
Scoubi
@ScoubiMtl
Followers
2K
Following
8K
Media
171
Statuses
3K
All Things BloodHound | InfoSec, Threat Hunting, Detection Engineering, DFIR and some personal stuff.
Montreal
Joined January 2009
My SANS #DFIRSummit talk is now public!.
🚨NEW VIDEO🚨.In his #DFIRSummit talk @ScoubiMtl presented playbooks for the #SOC, Critical Incident Playbooks for Incident Handlers, & Crisis Management Playbooks for C-level in the hopes that the community will use & make them better.
2
7
41
RT @DEATHCon2025: The final round of online tickets for DEATHCon 2025 will drop on 9/9 @ 0900 UTC. This round won't have pay-what-you-want….
eventbrite.com
Detection Engineering and Threat Hunting Conference: Workshops to help you learn by doing hands-on practical security skills from anywhere!
0
9
0
RT @RandomDhiraj: Just thought of sharing. YubiKey's OATH app lets you name accounts anything including base64 files, turning into a tiny f….
0
1
0
RT @bohops: In 3 weeks, @d_tranman and I will be giving our talk, "COM to the Darkside" at @MCTTP_Con in the Offensive Track. The talk will….
0
21
0
RT @m0rd4vid: 📷 BloodHound-MCP: The first-ever AI integration for BloodHound! I release it now! Make sure you star it on GitHub!. https://t.….
0
7
0
RT @LLMSherpa: Novel jailbreak discovered. Not only does OpenAi putting your name in the system prompt impact the way GPT responds, but it….
0
239
0
RT @_logangoins: I Just documented a cool way to authenticate proxied tooling to LDAP in an AD environment using C2 payload auth context, w….
specterops.io
TL;DR When operating out of a ceded access or phishing payload with no credential material, you can use low-privilege HTTP authentication from the current user context to perform a proxied relay to...
0
117
0
RT @hakluke: Calling all CTF creators. 🗣️. Want a job where you create CTF challenges all day, every day?. That is exactly what I'm hiring.….
0
23
0
RT @RedTeamPT: @SpecterOps found out that the EFS service (PetitPotam) can simply be activated by asking the endpoint mapper. Great researc….
github.com
The efsr_spray module was used to activate the EFS pipes on Windows 11, as EFS was disabled by default. In SpecterOps blog on the WebClient service they discovered that the EFS service has a networ...
0
39
0
RT @vmray: 🚨Alert: Internet Archive abused as hosting service for stealthy malware delivery. 🔍This delivery chain is another example of leg….
0
53
0
Interested in hands-on learning of #DetectionEngineering and #ThreatHunting ?.We still have a few tickets left for @DEATHCon2025 in #Montreal.We are lucky enough to have 4 Workshops Leaders with us that will be able to hosts a Live Play of their workshop and help you complete it!.
1
2
9
RT @AqaraSmarthouse: 🚨 Smart Home Tip Drop 🚨. One of our forum pros, RudyK, just dropped a masterclass on something every smart home owner….
0
1
0
RT @ransomnews: ⚠️ Not a 0day (Yet). #Elastic firmly refutes a zero-day RCE claim in its Defend EDR product. After a full investigation, no….
0
2
0
RT @securityaffairs: Exploit weaponizes #SAP NetWeaver bugs for full system compromise.#securityaffairs #hacking.
securityaffairs.com
Exploit chaining CVE-2025-31324 & CVE-2025-42999 in SAP NetWeaver enables auth bypass and RCE, risking compromise and data theft.
0
2
0
RT @SpecterOps: New #BloodHoundBasics post c/o @ScoubiMtl!. BloodHound v8 introduced Table View. It is the default view when the query retu….
0
4
0
RT @ednas: Tuned into @ScoubiMtl presentation on the new features in Bloodhound 8.0 at the WEDOFF by @RedSiege. Scoubi has a great demo! Th….
0
1
0
RT @RedSiege: Thanks all for joining today's Wednesday Offensive and thank you @ScoubiMtl for taking the time to showcase BloodHound's exci….
0
1
0
RT @RedSiege: Wake up, it's Wednesday! Today on the Wednesday Offensive we have @ScoubiMtl from @SpecterOps diving into BloodHound CE 8.0's….
0
5
0
RT @patrickwardle: Just posted my @defcon slides (talk #1): "Mastering Apple's Endpoint Security for Advanced macOS Malware Detection". Wri….
speakerdeck.com
Five years after Apple radically empowered third-party security developers on macOS with the introduction of Endpoint Security, most developers grasp it…
0
58
0