SpecterOps

Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management

2025-11-06

Attackers don’t exploit tools—they exploit identities. Learn how to defend where it matters. Join operators and defenders for one of our hands-on training courses at #SOCON2026.

In-person attendees also receive a free conference pass. Save your spot ➡️ ghst.ly/socon-2026

SO-CON 2026 Adversary Tactics Trainings
- Red Team Operations
- Identity-driven Offensive Tradecraft
- Tradecraft Analysis
- Detection
2025-10-30

See your network shares the way attackers do. 👀

Meet ShareHound, an OpenGraph collector for BloodHound CE & Enterprise that reveals share-level attack paths at scale. @podalirius unpacks all the details in our latest blog post. ghst.ly/4ogiBqt

SpecterOps boosted:
2025-10-28

🕵️ Uncovering network attack paths with runZeroHound!

As of today you can feed your runZero asset inventory into @SpecterOps BloodHound v8. runZeroHound is an open source toolkit that brings your runZero asset data into BloodHound’s OpenGraph model to reveal real-world attack paths.

👉 @hdm breaks it down in his latest post: runzero.com/blog/introducing-r

2025-10-24

Credential Guard was supposed to end credential dumping. It didn't.

Valdemar Carøe just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled.

Read for more: ghst.ly/4qtl2rm

2025-10-16

#SOCON2026 is where the global security community unites to push the boundaries of identity-first defense.

Got insights on attack paths, identity risks, or BloodHound OpenGraph? Submit your talk to our CFP before it closes Nov. 15 ➡️ ghst.ly/socon26-cfp

2025-10-15

The CFP for #SOCON2026 is OPEN! 🙌

Have you been working on something interesting in Attack Path Management or identity-first defense? Join us in Arlington, VA (April 13–14) and share your work with the community.

Submit your talk by Nov. 15 → ghst.ly/socon26-cfp

SO-CON 2026 Call for Presenters 
Submit by November 15
2025-10-15

Microsoft introduced nested application auth (NAA) in 2024. Researchers spotted FOCI similarities & dubbed it brokered client IDs (BroCI).

Hope Walker documents NAA flows and BroCI—filling a gap for research on Microsoft identity protocols. Read more: ghst.ly/3Jdhp7Z

2025-10-08

Your strongest platform is only as secure as its weakest dependency. And you probably don't know what those are.

Jared Atkinson dives into the Clean Source Principle, hidden trust relationships, & why BloodHound OpenGraph changes the game. ghst.ly/4pYTtFU

2025-10-03

Red teams slip past detection. Defenders adapt. The cycle continues. 🔄

John Wotton's latest on AI gated loaders shows how offensive operators are using LLMs to make shellcode execution context-aware, executing only when OPSEC policies are met. ghst.ly/4nvxsgh

2025-10-02

Securing Domain Controllers without breaking AD is harder than it sounds. Michael Grafnetter at HIP Conference covers:

✅ IaC approach to Windows Firewall policy
✅ RPC filters & outbound traffic controls
✅ Hybrid environment challenges
✅ Network service discovery

Learn more: www.hipconf.com/agenda/

Domain Controller Firewall: Fact or Fiction
Thursday, October 9 at 11:00am ET
Charleston, South Carolina
2025-10-01

The only conference dedicated to Attack Path Management is back!

3 tracks. Real-world case studies. Hands-on BloodHound Quest lab. Join us at #SOCON2026 and advance your identity-first security strategy.

🎟️ Save your spot: specterops.io/so-con

SO-CON 2026
Attack Path Management Starts Here
2025-09-22

🎙️ NEW PODCAST: #KnowYourAdversary

Jared Atkinson & Justin Kohler explore identity security from the attacker's perspective. Real stories, real tactics, real insights.

Check out our first three episodes now 👉 ghst.ly/kya-podcast

2025-09-11

From military to cybersecurity — your next mission awaits. Join our upcoming Hack the Hiring Process webinar where veterans from our Consulting Services team share their experiences transitioning into roles in cybersecurity.

We're covering the essentials: resume strategies that work, timing your applications right, and what consultant life actually looks like day-to-day.

Join March Kulvanish, Lance Cain, Joshua Prager, Matthew Merrill, and Antero Guy next Thursday! Register at ghst.ly/sep-web-tw

2025-09-03

We are back with our BloodHound t-shirt fundraiser! 🙌

Grab your BloodHound 8.0 shirt today. All funds raised will go directly to Hope for HIE, the global voice for families affected by Hypoxic Ischemic Encephalopathy.

👕: ghst.ly/bh8-tshirt

2025-08-25

📆 Save the date for #SOCON2026 in Arlington, VA! This next conference will be bigger than before with a new third talk track.

🧑‍🏫 Conference: April 13-14, 2026
💻 Training: April 15-18, 2026

Sign up now to receive updates → specterops.io/so-con

SpecterOps boosted:
2025-08-25

Big thanks to our channel partners @SpecterOps for their support with this video 💙 Map anything with the free and open-source BloodHound Community Edition, or defend your environment with Bloodhound Enterprise! jh.live/bloodhound

2025-07-29

If you're attending #BHUSA next week, make sure to stop by booth 4527 for a demo of BloodHound v8.0 to see some of these features in action & learn how they can transform your identity risk management strategy.

ghst.ly/bhusa-25

2025-07-29

Join us for the BloodHound v8.0 deep dive this Thursday!

Justin Kohler, Andy Robbins, Jared Atkinson, and Stephen Hinck will walk through all the new features & show you how to implement these updates in your environment.

Register at ghst.ly/july-web-tw

2025-07-29

BloodHound v8.0 is here! 🎉

This update introduces BloodHound OpenGraph, revolutionizing Identity Attack Path Management by exposing attack paths throughout your entire tech stack, not just AD/Entra ID.

Also new in this update:

➡️ Microsoft PIM Support - View where Privileged Identity Management roles are in use and verify they're properly secured, ensuring PIM isn't hiding attack paths you thought were eliminated.
➡️ Powerful Integrations - ServiceNow for vulnerability tracking, DUO for enhanced authentication, plus full Kali Linux support for pen testers.
➡️ Enhanced Usability - New Table View, inheritance tracking, advanced back button functionality for seamless collaboration, and the BloodHound Query Library.

Read more from Justin Kohler: ghst.ly/bloodhoundv8

2025-07-02

Dive into the world of machine learning! ⚙️

Kicking off his blog series, Diego Lomellini uses Micrograd to explain core ML concepts like supervised learning, regression, classification, loss functions, & gradient descent. ghst.ly/44n3IeJ

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst