Raj Patel

60 posts

Raj Patel

Raj Patel

@GrayHatKiller

Adversary Simulation @SpecterOps

Columbus, OH Katılım Temmuz 2015
242 Takip Edilen206 Takipçiler
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
MSSQL has always been a favorite target. Now it ships its own egress channel. @gershsec's latest research breaks down how SQL Server 2025's native AI features enable exfil, NTLM coercion, and C2 transport, all functioning as intended. Read more 👇 ghst.ly/4e2L3JX
English
0
65
224
16.5K
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
U2U powers UnPAC-the-Hash and chains into Shadow Credentials and ADCS ESC attacks, but most resources skip the “how.” @GrayHatKiller breaks down Kerberos U2U auth from the RFC to Windows’ divergences—and why modern attacks rely on it. ghst.ly/4egy4TT
English
0
21
38
2.5K
Raj Patel
Raj Patel@GrayHatKiller·
Checkout my blog which deep dives into Kerberos U2U authentication, with packet-level breakdowns of UnPAC-the-Hash and RDP with NLA specterops.io/blog/2026/06/0…
English
0
15
18
1.9K
Raj Patel retweetledi
Alex Neff
Alex Neff@al3x_n3ff·
SPN-less RBCD with NetExec🔥 While classic RBCD requires a computer account, you can use U2U authentication to perform RBCD with a normal user account, if a computer account is not available. Thanks to @azoxlpf, you can now perform this attack with NetExec as well🚀
Alex Neff tweet media
English
4
66
282
16K
Raj Patel retweetledi
Matt Creel
Matt Creel@Tw1sm·
Vibed up a quick tool to visualize and stack significant red/blue events that occurred during an assessment. Have always liked including a high-level visual like this in debriefs but made them by hand in the past using something like draw[.]io
English
6
18
91
7.5K
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
WSL2 is a powerful attacker hideout because it runs as a separate Hyper-V VM, and defenders rarely monitor it. Daniel Mayer explains how attackers pivot into WSL2 and what it took to build tooling that works across WSL2 versions. Read more ⤵️ ghst.ly/45fPUma
English
9
172
725
104.1K
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
The Azure AD Broker plays a key role in Entra ID sign-in & token handling, but how well do we really understand it? @winternl_t unpacks its on-disk cache, how to decode it, & the security implications. 🔐 ghst.ly/4oTR4v5
English
1
34
103
10K
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
Credential Guard was supposed to end credential dumping. It didn't. @bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more ⤵️ ghst.ly/4qtl2rm
English
11
336
738
137.1K
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
Lateral movement getting blocked by traditional methods? @werdhaihai just dropped research on a new lateral movement technique using Windows Installer Custom Action Server, complete with working BOF code. ghst.ly/4pN03PG
English
1
114
281
32.4K
Raj Patel retweetledi
Garrett
Garrett@unsigned_sh0rt·
frankensteined some code together to make a couple BOFs that set shadowcreds/rbcd for when proxying was acting up...maybe they're useful to you they dont clean up at the moment so that'll have to get added at some point...ops not done yet lol github.com/garrettfoster1…
English
4
36
132
6.5K
Raj Patel retweetledi
Garrett
Garrett@unsigned_sh0rt·
I pushed updates to SCCMHunter as part of my Arsenal demo at #BHUSA today! New features include a relay module for TAKEOVER-5 and a community contribution to coerce client push from a *nix host for ELEVATE-2. github.com/garrettfoster1….
English
1
52
136
7.3K
Raj Patel retweetledi
Chris Thompson
Chris Thompson@_Mayyhem·
This post about MSSQLHound, a PowerShell collector that adds 7 new nodes and 37 new edges to BloodHound, details my experience and lessons learned designing and implementing the tool using OpenGraph and provides examples of how to research and discover MSSQL attack paths.
SpecterOps@SpecterOps

MSSQLHound leverages BloodHound's OpenGraph to visualize MSSQL attack paths with 7 new nodes & 37 new edges, all without touching the SharpHound & BloodHound codebases. @_Mayyhem unpacks this new feature in his blog post. 👇 ghst.ly/4leRFFn

English
0
30
94
8K
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
MSSQLHound leverages BloodHound's OpenGraph to visualize MSSQL attack paths with 7 new nodes & 37 new edges, all without touching the SharpHound & BloodHound codebases. @_Mayyhem unpacks this new feature in his blog post. 👇 ghst.ly/4leRFFn
English
2
52
134
16.3K
Raj Patel retweetledi
Yuval Gordon
Yuval Gordon@YuG0rd·
Many missed this on #BadSuccessor: it’s also a credential dumper. I wrote a simple PowerShell script that uses Rubeus to dump Kerberos keys and NTLM hashes for every principal-krbtgt, users, machines. no DCSync required, no code execution on DC.
English
9
154
488
38.5K
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
BloodHound v8.0 is here! 🎉 This update introduces BloodHound OpenGraph, revolutionizing Identity Attack Path Management by exposing attack paths throughout your entire tech stack, not just AD/Entra ID. Read more from @JustinKohler10: ghst.ly/bloodhoundv8 🧵: 1/7
English
5
59
147
27.1K
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
The industry recommendation for DPAPI backup key compromise remediation is to destroy and rebuild the environment. @sou_predictable explores why this is the current industry guidance. ghst.ly/40DTLHk
English
1
50
125
6.8K
Raj Patel retweetledi
SpecterOps
SpecterOps@SpecterOps·
Classic NTLM relay problem: Stuck on port 445/TCP, can't use WMI (needs 135/TCP), and dumping hashes triggers EDR alerts. So what's a stealthy attacker to do? 🤔 Our latest blog post explores evasive alternatives beyond the old techniques. ghst.ly/3ILR1l0
English
2
119
315
14.5K
Raj Patel retweetledi
klez
klez@KlezVirus·
Had some time and decided to take a shot at Fabian’s RAITrigger project. After a look into the RPC internals, I put together a super lightweight C# version (no NtApiDotNet), plus a C++ and BOF version. Enjoy! github.com/klezVirus/RAIW…
English
3
73
196
15.4K