Research at @SpecterOps

Joined August 2009
189 Photos and videos
fable is a joke wtf
7
677
Garrett retweeted
I'm excited to be able to finally publish the public disclosure for CVE-2026-4387. Check out my blog on discovering the reuse of the state.kv file to get authenticated sessions with StrongDM (now fixed). specterops.io/blog/2026/06/0…
3
11
1,837
I guess it's dunk on MSRC day lol
2
25
865
Garrett retweeted
Phishing sandboxes don’t play fair. In his latest blog, @synzack21 walks through a real red team engagement against modern email sandboxes and techniques that helped keep payload redirects hidden from crawlers while preserving a familiar user experience. ghst.ly/3RDFWac
15
38
2,980
Garrett retweeted

11
26
9,224
👀👀
Just added krb5 auth over ADWS in my tool SOAPy. I noticed since SOAPy released 2 yrs ago with the first ADWS python code nobody had implemented krb5 auth in python. Check it out here, and stay tuned for an upcoming blog post big release 👀 github.com/logangoins/SOAPy/
2
16
2,061
Garrett retweeted
NTLMv1 is still out there. And now it’s easier than ever to break. @skylerknecht walks through how Google’s rainbow tables make NT hash recovery practical, no third-party service required. Check it out! ⤵️ ghst.ly/4vqx9Id
3
62
161
8,014
Garrett retweeted
I explored how privilege connects DevOps and MLOps into attack paths that are often missed in traditional threat models. I will be presenting this at #SOCON2026 next week. @ArmadinSecurity Research here 👇 armadin.com/blog-posts/pipel…
1
13
22
7,182
Garrett retweeted
Pasting API keys in an LLM makes me feel kinda gross, so I created agentcordon. It's an agentic key vault that's: ✅Agent agnostic ✅Cedar policies for clear authorization ✅Fully auditable ✅Remote MCP Support
1
8
25
2,142
Garrett retweeted
I got tired of manually doing the "enum DNS -> figure out which ones are live -> request each one in the browser to populate Burp target sitemap" loop ad nauseam. I built a lightweight command line tool Burp extension to automate this entire process. Simply run the tool with very basic args, load the extension, and get everything into your Burp project with no hassle. Also really nice for passive checks (--no-nmap) in the pre-sales/scoping process with prospective clients to get an idea of what all they have actually exposed from an application standpoint at a birds-eye view. Enjoy. github.com/logansdiomedi/per…
1
9
43
3,518
Idk what happened but the end of last year MSRC was quick, responsive, and overall just better. Lately it's a ghost town with auto responses and no updates.
2
1
13
1,508
everyone freaking out about quotes dropping haven't people been warning about this for weeks? that everything was heavily subsidized and wasn't sustainable?
2
3
493
quotas*
2
344
Garrett retweeted
Somewhat a first draft / try to get some initial info on Failover Cluster setups, based on all the awesome work @unsigned_sh0rt did recently github.com/LuemmelSec/Pentes… Will give you an overview of Cluster setups, over permissive rights, ownership, OU structure
6
27
2,177
Garrett retweeted
It's been a few months since I released a few short "Mythic Developer" videos. Before making more, I'd like to first get your feedback on the current ones. Please take a few min and fill this out so I can make sure you get the best content :) specterops.typeform.com/Myth…

ALT The Rookie Win GIF by ABC Network

11
16
7,417
Garrett retweeted
Very proud of our team that built and contributed one of our (many) cybersecurity ranges for this AISI research. We're happy to collaborate with others in the AI eval research space as well. arxiv.org/pdf/2603.11214

3
26
2,980
new ludus features are sick
1
1
26
3,676
someone reaching out to share they hit an objective from research I worked on or a tool I wrote is one of the best feelings
1
25
1,061