Co-founder of SpecterOps. Co-creator of BloodHound. bsky.app/profile/andyrobbins…

Seattle, WA
I'm on Bluesky here: bsky.app/profile/andyrobbins…
2
9
4,251
Andy Robbins retweeted
BloodHound is 10 🎉 To celebrate, creators @_wald0, @CptJesus & @harmj0y joined for a special two-part #KnowYourAdversary. They reminisce on the first attack graphs and look ahead to what’s next for BloodHound. 1️⃣: ghst.ly/4xT4WdA 2️⃣: ghst.ly/4zIIeqj
2
9
33
11,002
Andy Robbins retweeted
I can't believe it's already been 10 years, what an insane ride! At this point I'm sure we'll all have BloodHound etched on our tombstones (maybe @_wald0 will have 'Thought in graphs...' 😂) - it truly was an honor working on this project with these two <3
BloodHound is 10 🎉 To celebrate, creators @_wald0, @CptJesus & @harmj0y joined for a special two-part #KnowYourAdversary. They reminisce on the first attack graphs and look ahead to what’s next for BloodHound. 1️⃣: ghst.ly/4xT4WdA 2️⃣: ghst.ly/4zIIeqj
7
4
76
7,311
Andy Robbins retweeted
BloodHound turns 10 🎉 Congrats @_wald0, @CptJesus, @harmj0y Original pic 👇 taken on @BlackHatEvents #BHUSA arsenal.
Just saw a demo of bloodhound. Mind blowing
3
8
43
4,177
Andy Robbins retweeted
My SCCM BloodHound OpenGraph collector, ConfigManBearPig, is finally ready to share! It can enumerate all of the relay TAKEOVERs and a few CRED and ELEVATE techniques from Misconfiguration Manager with just a domain account. Let me know what you find! specterops.io/blog/2026/01/1…
5
74
177
15,508
Andy Robbins retweeted
Stack spoofing isn’t dead. Hear from @klezvirus at #BHEU on how modern detection still breaks, and unveils the first CET-compliant stack spoofing framework. Learn more ➡️ ghst.ly/4izmuou
2
20
45
5,738
Andy Robbins retweeted
See you all next week...excited to present with @breakfix at #BHEU! 💣
SCOM monitors critical systems, but insecure defaults make it a powerful attack vector. At #BHEU, @unsigned_sh0rt & @breakfix show how to abuse SCOM for credential theft, lateral movement, and domain escalation, plus how to defend it. ghst.ly/4aoggph
3
40
131
19,369
Andy Robbins retweeted
SCOM monitors critical systems, but insecure defaults make it a powerful attack vector. At #BHEU, @unsigned_sh0rt & @breakfix show how to abuse SCOM for credential theft, lateral movement, and domain escalation, plus how to defend it. ghst.ly/4aoggph
31
73
25,668
Andy Robbins retweeted
Just in time for the holidays, I wanted to share something that a lot of people have asked for: piped.video/playlist?list=PL… Short videos about Mythic development and customizations. This is just the start - I'll release a survey soon that'll get feedback for the next batch :)

ALT Turning Around GIF by HBO Max

2
18
46
5,844
Andy Robbins retweeted
Credential Guard was supposed to end credential dumping. It didn't. @bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more ⤵️ ghst.ly/4qtl2rm
11
335
729
137,765
Andy Robbins retweeted
In this post @_wald0 introduces PingOneHound, a BloodHound OpenGraph extension that allows users to visualize, audit, and remediate attack paths in their PingOne environment. The blog post also serves as an introduction to the PingOne architecture. specterops.io/blog/2025/10/2…
22
50
8,036
Andy Robbins retweeted
BloodHound isn't just for Active Directory anymore. 🤯 @SadProcessor dives into the BloodHound OpenGraph functionality & demonstrates the new PowerShell cmdlets added to the BloodHound Operator module to work with the OpenGraph feature. ghst.ly/4peTTrB
1
22
74
6,450
Andy Robbins retweeted
ICYMI: BloodHound OpenGraph, introduced with BloodHound v8.0, allows you to map attack paths across your entire tech stack. @JustinKohler10 & @_wald0 recently joined @_JohnHammond to discuss the new feature and share a demo. Watch the conversation 👉 ghst.ly/4fNZLDM
3
15
3,121
🚨 New #BloodHound shirt alert 🚨 ✅ - Unisex and ladies sizes available ✅ - Cool design :) ✅ - ALL profits go to charity: Hope for HIE, which supports families suffering the effects of hypoxic ischemic encephalopathy Get your shirt here: ghst.ly/bh8-tshirt
1
11
21
5,863
Andy Robbins retweeted
We are back with our BloodHound t-shirt fundraiser! 🙌 Grab your BloodHound 8.0 shirt today. All funds raised will go directly to @HopeforHIE, the global voice for families affected by Hypoxic Ischemic Encephalopathy. 👕: ghst.ly/bh8-tshirt
12
33
7,127
Andy Robbins retweeted
Check out my new blog on nested app authentication and brokered authentication.
Why should Microsoft's Nested App Authentication (NAA) should be on your security team's radar? @Icemoonhsv breaks down NAA and shows how attackers can pivot between Azure resources using brokered authentication. ghst.ly/45h2Zw3
2
17
41
12,905
Andy Robbins retweeted
Dear fellow pentesters & red teamers, How often do you run into a vCenter in your client’s environment? 🖥️ I just built one for vCenter - meet vCenterHound 🐾😉 This is just the beginning… more collectors and surprises are on the way. #Pentesting #RedTeam #BloodHound #vCenter
1
39
157
9,766
Andy Robbins retweeted
This post about MSSQLHound, a PowerShell collector that adds 7 new nodes and 37 new edges to BloodHound, details my experience and lessons learned designing and implementing the tool using OpenGraph and provides examples of how to research and discover MSSQL attack paths.
MSSQLHound leverages BloodHound's OpenGraph to visualize MSSQL attack paths with 7 new nodes & 37 new edges, all without touching the SharpHound & BloodHound codebases. @_Mayyhem unpacks this new feature in his blog post. 👇 ghst.ly/4leRFFn
29
93
8,042
Andy Robbins retweeted
MSSQL support just landed in BloodHound! You can now map out how attackers might use SQL servers to move laterally. This is incredibly useful in hybrid and legacy heavy environments. Let us know what you find. Learn more ➡️ ghst.ly/MSSQLHound
1
20
63
4,583
Andy Robbins retweeted
MSSQLHound leverages BloodHound's OpenGraph to visualize MSSQL attack paths with 7 new nodes & 37 new edges, all without touching the SharpHound & BloodHound codebases. @_Mayyhem unpacks this new feature in his blog post. 👇 ghst.ly/4leRFFn
2
52
133
16,327
Andy Robbins retweeted
More on BH OpenGraph: Ran into some issues when attempting to map objects collected with partial info back to existing BH objects. Built out a small tool that allows for connecting objects in a more flexible manner: github.com/G0ldenGunSec/Open…
1
24
59
6,264