Latest talks & writing

  1. Black Hat USA 2026 workshop card for From Dev to Prod, presented by Julian Catrambone and Daniel Heinsen.
    Workshop

    From Dev to Prod: AWS Cross Account Privilege Escalation

  2. SO-CON 2026 title card for Your CI/CD Pipeline is My Attack Path by Julian Catrambone.
    Talk

    Your CI/CD Pipeline is My Attack Path: Graphing GitHub OIDC to Cloud Takeover

  3. Diagram of a OneLogin AD Connector linking an on-premises domain, a OneLogin tenant, an AWS application, and an S3 logging bucket.
    Writing

    OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys

All writing

12 records · 2017–2025

2025

  1. SpecterOps 10 min

    OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys

    How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.

2020

  1. SpecterOps Attacking FreeIPA · Part 4 7 min

    Attacking FreeIPA — Part IV: CVE-2020–10747

    A detailed examination of FreeIPA role boundaries, privilege escalation behavior, and the issue originally assigned CVE-2020-10747.

  2. SpecterOps Attacking FreeIPA · Part 3 7 min

    Attacking FreeIPA — Part III: Finding A Path

    Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.

  3. SpecterOps 7 min

    Building a FreeIPA Lab

    Building a repeatable FreeIPA research environment in containers, from domain setup through enrolled clients and test identities.

2019

  1. SpecterOps Attacking FreeIPA · Part 2 10 min

    Attacking FreeIPA — Part II: Enumeration

    Enumerating the users, hosts, groups, policies, and trust relationships that reveal attack paths through a FreeIPA environment.

  2. SpecterOps Attacking FreeIPA · Part 1 9 min

    Attacking FreeIPA — Part I: Authentication

    Host indicators and authentication material in FreeIPA environments, including keytab files, CCACHE tickets, and credentials held in the Linux kernel keyring.

2017

  1. SpecterOps 6 min

    Spear Phishing 101

    An end-to-end field guide to the infrastructure, delivery, payload, and operational details behind an authorized spear-phishing campaign.

  2. SpecterOps 5 min

    Mod_Rewrite Automatic Setup

    Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.

  3. SpecterOps 7 min

    From Patch Tuesday to DA

    Turning a newly published COM moniker privilege escalation into a working payload and a path to domain administrator during an assessment.

  4. SpecterOps 5 min

    Mail Servers Made Easy

    A repeatable Postfix and Dovecot mail-server build for authorized phishing infrastructure, including TLS and the DNS records required for delivery.

  5. SpecterOps 2 min

    WMI Persistence with Cobalt Strike

    A PowerShell workflow for creating a permanent WMI event subscription and using it as durable Cobalt Strike persistence.

  6. SpecterOps 3 min

    Cloning and Hosting Evil Captive Portals using a Wifi PineApple

    Cloning a target’s captive portal with Portal Auth and hosting it with Evil Portal on a WiFi Pineapple Tetra during an authorized wireless assessment.

New research lands here first. Subscribe via RSS.