Chris Thompson

506 posts

Chris Thompson banner
Chris Thompson

Chris Thompson

@_Mayyhem

Senior Security Researcher @SpecterOps https://t.co/Sz5fRYkX6u

Katılım Ağustos 2015
487 Takip Edilen2.8K Takipçiler
Sabitlenmiş Tweet
Chris Thompson
Chris Thompson@_Mayyhem·
My SCCM BloodHound OpenGraph collector, ConfigManBearPig, is finally ready to share! It can enumerate all of the relay TAKEOVERs and a few CRED and ELEVATE techniques from Misconfiguration Manager with just a domain account. Let me know what you find! specterops.io/blog/2026/01/1…
English
5
75
182
14.6K
Chris Thompson
Chris Thompson@_Mayyhem·
@miketerrill I'm not super familiar with this but it does sound like the exploit was an abuse of that functionality: #windows-re-and-bitlocker-recovery" target="_blank" rel="nofollow noopener">learn.microsoft.com/en-us/windows/…
English
1
0
3
323
Chris Thompson
Chris Thompson@_Mayyhem·
Very compelling read on OpenGraph's beginnings. The content is interesting, but also I just love Brandon's writing! It makes you feel like you're there on a personal journey instead of just dumping technical info onto the page, which I tend to do and would love to improve upon.
SpecterOps@SpecterOps

What does it take to build the foundation for a graph that can grow beyond Active Directory? In his latest blog post, Brandon Shearin reflects on a year building OpenGraph for BloodHound, & the work of turning ambiguity into architecture. Check it out ⤵️ ghst.ly/3QYKrvG

English
0
0
6
419
Chris Thompson retweetledi
SpecterOps
SpecterOps@SpecterOps·
"Red team" has become a catchall term. Some vendors mean pentesting. Others mean compliance theater. None of that tells you what actually matters: Would you detect an attacker once they're already in? @Ne0nd0g breaks it down ⤵️ ghst.ly/4uk1qaj
English
0
20
81
4.7K
Chris Thompson
Chris Thompson@_Mayyhem·
MSSQLHound runtime is down from 17 minutes to 17 seconds in my lab after rewriting the BloodHound collector in Go with Javier Azofra and added SOCKS proxying, Kerberos and NT hash auth, and pathfinding. Hope this is more useful for ops than PowerShell! Let me know how it goes!
SpecterOps@SpecterOps

If MSSQL isn't in your attack path visibility yet, this is your sign. @Mayyhem just shipped a major MSSQLHound upgrade with Javier Azofra Ovejero (github.com/jazofra): faster, cross-platform, and pathfinding-ready in BloodHound. Check it out! ghst.ly/4cUKgtJ

English
2
22
103
16.8K
Chris Thompson retweetledi
Jacob Paullus
Jacob Paullus@psycep_·
gopacket is live! Check it out, it is intended to be a full reimplementation of Impacket in Go (it is in beta please send me bug reports) github.com/mandiant/gopac…
English
7
125
421
60.4K
Chris Thompson retweetledi
SpecterOps
SpecterOps@SpecterOps·
BloodHound users: your query workflow just got better. With this latest update, @martinsohndk and @joeydreijer introduce multi-source loading, multi-server support, and dozens of new queries, now live in the Query Library. Check it out: ghst.ly/4vBic6c
English
0
6
17
2.9K
Chris Thompson retweetledi
SpecterOps
SpecterOps@SpecterOps·
Missed @jaredcatkinson & @JustinKohler10's talk at #SOCON2026? They announced BloodHound 9.0! Attack paths span SaaS, cloud, endpoints & identity providers. Attackers have exploited these connections for years. BloodHound 9.0 closes that gap. Learn how: ghst.ly/3OmSe5A
SpecterOps tweet media
English
0
22
77
5.8K
Chris Thompson retweetledi
SpecterOps
SpecterOps@SpecterOps·
Relayed NTLM creds are powerful, if you can use them. @senderend shows why browsers fail through ntlmrelayx SOCKS and introduces ghostsurf to make NTLM-authenticated web apps accessible. Read more ⤵️ ghst.ly/4tnJOtx
English
2
90
275
17.8K
Chris Thompson retweetledi
Lukas Klein | @rantasec.bsky.social
Check out GoLinHound: - Discovers Linux & SSH attack paths - Outputs OpenGraph JSON for BloodHound ingestion - Integrates with SharpHound and AzureHound data to unveil cross-technology attack paths github.com/RantaSec/golin…
English
2
34
76
4.1K
Chris Thompson retweetledi
SpecterOps
SpecterOps@SpecterOps·
Every Entra ID assessment ends here: “How do I get a token without triggering Conditional Access controls?” 🤔 @rbnroot built CAPSlock, an offline ROADrecon-based Conditional Access engine that simulates sign-ins & flags gaps without touching the tenant. ghst.ly/4aKIk64
English
3
89
278
29K
Chris Thompson retweetledi
SpecterOps
SpecterOps@SpecterOps·
Introducing BloodHound Scentry: BloodHound Enterprise + SpecterOps experts working alongside your team to eliminate attack paths and accelerate APM. Level 0 → Level 3 maturity in ~6 months. Not theory. Tradecraft. 🎯 Learn more ➡️ ghst.ly/bhscentry-tw
SpecterOps tweet media
English
1
12
27
2.8K
Chris Thompson retweetledi
Jonny Johnson
Jonny Johnson@JonnyJohnson_·
@_subTee reminded me that the Projected File System existed on Windows recently, so I decided to do a deep dive. Turns out - this is probably the best base technology for canary/deception features out there. There is also a splash of offensive use cases😎 @HuntressLabs Blog: huntress.com/blog/windows-p…
English
1
38
113
11.4K
Chris Thompson retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
I can't believe Microsoft killed one of my favorite labs in my Entra ID training 😭. The Azure CLI and Azure PowerShell are no longer FOCI clients. On a serious note: good for security!
English
6
28
115
15.2K
Chris Thompson
Chris Thompson@_Mayyhem·
@jannisj If it's breaking due to the new NTLM rejection, there should be a way to force the use of Kerberos by supplying a fully qualified domain name. Looks like there's an issue tracking this that might help: github.com/MSEndpointMgr/…
English
1
0
1
101
Jannis Jacobsen
Jannis Jacobsen@jannisj·
@_Mayyhem And after you upgrade to 2509, modern driver management breaks :/
English
1
0
0
115
Chris Thompson
Chris Thompson@_Mayyhem·
RIP SCCM hierarchy TAKEOVER-5: #adminservice-now-rejects-ntlm-authentication" target="_blank" rel="nofollow noopener">learn.microsoft.com/en-us/intune/c… github.com/subat0mik/Misc… It's a good idea to upgrade to 2509 ASAP, sysadmin friends! There's no other mitigation if you have an SMS Provider hosted remotely from the site server AFAIK.
English
12
40
102
12.7K
Chris Thompson retweetledi
Garrett
Garrett@unsigned_sh0rt·
I found unauthenticated bugs in MDT that can be abuse to coerce authenticaton from the host server or to leak creds stored in the deployment share's rules file. Instead of fixing the issues, Microsoft retired MDT. specterops.io/blog/2026/01/2…
English
2
56
125
17.8K