home.social

#bloodhound — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bloodhound, aggregated by home.social.

fetched live
  1. 📢 Un acteur malveillant utilise l'IA (Claude Opus) pour développer et tester des techniques d'évasion EDR
    📝 ## 🔍 Contexte

    Publié le 2 juin 2026 par la **Sophos Counter Threat Unit (CTU)**, cet ar...
    📖 cyberveille : cyberveille.ch/posts/2026-06-0
    🌐 source : sophos.com/en-us/blog/pointing
    #BloodHound #Claude_Opus #Cyberveille

  2. Reset — прохождение сложной машины от Tryhackme

    Годная машина на тему Windows AD, Kerberos. В начале разведки получаем доступ к гостевой шаре. Оттуда достаем файл с паролем, но не знаем от какой учетной записи. Проводим разведку юзеров, получаем список и находим 1 пользователя к которому подходит этот пароль. Далее проводим разведку с помощью BloodHound и по цепочке получаем доступ к нескольким аккаунтам у последнего есть права Unconstrained Delegation Privilege на доменный компьютер. С помощью механизма S4U2self, запрашиваем билет на имя администратора и захватываем компьютер.

    habr.com/ru/articles/1041620/

    #windows #reset #kerberos #bloodhound #impacket #hashcat #asrep_roasting #delegation #activedirectory #active_directory

  3. Reset — прохождение сложной машины от Tryhackme

    Годная машина на тему Windows AD, Kerberos. В начале разведки получаем доступ к гостевой шаре. Оттуда достаем файл с паролем, но не знаем от какой учетной записи. Проводим разведку юзеров, получаем список и находим 1 пользователя к которому подходит этот пароль. Далее проводим разведку с помощью BloodHound и по цепочке получаем доступ к нескольким аккаунтам у последнего есть права Unconstrained Delegation Privilege на доменный компьютер. С помощью механизма S4U2self, запрашиваем билет на имя администратора и захватываем компьютер.

    habr.com/ru/articles/1041620/

    #windows #reset #kerberos #bloodhound #impacket #hashcat #asrep_roasting #delegation #activedirectory #active_directory

  4. Reset — прохождение сложной машины от Tryhackme

    Годная машина на тему Windows AD, Kerberos. В начале разведки получаем доступ к гостевой шаре. Оттуда достаем файл с паролем, но не знаем от какой учетной записи. Проводим разведку юзеров, получаем список и находим 1 пользователя к которому подходит этот пароль. Далее проводим разведку с помощью BloodHound и по цепочке получаем доступ к нескольким аккаунтам у последнего есть права Unconstrained Delegation Privilege на доменный компьютер. С помощью механизма S4U2self, запрашиваем билет на имя администратора и захватываем компьютер.

    habr.com/ru/articles/1041620/

    #windows #reset #kerberos #bloodhound #impacket #hashcat #asrep_roasting #delegation #activedirectory #active_directory

  5. The scariest thing in your Active Directory isn't what you can see. It's the permissions you thought you removed.
    At BSides312, Kyprianos Vasilopoulos and Nikos Vourdas are showing how legacy DACL misconfigs and recycled accounts create hidden escalation paths in AD. They built a BloodHound integration to find them first.
    May 16th. Chicago.
    🎟️ bsides312.org
    #BSides312 #InfoSec #CyberSecurity #ActiveDirectory #RedTeam #BloodHound #Chicago

  6. The scariest thing in your Active Directory isn't what you can see. It's the permissions you thought you removed.
    At BSides312, Kyprianos Vasilopoulos and Nikos Vourdas are showing how legacy DACL misconfigs and recycled accounts create hidden escalation paths in AD. They built a BloodHound integration to find them first.
    May 16th. Chicago.
    🎟️ bsides312.org
    #BSides312 #InfoSec #CyberSecurity #ActiveDirectory #RedTeam #BloodHound #Chicago

  7. The scariest thing in your Active Directory isn't what you can see. It's the permissions you thought you removed.
    At BSides312, Kyprianos Vasilopoulos and Nikos Vourdas are showing how legacy DACL misconfigs and recycled accounts create hidden escalation paths in AD. They built a BloodHound integration to find them first.
    May 16th. Chicago.
    🎟️ bsides312.org
    #BSides312 #InfoSec #CyberSecurity #ActiveDirectory #RedTeam #BloodHound #Chicago

