? Think again.
Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
08.04.2025 23:00 β π 27 π 20 π¬ 1 π 2
An Operatorβs Guide to Device-Joined Hosts and the PRT Cookie
Introduction
Nothing new, but formalized some operator notes on Entra ID/Azure tradecraft I've found to be exceptionally useful on ops. Overlooked this myself for quite some time and thought others in the same boat might find it worth a read! π
medium.com/specter-ops-...
07.04.2025 16:34 β π 5 π 2 π¬ 0 π 0
1 year anniversary at SpecterOps, so many personal and professional achievements in a short space of time. My advice for anyone getting into this field, try and make sure that you work companies and colleagues that push you beyond your comfort level. \o/
06.04.2025 17:17 β π 23 π 1 π¬ 0 π 0
We are excited to see everyone at #SOCON2025 tomorrow! π
Get the details on everything you need to know before arriving at the conference: specterops.io/so-con
30.03.2025 19:04 β π 16 π 4 π¬ 0 π 0
GitHub - atomicchonk/roadrecon_mcp_server: Claude MCP server to perform analysis on ROADrecon data
Claude MCP server to perform analysis on ROADrecon data - atomicchonk/roadrecon_mcp_server
Spent the evening deep diving into MCPs and started a new project: roadrecon_mcp_server! This #MCP takes the web GUI output from the awesome ROADtools by @dirkjanm.io and offers tools to Claude (or your #AI agent of choice) to interact with the data:
github.com/atomicchonk/...
29.03.2025 03:17 β π 11 π 5 π¬ 2 π 0
What's the purpose of the x-ms-DeviceCredential header if the device id claim is already included in the user access token? It seems redundant
21.03.2025 17:48 β π 1 π 1 π¬ 0 π 0
ποΈ BIG NEWS: I'm launching Entra.Chat - the podcast identity pros have been waiting for!
After years in the identity trenches, I've seen a lot - the midnight calls, the authentication puzzles, and those "how is this even possible?" moments.
10.03.2025 23:01 β π 62 π 15 π¬ 2 π 3
Has anyone heard of anyone actually setting up WHFB certificate trust? it's gotta be a MS troll
06.03.2025 23:48 β π 1 π 1 π¬ 0 π 0
Security researcher in Google Project Zero. Author of Attacking Network Protocols. Posts are my own etc.
Associate Consultant @SpecterOps
Adversary Simulation
Active Directory | Web Apps | Social Engineering | Physical Security
Lead Customer Engineer (Intune/ConfigMgr)
Endpoint Management Enthusiast
Admin: WinAdmins Community (@winadmins.io)
About Me: https://ajf.one/me
Blog: https://ajf.one/blog
All views are my own.
Your Only Source For Professional Dog Ratings
nonprofit: @15outof10.org β€οΈβπ©Ή
links.weratedogs.com
Menswear writer. Editor at Put This On. Words at The New York Times, The Washington Post, The Financial Times, Esquire, and Mr. Porter.
If you have a style question, search:
https://dieworkwear.com/ | https://putthison.com/start-here/
Long time dumpster fire connoisseur.
Minnesota Stan.
MN and IN CCDC Red Team Lead.
Associate AdSim Consultant at SpecterOps.
Opinions are my own, not of any other entity.
{"Title":"Microsoft MVP","Talks About":"Intune, Autopilot, MMP-C ","Function":"Master Chief Content creator PMPC","Blog":"https://Call4cloud.nl"}
#Microsoft MVP | #CloudSecurity Architect βοΈ | #Entra #AzureAD π + #AzureSecurity π‘οΈ | #CommunityRocks | #Schaengel
- [REDACTED]βs husband
- Bear's dad
- Recovering sysadmin
- Microsoft MVP (PowerShell/Identity)
- Forever student
- Open-Source Toolmaker
- Whisk(e)y fan
- College football fan (Go Blue!)
- Stuff: https://dotdot.horse
Idiot of note. Principal something or other. Runs the Windows Authentication team at Microsoft. It's my fault your password doesn't work.
Mostly dog pictures. Might actually be two dogs in a trench coat. πΊπΈ / π¨π¦
https://syfuhs.net/
Remote desktop protocol expert, OSS contributor and Microsoft MVP. I love designing products with Rust, C# and PowerShell. Proud to be CTO at Devolutions. π¨π¦
Home of the Microsoft Tech Community and its friends. Posts about events, content from great creators and experts, inside and outside of Microsoft about our products.
We advance science and technology to benefit humanity.
http://microsoft.com/research
AI, Cloud, Productivity, Computing, Gaming & Apps βοΈ
personal website @ cloudcurio.us β¦ researching @ Wiz Security (threats.wiz.io) π maintaining @ cloudvulndb.org ποΈ podcasting @ cryingoutcloud.io πΊοΈ pivoting @ Pivot Atlas (gopivot.ing)
Read our Security Labs blog: https://securitylabs.datadoghq.com
Subscribe to our monthly newsletter: https://securitylabs.datadoghq.com/newsletters/
@chvancooten on the bird app π¦
---
Benevolently malicious offensive security enthusiast || OffSec Developer & Malware Linguist || NimPlant & NimPackt author || @ABNAMRO Red Team
Security researcher.
I have a blog: https://sapirxfed.com
Security Engineer / IAM Security. Defending against people like me.