GitHub isn’t just a code platform anymore. It’s a security boundary.
New from @jaredcatkinson: how GitHub creates real attack paths into repos, secrets, CI/CD, and even cloud environments.
Read more: https://t.co/E8sLYPmEKL
Just in time for the holidays, I wanted to share something that a lot of people have asked for: https://t.co/DfXyf2TTBp
Short videos about Mythic development and customizations. This is just the start - I'll release a survey soon that'll get feedback for the next batch :)
In this post @_wald0 introduces PingOneHound, a BloodHound OpenGraph extension that allows users to visualize, audit, and remediate attack paths in their PingOne environment. The blog post also serves as an introduction to the PingOne architecture.
https://t.co/BjD5DPiih1
@bill_e_ghote@SpecterOps More feature will be added in the future, but this is already available in BHE and BHCE.
Everything covered in this post should work in both version of BloodHound 👍
Hey you, ya you!! Have something cool to share? How about a submission to SO-CON 2025 - the CFP closes on Nov 15 (we cover travel + a free training seat!). It was a blast last year and we hope to see everyone again next April!
https://t.co/x2XuHovHmX
Part 4 of our Tier Zero webinar series is happening tomorrow! 🙌 Join @Jonas_B_K, @martinsohndk & @tifkin_ as they discuss the intricate world of Microsoft Exchange Server & AD CS.
Register ▶️ https://t.co/EwwmstE43k
Mine & @sabi_elezi's #MaLDAPtive presentation from @defcon is now posted on YouTube! LDAP obfuscation, deobfuscation & detection - all built on our 100% custom LDAP parser.
Recording: https://t.co/pDAqDUrAOF
Tool: https://t.co/ZoDhXt4AxT
@permisosecurity#LDAP#ClippyGotJokes
GOADv3 🏰 is almost ready !
You can now try the v3-beta version 🥳
📂 Repository : https://t.co/efjhSZddsa
📖 Documentation :
https://t.co/85kBU6q95u
What's new ? 🧵👇
Learn how you can now map hybrid Attack Paths from on-prem Active Directory to Azure Entra ID using BloodHound Community Edition & BloodHound Enterprise.
Check out @_wald0 & @JustinKohler10's full conversation w/ @_JohnHammond at https://t.co/JlrCWTVkZ6
You can now register for #SOCON2025! Save your spot at the conference and check out our onsite trainings.
Register today & take advantage of the 50% off early bird discount available until December 1.
▶️ https://t.co/0njiU2f3ac
Nine new functions in BARK:
Get-AllEntraRoles
Enable-EntraRole
Get-EntraDeviceRegisteredUsers
Get-IntuneManagedDevices
Get-IntuneRoleDefinitions
New-EntraIDAbuseTestUsers
New-EntraIDAbuseTestSPs
New-IntuneAbuseTestUsers
New-MSGraphAppRoleTestSPs
https://t.co/FwKiY6vuTv
Mythic3.3 has been in Beta for 6 weeks now, so it's time to officially release it! Over the past 6 weeks, @tifkin_ provided a LOT of amazing quality of life requests, so I wanted to highlight them in a new blog https://t.co/ZtkaUIEgzb. I think you're gonna really like it :)
For anyone that missed my @cloudvillage_dc talk ("Identity Theft is Not a Joke, Azure!"), I recorded a slightly extended version to put up on the @NetSPI YouTube page - https://t.co/RbKBFDXzYk
📆 Mark your calendar! #SOCON2025 is happening March 31-April 1. Join us for two days all about Attack Path Management.
Register today to get 50% off and learn about our CFP, opening Oct. 1st!
👉 https://t.co/nLesCvqBol