BloodHound 8.0 update adds BloodHound OpenGraph — expanding attack path visibility beyond AD and Entra ID. Learn More

  • Contact Us
  • Support
  • Blog
Book a Demo
  • Platform
    • BloodHound Enterprise

      Advance from mapping to eliminating attack paths with the enterprise platform that delivers at scale

      Identity Attack Path Management
      Privilege Zones
      BloodHound Feature Comparisons
      Integrations
      Interactive Demo

      BloodHound Community Edition

      Start mapping attack paths with the open-source tool that started it all

      GitHub
      OpenGraph
      Documentation
      Join the Community on Slack
      Cover of the State of APM report

      State of Attack Path Management

      SpecterOps's inaugural report, highlighting the biggest growing problem facing the security community: Identity Security.

      Learn more
  • Services & Tradecraft
    • OFFENSIVE SERVICES

      Red Team
      Purple Team
      AI Red Team
      Penetration Testing
      Maturity Assessments
      Attack Path Assessment

      TRAINING & TRADECRAFT

      Adversary Tactics

      Red Team Operations
      Identity-Driven Offensive Tradecraft
      Detection
      Tradecraft Analysis

      Adversary Perspectives

      Active Directory
      Azure

      JOIN US

      SpecterBash 2025

      Trainings, evening sessions, and more with a Halloween twist to ring in the spooky time of year.

      More Info
  • Solutions
    • SOLUTIONS

      Privileged Access Governance & Compliance
      Eliminate Lateral Movement
      Manage Identity Risk
      Secure Scaling
      Mergers & Acquisitions

      INDUSTRIES

      Public Sector
      Healthcare
      Financial Services

      PARTNERS & INTEGRATIONS

      Partners
      Integrations

      RESOURCES

      Attack Path Management Maturity Model

      Evaluate your ability to stop identity-based attacks

      Read the Whitepaper
  • Community
    • Our Commitment to 
Open Source

      Committed to advancing the community through open source contributions, cutting-edge research, and knowledge sharing

      OPEN SOURCE TOOLS

      BloodHound Community Edition
      Mythic
      Ghostwriter
      Nemesis 2.0
      See All Tools

      Join the Conversation

      Learn from others and share your story on the BloodHoundGang Slack Community

      Connect with us

      OPEN SOURCE RESEARCH

      Ghostwriter illustration

      Collaborative Editing

      Ghostwriter now supports real-time collaborative editing for observation...

      More Info
  • Company
    • ABOUT US

      Our Mission
      The SpecterOps Difference
      Customers
      Team
      News

      GET IN TOUCH

      Careers
      Contact Us

      PRESS RELEASE

      Specter Ops logo on a blue background

      SpecterOps Expands the Power of Attack Path Management to Reduce Identity Risk Across the Enterprise with BloodHound OpenGraph and v8.0

      Learn More

      FEATURED EVENT

      Gartner Security & Risk Management Summit

      September 22 - 24, 2025 | London UK

      More Info
  • Resources
    • RESEARCH

      Case Studies
      White Papers
      Tools
      Datasheets
      View All

      BLOG

      Research & Tradecraft
      BloodHound
      Industry Insights
      Company Updates
      View All

      EVENTS

      SpecterOps Events
      Webinars
      Meetups
      Talks
      View All

      BLOG

      Specter Ops logo on a blue background

      Fueling the Fight Against Identity Attacks

      When we founded SpecterOps, one of our core principles was to build a...

      Read article

      RESOURCES

      The Renaissance of NTLM Relay Attacks

      NTLM relay attacks have been around for a long time. While many security...

      Read the Whitepaper
  • Book a Demo
  • Contact Us
    Support
    Blog
  • Book a Demo
< Back to Blog
Default Author Image

Daniel Heinsen

See the latest by Daniel Heinsen

Image for post titled Entra Connect Attacker Tradecraft: Part 3

Entra Connect Attacker Tradecraft: Part 3

TL;DR Attackers can exploit Entra Connect sync accounts to hijack device userCertificate properties, enabling device impersonation...

