GitHub isn’t just a code platform anymore. It’s a security boundary.
New from @jaredcatkinson: how GitHub creates real attack paths into repos, secrets, CI/CD, and even cloud environments.
Read more: ghst.ly/4cU3QHd
Just in time for the holidays, I wanted to share something that a lot of people have asked for: youtube.com/playlist?list=PL…
Short videos about Mythic development and customizations. This is just the start - I'll release a survey soon that'll get feedback for the next batch :)
In this post @_wald0 introduces PingOneHound, a BloodHound OpenGraph extension that allows users to visualize, audit, and remediate attack paths in their PingOne environment. The blog post also serves as an introduction to the PingOne architecture.
specterops.io/blog/2025/10/2…
Hey you, ya you!! Have something cool to share? How about a submission to SO-CON 2025 - the CFP closes on Nov 15 (we cover travel a free training seat!). It was a blast last year and we hope to see everyone again next April!
sessionize.com/socon-2025
Part 4 of our Tier Zero webinar series is happening tomorrow! 🙌 Join @Jonas_B_K, @martinsohndk & @tifkin_ as they discuss the intricate world of Microsoft Exchange Server & AD CS.
Register ▶️ ghst.ly/tier0-tw
Learn how you can now map hybrid Attack Paths from on-prem Active Directory to Azure Entra ID using BloodHound Community Edition & BloodHound Enterprise.
Check out @_wald0 & @JustinKohler10's full conversation w/ @_JohnHammond at ghst.ly/4eJ235g
You can now register for #SOCON2025! Save your spot at the conference and check out our onsite trainings.
Register today & take advantage of the 50% off early bird discount available until December 1.
▶️ specterops.io/so-con
Nine new functions in BARK:
Get-AllEntraRoles
Enable-EntraRole
Get-EntraDeviceRegisteredUsers
Get-IntuneManagedDevices
Get-IntuneRoleDefinitions
New-EntraIDAbuseTestUsers
New-EntraIDAbuseTestSPs
New-IntuneAbuseTestUsers
New-MSGraphAppRoleTestSPs
github.com/BloodHoundAD/BARK
Mythic3.3 has been in Beta for 6 weeks now, so it's time to officially release it! Over the past 6 weeks, @tifkin_ provided a LOT of amazing quality of life requests, so I wanted to highlight them in a new blog posts.specterops.io/mythic-3…. I think you're gonna really like it :)
📆 Mark your calendar! #SOCON2025 is happening March 31-April 1. Join us for two days all about Attack Path Management.
Register today to get 50% off and learn about our CFP, opening Oct. 1st!
👉 specterops.io/so-con-2025/
Our webinar w/ @_wald0 & @its_a_feature_ is just a few days away!
Grab your spot now & get ready to hear all about discovery, execution, and remediation of those hybrid Attack Paths.
Register today! ▶️ ghst.ly/3YsgB4n