Garrett retweeted
At #OffensiveAICon, @harmj0y & @tifkin_ will explore optimized evasion attacks & their transferability across EDR products. They’ll share findings from reverse engineering four EDRs and experimenting with LLMs & GEPA to expand the search space for effective obfuscation.
5
22
1,929
Garrett retweeted
Replying to @MSNightmare2000
1
9
220
5,719
Garrett retweeted
Worried about your production agents going out of scope? Us too. AgentJudge is our agent hall monitor that stops out of scope tool calls before they execute. Before a tool runs, the judge reads the agent’s intent, the proposed call, and a rubric you define, then returns allow, deny, or ask (escalate to you). The agent stays autonomous; the judge is the guardrail. Available in the TUI today, UI updates coming to the Dreadnode Platform soon! 👀 Get Started: docs.dreadnode.io/getting-st… AgentJudge Docs: docs.dreadnode.io/tui/guard-… Related Research: dreadnode.io/research/scope-…
9
26
3,309
Garrett retweeted
Local AI is never down.
我的 Spark Cluster 还在线 😎
29
20
326
17,433
Garrett retweeted
ServiceNow won't let you query cleartext discovery credentials, not even as admin. @Tw1sm found a way to make the server hand them over anyway, no coercion or relay needed. Works on SSH keys, AWS keys, Entra secrets, and LDAP creds. Check it out ⤵️ ghst.ly/4y37KVo
1
68
188
13,554
Garrett retweeted
ConfigManBearPig 2.0 is out, a full Python rewrite built on OpenHound. Faster, runs on Linux, SOCKS proxy support, better BloodHound pathfinding for SCCM attacks. ➡️ ghst.ly/3RGyETm Catch @_Mayyhem demo-ing it live at #BHUSA Arsenal TOMORROW, Tue 8/4, 5:15pm, Station 6.
45
118
13,246
Garrett retweeted
I'm releasing a new Python rewrite of ConfigManBearPig, my BloodHound collector for SCCM, next week w/ a TON of upgrades (SOCKS, hash/kerb auth, CVE scan, threads, pathfind) and am presenting at Black Hat Arsenal next Tues. Come say hi and grab a sticker! blackhat.com/us-26/arsenal/s…
1
3
15
1,389
Garrett retweeted
Compromise one node in a Windows Server Failover Cluster and you've compromised all of them. @unsigned_sh0rt dug into why: shared credentials, forged tickets, and a full attack chain to own the cluster. Check it out! ghst.ly/4wSZSoW
50
162
9,458
Garrett retweeted
The ADHD dream career is being a highly paid consultant who swoops in, solves a complex crisis with a chaotic stroke of genius, and immediately exits before having to fill out the timesheets.
284
1,891
22,371
2,746,020
Garrett retweeted
We used this technique on an op recently, and I wanted to create a simple resource on it due to it being seldom covered but very useful. It's a cool way to get around various NTLM relay constraints when operating over C2 from low-privilege. See it here: specterops.io/blog/2026/07/1…
1
26
96
4,764
If you're at Blackhat USA next month, I'm giving a talk on the Wednesday. Currently working on the presentation and attempting to avoid other rabbit holes until it's done! Excited to talk about this 😈 #BHUSA blackhat.com/us-26/briefings…
1
4
30
1,972
Garrett retweeted
[TALK] My latest Black Hat Europe talk is now publicly available. If you can look past the painfully obvious anxiety and a speaker who occasionally sounds like his brain has stopped cooperating, you might find something useful. Who knows? piped.video/watch?v=tOVcScKu…
5
38
162
14,299
Garrett retweeted
Planning to cover abuse cases relevant to initial access, post-exploitation techniques, lateral movement, and privilege escalation in this one. I'll be talking at the speed of a professional auctioneer to cover all of it. Come through if you're in Vegas this year!
3
28
1,647
Garrett retweeted
What happens when a new Mythic agent can be generated, tested, and deployed in ~2 hours? @_xpn_ explores "disposable tooling" and the implications for offensive operations and defenders alike. Check out the latest from GhostWorks ⬇️ ghst.ly/4oMyrdC
24
86
16,307
Garrett retweeted
1
5
28
fable is a joke wtf
7
841
Garrett retweeted
I'm excited to be able to finally publish the public disclosure for CVE-2026-4387. Check out my blog on discovering the reuse of the state.kv file to get authenticated sessions with StrongDM (now fixed). specterops.io/blog/2026/06/0…
3
10
1,922
I guess it's dunk on MSRC day lol
2
24
979