blog category

Research & Tradecraft

image for Mythic 2.3 — An Interface Reborn

Research & Tradecraft

Mythic 2.3 — An Interface Reborn

Mythic 2.3 — An Interface Reborn New Mythic Search Mythic started off as a proof of concept, open source...

Jan 31, 2022 • 13 min read
Read Post
image for Ghostwriter: Looking Back at 2021

Research & Tradecraft

Ghostwriter: Looking Back at 2021

It has been a while since we last published details about the Ghostwriter project, but the...

Dec 22, 2021 • 6 min read
Read Post
image for Capability Abstraction Case Study: Detecting Malicious Boot Configuration Modifications

Research & Tradecraft

Capability Abstraction Case Study: Detecting Malicious Boot Configuration Modifications

Nov 9, 2021 • 24 min read
Read Post
image for AWS ReadOnlyAccess: Not Even Once

Research & Tradecraft

AWS ReadOnlyAccess: Not Even Once

Aug 27, 2021 • 9 min read
Read Post
image for Entity Based Detection Engineering with BloodHound Enterprise

Research & Tradecraft

Entity Based Detection Engineering with BloodHound Enterprise

Critical Attack Path with Auditing Table of Contents Introduction Enterprise Access Model BloodHound and Detection BloodHound Enterprise Entity Based...

Aug 18, 2021 • 13 min read
Read Post
image for Playing Detection with a Full Deck

Research & Tradecraft

Playing Detection with a Full Deck

Aug 16, 2021 • 12 min read
Read Post
image for Learning from our Myths

Research & Tradecraft

Learning from our Myths

Jun 22, 2021 • 20 min read
Read Post
image for Certified Pre-Owned

Research & Tradecraft

Certified Pre-Owned

L;DR Active Directory Certificate Services has a lot of attack potential! Check out our whitepaper “Certified Pre-Owned:...

Jun 17, 2021 • 28 min read
Read Post
image for Proxy Windows Tooling via SOCKS

Research & Tradecraft

Proxy Windows Tooling via SOCKS

Jun 10, 2021 • 14 min read
Read Post