  8. The scariest thing in your Active Directory isn't what you can see. It's the permissions you thought you removed.
    At BSides312, Kyprianos Vasilopoulos and Nikos Vourdas are showing how legacy DACL misconfigs and recycled accounts create hidden escalation paths in AD. They built a BloodHound integration to find them first.
    May 16th. Chicago.
    🎟️ bsides312.org
    #BSides312 #InfoSec #CyberSecurity #ActiveDirectory #RedTeam #BloodHound #Chicago

  9. The scariest thing in your Active Directory isn't what you can see. It's the permissions you thought you removed.
    At BSides312, Kyprianos Vasilopoulos and Nikos Vourdas are showing how legacy DACL misconfigs and recycled accounts create hidden escalation paths in AD. They built a BloodHound integration to find them first.
    May 16th. Chicago.
    🎟️ bsides312.org
    #BSides312 #InfoSec #CyberSecurity #ActiveDirectory #RedTeam #BloodHound #Chicago

  10. Думаем графами с IPAHound

    Всем привет, меня зовут Михаил Сухов, я участник команды PT SWARM. Нам в команде все чаще встречается инфраструктура, построенная на базе альтернативных реализаций службы каталога Microsoft Active Directory. Одной из таких реализаций, заслуженно получившей большое распространение является FreeIPA. В ходе работы с FreeIPA стало очевидно, что можно изучать еще и архитектурные особенности, которые сильно отличаются от AD. Так появился IPAHound — наш аналог BloodHound для FreeIPA. За основу был взят проект BloodHound Legacy с поддержкой PKI. Мы неоднократно использовали IPAHound в своих проектах по поиску уязвимостей. В этой статье я расскажу о нашем инструменте. Также посмотрим на различные способы анализа связей, облегчающие продвижение в FreeIPA.

    habr.com/ru/companies/pt/artic

    #ipahound #freeipa #ldap #sudo #selinux #kerberos #pentest #ald pro #bloodhound

  11. Думаем графами с IPAHound

    Всем привет, меня зовут Михаил Сухов, я участник команды PT SWARM. Нам в команде все чаще встречается инфраструктура, построенная на базе альтернативных реализаций службы каталога Microsoft Active Directory. Одной из таких реализаций, заслуженно получившей большое распространение является FreeIPA. В ходе работы с FreeIPA стало очевидно, что можно изучать еще и архитектурные особенности, которые сильно отличаются от AD. Так появился IPAHound — наш аналог BloodHound для FreeIPA. За основу был взят проект BloodHound Legacy с поддержкой PKI. Мы неоднократно использовали IPAHound в своих проектах по поиску уязвимостей. В этой статье я расскажу о нашем инструменте. Также посмотрим на различные способы анализа связей, облегчающие продвижение в FreeIPA.

    habr.com/ru/companies/pt/artic

    #ipahound #freeipa #ldap #sudo #selinux #kerberos #pentest #ald pro #bloodhound

  12. Думаем графами с IPAHound

    Всем привет, меня зовут Михаил Сухов, я участник команды PT SWARM. Нам в команде все чаще встречается инфраструктура, построенная на базе альтернативных реализаций службы каталога Microsoft Active Directory. Одной из таких реализаций, заслуженно получившей большое распространение является FreeIPA. В ходе работы с FreeIPA стало очевидно, что можно изучать еще и архитектурные особенности, которые сильно отличаются от AD. Так появился IPAHound — наш аналог BloodHound для FreeIPA. За основу был взят проект BloodHound Legacy с поддержкой PKI. Мы неоднократно использовали IPAHound в своих проектах по поиску уязвимостей. В этой статье я расскажу о нашем инструменте. Также посмотрим на различные способы анализа связей, облегчающие продвижение в FreeIPA.

    habr.com/ru/companies/pt/artic

    #ipahound #freeipa #ldap #sudo #selinux #kerberos #pentest #ald pro #bloodhound

  13. Кто выпустил гончую. Ищем следы коллекторов BloodHound в логах Windows

    Служба каталогов Active Directory остается одной из самых популярных целей как среди злоумышленников, так и среди специалистов по Red Teaming и пентестеров. С выходом новых версий операционных систем семейства Windows продолжают появляться новые векторы атак на AD, например атаки на Delegated Managed Service Accounts (dMSA) в 2025-м. В ходе каждой атаки есть этап сбора информации, обнаружение которого является более сложной задачей, чем кажется на первый взгляд. Согласно аналитическому отчету нашего сервиса MDR за 2025 год в целом обнаружение данного этапа атак затруднено из-за большого количества ложных срабатываний, что снижает качество обнаружения и уменьшает вероятность предотвращения атаки, особенно в больших инфраструктурах с тысячами активов. Меня зовут Степан Ляхов, я работаю старшим инженером SOC в «Лаборатории Касперского». В этой статье я хочу рассмотреть один из самых популярных инструментов для сбора информации о домене Active Directory, разобрать, какие следы он оставляет в журналах и как обнаружить его активность.

    habr.com/ru/companies/kaspersk

    #Bloodhound #active_directory #enumerate #siem #soc #журналы_windows #sharphound

  14. Кто выпустил гончую. Ищем следы коллекторов BloodHound в логах Windows

    Служба каталогов Active Directory остается одной из самых популярных целей как среди злоумышленников, так и среди специалистов по Red Teaming и пентестеров. С выходом новых версий операционных систем семейства Windows продолжают появляться новые векторы атак на AD, например атаки на Delegated Managed Service Accounts (dMSA) в 2025-м. В ходе каждой атаки есть этап сбора информации, обнаружение которого является более сложной задачей, чем кажется на первый взгляд. Согласно аналитическому отчету нашего сервиса MDR за 2025 год в целом обнаружение данного этапа атак затруднено из-за большого количества ложных срабатываний, что снижает качество обнаружения и уменьшает вероятность предотвращения атаки, особенно в больших инфраструктурах с тысячами активов. Меня зовут Степан Ляхов, я работаю старшим инженером SOC в «Лаборатории Касперского». В этой статье я хочу рассмотреть один из самых популярных инструментов для сбора информации о домене Active Directory, разобрать, какие следы он оставляет в журналах и как обнаружить его активность.

    habr.com/ru/companies/kaspersk

    #Bloodhound #active_directory #enumerate #siem #soc #журналы_windows #sharphound

  15. Кто выпустил гончую. Ищем следы коллекторов BloodHound в логах Windows

    Служба каталогов Active Directory остается одной из самых популярных целей как среди злоумышленников, так и среди специалистов по Red Teaming и пентестеров. С выходом новых версий операционных систем семейства Windows продолжают появляться новые векторы атак на AD, например атаки на Delegated Managed Service Accounts (dMSA) в 2025-м. В ходе каждой атаки есть этап сбора информации, обнаружение которого является более сложной задачей, чем кажется на первый взгляд. Согласно аналитическому отчету нашего сервиса MDR за 2025 год в целом обнаружение данного этапа атак затруднено из-за большого количества ложных срабатываний, что снижает качество обнаружения и уменьшает вероятность предотвращения атаки, особенно в больших инфраструктурах с тысячами активов. Меня зовут Степан Ляхов, я работаю старшим инженером SOC в «Лаборатории Касперского». В этой статье я хочу рассмотреть один из самых популярных инструментов для сбора информации о домене Active Directory, разобрать, какие следы он оставляет в журналах и как обнаружить его активность.

    habr.com/ru/companies/kaspersk

    #Bloodhound #active_directory #enumerate #siem #soc #журналы_windows #sharphound

  16. Full Metal Mayrhoffen in the Tyrolean Alps

    (photo credit: Full Entertainment GmbH) A fantastic week of snow-covered slopes, blazing riffs, and great vibes is coming to an end: in the Mayrhofen-Hippach holiday region in the Zillertal Valley of Tyrol Full Metal Mayrhofen took place once again from March 23 to 28 – and what a success it was!Monday kicks off with the launch of the Europahaus as a new venue: following an opening set by DJ Markus Babbel and The Biest Jörg Michael, Dragony and Bloodhound get the “Hall of […]

    metalphotos.org/2026/04/01/ful

  17. Full Metal Mayrhoffen in the Tyrolean Alps

    (photo credit: Full Entertainment GmbH) A fantastic week of snow-covered slopes, blazing riffs, and great vibes is coming to an end: in the Mayrhofen-Hippach holiday region in the Zillertal Valley of Tyrol Full Metal Mayrhofen took place once again from March 23 to 28 – and what a success it was!Monday kicks off with the launch of the Europahaus as a new venue: following an opening set by DJ Markus Babbel and The Biest Jörg Michael, Dragony and Bloodhound get the “Hall of […]

    metalphotos.org/2026/04/01/ful

  18. Full Metal Mayrhoffen in the Tyrolean Alps

    (photo credit: Full Entertainment GmbH) A fantastic week of snow-covered slopes, blazing riffs, and great vibes is coming to an end: in the Mayrhofen-Hippach holiday region in the Zillertal Valley of Tyrol Full Metal Mayrhofen took place once again from March 23 to 28 – and what a success it was!Monday kicks off with the launch of the Europahaus as a new venue: following an opening set by DJ Markus Babbel and The Biest Jörg Michael, Dragony and Bloodhound get the “Hall of […]

    metalphotos.org/2026/04/01/ful

  19. Full Metal Mayrhoffen in the Tyrolean Alps

    (photo credit: Full Entertainment GmbH) A fantastic week of snow-covered slopes, blazing riffs, and great vibes is coming to an end: in the Mayrhofen-Hippach holiday region in the Zillertal Valley of Tyrol Full Metal Mayrhofen took place once again from March 23 to 28 – and what a success it was!Monday kicks off with the launch of the Europahaus as a new venue: following an opening set by DJ Markus Babbel and The Biest Jörg Michael, Dragony and Bloodhound get the “Hall of […]

    metalphotos.org/2026/04/01/ful

  20. Full Metal Mayrhoffen in the Tyrolean Alps

    (photo credit: Full Entertainment GmbH) A fantastic week of snow-covered slopes, blazing riffs, and great vibes is coming to an end: in the Mayrhofen-Hippach holiday region in the Zillertal Valley of Tyrol Full Metal Mayrhofen took place once again from March 23 to 28 – and what a success it was!Monday kicks off with the launch of the Europahaus as a new venue: following an opening set by DJ Markus Babbel and The Biest Jörg Michael, Dragony and Bloodhound get the “Hall of […]

    metalphotos.org/2026/04/01/ful

  21. ----------------

    🔎 AI: Integrating LLMs into Offensive Security Workflows

    Summary

    This blog outlines practical integration of large language models into offensive security engagements. Authors describe improving public proof‑of‑concept Model Context Protocol (MCP) servers for BloodHound and Burp Suite to support real‑world testing, and present LLM CLI usage patterns that enable agentic execution across reconnaissance, data enrichment, attack chaining, and reporting.

    Technical specifics
    • MCP servers: Existing MCP server projects for BloodHound and Burp Suite were adapted to work in offensive engagements, enabling LLMs to fetch, query, and reason over structured data such as Active Directory graphs and proxied web traffic.
    • LLM CLI agents: Modern CLIs (examples cited include Gemini CLI, Claude Code, and OpenAI’s Codex) shift models from single‑shot responders to autonomous operators capable of chaining actions: run a tool, parse output, decide next steps, and continue until objectives are met.
    • Example capabilities: An LLM connected to an AD graph via a MCP server can rapidly enumerate privilege escalation paths that would otherwise require hours of manual review. When paired with Burp Suite MCP, LLMs can correlate requests/responses across sessions to accelerate vulnerability triage. The authors also describe an NTLM relaying Gemini extension that demonstrates chaining of attack steps.

    Operational characteristics
    • Scope of access: An LLM CLI can operate on any tool or artifact the host environment exposes—OS utilities, custom scripts, open‑source offensive tooling, and locally hosted services—then interpret outputs to guide successive actions.
    • Agentic execution model: Gemini’s agentic design emphasizes iterative, feedback‑driven workflows where the model determines subsequent commands based on intermediate results rather than relying on a single prompt.

    What was demonstrated
    • Improved MCP integrations for BloodHound and Burp Suite adapted from public proof‑of‑concept servers.
    • A proof‑of‑concept Gemini extension automating NTLM relay orchestration.
    • Use cases spanning AD privilege path identification, web traffic correlation, automated triage, and multi‑step attack choreography.

    Limitations & considerations (as presented)
    • The writeup focuses on capabilities and demonstrated integrations; implementation specifics and environmental constraints are described at a conceptual level. The examples show how LLMs can reduce manual effort and expand coverage when granted appropriate tool access.

    🔹 llm #mcp #bloodhound #burpsuite #ntlm

    🔗 Source: armadin.com/blog-posts/automat

  22. Recently, I wrote a write-up for the vulnerable machine from #VulNyx called Controler. It’s a medium-level #Windows machine. #Enumeration begins with the Kerberos account, which I use to gain initial system access. Through further Active Directory enumeration, I #exploit replication rights, ultimately extracting the Domain Administrator’s password hash and gaining full administrative control.

    Solving this machine took me some time, but I learned a lot. I touched on new tools like #BloodHound, delved a bit deeper into Active Directory, and, in general, kept my #pentesting skills in check.

