An Operators Guide to Stealthy AD Collection Using ADWS
ID: 430914bd-84ed-5867-8c27-18e05913fb20
STIX ID: report--430914bd-84ed-5867-8c27-18e05913fb20
Feed Name: SpecterOps Blog
Technical guide explaining how operators can perform stealthy Active Directory reconnaissance over ADWS using the Python-based `SoaPy` integrated with `BOFHound` to generate `BloodHound`-ready data, enabling constrained, incremental collection via SOCKS-proxied Linux workflows; it contrasts this with noisier `SOAPHound`, shows example queries (e.g., ADCS objects), and concludes with defensive guidance emphasizing ADDS logging and `SACL` canaries that alert on `ReadProperty` to detect LDAP/ADWS enumeration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
