user avatar
Will Schroeder
@harmj0y
Researcher @SpecterOps. Coding towards chaotic good while living on the decision boundary.
Seattle, WA
Joined August 2012
Posts
  • Pinned
    user avatar
    5 months ago @tifkin_ and I started looking into the security of Active Directory Certificate Services. Today we're releasing the results of that research- a blog post posts.specterops.io/certified-pre-… + a 140-page whitepaper and defensive audit tool (links at the top of the post) [1/6]
  • user avatar
    Active Directory forests are no longer a security boundary thanks to @tifkin_'s printer bug. Check out posts.specterops.io/not-a-security… for weaponization and mitigation details and @Cyb3rWard0g's post for detection guidance posts.specterops.io/hunting-in-act…
  • user avatar
    So excited - here's my updated "Guide to Attacking Domain Trusts" posts.specterops.io/a-guide-to-att… ! Was a blast to write
  • user avatar
    In case you were worried
  • user avatar
    Y’all knew it was just a matter of time : ) PowerShell is definitely a "gateway drug" to C# - GhostPack is a collection of new security tools (currently C#) details at posts.specterops.io/ghostpack-d835… , code live at github.com/GhostPack
  • user avatar
    If you're interested in Kerberos or Active Directory and haven't read @elad_shamir's "Wagging the Dog" post, do yourself a favor and dive in. You won't regret it.
  • user avatar
    Hey, do you like tokens? Have you always wanted to "harvest" tokens for offensive purposes? If so check out my new post posts.specterops.io/koh-the-token-… where I show I can (finally) write a technical post without memes, and then check out the Koh toolset at github.com/GhostPack/Koh
  • user avatar
    "Operational Guidance for Offensive User DPAPI Abuse" posts.specterops.io/operational-gu… documenting some of the ways to use Mimikatz to play with DPAPI. Thanks @gentilkiwi for all the awesome features! :)
  • user avatar
    The offensive AD CS tools from @tifkin_'s and my "Certified Pre-Owned" talk, Certify and ForgeCert, are now live at github.com/GhostPack/Cert… / github.com/GhostPack/Forg… ! Thanks to everyone who attended the talk stream!
  • user avatar
    The offensive security community means a lot to me. Following @Antonlovesdnb's great thread that injected some much needed infosec positivity, I wanted to highlight a few (offensive-ish) posts/talks that my team and myself enjoyed over the last year or so.
  • user avatar
    Mad props to Microsoft for taking this very very seriously! techcommunity.microsoft.com/t5/Premier-Fie… Reminder that on July 9 things flip, disallowing delegated TGTs across forest trust boundaries by default. This is an awesome fix for the issue that @tifkin_ and I discovered, hats off 👍
  • user avatar
    Finally the end of a very fun ride- I've merged Dev to Master for PowerSploit and marked the project as no longer supported. Offensive PowerShell was how I started my career, and I owe @obscuresec and @mattifestation a debt of gratitude for bringing me in. [1/3]
  • user avatar
    Over the last year @tifkin_ and I rewrote GhostPack's Seatbelt from the ground up. Highlights- completely modularized, nearly 2x increase in checks, remote enumeration options, and structured output. Complete changelog at github.com/GhostPack/Seat… , code at github.com/GhostPack/Seat…
  • user avatar
    The slides for my @DerbyCon talk "Kerberoasting Revisited" are up at slideshare.net/harmj0y/derbyc… . Thanks to everyone who came out!