    If you are starting in #cybersecurity, I would definitely recommend checking some VMs from VulNyx.

    medium.com/@thecybercraft/vuln

  23. Recently, I wrote a write-up for the vulnerable machine from #VulNyx called Controler. It’s a medium-level #Windows machine. #Enumeration begins with the Kerberos account, which I use to gain initial system access. Through further Active Directory enumeration, I #exploit replication rights, ultimately extracting the Domain Administrator’s password hash and gaining full administrative control.

    Solving this machine took me some time, but I learned a lot. I touched on new tools like #BloodHound, delved a bit deeper into Active Directory, and, in general, kept my #pentesting skills in check.

    If you are starting in #cybersecurity, I would definitely recommend checking some VMs from VulNyx.

    medium.com/@thecybercraft/vuln

  24. Recently, I wrote a write-up for the vulnerable machine from #VulNyx called Controler. It’s a medium-level #Windows machine. #Enumeration begins with the Kerberos account, which I use to gain initial system access. Through further Active Directory enumeration, I #exploit replication rights, ultimately extracting the Domain Administrator’s password hash and gaining full administrative control.

    Solving this machine took me some time, but I learned a lot. I touched on new tools like #BloodHound, delved a bit deeper into Active Directory, and, in general, kept my #pentesting skills in check.

    If you are starting in #cybersecurity, I would definitely recommend checking some VMs from VulNyx.

    medium.com/@thecybercraft/vuln

  25. 🛠️ Tool
    ===================

    Executive summary: ADTrapper is a self-contained Active Directory security analysis platform that ingests Windows authentication logs, applies a library of detection rules, and provides interactive visualizations and integration points for AD graph data. The project emphasizes detection coverage for credential-based abuse and certificate-related attacks and supports import of BloodHound/SharpHound collections for enriched analysis.

    Technical details and key features:
    • Detection ruleset: Over 54 detection rules covering brute force, password spray, privilege escalation indicators, ADCS/certificate abuse events, and suspicious account behaviors.
    • Data inputs: Primary intake is Windows authentication/event logs; optional enrichment from AD enumeration data and uploaded SharpHound/BloodHound collections to map relationships.
    • Visualization: Force-directed graphs expose account/computer relationships and authentication paths to aid investigation and threat hunting.
    • Architecture overview: Front-end built with Next.js and TypeScript, storage backed by a relational DB (migrations present), and the application distributed as a containerized package for self-hosted use.

    How it works conceptually:
    • Logs are parsed into structured events and correlated against the rule set to produce alerts and anomalies.
    • Graph data from SharpHound is merged with log-derived edges to reveal potential attack paths and privilege escalation chains.
    • ADCS-related events are analyzed to surface certificate enrollment anomalies or suspicious CA activity indicative of certificate-based attacks.

    Use cases:
    • Incident investigation focused on authentication anomalies and lateral movement paths.
    • SOC triage for credential stuffing, account takeover, and certificate abuse scenarios.
    • Enrichment of BloodHound analyses with actual authentication telemetry to validate observed paths.

    Limitations and considerations:
    • The project accepts anonymous uploads; operators should assess privacy and operational risks before using public instances.
    • Detection efficacy depends on log completeness and AD enrichment quality; absent telemetry reduces rule coverage.
    • No managed deployment guarantees are provided; platform is intended for self-hosted analysis and evaluation.

    References and signals:
    • Notable integrations: SharpHound/BloodHound, AD CS event analysis, force-directed graph visualization.

    🔹 tool #ActiveDirectory #ADCS #BloodHound #security

    🔗 Source: github.com/MHaggis/ADTrapper

  26. 🛠️ Tool
    ===================

    Executive summary: AzureHound is an open-source Go-based data collection tool (distributed precompiled for Windows, Linux and macOS) that enumerates Entra ID and Azure resources using the Microsoft Graph and Azure REST APIs. It produces JSON output consumable by BloodHound to visualize relationships and potential attack paths for privilege escalation.

    Key features:
    • Automated enumeration of identities, groups, role assignments and Azure resources via Microsoft Graph and Azure REST API.
    • JSON export format compatible with BloodHound for graph-based analysis of potential attack paths.
    • Focus on discovering indirect escalation vectors across Entra ID and ARM-managed resources.

    Technical implementation:
    • Written in Go and uses authenticated queries to both Microsoft Graph (identity plane) and Azure Resource Manager (control plane).
    • Collects data points such as users, service principals, role assignments, subscriptions, resource groups and permissions relationships, then normalizes them to JSON for downstream graph analysis.
    • Does not require execution from within the target tenant because the APIs it queries are externally accessible given appropriate credentials.

