Prioritization of the Detection Engineering Backlog
https://posts.specterops.io/prioritization-of-the-detection-engineering-backlog-dcb18a896981
https://posts.specterops.io/prioritization-of-the-detection-engineering-backlog-dcb18a896981
Medium
Prioritization of the Detection Engineering Backlog
Written by Joshua Prager and Emily Leidy
The Defender’s Guide to the Windows Registry
https://posts.specterops.io/the-defenders-guide-to-the-windows-registry-febe241abc75
https://posts.specterops.io/the-defenders-guide-to-the-windows-registry-febe241abc75
SpecterOps
The Defender’s Guide to the Windows Registry - SpecterOps
This is a series of blog posts designed to give you a ground-up start to defending a specific technology from potential attackers.
Uncovering Window Security Events
Part 1: TelemetrySource
https://posts.specterops.io/uncovering-window-security-events-ab72e1ec745c
Part 1: TelemetrySource
https://posts.specterops.io/uncovering-window-security-events-ab72e1ec745c
SpecterOps
Blog
Your new best friend: Introducing BloodHound Community Edition!
Stalking inside of your Chromium Browser
https://posts.specterops.io/stalking-inside-of-your-chromium-browser-757848b67949
https://posts.specterops.io/stalking-inside-of-your-chromium-browser-757848b67949
SpecterOps
Stalking inside of your Chromium Browser
With chromium-based browsers being the new favorite, learn how to combine multiple commands supported by CDP to save time and increase efficiency in a red team engagement.
Passwordless Persistence and Privilege Escalation in Azure
https://posts.specterops.io/passwordless-persistence-and-privilege-escalation-in-azure-98a01310be3f
https://posts.specterops.io/passwordless-persistence-and-privilege-escalation-in-azure-98a01310be3f
SpecterOps
Passwordless Persistence and Privilege Escalation in Azure
How Certificate Based Authentication works, passwordless persistence with CBA, passwordless privilege escalation, prevention, detection, and more.
The Defender’s Guide to Windows Services (update)
https://posts.specterops.io/the-defenders-guide-to-windows-services-67c1711ecba7
https://posts.specterops.io/the-defenders-guide-to-windows-services-67c1711ecba7
SpecterOps
Blog
Your new best friend: Introducing BloodHound Community Edition!
🔥1
At the Edge of Tier Zero: The Curious Case of the RODC
https://posts.specterops.io/at-the-edge-of-tier-zero-the-curious-case-of-the-rodc-ef5f1799ca06
https://posts.specterops.io/at-the-edge-of-tier-zero-the-curious-case-of-the-rodc-ef5f1799ca06
SpecterOps
At the Edge of Tier Zero: The Curious Case of the RODC
In this blog post, we’ll answer the question, “If I compromise a Read-Only Domain Controller, can I compromise the domain?” or, “Do RODCs belong in Tier Zero?”
Abusing Azure App Service Managed Identity Assignments
https://posts.specterops.io/abusing-azure-app-service-managed-identity-assignments-c3adefccff95
https://posts.specterops.io/abusing-azure-app-service-managed-identity-assignments-c3adefccff95
SpecterOps
Abusing Azure App Service Managed Identity Assignments
Managed Identities eliminate huge amounts of risk, but they do create new types of risks that Azure admins must be aware of...
BOFHound: Session Integration #BOFHound #SessionIntegration #LDAPenumeration #BloodHound #AttackPathMapping https://posts.specterops.io/bofhound-session-integration-7b88b6f18423
SpecterOps
BOFHound: Session Integration
In this post, we examine BOFHound-compatible BOFs and usage examples that allow an operator to take a manual and targeted approach to attack path mapping.
Getting Started with BHE — Part 2
https://posts.specterops.io/getting-started-with-bhe-part-2-fbeeeb2501ee
https://posts.specterops.io/getting-started-with-bhe-part-2-fbeeeb2501ee
SpecterOps
Getting Started with BHE — Part 2
Contextualizing Tier Zero TL;DR An accurately defined Tier Zero provides an accurate depiction of Attack Path Findings in your BHE tenant. Different principals (groups, GPOs, OUs, etc.) have different implications when Tier Zero is defined — understanding…
👍2