Ghostwriter v7: Safer Tokens, Scoped Access, and Better Automation
ID: 1d5a7f0a-f869-55fb-b6fe-fd97d578a0f8
STIX ID: report--1d5a7f0a-f869-55fb-b6fe-fd97d578a0f8
Feed Name: SpecterOps Blog
Ghostwriter v7.0.0 modernizes authentication and automation by replacing user-managed JWTs with opaque Ghostwriter Access Tokens (gwat_ prefix), introducing scoped service principals and opaque service tokens (gwst_ prefix) with hashed secrets, expirations, revocation, and last-used tracking, and enabling narrowly scoped permissions for non-human integrations (including operation-log–scoped tokens and project read-only tokens). The release aims to simplify token lifecycle management (rotating credentials on expiry changes), improve UX for token management, and provide safer paths for LLM-driven workflows and oplog utilities; existing tokens must be rotated after upgrade.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