    Use cases:
    • Red teams and penetration testers use AzureHound to map attack surface and privilege paths in preparation for controlled assessments.
    • Adversaries with initial access can run AzureHound to accelerate discovery of high-value principals and misconfigurations enabling lateral movement or escalation.

    Limitations:
    • Requires credentials or tokens that grant API access; the scope of data returned is limited by the permissions associated with those credentials.
    • Enumerated data quality depends on API rate limits and permission scoping; not all environmental context (e.g., private artifacts outside ARM) may be captured.

    Detection and logging notes:
    • Activities appear as Microsoft Graph and ARM API calls in Azure control-plane logs; monitoring API call patterns, unusual service principal usage, and large-scale enumeration queries can surface misuse.
    • The article highlights mapping of AzureHound behaviors to the MITRE ATT&CK framework and notes how Cortex XSIAM and related products can enhance detection and incident response.

    References and tags:
    • Tool: AzureHound; Integration: BloodHound; Data sources: Microsoft Graph, Azure REST API

    🔹 AzureHound #BloodHound #MicrosoftGraph #CortexXSIAM #tool

    🔗 Source: unit42.paloaltonetworks.com/th

  27. 🛠️ Tool
    ===================

    Executive summary: SpecterOps outlines a practical approach to deception planning by extending BloodHound’s attack-path mapping into third‑party technologies via OpenGraph. The piece emphasizes using mapped attack paths to place believable deception artifacts and mentions a small utility, deceptionClone, for prototyping deception paths.

    Technical context: BloodHound provides graph-based discovery of user/computer relationships in Active Directory, and OpenGraph generalizes that model to represent dependencies and privileges in non-AD systems. By modeling third-party services and their access relationships, defenders gain visibility into chains of abuse that span both AD and external systems.

    Key capabilities described:
    • Mapping of chained privileges and discovery paths across AD and third‑party systems using OpenGraph-enhanced graphs.
    • Identification of realistic locations for deception artifacts (canary tokens, honey accounts, honey endpoints) that sit on existing reconnaissance paths.
    • Use of deceptionClone to create lightweight deception replicas for testing how an attacker would discover and follow a fake path.

    Technical implementation (conceptual):
    The article frames OpenGraph as a schema/collection approach that models nodes and edges representing principals, services, and permission relationships beyond AD objects. This conceptual model enables defenders to trace potential reconnaissance sequences and privilege escalations across heterogeneous systems without requiring procedural details.

    Use cases:
    • Converting irrevocable or business-justified attack paths into detection opportunities by planting believable deception artifacts along those paths.
    • Validating the discoverability and context of deception artifacts by simulating attacker reconnaissance with deceptionClone.
    • Prioritizing remediation versus deception based on whether a mapped path can be fully removed or should be instrumented for detection.

    Limitations and considerations:
    • The approach depends on accurate modeling of third‑party relationships; incomplete data will yield blind spots.
    • Deceptions must be sufficiently realistic and contextual; simply placing decoys without mapping can produce low‑value signals or false positives.

    References and tags:
    SpecterOps blog post by Ben Schroeder; acknowledgement to Josh Prager for review. #tool #bloodhound #OpenGraph #deception #attack_path

    🔗 Source: specterops.io/blog/2025/12/23/

  28. Rook: Exodus #9 Review
    Arachnid Takes Over With Terrifying Power

    Brooooo… lean in real close because this one right here? This Rook: Exodus #9 joint is straight up WILD. I’m talkin’ “call your cousins, grab the popcorn, brace your soul” wild. Geoff Johns and Jason Fabok...
    comiccrusaders.com/comic-books
    #Arachnid #Bloodhound #Comic Review #GEOFF JOHNS #ghost machine #horror comics #Image Comics #JASON FABOK #Rook Exodus #Stag #Warden helmets

  29. Rook: Exodus #9 Review
    Arachnid Takes Over With Terrifying Power

    Brooooo… lean in real close because this one right here? This Rook: Exodus #9 joint is straight up WILD. I’m talkin’ “call your cousins, grab the popcorn, brace your soul” wild. Geoff Johns and Jason Fabok...
    comiccrusaders.com/comic-books
    #Arachnid #Bloodhound #Comic Review #GEOFF JOHNS #ghost machine #horror comics #Image Comics #JASON FABOK #Rook Exodus #Stag #Warden helmets

  30. The Guardian: ‘Are they going to eat me alive?’: trail runners become prey in newest form of hunting

    "...Would you like to be chased by a pack of hounds? It’s a question often put to highlight the cruelty of hunting, because the answer would seem to be no. Or so you would think.

