Raj Patel (@grayhatkiller) 's Twitter Profile
Raj Patel

@grayhatkiller

Adversary Simulation @SpecterOps

ID: 3301418017

calendar_today30-07-2015 09:42:47

29 Tweet

253 Followers

184 Following

Sebas (@0xroot) 's Twitter Profile Photo

⚔ Abuse the Power of DCOM Excel Application Discover lateral movement tactics using DCOM's 'ActivateMicrosoftApp()' method in Excel for persistence in legacy systems By Raj Patel posts.specterops.io/lateral-moveme…

Jonas Bülow Knudsen (@jonas_b_k) 's Twitter Profile Photo

ADCS attack paths in BloodHound! 🥳 This blog post breaks down the implementation of the ESC1 requirements and guides you on effectively leveraging BloodHound to identify attack paths that include ESC1 privileges. posts.specterops.io/adcs-attack-pa…

SpecterOps (@specterops) 's Twitter Profile Photo

What's new with BOFHound? 🤷 Check out Matt Creel's latest blog post which delves into several new BOFs as well as an example attack path visualized using the BOFs, BOFHound, and BHCE. ghst.ly/3udnFVM

Andy Robbins (@_wald0) 's Twitter Profile Photo

In this blog post: ● My analysis of the Midnight Blizzard breach affecting Microsoft ● Step-by-step explanation of the attack path the adversary took ● Practical, free steps ANY Azure admin can take to protect themselves posts.specterops.io/microsoft-brea…

In this blog post:

● My analysis of the Midnight Blizzard breach affecting Microsoft
● Step-by-step explanation of the attack path the adversary took
● Practical, free steps ANY Azure admin can take to protect themselves

posts.specterops.io/microsoft-brea…
Garrett (@garrfoster) 's Twitter Profile Photo

SCCM hierarchy takeover by abusing site server high availability. In this blog, I walkthrough what active and passive site servers are and share multiple abusable scenarios that come bundled in. posts.specterops.io/sccm-hierarchy…

Duane Michael (@subat0mik) 's Twitter Profile Photo

Join Chris Thompson and me at SpecterOps SO-CON on March 11 at 9 AM as we present our talk, Misconfiguration Manager: Overlooked and Overprivileged. Also, here's an SCCM haiku teaser to hold you over!

Join <a href="/_Mayyhem/">Chris Thompson</a> and me at <a href="/SpecterOps/">SpecterOps</a> SO-CON on March 11 at 9 AM as we present our talk, Misconfiguration Manager: Overlooked and Overprivileged.

Also, here's an SCCM haiku teaser to hold you over!
Chris Thompson (@_mayyhem) 's Twitter Profile Photo

I'm pumped to announce the release of Misconfiguration Manager, a knowledge base and how-to for both offensive and defensive SCCM attack path management, that Duane Michael, Garrett, and I have been working on! Check it out and let us know what you think! posts.specterops.io/misconfigurati…

Will Schroeder (@harmj0y) 's Twitter Profile Photo

"Summoning RAGnarok With Your Nemesis" posts.specterops.io/summoning-ragn… I detail how we built a a Nemesis powered Retrieval-Augmented Generation (RAG) chatbot PoC, code now public at github.com/GhostPack/Ragn… ! Fun example of how to build on top of Nemesis' functionality.

Zach Stein (@synzack21) 's Twitter Profile Photo

Curious about Intune's new EPM feature? So were we. In this blog Duane Michael and I explore the internals of EPM and share some interesting findings. posts.specterops.io/getting-intune…

Daniel Mayer (@dan__mayer) 's Twitter Profile Photo

Tired of having to write your payload to disk to move laterally? Make a .NET Profiler DLL and load it straight from a webDAV server! Hook functions, monitor assembly loads and more as lagniappe. posts.specterops.io/lateral-moveme…

Nick Powers (@zyn3rgy) 's Twitter Profile Photo

[Tool & Blog release] - smbtakeover, a technique to unbind/rebind port 445 without loading a driver, loading a module into LSASS, or rebooting the target machine. The goal is to ease exploitation of targeted NTLM relay primitives while operating over C2. Github repo is linked at

Alex Neff (@al3x_n3ff) 's Twitter Profile Photo

Inspired by the great talk by Duane Michael, Chris Thompson and Garrett at #Troopers24, I wrote a new SCCM reconnaissance module that implements the RECON-1 (LDAP) part of the Misconfiguration Manager. This makes it much easier to enumerate the existing SCCM infrastructure🎯

Inspired by the great talk by <a href="/subat0mik/">Duane Michael</a>, <a href="/_Mayyhem/">Chris Thompson</a> and <a href="/garrfoster/">Garrett</a> at #Troopers24, I wrote a new SCCM reconnaissance module that implements the RECON-1 (LDAP) part of the Misconfiguration Manager.

This makes it much easier to enumerate the existing SCCM infrastructure🎯
Daniel Heinsen (@hotnops) 's Twitter Profile Photo

It's alive! Apeman is a graph-based tool to model AWS IAM permissions. This marks the start of a new journey to methodically identify and remediate IAM attack paths, and I look forward to learning together with y'all. github.com/hotnops/apeman

Forrest Kasler (@fkasler) 's Twitter Profile Photo

This is the last of my phishing series! It's a recap and reference for the whole thing. Hope it was as fun to read as it was to write:

Duane Michael (@subat0mik) 's Twitter Profile Photo

I wrote a blog post about some of the intangible benefits of working as a red team operator and adversary simulation consultant at SpecterOps. It's pretty awesome here. And we're hiring! posts.specterops.io/life-at-specte…

SpecterOps (@specterops) 's Twitter Profile Photo

Thanks to all the ghouls and ghosts who joined us for the chilling training sessions and spine-tingling fun at Specter Bash in Denver! 👻🎃 Our team loved sharing hacking horror stories and indulging in eerie Halloween activities. We hope you had a frightfully good time!

Thanks to all the ghouls and ghosts who joined us for the chilling training sessions and spine-tingling fun at Specter Bash in Denver! 👻🎃 

Our team loved sharing hacking horror stories and indulging in eerie Halloween activities. We hope you had a frightfully good time!
Cody Thomas (@its_a_feature_) 's Twitter Profile Photo

I'm starting to use GitHub Discussions (github.com/its-a-feature/…) and will be creating a public roadmap for Mythic too using GitHub Projects (github.com/users/its-a-fe…). Please keep an eye out and join in! :)

Matt Creel (@tw1sm) 's Twitter Profile Photo

New blog up to cover manual AD CS enumeration using ldapsearch and the new release of bofhound 🔍 posts.specterops.io/bofhound-ad-cs…