XPN
banner
xpnsec.com
XPN
@xpnsec.com
Hacker for hire at @specterops.bsky.social
Blog: https://blog.xpnsec.com
February 8, 2026 at 8:47 PM
Reposted by XPN
Next week at WWHF Mile High I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀
February 6, 2026 at 12:16 PM
Reposted by XPN
What do you MEAN the president audibly SHIT himself live on camera and they immediately cancelled the press conference and rushed everyone out of the room like it's a fire drill, and it happened two days ago, and I'm just hearing about it NOW?
February 1, 2026 at 4:00 PM
Beach walk with the doggos 🐶
February 1, 2026 at 2:54 PM
Finally watching Welcome to Derry, took until the final few episodes to see Pennywise but the show stands well on its own 🎈
a clown on a stage in front of a banner that says time to dance
ALT: a clown on a stage in front of a banner that says time to dance
media.tenor.com
January 25, 2026 at 9:38 PM
Reposted by XPN
AI tooling and MCP servers are entering enterprises fast, often faster than security teams can assess the risks.

During a recent engagement, @xpnsec.com found a new Claude Code vuln (CVE-2025-64755) while exploring MCP abuse paths.

👀 Read the details: ghst.ly/49ybl4W
An Evening with Claude (Code) - SpecterOps
This blog post explores a bug, (CVE-2025-64755), I found while trying to find a command execution primitive within Claude Code to demonstrate the risks of web-hosted MCP to a client.
ghst.ly
November 21, 2025 at 4:34 PM
Still here.. still lurking
October 28, 2025 at 1:25 PM
My second post for the month is now live 🎉
Get the scoop on the incoming Administrator Protection for Windows 11.

@xpnsec.com covers the architecture, access controls, and why some legacy UAC bypass techniques remain effective in his latest blog post. ghst.ly/44mw5JM
Administrator Protection Review - SpecterOps
Microsoft will be introducing Administrator Protection into Windows 11. This post explores security considerations for red teamers.
ghst.ly
June 18, 2025 at 6:54 PM
Talking Heads released a music video for Psycho Killer and it's fucking awesome :D www.youtube.com/watch?v=CJ54...
Talking Heads - Psycho Killer (Official Video)
YouTube video by Talking Heads
www.youtube.com
June 13, 2025 at 11:37 AM
Reposted by XPN
🚨 New blog post alert!

@xpnsec.com drops knowledge on LLM security w/ his latest post showing how attackers can by pass LLM WAFs by confusing the tokenization process to smuggle tokens to back-end LLMs.

Read more: ghst.ly/4koUJiz
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
ghst.ly
June 3, 2025 at 5:44 PM
New blog post is up! Stepping out of my comfort zone (be kind), looking at Meta's Prompt Guard 2 model, how to misclassify prompts using the Unigram tokenizer and hopefully demonstrate why we should invest time looking beyond the API at how LLMs function. specterops.io/blog/2025/06...
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
specterops.io
June 3, 2025 at 4:57 PM
The level of snark in my upcoming blogpost is next level... And I'm not even sorry!
taylor swift is wearing a black off the shoulder top .
ALT: taylor swift is wearing a black off the shoulder top .
media.tenor.com
May 21, 2025 at 3:34 PM
Reposted by XPN
Didn’t know this impressive fact. @xpnsec.com did you?
Each year, Eurovision has more live viewers than the Super Bowl, Oscars and Grammys combined. This shocks Europeans when I tell them.

So check it out. Live semi-final 1 airing now: www.youtube.com/live/0HNXVB2...
Eurovision Song Contest 2025 - First Semi-Final - Livestream | #Eurovision2025
YouTube video by Eurovision Song Contest
www.youtube.com
May 13, 2025 at 8:47 PM
Reposted by XPN
You've been prepping for #OSCP exam day, and it finally arrives. 🙇

In Part 4 of his blog series, @anam0x.bsky.social focuses on the test & how to maximize the educational, financial, & professional value of the exam experience.

Read more: ghst.ly/4lHDw4M

🧵: 1/4
April 22, 2025 at 4:14 PM
Worked on a simple POC last night for connecting Mythic up to LiteLLM (pointing to Claude) for riding shotgun on a C2 session. Only using shell cmd, but provides oversight and hints to potential paths to explore. Quite happy for a weekend project :D youtu.be/C9J5okm6cA4
Superintendent POC
YouTube video by Adam Chester
youtu.be
April 20, 2025 at 10:53 AM
New AI Slop Avatar, who dis?
April 18, 2025 at 12:02 PM
Reposted by XPN
WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more!

blog.badsectorlabs.com/last-week-in...
Last Week in Security (LWiS) - 2025-04-14
WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more!
blog.badsectorlabs.com
April 15, 2025 at 7:46 PM
Slides from my SOCON 2025 presentation are now up on GitHub github.com/xpn/Presenta...
Presentations/SOCON2025 at main · xpn/Presentations
A collections of presentations. Contribute to xpn/Presentations development by creating an account on GitHub.
github.com
April 15, 2025 at 9:36 AM
Awesome post from @atomicchonk.bsky.social on NLP Tokenizing. We need more content like this to show the "how" behind the LLM :) www.corgi-corp.com/post/tokeniz...
Tokenizing the Sandwich Debate: How NLP Models Weigh In on Hot Dogs
Get the gist for Natural Language Processing (NLP) and how tokenization plays a factor
www.corgi-corp.com
April 11, 2025 at 1:51 PM
Reposted by XPN
Think NTLM relay is a solved problem? Think again.

Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
April 8, 2025 at 11:00 PM
New blog post 🤗
In our latest blog post, @xpnsec.com breaks down how SQL Server Transparent Data Encryption works, shares new methods for brute-forcing database encryption keys, & reveals a default key used by ManageEngine's ADSelfService product backups.

Read more 👉 ghst.ly/4iXFTyF
April 8, 2025 at 6:45 PM
Celebrating 1 year at SpecterOps, this was the first project I worked on after starting. Looking at SQL Server Transparent Data Encryption, how to bruteforce weak keys, and how ManageEngine's ADSelfService product uses TDE with a suspect key. Enjoy :) specterops.io/blog/2025/04...
The SQL Server Crypto Detour - SpecterOps
As part of my role as Service Architect here at SpecterOps, one of the things I’m tasked with is exploring all kinds of technologies to help those on assessments with advancing their engagement. Not l...
specterops.io
April 8, 2025 at 4:03 PM
Love this article. It’s something that I’ve tried to follow throughout my career, having a line of sight to business profit centres. Even more important in the days of tech layoffs www.seangoedecke.com/where-the-mo...
Knowing where your engineer salary comes from
How tech companies make money and why it's important
www.seangoedecke.com
April 8, 2025 at 2:37 PM
1 year anniversary at SpecterOps, so many personal and professional achievements in a short space of time. My advice for anyone getting into this field, try and make sure that you work companies and colleagues that push you beyond your comfort level. \o/
April 6, 2025 at 5:17 PM
I did a talk!! #socon2025
April 1, 2025 at 9:47 PM