    Yet increasing numbers of people are volunteering to be chased across the countryside by baying bloodhounds in what could soon be the only legal way to hunt with dogs in England and Wales, rather than pursuing animals or their scents...."

    #trailrunning #sports #bloodhound #hunting

    theguardian.com/uk-news/2025/n

  31. The Guardian: ‘Are they going to eat me alive?’: trail runners become prey in newest form of hunting

    "...Would you like to be chased by a pack of hounds? It’s a question often put to highlight the cruelty of hunting, because the answer would seem to be no. Or so you would think.

    Yet increasing numbers of people are volunteering to be chased across the countryside by baying bloodhounds in what could soon be the only legal way to hunt with dogs in England and Wales, rather than pursuing animals or their scents...."

    #trailrunning #sports #bloodhound #hunting

    theguardian.com/uk-news/2025/n

  32. The Guardian: ‘Are they going to eat me alive?’: trail runners become prey in newest form of hunting

    "...Would you like to be chased by a pack of hounds? It’s a question often put to highlight the cruelty of hunting, because the answer would seem to be no. Or so you would think.

    Yet increasing numbers of people are volunteering to be chased across the countryside by baying bloodhounds in what could soon be the only legal way to hunt with dogs in England and Wales, rather than pursuing animals or their scents...."

    #trailrunning #sports #bloodhound #hunting

    theguardian.com/uk-news/2025/n

  33. The Guardian: ‘Are they going to eat me alive?’: trail runners become prey in newest form of hunting

    "...Would you like to be chased by a pack of hounds? It’s a question often put to highlight the cruelty of hunting, because the answer would seem to be no. Or so you would think.

    Yet increasing numbers of people are volunteering to be chased across the countryside by baying bloodhounds in what could soon be the only legal way to hunt with dogs in England and Wales, rather than pursuing animals or their scents...."

    #trailrunning #sports #bloodhound #hunting

    theguardian.com/uk-news/2025/n

  34. The Guardian: ‘Are they going to eat me alive?’: trail runners become prey in newest form of hunting

    "...Would you like to be chased by a pack of hounds? It’s a question often put to highlight the cruelty of hunting, because the answer would seem to be no. Or so you would think.

    Yet increasing numbers of people are volunteering to be chased across the countryside by baying bloodhounds in what could soon be the only legal way to hunt with dogs in England and Wales, rather than pursuing animals or their scents...."

    #trailrunning #sports #bloodhound #hunting

    theguardian.com/uk-news/2025/n

  35. 🛠️ Tool
    ===================

    Executive summary: PingOneHound is an OpenGraph extension for BloodHound Community Edition and BloodHound Enterprise designed to discover, analyze, and help remediate identity-based attack paths inside PingOne organizations. The work was carried out by SpecterOps researchers using a Ping Identity–provided PingOne environment.

    Technical details:
    • Purpose: Map PingOne objects (organization, environments, users, groups, roles, applications) into a graph model consumable by BloodHound to reveal chains of authorization and authentication that can be abused.
    • Primary mechanics: PingOne supports identity federation standards such as SAML and OIDC, enabling authentication from one system and authorization by another; these federated flows expand the potential attack surface across trust boundaries.
    • Vocabulary modeled: organization (top level), environment (contains users/groups/roles/apps), the auto‑created Administrators environment, users, groups, and role assignments.

    Key features of PingOneHound:
    • Graph ingestion of PingOne environment objects into BloodHound-compatible schemas.
    • Identification of role assignment propagation rules and group membership behaviors that affect privilege paths.
    • Visibility into federation‑driven paths that reach into or out of a PingOne instance.

    Implementation concepts:
    • The extension maps PingOne API objects into nodes and relationships, preserving distinctions between direct group membership and nested group structures.
    • The model encodes that role assignments are delegated only to direct group members; nested group membership does not confer those roles, and attribute‑based automatic group membership is blocked for groups that hold role assignments.

    Use cases:
    • Red teaming and purple team exercises focused on identity abuse in cloud IdPs.
    • Defender analysis to enumerate risky role assignments, overly broad group configurations, and federation trust paths.

    Limitations and considerations:
    • Behavior modeled is constrained by PingOne configuration and API visibility; findings depend on the available object graph from the environment provided.
    • The extension surfaces paths but does not by itself exploit them; operationalization requires complementary tools and context.

