š” WHAT IS PURPLE TEAMING AT SPECTEROPS?
SpecterOps recently introduced our Purple Team service offering, but what is it? We define it as "the evaluation of security control efficacy through atomic testing using deliberately selected test cases."
ghst.ly/3EUVRHB
This work is published as part of GhostWorks, an AI-focused engineering and research initiative at SpecterOps, focused on the disciplined exploration of frontier AI-enabled cybersecurity tooling. Read more ā¤µļø ghst.ly/4otZ1rJ
Most prompt engineering still boils down to vibes.
@_xpn_ explores GEPA, a framework for optimizing prompts using eval results, execution traces, & iterative refinement.
Read this practical look at bringing measurable engineering practices to AI agents. ghst.ly/4vGffAp
Ghostwriter v7 just dropped! š»
@cmaddalena built the release operators have been asking for, scoped service tokens, opaque API credentials, and non-human automation.
Now you can connect an LLM with read-only tokens without having to hope it behaves. ghst.ly/4o04tm3
AI and non-human identities are changing identity security.
Join @jaredcatkinson & @JustinKohler10 for a webinar on our latest research into Identity APM adoption, challenges, and operational maturity.
Save your spot: ghst.ly/3QQDhcJ
If MSSQL isn't in your attack path visibility yet, this is your sign. @Mayyhem just shipped a major MSSQLHound upgrade with Javier Azofra Ovejero (github.com/jazofra): faster, cross-platform, and pathfinding-ready in BloodHound.
Check it out! ghst.ly/4cUKgtJ
A compromised AI tool became an attack path into enterprise identity.
@jaredcatkinson breaks down the lesson from the recent Vercel breach: AI tools are non-human identities w/ delegated access. If compromised, attackers inherit it.
Read more ā¤µļø ghst.ly/4sSGW7p
Anthropicās Mythos points to a future of machine-speed attacks.
What changes for defenders? š¤
Join @JustinKohler10 & @jaredcatkinson and learn how AI is accelerating compromise, why identity attack paths matter, and what you can do now.
Register ā ghst.ly/47PJs6E
Not all attackers want data or money. Some aim for disruption.
@jaredcatkinson spoke w/ @TechJournalist on why orgs need to model impact, not just attacker type. If your risk model is still centered on theft or #ransomware, itās outdated. ghst.ly/41K0jnS
Don't miss this one!
Join @JustinKohler10 & @jaredcatkinson TOMORROW for a walkthrough of how BloodHound Enterprise now maps risk across Okta, GitHub, and Mac environments.
There's still time to register š ghst.ly/4bFEnir
Identity moves across systems like AD, Okta, Entra, & GitHub. A compromise in one place can quickly turn into control somewhere else.
@jaredcatkinson breaks down how we modeled Okta in BloodHound Enterprise to make those attack paths visible.
Learn more: ghst.ly/3PpLKmJ
What do hundreds of incident response engagements reveal? Identity is the battleground. āļø
Steve Elovitz from @Unit42_Intel joins #KnowYourAdversary to break down how attacks unfold, from phishing to privilege escalation to SaaS expansion.
š§: ghst.ly/4uFeMie
GitHub isnāt just a code platform anymore. Itās a security boundary.
New from @jaredcatkinson: how GitHub creates real attack paths into repos, secrets, CI/CD, and even cloud environments.
Read more: ghst.ly/4cU3QHd
BloodHound Enterprise is expanding.
New OpenGraph extensions now uncover identity attack paths across Okta, GitHub, and Jamf-managed macOSāconnecting identities, repositories, and endpoints across hybrid environments.
ghst.ly/3N7X7yY
š§µ: 1/3
Can AI agents conduct advancedĀ cyber-attacksĀ autonomously?
We tested seven models released between August 2024 andĀ FebruaryĀ 2026 on two custom-built cyber rangesĀ designed to replicate complex attack environments.
HereāsĀ what we foundš§µ
Releasing PrivHound ā Bloodhound collector to model Windows local Privilege Escalation as a graph.
Still early ā bugs and PRs welcome.
github.com/dazzyddos/PrivHouā¦
Check out GoLinHound:
- Discovers Linux & SSH attack paths
- Outputs OpenGraph JSON for BloodHound ingestion
- Integrates with SharpHound and AzureHound data to unveil cross-technology attack paths
github.com/RantaSec/golinhouā¦
Incredibly proud of the team over here at @HuntressLabs as we announce a new really cool feature in our EDR - the āAttack Disruption Engineā. This new capability allows us to identify threats quicker on the endpoint and change response time from minutes to seconds. Full blog:
huntress.com/blog/disruptingā¦
Identity risk isnāt just about who has access. Itās about how access connects.
@jaredcatkinson dives into how Attack Path Management reframes modern security strategy in his article for @IdentityWeek_ID. ghst.ly/4txClZI
Introducing BloodHound Scentry: Accelerating Attack Path Management
Join Duane Michael and Robby Winchester as they discuss BloodHound Scentry
specterops.zoom.us/webinar/rā¦