hotnops
@hotnops.bsky.social
150 followers 76 following 13 posts
Does stuff at @specterops Cloud security research
Posts Media Videos Starter Packs
Reposted by hotnops
specterops.io
The AD CS security landscape keeps evolving, and so does our tooling. 🛠️

Valdemar Carøe drops info on Certify 2.0, including a suite of new capabilities and refined usability improvements. ghst.ly/45IrBxI
Certify 2.0 - SpecterOps
Certify 2.0 features a suite of new capabilities and usability enhancements. This blogpost introduces changes and features additions.
ghst.ly
Reposted by hotnops
specterops.io
Red teamers know the drill: endless file churning, hunting for passwords & tokens. 🔍

Meet DeepPass2, our new secret scanning tool that goes beyond structured tokens to catch those tricky free-form passwords too. Read Neeraj Gupta's blog post for more. ghst.ly/40HLNNA
What’s Your Secret?: Secret Scanning by DeepPass2  - SpecterOps
Discover DeepPass2 - a secret scanning tool combining BERT-based model and LLMs to detect free-form passwords, and other structured tokens and secrets with high accuracy.
ghst.ly
hotnops.bsky.social
The best creds are the ones you simply ask for =)
specterops.io/blog/2025/07...
Reposted by hotnops
nathanmcnulty.com
Looks like the Entra QR code authentication method is going GA 🥳

They've also added some great guidance on suppressing the camera permission prompt for iOS :)

learn.microsoft.com/...
Reposted by hotnops
xpnsec.com
XPN @xpnsec.com · Jun 18
My second post for the month is now live 🎉
specterops.io
Get the scoop on the incoming Administrator Protection for Windows 11.

@xpnsec.com covers the architecture, access controls, and why some legacy UAC bypass techniques remain effective in his latest blog post. ghst.ly/44mw5JM
Administrator Protection Review - SpecterOps
Microsoft will be introducing Administrator Protection into Windows 11. This post explores security considerations for red teamers.
ghst.ly
Reposted by hotnops
frichetten.com
A little over a year ago I published research on how you could leverage non-production AWS API endpoints to enumerate permissions without logging to CloudTrail. A year later...I'm still finding them. Red Teamers, these can be super useful and really up your game!
Reposted by hotnops
davidfowl.com
We’re about to take C# to the next level!

#dotnet #csharp
A command line interface Some c# code
Reposted by hotnops
specterops.io
Did you miss #SOCON2025? Did you have a favorite talk you'd like to rewatch?

🎥 All presentations from SO-CON 2025 are now live at ghst.ly/socon25-talks.

💻 Slides for each talk are available at ghst.ly/socon25-slides.
Reposted by hotnops
fabian.bader.cloud
Application Based Authentication on Microsoft Entra Connect Sync is near. With this change you will be able to use a TPM backed certificate in Entra Connect Sync for authentication.

This is a welcome change to prevent the compromise of this high privileged account.

#Entra #Certificate
Reposted by hotnops
ajf8729.com
Did you know you can send LAPS passwords to Entra on Server OS? Neither did @adamgrosstx.bsky.social or I until yesterday! Just need to hybrid join the server(s) and set the GPO to backup to "AAD"! Neat!
hotnops.bsky.social
Can you use the on-behalf-of flow to bypass conditional access policies? If the middleware app satisfies conditional access, can it exchange an access token to an otherwise blocked backend resource? It turns out... no. No it can't. The CAP will kick in when the middleware app uses the OBO flow.
Reposted by hotnops
fabian.bader.cloud
A new dedicated resource application to enable Active Directory to Microsoft Entra ID sync using Microsoft Entra Connect Sync or Cloud Sync is coming 😱

In the announcement the mentioned reason is "upcoming security hardening"...

6bf85cfa-ac8a-4be5-b5de-425a0d0dc016

#EntraID
Reposted by hotnops
50501movement.bsky.social
🚨 Join the #PeoplesMovement this Saturday #April19 for a National Day of Action!

Yes, people will be in the streets again. Others will be organizing food drives, volunteering at shelters, hosting teach-ins, and more.

Hundreds of events are already listed at www.FiftyFifty.one/events.
Reposted by hotnops
specterops.io
Understanding Windows access tokens could be your best defense. At @cackalackycon.bsky.social, @atomicchonk.bsky.social will be peeling back the layers on potato exploits that threat actors use for privilege escalation.

Check out the schedule to learn more ➡️ ghst.ly/4jzjlnI
Reposted by hotnops
unsignedsh0rt.bsky.social
Had some fun with PDQ deploy/inventory credential decryption and wrote about it here: unsigned-sh0rt.net/posts/pdq_cr... thanks to
@dru1d.bsky.social for writing a BOF out of the POC

tl;dr get admin on PDQ box, decrypt privileged creds
Decrypting PDQ credentials | unsigned_sh0rt's blog
Walkthrough of how PDQ credentials encrypts service credentials
unsigned-sh0rt.net
Reposted by hotnops
atomicchonk.bsky.social
Everybody’s using AI assistants and tools these days, but do most of us understand how our text-based input is being interpreted and processed? Check out my latest blog post for a basic intro to text interpretation by AI assistants. www.corgi-Corp.com/post/tokeniz...
Tokenizing the Sandwich Debate: How NLP Models Weigh In on Hot Dogs
Get the gist for Natural Language Processing (NLP) and how tokenization plays a factor
www.corgi-Corp.com
Reposted by hotnops
specterops.io
Think NTLM relay is a solved problem? Think again.

Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
Reposted by hotnops
tw1sm.bsky.social
Nothing new, but formalized some operator notes on Entra ID/Azure tradecraft I've found to be exceptionally useful on ops. Overlooked this myself for quite some time and thought others in the same boat might find it worth a read! 📖

medium.com/specter-ops-...
An Operator’s Guide to Device-Joined Hosts and the PRT Cookie
Introduction
medium.com
Reposted by hotnops
xpnsec.com
XPN @xpnsec.com · Apr 6
1 year anniversary at SpecterOps, so many personal and professional achievements in a short space of time. My advice for anyone getting into this field, try and make sure that you work companies and colleagues that push you beyond your comfort level. \o/
Reposted by hotnops
specterops.io
We are excited to see everyone at #SOCON2025 tomorrow! 🙌

Get the details on everything you need to know before arriving at the conference: specterops.io/so-con