@_sigil@IAMERICAbooted Yes, it does require some high privileges, but it started as a research to prove that this permission can be dangerous (some organizations claim its not)...
Anyway, interesting point:)
Going to release two new tools next week that will be showcased at Blackhat Arsenal USA 2025 and Defcon 33 Demo Labs 😃
1️⃣ EntraGoat - a deliberately vulnerable Entra ID environment - Built together with Jonathan Elkabas.
2️⃣ SAMLSmith - Built together with @ericonidentity
Today, together with Jonathan Elkabas, we're releasing EntraGoat - A Deliberately Vulnerable Entra ID Environment.
Your own hands-on Entra lab for identity attack simulation.
Built for red teams, blue teams and identity nerds.
Check it out here👉github.com/semperis/entra…
I'm SO hyped to finally make MSSQLHound public! It's a new BloodHound collector that adds 37 new edges and 7 new nodes for MSSQL attack paths using the new OpenGraph feature for 8.0!. Let me know what you find with it!
- github.com/SpecterOps/MSS…
- specterops.io/blog/2025/07/2…
Golden dMSA: One key to rule them all
Just found a new flaw in Windows Server 2025's dMSAs that lets attackers brute-force ALL managed service account passwords with 1024 attempts. This research builds on the awesome research Golden gMSA (@YuG0rd ).
semperis.com/blog/golden-dm…
21K Followers 2K FollowingPrincipal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK).
And yes, opinions are my own ;)
2K Followers 729 FollowingChief Identity Architect @SemperisTech. Microsoft Security MVP, Entra nerd. Part-time hiker, full-time dad and partner. Opinions expressed are from my cat.
47K Followers 2K FollowingChief Technical Innovation Officer @crowdstrike. Windows Internals author and trainer. He/Him. RTs are not endorsements, opinions are my own.
20K Followers 437 FollowingHacker, Infosec Researcher, Military Affairs & History, PowerShell, AD and Azure pwner, Creator of Nishang and others :)
Founder @alteredsecurity
2K Followers 729 FollowingChief Identity Architect @SemperisTech. Microsoft Security MVP, Entra nerd. Part-time hiker, full-time dad and partner. Opinions expressed are from my cat.
5K Followers 196 FollowingDoing things @wiz_io And then doing more things at home | Failed research blog: https://t.co/j2HT1Tpscs |
Trying to be more chill🧘♀️
30K Followers 205 FollowingHacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
49K Followers 336 FollowingSecurity researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc. Mastodon: @[email protected]
62K Followers 292 FollowingA kiwi coding mimikatz & kekeo
github: https://t.co/eS3LVgU6i0
Head of security services @banquedefrance
Tweets are my own and not the views of my employer
21K Followers 2K FollowingPrincipal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK).
And yes, opinions are my own ;)