By: Daniel Heinsen
Jul 30, 2025 • 16 min read
Read Post
Image for post titled Update: Dumping Entra Connect Sync Credentials

Update: Dumping Entra Connect Sync Credentials

TL;DR Microsoft has recently changed how Entra Connect Sync authenticates to Entra ID. This blog post...

By: Daniel Heinsen
Jun 9, 2025 • 10 min read
Read Post
Image for post titled Entra Connect Attacker Tradecraft: Part 2

Entra Connect Attacker Tradecraft: Part 2

Now that we know how to add credentials to an on-premises user, lets pose a question:...

By: Daniel Heinsen
Jan 22, 2025 • 11 min read
Read Post
Image for post titled Attacking Entra Metaverse: Part 1

Attacking Entra Metaverse: Part 1

This is part one in a two (maybe three…) part series regarding attacker tradecraft around the...

By: Daniel Heinsen
Dec 13, 2024 • 8 min read
Read Post
Image for post titled An AWS Administrator Identity Crisis: Part 1

An AWS Administrator Identity Crisis: Part 1

BLUF: Every attack path needs a destination. This is a formalized way of describing destinations in...

By: Daniel Heinsen
Jun 28, 2024 • 11 min read
Read Post
Image for post titled I’d TAP That Pass

I’d TAP That Pass

Summary: Given that: Temporary Access Passes (TAP) are enabled in the Azure AD tenant AND You...

By: Daniel Heinsen
Mar 29, 2023 • 22 min read
Read Post
Image for post titled AWS ReadOnlyAccess: Not Even Once

AWS ReadOnlyAccess: Not Even Once

By: Daniel Heinsen
Aug 27, 2021 • 9 min read
Read Post
Image for post titled Updates to Ghostwriter: UI and Operation Logs

Updates to Ghostwriter: UI and Operation Logs

By: Daniel Heinsen
Sep 30, 2020 • 7 min read
Read Post
Image for post titled Persistent AWS access with role chain juggling

Persistent AWS access with role chain juggling

By: Daniel Heinsen
Jul 16, 2020 • 7 min read
Read Post

Never miss an update

  • Sign Up For Updates From SpecterOps

  • This field is for validation purposes and should be left unchanged.

Platform

BloodHound Enterprise

Identity Attack Path Management
Privilege Zones
BloodHound Feature Comparison
Integrations
Interactive Demo

BloodHound Community Edition

GitHub
OpenGraph
Documentation
Join the Community on Slack

Services and Tradecraft

OFFENSIVE SERVICES

Red Team
Purple Team
AI Red Team
Penetration Testing
Maturity Assessments
Attack Path Assessment

TRAINING & TRADECRAFT

Adversary Tactics

Red Team Operations
Identity-Driven Offensive Tradecraft
Detection
Tradecraft Analysis

Adversary Perspectives

Active Directory
Azure

Solutions

SOLUTIONS

Privileged Access Governance and Compliance
Eliminate Lateral Movement
Manage Identity Risk
Secure Scaling
Mergers & Acquisitions

INDUSTRIES

Public Sector
Healthcare
Financial Services

PARTNERS & INTEGRATIONS

Partners
Integrations

Resources

RESEARCH

Case Studies
White Papers
Tools
Datasheets
View All

BLOG

Research & Tradecraft
BloodHound
Industry Insights
Company Updates
View All

EVENTS

SpecterOps Events
Webinars
Meetups
Talks
View All

Platform

BloodHound Enterprise

Identity Attack Path Management
Privilege Zones
BloodHound Feature Comparison
Integrations
Interactive Demo

BloodHound Community Edition

GitHub
OpenGraph
Documentation
Join the Community on Slack

Follow Us

Company

ABOUT US

Our Mission
The SpecterOps Difference
Customer
Team
News

GET IN TOUCH

Careers
Contact Us

Community

OPEN SOURCE TOOLS

Our Commitment to Open Source
BloodHound Community Edition
Mythic
Ghostwriter
Nemesis 2.0
See All Tools

Follow Us

Copyright 2025 Specter Ops, Inc. All Rights Reserved.

Terms of Service
|
Privacy Policy
|
Trust Center