Introducing Ghostwriter Skills, a new collection of portable Agent Skills for common Ghostwriter workflows. The first release helps teams turn existing reports into templates, check templates for issues, review whether a project is ready for final reporting and draft an executive summary from report content. These skills handle repeatable steps so practitioners can spend more time on the analysis and judgment an assessment requires. Check out the latest from Christopher Maddalena to explore each skill and how to get started: https://ghst.ly/46zigYS
SpecterOps
Computer and Network Security
Alexandria, Virginia 34,238 followers
Know Your Adversary
About us
SpecterOps is the creator of BloodHound and a leader in Identity Risk Management. We use our deep expertise in adversary tradecraft to help organizations detect and remove critical attack paths before sophisticated attackers can take advantage of them. We call this Identity Attack Path Management, and we're deeply committing to helping security teams build this practice through industry-leading technology, research, training, and wide range of open source tools.
- Website
-
http://www.specterops.io
External link for SpecterOps
- Industry
- Computer and Network Security
- Company size
- 201-500 employees
- Headquarters
- Alexandria, Virginia
- Type
- Privately Held
- Founded
- 2017
- Specialties
- Red Team Operations, Penetration Testing, Hunt Operations, Breach Assessments, Active Directory Security, Security Research, Adversary Simulation, and Attack Path Management
Products
Locations
-
Primary
Get directions
100 N Pitt St
Alexandria, Virginia 22314, US
-
Get directions
307 3rd Ave S
Seattle, Washington 98104, US
Employees at SpecterOps
Updates
-
We're kicking off SO:Brief, a new video series delivering quick insights from SpecterOps experts on the security research and topics worth knowing. In our first installment, Michael Grafnetter looks at passkey phishing: what an attack can actually look like, why user interaction matters, and the important distinction with Windows Hello for Business passkeys. Watch the brief, then join Michael tomorrow, September 23, for The Red Teamer’s Guide to Passkeys to get the full technical breakdown: https://ghst.ly/4hDFeUS
-
New #BloodHoundBasics post courtesy of Mathieu S.! 🎉 As of v9.7 BH supports multiple destinations in Pathfindings. You can force a path to traverse a specific node. It is also possible to rearrange the order of the nodes a path must traverse. For more info 👉 https://ghst.ly/4cOBtt9
-
Our team is at #InfosecNashville 🤠 Stop by to say hi to the team, discuss your burning questions on identity attack path management & BloodHound, and grab some swag!
-
-
Four courses. Exclusive spooky swag. Evening events all week. Come for the training, stay for everything else. 🎃 Learn more about #SpecterBash: https://lnkd.in/gsuePjZk
-
-
Auditing Cilium network policies across a Kubernetes cluster usually means reading through dozens of YAML files and trying to hold it all in your head. We built CiliumHound to fix that. CiliumHound is a new BloodHound OpenGraph extension that ingests a folder of Cilium network policy files (YAML or JSON) and turns them into a searchable, namespace-scoped graph — so you can quickly answer questions like: ➡️ What can get into this isolated namespace, and how? ➡️ Which egress rules have no port restrictions? ➡️ What does this specific policy actually allow, in isolation from everything else applied to the namespace? It comes with a set of saved Cypher queries out of the box and includes example policies so you can try it out right away. Read the full writeup on the design decisions, CiliumHound usage, and where Andrew Luke is headed next (nodeSelector support, pathfinding between namespaces): https://lnkd.in/gREWSufp
-
Ghostwriter is getting a fresh new look. 👻 The upcoming v7.3.0 release brings a major UI refresh across nearly every part of the application, designed to make Ghostwriter easier to navigate, more accessible, and better organized. The refresh includes a new engagement bar, customizable sidebar with pinned work, a redesigned dashboard, improved accessibility, and updates across cards, tables, forms, menus, filters, and more. Ghostwriter v7.3.0 is currently in testing through September 30, and we want your feedback. Check out Christopher Maddalena's write up to get a closer look at what’s changing and learn how you can try it out: https://lnkd.in/g7-SpVKv
-
What does effective exposure management look like inside a large enterprise? On the latest episode of #KnowYourAdversary, Jared Atkinson and Justin Kohler sit down with Vladlen Rotshteyn to discuss why understanding exposure starts with visibility across assets, identities, vulnerabilities, and security tooling. They dig into prioritizing risk with context rather than vulnerability severity alone, how Attack Path Management and BloodHound can help provide a clearer picture of exposure, and why improving visibility can sometimes make your security metrics look worse before they get better. They also explore where AI fits into the picture and why strong security fundamentals still matter as new technology enters the environment. Listen to the full episode: https://lnkd.in/gxjypGuB
-
Identity-driven attacks are one of the most critical threat vectors in modern environments. Adversary Tactics: Identity-driven Offensive Tradecraft at #SpecterBash covers the full methodology for discovering and exploiting identity attack paths across on-premises and hybrid environments. Some attack paths are scarier than others. 👻 https://lnkd.in/gsuePjZk
-
-
AI is accelerating the speed of attacks while expanding the enterprise attack surface. At Infosec Nashville, Justin Kohler will explore what that means for defenders as AI-enhanced phishing, automated attacks, agents, non-human identities, and hidden trust reshape the security landscape. Join his session to learn why defenders need to shift focus to the identity layer across hybrid environments as detection-first approaches struggle to keep pace. https://lnkd.in/eJVy6Jv7
-