logo

Leveraging Tailscale Keys

ID: f6faf2ad-b6c1-5772-a05d-82d0669a6f91

STIX ID: report--f6faf2ad-b6c1-5772-a05d-82d0669a6f91

Feed Name: SpecterOps Blog

Date Published: 2026-03-12

Date Updated: 2026-05-01

...
...

This post is a red-team oriented walkthrough on identifying and abusing Tailscale authentication artifacts (Trusted Keys and auth keys) found in CI/CD or code repositories to programmatically join a target Tailnet. It covers key formats and how to exchange Trusted Keys for API tokens, creating auth keys (ephemeral, reusable, preauthorized), using tags and access controls, joining nodes with tailored tags, enumerating Tailnet state (e.g., tailscale status --json), and abusing subnet routers, exit nodes, and Tailscale SSH to access internal networks, proxy traffic, and achieve passwordless lateral movement; it also highlights defensive indicators such as admin console alerts and the value of protecting access control policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.