logo

SpecterOps Blog

ID: 1ae489cf-f335-57a8-b96d-c87e1cd0eb78

STIX ID: identity--1ae489cf-f335-57a8-b96d-c87e1cd0eb78

Feed Type: skeleton

Earliest post: 2017-07-14

Latest post: 2026-03-12

The SpecterOps Blog shares deep technical research, red-team insights, attack techniques, and defensive guidance to help security professionals better understand adversary behavior and improve detection and response.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
CVE-2026-4387: StrongDM State File Reuse2026-06-01TrueTrue
Don’t Jump the Turnstile: Lessons from the Field2026-05-28TrueTrue
Shift Happens – Uncovering Two Built-in Command Injections in Windows Context Menus2026-05-07TrueTrue
The Accidental C2: Exploring Dev Tunnels for Remote Access2026-05-06TrueTrue
Vercel Breach Analysis: How an OAuth Token Became an Identity Attack Path2026-04-21TrueTrue
Into The Rainbow: Google’s NTLMv1 Rainbow Tables Explained in a Bit Too Much Detail2026-04-16TrueTrue
ghostsurf: From NTLM Relay to Browser Session Hijacking2026-04-02TrueTrue
JamfHound v1.1 Update: SSO Attack Paths and Okta Additions2026-03-31TrueTrue
When Vendor Documentation Creates Critical Attack Paths2026-03-24TrueTrue
Discovering Unexpected Okta Attack Paths with BloodHound2026-03-23TrueTrue
Graph the Planet: Shai-Hulud 2.02026-03-19TrueTrue
Introducing Attack Path Management for GitHub in BloodHound Enterprise2026-03-18TrueTrue
Offensive DPAPI With Nemesis2026-03-04TrueTrue
V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome's Memory2026-02-11TrueLiam DTrue
Microsoft’s “Immediate” Retirement of MDT2026-01-21TrueGarrett FosterTrue
Updates to the MSSQLHound OpenGraph Collector for BloodHound2026-01-20TrueChris ThompsonTrue
MSSQL and SCCM Elevation of Privilege Vulnerabilities2026-01-15TrueChris ThompsonTrue
Wait, Why is my WebClient Started?: SCCM Hierarchy Takeover via NTLM Relay to LDAP2026-01-14TrueLogan GoinsTrue
Attacking System Center Operations Manager (Part 1)2025-12-10TrueGarrett FosterTrue
An Evening with Claude (Code)2025-11-21TrueAdam ChesterTrue
SCCM Hierarchy Takeover via Entra Integration…Because of the Implication2025-11-19TrueGarrett FosterTrue
Catching Credential Guard Off Guard2025-10-23TrueValdemar CarøeTrue
The (Near) Return of the King: Account Takeover Using the BadSuccessor Technique2025-10-20TrueLogan GoinsTrue
NAA or BroCI...? Let Me Explain2025-10-15TrueHope WalkerTrue
WriteAccountRestrictions (WAR)2025-10-01TrueGarrett FosterTrue
The Salesloft–Drift Breach: An Attack Path Case Study2025-09-24TrueJared AtkinsonTrue
The (Static) Keys to Abusing PDQ SmartDeploy2025-08-12TrueGarrett FosterTrue
Certify 2.02025-08-11TrueValdemar CarøeTrue
Entra Connect Attacker Tradecraft: Part 32025-07-30TrueDaniel HeinsenTrue
I’d Like to Speak to Your Manager: Stealing Secrets with Management Point Relays2025-07-15TrueGarrett FosterTrue
Untrustworthy Trust Builders: Account Operators Replicating Trust Attack (AORTA)2025-06-25TrueJonas Bülow KnudsenTrue
Administrator Protection Review2025-06-18TrueAdam ChesterTrue
OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys2025-06-10TrueJulian CatramboneTrue
Understanding & Mitigating BadSuccessor2025-05-27TrueJim SykoraTrue
Apollo 2.0 — New Year, New Features2022-02-02TrueDwight HohnsteinTrue
Azure Privilege Escalation via Azure API Permissions Abuse2021-12-01TrueAndy RobbinsTrue
1Password Secret Retrieval — Methodology and Implementation2021-08-17TrueDwight HohnsteinTrue
Certified Pre-Owned2021-06-17TrueWill SchroederTrue
Attacking FreeIPA — Part IV: CVE-2020–107472020-06-28TrueJulian CatramboneTrue
War Never Changes: Attacks Against WPA3’s “Enhanced Open” — Part 3: OWE Nearly Indistinguishable From Open Wireless In Terms of Risk2020-02-12TrueGabriel RyanTrue

1–40 of 40