Rob Winchester

427 posts

Rob Winchester banner
Rob Winchester

Rob Winchester

@robwinchester3

Vice President @SpecterOps | Former USAF | Problem Solver

Katılım Ocak 2011
229 Takip Edilen1.3K Takipçiler
Rob Winchester retweetledi
SpecterOps
SpecterOps@SpecterOps·
Good morning from #SOCON2024! Follow along with us here this week and please share your experience using our hashtag. You can also now follow us on Instagram 👉 instagram.com/specterops.io
SpecterOps tweet mediaSpecterOps tweet mediaSpecterOps tweet media
English
0
8
11
2.4K
Rob Winchester retweetledi
SpecterOps
SpecterOps@SpecterOps·
We're thrilled to announce BloodHound Community Edition (CE) -- the next evolution of #BloodHound. Scheduled for release on 8/8, BloodHound CE has many new features & enhancements, making it easier for users to deploy, manage, and utilize. Learn more: ghst.ly/458lIGX
SpecterOps tweet media
English
6
115
273
32.3K
Rob Winchester retweetledi
SpecterOps
SpecterOps@SpecterOps·
There's still time to register for one of our six courses, including our Adversary Tactics courses! See our full listing of courses here: ghst.ly/blackhat2023
SpecterOps tweet media
English
0
4
2
1.8K
Rob Winchester retweetledi
Jared Atkinson
Jared Atkinson@jaredcatkinson·
I've been writing a bunch of Twitter threads recently & have been asked to codify them into blogposts. Here's one describing how there's more than meets the eye when it comes to API functions. My goal is to build on this post w/ some cool new ideas. posts.specterops.io/understanding-…
English
5
104
226
0
Rob Winchester retweetledi
Matt Hand
Matt Hand@matterpreter·
In our never-ending hunt for new persistence techniques, @mutantvillian and I spent some time digging into using preview handlers over the past few weeks. Today we're publishing our research along with detection guidance. posts.specterops.io/life-is-pane-p…
English
7
139
241
0
Rob Winchester retweetledi
Will Schroeder
Will Schroeder@harmj0y·
5 months ago @tifkin_ and I started looking into the security of Active Directory Certificate Services. Today we're releasing the results of that research- a blog post posts.specterops.io/certified-pre-… + a 140-page whitepaper and defensive audit tool (links at the top of the post) [1/6]
English
32
638
1.3K
0
Rob Winchester retweetledi
Andy Robbins
Andy Robbins@_wald0·
I'm extremely proud to announce The Attack Path Management Manifesto - our perspective, thoughts, and vision for directly dealing with the problem of Attack Paths: posts.specterops.io/the-attack-pat…
Andy Robbins tweet media
English
5
129
294
0
Rob Winchester retweetledi
Dwight Hohnstein
Dwight Hohnstein@djhohnstein·
Man in the Terminal - Leveraging environment $PATH variables to keylog, hijack SSH sessions, and more. Useful for post-ex activities on shared *nix jumpboxes or developer workstations. Blog: posts.specterops.io/man-in-the-ter…
English
3
158
335
0
Rob Winchester retweetledi
Joe Vest
Joe Vest@joevest·
I am incredibly excited to announce I will soon join Help Systems as Tech Director for Cobalt Strike. I look forward to starting this new journey and expect great things to come. Please help me share this great news @HelpSystemMN @CoreAdvisories #cobaltstrike #redteam #blueteam
Joe Vest tweet media
English
33
46
273
0
Rob Winchester retweetledi
Jonny Johnson
Jonny Johnson@JonnyJohnson_·
Happy Monday everyone! Today @matterpreter and I are releasing a joint blog where we dive deep into the methodology we used to uncover the technology that atsvc utilizes within scheduled tasks. Hope you enjoy! posts.specterops.io/abstracting-sc…
English
0
61
149
0
Rob Winchester
Rob Winchester@robwinchester3·
I wrote a blog talking about the "when" of building detections, a concept that doesn't always make into the detection development process. I discuss considerations of detections past, present, and future. posts.specterops.io/detections-of-…
English
1
21
75
0
Rob Winchester
Rob Winchester@robwinchester3·
@PyroTek3 You stopped this rabbit hole much earlier than I initially thought
English
2
0
5
0
Sean Metcalf
Sean Metcalf@PyroTek3·
Coding always seems to start with something simple like: "Determine how long ago something happened on a system." Easy. Done. Then... "Wait, that date/time is UTC. I need this converted to my current time zone" "Ok, I got this." Did you account for Daylight Savings Time?
English
4
0
17
0
Rob Winchester
Rob Winchester@robwinchester3·
This course taught me how much more I had to learn about PowerShell and Windows internals related to it. Definitely recommend you take advantage of this exceptional material. Makes me proud to be part of a company so dedicated to furthering the industry
SpecterOps@SpecterOps

Despite its incredible security enhancements, PowerShell continues to be abused by adversaries. A strong knowledge of PowerShell enables defenders to effectively manage and respond to its abuse. (1/4)

English
0
0
4
0
Rob Winchester retweetledi
Max Harley
Max Harley@0xdab0·
Just released Satellite, a payload hosting and proxy software for red team operations. In the blog post, I discuss the feature set of Satellite as well as why an operator would choose it over Apache or Nginx. posts.specterops.io/satellite-a-pa…
English
8
157
347
0