Hope Walker
@Icemoonhsv
Followers
1K
Following
166
Media
3
Statuses
84
Senior Security Researcher at @SpecterOps. All opinions are my own.
Joined July 2018
Credential Guard was supposed to end credential dumping. It didn't. @bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more ⤵️
specterops.io
Uncovering the protection mechanisms provided by modern Windows security features and identifying new methods for credential dumping.
4
309
651
Check out my new blog post diving deeper into BroCI.
Microsoft introduced nested application auth (NAA) in 2024. Researchers spotted FOCI similarities & dubbed it brokered client IDs (BroCI). @Icemoonhsv documents NAA flows and BroCI—filling a gap for research on Microsoft identity protocols.
1
10
26
Check out my new blog on nested app authentication and brokered authentication.
Why should Microsoft's Nested App Authentication (NAA) should be on your security team's radar? @Icemoonhsv breaks down NAA and shows how attackers can pivot between Azure resources using brokered authentication.
2
17
42
Ready to level up your offensive security career? 📈 Join our Consulting Services team as a Senior Offensive Security Consultant doing what you love: red teaming, penetration testing, capability assessments, and research. Learn more & apply today: https://t.co/IKqBYtLBMz
0
5
14
What can you expect to learn in our Azure Security Fundamentals training at #SOCON2025? Course architect @Icemoonhsv shares that students will dive into: ➡️ Azure Resource Manager ➡️ Common security misconfigurations ➡️ Entra ID authentication Register: https://t.co/UOOmhWc2Zi
1
2
8
Join our Azure Security Fundamentals course at #SOCON2025! Learn to secure Azure environments & spot misconfigs commonly exploited by attackers. 🐦 Early bird deadline = Dec 1 🎟️ In-person attendees receive a free conference pass. Register today 👉 https://t.co/UOOmhWc2Zi
1
2
3
I wrote a blog post about some of the intangible benefits of working as a red team operator and adversary simulation consultant at SpecterOps. It's pretty awesome here. And we're hiring! https://t.co/d8ShLewzJd
posts.specterops.io
Come work with us!
2
47
189
Dig into Active Directory with us at #BHUSA! Join @Icemoonhsv & @_wald0 for our AD Security Fundamentals training and learn the key components of AD and get hands-on practice analyzing live AD environments. Aug. 3-4 ▶️ https://t.co/DU3A5NtW2S Aug. 5-6 ▶️ https://t.co/77Y56IylrE
0
6
9
New blog on some considerations when using CAPs and PIM in an Entra ID tenant together. I also cover potential complications for defensive posture, disaster recovery, and offensive engagements.
posts.specterops.io
Introduction
0
21
34
Published part 2 of Manual LDAP Querying. This blog covers additional topics like user account control, password attributes, domain trusts, and more.
posts.specterops.io
This post is a follow-up to my previous post on manual LDAP querying. I would highly recommend reading that post prior to reading this one…
0
49
106
In #BHUSA training “Active Directory Security Fundamentals,” get hands-on with Active Directory (AD), enabling participants to gather answers directly when questions surrounding their organization's AD architecture arise in the future. Reg now >> https://t.co/IXsfiG0cvc
1
4
14
I am very excited to see the Azure Security Fundamentals course to come out at SO-CON this year!
Our *NEW* Azure Security Fundamentals training will be introduced at SO-CON 2024! Course architect @Icemoonhsv shares what you can expect to learn, including common security misconfigurations and attacker insights. Register today 👉 https://t.co/BpBwyJ0UG7
0
6
22
We're thrilled to announce BloodHound Community Edition (CE) -- the next evolution of #BloodHound. Scheduled for release on 8/8, BloodHound CE has many new features & enhancements, making it easier for users to deploy, manage, and utilize. Learn more: https://t.co/aLMuHQvwfB
6
117
276
I am extremely excited for the AD Security Fundamentals course. I have put in a lot of work over the last few months to get this course ready. Can't wait to deliver it at Black Hat this year.
Learn the key components of AD and get hands-on practice analyzing live AD environments during our hands-on AD Security Fundamentals training course at #BHUSA. Register: https://t.co/b0JTpjAU1v
2
12
46
I've long been interested in how EDRs work under the hood and how we can apply a more evidence-based approach to evasion. I'm happy to announce that I've written a book covering these topics with @nostarch which is now available for preorder 🎉 https://t.co/tHSWnVzuMX
nostarch.com
A guide to understanding the attack-detection software running on Microsoft systems, and how to evade it.
46
332
1K
@SpecterOps will be at NorthSec in full force. @zyn3rgy and @Icemoonhsv will be teaching our Red Team Operations course and @jsecurity101 and I will be teaching our new Malware Morphology for Detection Engineers workshop! We'd love to meet up and chat!
It’s no secret that @SpecterOps has some of the most popular FOSS for OffSec and shares tons of knowledge for free. For a 5th year in a row, we are happy to host one of their most famous training! 🗓️May 23-26 🏛️On site It sold out last time, so hurry up👉 https://t.co/0oOHsk1GPz
1
18
38
#specterops Adversary Tactics: Red Team Operations day 1 of 4 with @harmj0y @enigma0x3 @Ne0nd0g @_Mayyhem @Icemoonhsv @0xthirteen @Nc3pt0r @0xdab0 was a success!
1
9
65
Come join @harmj0y @Nc3pt0r @enigma0x3 @0xthirteen @Ne0nd0g @_Mayyhem @Icemoonhsv and myself in our AT:RTO course at #BHUSA !
Have you been thinking about taking our Adversary Tactics: Red Team Operations training? Take it at #BHUSA! RTO will be held in-person in Las Vegas August 6th-9th. You can secure your seat here: https://t.co/MHAf9Zl3sc
0
8
13
Looking forward to being an instructor on our AT:RTO class with a great team of other instructors at #BHUSA this year.
Have you been thinking about taking our Adversary Tactics: Red Team Operations training? Take it at #BHUSA! RTO will be held in-person in Las Vegas August 6th-9th. You can secure your seat here: https://t.co/MHAf9Zl3sc
1
0
12
We're excited to announce that SO-CON will be back October 24-28, 2022 in Reston, VA! We'll be offering all of our trainings, and will end the week with a series of new training workshops developed by our team of Specters. Click here for more info: https://t.co/OoBYRhi4pT
0
10
23