blog category

Blog

image for Will WebClient Start

Research & Tradecraft

Will WebClient Start

TL;DR WebClient is a common targeted service for NTLM relay attacks. In this post we will...

By: Steven Flores
Aug 19, 2025 • 31 min read
Read Post
image for Pantheon Introduction: A Guide and Script Collection for Mythic Eventing

Blog

Pantheon Introduction: A Guide and Script Collection for Mythic Eventing

TL;DR Mythic Eventing automates repetitive tasks during red team operations (RTO). This blog documents the eventing...

By: Gavin Kramer
Aug 15, 2025 • 9 min read
Read Post
image for Juicing ntds.dit Files to the Last Drop

Research & Tradecraft

Juicing ntds.dit Files to the Last Drop

TL;DR Several new Active Directory offline attack capabilities have recently been added to the DSInternals PowerShell module....

By: Michael Grafnetter
Aug 14, 2025 • 11 min read
Read Post
image for Going for Broke(ring) – Offensive Walkthrough for Nested App Authentication

Research & Tradecraft

Going for Broke(ring) – Offensive Walkthrough for Nested App Authentication

TL;DR: Microsoft uses nested app authentication (NAA) for many applications. Access and refresh tokens for select...

By: Hope Walker
Aug 13, 2025 • 19 min read
Read Post
image for HKLM\SYSTEM\Setup\sMarTdEpLoY –  The (Static) Keys to Abusing PDQ SmartDeploy

Research & Tradecraft

HKLM\SYSTEM\Setup\sMarTdEpLoY –  The (Static) Keys to Abusing PDQ SmartDeploy

TL;DR: Prior to version 3.0.2046, PDQ SmartDeploy used static, hardcoded, and universal encryption keys for secure...

By: Garrett Foster
Aug 12, 2025 • 10 min read
Read Post
image for Certify 2.0

Research & Tradecraft

Certify 2.0

TL;DR Due to modern advances in the AD CS attack landscape, an update to Certify was...

By: Valdemar Carøe
Aug 11, 2025 • 16 min read
Read Post
image for Nemesis 2.0

Research & Tradecraft

Nemesis 2.0

TL;DR We took a chainsaw to Nemesis 1.0, kept the parts that operators loved (i.e., automated...

By: Will Schroeder
Aug 5, 2025 • 7 min read
Read Post
image for Adding MSSQL to BloodHound with OpenGraph

BloodHound

Adding MSSQL to BloodHound with OpenGraph

TL;DR MSSQLHound is a standalone PowerShell collector that adds 7 new nodes and 37 new MSSQL...

By: Chris Thompson
Aug 4, 2025 • 27 min read
Read Post
image for Attack Graph Model Design Requirements and Examples

BloodHound

Attack Graph Model Design Requirements and Examples

TL;DR OpenGraph makes it easy to add new nodes and edges into BloodHound, but doesn’t design...

By: Andy Robbins
Aug 1, 2025 • 34 min read
Read Post