    🔹 PingOne #BloodHound #PingOneHound #SpecterOps #tool

    🔗 Source: specterops.io/blog/2025/10/20/

  36. 🎙️ Mathieu Saulnier sur BloodHound v8 et OpenGraph !
    Au menu : chemins d'attaque au-delà d'Active Directory, collecteurs pour One Password/Snowflake/Jamf, et un cas réel édifiant où 60 000 utilisateurs pouvaient devenir admin du domaine en 3 étapes.
    "Les attaquants pensent en graphe, les défenseurs en liste" - visualiser change tout.

    🎧 Web: polysecure.ca/posts/episode-0x
    🎧 Spotify: open.spotify.com/episode/7fYu0
    🎧 YouTube: youtu.be/zzoFVuK2GzQ

    #Cybersécurité #BloodHound #InfoSec #ThreatHunting

  37. 🛠️ Tool
    ===================

    Opening: NetworkHound is an Active Directory network topology analyzer designed to enumerate computer objects from Domain Controllers, resolve hostnames to IPs using multiple DNS methods, perform network scanning and service validation, and export results as BloodHound‑compatible OpenGraph JSON.

    Key Features:
    • AD enumeration of computer objects, SIDs and hostnames
    • Multiple DNS resolution methods to increase hostname/IP coverage
    • TCP port scanning with service identification and concurrent threads
    • HTTP/HTTPS validation with optional SSL certificate extraction
    • SMB connectivity validation, share enumeration and server info collection
    • Shadow‑IT discovery via subnet scanning
    • Export to OpenGraph JSON consumable by BloodHound for graph analysis

    Technical Implementation:
    NetworkHound leverages impacket for all Active Directory authentication flows (password, NTLM hash, Kerberos). AD queries are issued against a specified Domain Controller to list computer objects and site/subnet metadata. Host resolution combines DNS queries and AD name mappings to maximize discovery accuracy. A threaded TCP scanner enumerates open ports and fingerprints services; optional modules perform HTTP(S) probing and SMB validation, including share enumeration and basic server information collection. The exporter constructs nodes and edges in an OpenGraph JSON schema compatible with BloodHound ingestion.

    Use Cases:
    • Red‑team reconnaissance to map internal AD network topology and service exposure
    • Blue team asset discovery and gap analysis for unmanaged devices (shadow‑IT)
    • Enrichment of BloodHound data with network and service context for improved attack path analysis

    Installation/Setup:
    A Python 3.8+ toolchain is required and dependencies are installed via pip3 install -r requirements.txt. Impacket is a hard dependency for AD authentication and LDAP/SMB interactions.

    Limitations:
    NetworkHound requires valid domain credentials or Kerberos tickets to query AD; unauthenticated enumeration is limited. SSL certificate extraction increases scan time and may generate noticeable network traffic. Large networks may need tuning of thread counts and scan timeouts to avoid disruption.

    References:
    Impacket for AD auth; BloodHound OpenGraph JSON format for graph ingestion.

    🔹 tool #ActiveDirectory #SMB #impacket #BloodHound

    🔗 Source: github.com/mordavid/NetworkHou

  38. #infosecurity #pentest #bloodhound

    BloodHound Query Library (queries.specterops.io/)

    A collection of Cypher queries designed to help BloodHound users to unlock the full potential of the BloodHound platform by creating an open query ecosystem.

    Blog: specterops.io/blog/2025/06/17/

  39. #infosecurity #pentest #bloodhound

    BloodHound Query Library (queries.specterops.io/)

    A collection of Cypher queries designed to help BloodHound users to unlock the full potential of the BloodHound platform by creating an open query ecosystem.

    Blog: specterops.io/blog/2025/06/17/

  40. #infosecurity #pentest #bloodhound

    BloodHound Query Library (queries.specterops.io/)

    A collection of Cypher queries designed to help BloodHound users to unlock the full potential of the BloodHound platform by creating an open query ecosystem.

    Blog: specterops.io/blog/2025/06/17/

  41. Fermented Friday: 2025 Winking Lizard Beer Tour 16 – Thirsty Dog Blood Hound Orange IPA Pint Glass (172)

    I am such a sucker for citrus IPAs, and this one is no expectation. Yes, you get the bitterness, but the citrus flavor balances well with it.

  42. Fermented Friday: 2025 Winking Lizard Beer Tour 16 – Thirsty Dog Blood Hound Orange IPA Pint Glass (172)

    I am such a sucker for citrus IPAs, and this one is no expectation. Yes, you get the bitterness, but the citrus flavor balances well with it.