_logangoins Profile Banner
Logan Goins Profile
Logan Goins

@_logangoins

Followers
1K
Following
213
Media
4
Statuses
60

Adversary Simulation @SpecterOps

United States
Joined April 2024
Don't wanna be here? Send us removal request.
@_logangoins
Logan Goins
1 month
I'm super happy to announce an operationally weaponized version of @YuG0rd's BadSuccessor in .NET format! With a minimum of "CreateChild" privileges over any OU it allows for automatic escalation to Domain Admin (DA). Enjoy your inline .NET execution!.
7
168
440
@_logangoins
Logan Goins
3 days
RT @G0ldenGunSec: Azure Arc is Microsoft's solution for managing on-premises systems in hybrid environments. My new blog covers how it can….
0
66
0
@_logangoins
Logan Goins
4 days
RT @Yeeb_: Created small tool that joins a device to a Tailscale network and exposes a local SOCKS proxy. It’s built for red team pivots an….
0
59
0
@_logangoins
Logan Goins
6 days
RT @unsigned_sh0rt: Last week we added ELEVATE-4 to Misconfiguration Manager. tl;dr If SCCM uses AD CS for PKI, cl….
0
47
0
@_logangoins
Logan Goins
8 days
RT @SpecterOps: So you've compromised a host that isn’t cloud-joined. Antero Guy breaks down how to request OAuth tokens & enumerate an Ent….
0
54
0
@_logangoins
Logan Goins
10 days
RT @ShitSecure: After today’s talk at #TROOPERS25 I’m releasing BitlockMove, a PoC to execute code on remote systems in the context of a lo….
0
170
0
@_logangoins
Logan Goins
10 days
RT @subat0mik: Thanks to everyone who attended our (@unsigned_sh0rt) talk at @WEareTROOPERS! Here is the companion blog post: https://t.c….
0
22
0
@_logangoins
Logan Goins
10 days
RT @SpecterOps: Are you at #TROOPERS25? Don't miss @subat0mik & @unsigned_sh0rt's follow-up to their talk last year, providing an update on….
0
5
0
@_logangoins
Logan Goins
11 days
RT @Jonas_B_K: I publish two blog posts today! 📝🐫 . The first dives into how we're improving the way BloodHound models attack paths through….
0
68
0
@_logangoins
Logan Goins
18 days
RT @SpecterOps: Introducing the BloodHound Query Library! 📚. @martinsohndk & @joeydreijer explore the new collection of Cypher queries desi….
0
112
0
@_logangoins
Logan Goins
23 days
RT @hullabrian: I just released COMmander - a .NET tool designed to provide an easy to use interface for COM and RPC based attacks. It taps….
0
30
0
@_logangoins
Logan Goins
23 days
RT @harmj0y: Thank you so much to @x33fcon and its organizers for an awesome experience! @tifkin_ and I had a blast talking about the new N….
0
68
0
@_logangoins
Logan Goins
25 days
RT @Synacktiv: Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromi….
0
262
0
@_logangoins
Logan Goins
25 days
RT @RedTeamPT: 🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live:. 🪞 The Reflective Kerberos Relay Attack - Remo….
0
180
0
@_logangoins
Logan Goins
26 days
RT @SpecterOps: Recently, Microsoft changed the way the Entra Connect Sync agent authenticates to Entra ID. Check out our latest blog pos….
0
41
0
@_logangoins
Logan Goins
1 month
RT @SpecterOps: Ready to level up your offensive security career? 📈. Join our Consulting Services team as a Senior Offensive Security Consu….
0
5
0
@_logangoins
Logan Goins
1 month
RT @SpecterOps: BadSuccessor is a new AD attack primitive that abuses dMSAs, allowing an attacker who can modify or create a dMSA to escala….
0
105
0
@_logangoins
Logan Goins
1 month
RT @theluemmel: Extended on @_logangoins work for BadProcessor.Fully native PowerShell.Domain joined or not doesn't matter.Check DCs.Check….
0
22
0
@_logangoins
Logan Goins
1 month
RT @YuG0rd: Many missed this on #BadSuccessor: it’s also a credential dumper. I wrote a simple PowerShell script that uses Rubeus to dump….
0
148
0
@_logangoins
Logan Goins
1 month
RT @Shikata_VX: Bad successor.
Tweet media one
0
1
0