We used this technique on an op recently, and I wanted to create a simple resource on it due to it being seldom covered but very useful. It's a cool way to get around various NTLM relay constraints when operating over C2 from low-privilege. See it here: specterops.io/blog/2026/07/1…
1
26
96
4,764
Logan Goins retweeted
Need to circumvent Constrained Language Mode while operating in an environment with App Control for Business enabled? gist.github.com/enigma0x3/22… (Was reported, is by design). Enjoy!
4
33
136
11,797
Logan Goins retweeted
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/askWAM
7
75
233
18,494
Speaking at RedTreat 2026 was a blast. Amazing people, amazing talks, best conference.
1
38
1,004
Logan Goins retweeted
ServiceNow won't let you query cleartext discovery credentials, not even as admin. @Tw1sm found a way to make the server hand them over anyway, no coercion or relay needed. Works on SSH keys, AWS keys, Entra secrets, and LDAP creds. Check it out ⤵️ ghst.ly/4y37KVo
1
68
188
13,554
Logan Goins retweeted
Watching fellow Specter @0xthirteen talk about WMI Post-Ex capabilities!
2
6
69
5,090
CVE-2026-34348 exploitation demo from my #BHUSA "Pass-the-Passkey Family of Attacks" talk: WebAuthn assertion from recent YubiKey authentication is extracted from Windows Event Log and replayed against Microsoft Entra ID using Passkey Injector. Whitepaper: specterops.io/passkeys
16
188
847
123,496
Logan Goins retweeted
Happening now! @bagelbyt3s is kicking of his briefing session presenting original research into a new Attack Path technique that results in full WSUS infrastructure takeover. #BHUSA
2
14
37
3,815
Logan Goins retweeted
Compromise one node in a Windows Server Failover Cluster and you've compromised all of them. @unsigned_sh0rt dug into why: shared credentials, forged tickets, and a full attack chain to own the cluster. Check it out! ghst.ly/4wSZSoW
50
162
9,458
Logan Goins retweeted
Need to do an NTLM relay over C2 but local priv-esc isn't possible? @_logangoins new post walks through relaying NTLM auth out of a network and back in through red team infra to bypass traditional relay controls, plus how defenders actually stop it. specterops.io/blog/2026/07/1…
1
66
225
12,354
Logan Goins retweeted
Registration for training at #BHUSA 2026 is officially open, and we are bringing a full slate of adversary-focused courses to Las Vegas. 🎰 Early reg. pricing ends May 22, so now is the time to lock in your seat. 🧵 Links to each course ⤵️
1
5
15
4,739
Logan Goins retweeted
Yes! We have a library of other scenarios and testing ranges available as well. I'm happy to talk through what we offer whenever you'd like. Linking our 2-pager on that service below: specterops.io/wp-content/upl…
2
11
1,195
Logan Goins retweeted
CopyFail (CVE-2026-31431) in Go. In case you want to get root from a static binary without Python as a dependency. github.com/badsectorlabs/cop…
16
220
1,084
78,748
Just added krb5 auth over ADWS in my tool SOAPy. I noticed since SOAPy released 2 yrs ago with the first ADWS python code nobody had implemented krb5 auth in python. Check it out here, and stay tuned for an upcoming blog post + big release 👀 github.com/logangoins/SOAPy/
1
39
121
9,814
Logan Goins retweeted
Tired of fighting K8s for security research? Spin up K8s environments in @badsectorlabs' Ludus with: * Falco + Grafana/Loki detections * @SpecterOps' Mythic C2 callbacks * @grahamhelton3's nodes/proxy RCE demo * Common misconfigs out of the box github.com/heilancoos/ludus_…
1
10
58
6,969
Logan Goins retweeted
New Titanis release => github.com/trustedsec/Titani… The new Dsrep lets you dump secrets from AD, Ldap supports queries for DNS records and timestamp conversions, Dcom supports dotted-property notation, along with other enhancements and fixes.
2
30
85
6,025
Logan Goins retweeted
A debate in the BloodHound Slack: can you attribute the originating host from an ADWS query? 🤨 Challenge accepted. Part 5B continues the ADWS blind spot: Event 5156 recovers the attacker’s real IP in ~60ms. 🕵️ Check out my latest post… huntress.com/blog/ldap-activ…
1
8
24
2,858
Logan Goins retweeted
SCCM is everywhere, but realistic testing environments aren’t. In his latest blog post, @_Mayyhem expands on work by @synzack21 and @badsectorlabs with a Ludus-based SCCM lab for research and attack path testing. Read more ⬇️ ghst.ly/4bYltDo
23
54
4,187
Logan Goins retweeted
I added an SCCM central admin site, child site, passive site server, secondary site, and remote system roles to @synzack21 and @badsectorlabs Ludus lab so you can skip the manual deployment. It's vuln to almost every technique in Misconfiguration Manager. specterops.io/blog/2026/04/0…
1
19
64
2,345