Skip to content
Artwork for Know Your Adversary

Know Your Adversary

SpecterOps

Know Your Adversary is a podcast by SpecterOps that dives deep into identity security through the lens of the attacker. Hosted by Jared Atkinson and Justin Kohler, each episode unpacks the methods, mindsets, and missteps that shape modern identity risk. From real-world war stories to cutting-edge research, the show brings together practitioners, researchers, and engineers to explore how adversaries think—and how defenders can get ahead.

Play
  • 14 episodes
  • Avg 31 min
  • English
  • S1 · E14
    August 17 · 45 min

    Episode 14: BloodHound 10-Year Anniversary Pt. 2

    In Part 2 of Know Your Adversary’s celebration of 10 years of BloodHound, Jared Atkinson and Justin Kohler are joined once again by BloodHound creators Andy Robbins, Will Schroeder, and Rohan Vazarkar. Picking up where Part 1 left off, the group explores how lessons from the original BloodHound and the Active Directory Adversary Resilience Assessment (ADARA) helped turn attack path analysis into a methodology defenders could operationalize, ultimately laying the groundwork for BloodHound Enterprise. The conversation dives into a fundamental challenge they discovered along the way: defenders can’t simply enumerate and fix every attack path. Instead, they need to understand what’s wrong, how much it matters, and what to fix first. The group discusses how this realization shaped BloodHound’s approach to prioritization, tier-zero isolation, continuous monitoring, and giving defenders the context they need to reduce attack path risk as identity environments constantly change. From there, they trace BloodHound’s expansion beyond on-premises Active Directory into Azure, hybrid identity environments, GitHub, and other platforms. They share the technical and engineering challenges of modeling increasingly complex systems at enterprise scale, how experimentation with GitHub helped accelerate the development of OpenGraph, and why extensibility became essential to BloodHound’s future. The episode closes with a look toward what comes next, including new attack graph coverage and the continued expansion of BloodHound into emerging identity systems.

  • S1 · E13
    August 17 · 55 min

    Episode 13: BloodHound 10-Year Anniversary Pt. 1

    In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler are joined by Andy Robbins, Will Schroeder, and Rohan Vazarkar, the original creators of BloodHound, to celebrate ten years since the tool was first introduced. Together, they revisit the offensive security challenges that led to BloodHound and how a need to understand increasingly complex Active Directory environments ultimately led them to graph theory and attack path analysis. The discussion traces BloodHound's evolution from a tool built by red teamers to solve their own operational problems into an open source project that changed how practitioners understand identity-based attack paths. The group shares stories from its early development and DEF CON debut, the expansion from a simple graph of three node and edge types, and the realization that BloodHound wasn't creating attack paths, but providing a map of relationships and opportunities that had been there all along. Along the way, they explore how BloodHound changed offensive tradecraft, why visualization made complex attack paths easier to understand, and how defenders began using the same capabilities to find and eliminate those paths at scale. They also reflect on the project's transition from an offensive tool toward a defensive capability, setting the stage for BloodHound Enterprise and the next chapter of BloodHound's evolution.

  • S1 · E12
    June 30 · 38 min

    Episode 12: runZero with Special Guest HD Moore

    In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler are joined by HD Moore, CEO of runZero. Drawing from decades of experience in offensive security, vulnerability research, and network discovery, HD shares his perspective on how defenders can better understand the real attack surface of modern enterprise environments. The discussion explores the intersection of identity and network security, including RunZeroHound, HD's BloodHound OpenGraph project that brings network topology and exposure data into attack path analysis. The group examines how security dependencies, hidden connectivity, and infrastructure exposure create opportunities for attackers that traditional vulnerability management often misses. Along the way, they discuss OT and industrial networks, the myth of air-gapped environments, the growing impact of AI on offensive security, and why understanding how systems are connected may be more important than understanding individual vulnerabilities.

  • S1 · E11
    June 2 · 38 min

    Episode 11: ProSec GmbH with Special Guest Robin Unglaub

    In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler are joined by Robin Unglaub, creator of TaskHound, an open-source BloodHound OpenGraph extension designed to uncover credential exposure and attack paths hidden within Windows scheduled tasks. Drawing from years of offensive security experience, Robin explains how a common administrative feature can become a valuable source of privilege escalation and lateral movement opportunities for attackers. The discussion covers how scheduled tasks store and use credentials, why they frequently appear during security assessments, and how TaskHound helps operators and defenders visualize these relationships directly within BloodHound. Robin also demonstrates how graph-based analysis can reveal tier-zero exposure, identify high-value targets, and uncover misconfigurations that might otherwise go unnoticed. Along the way, the group explores OpenGraph, operational security considerations, and upcoming TaskHound features that expand visibility into additional credential sources across enterprise environments.

  • S1 · E10
    April 10 · 42 min

    Episode 10: Siemens Healthineers with Special Guest Javier Azofra

    In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler are joined by Javier Azofra from Siemens Healthineers, where he leads the continuous assessments team focused on enterprise security posture. Javier shares how his team approaches identity security and the challenges of maintaining visibility across complex environments.The conversation focuses on how security gaps emerge between systems like Active Directory, Entra ID, and CyberArk. Javier explains how his team built a BloodHound OpenGraph integration (CyberArkHound) to connect these platforms and uncover hidden attack paths that weren’t visible in isolation. They also break down how CyberArk models users, safes, and accounts—and how those relationships can unintentionally enable privilege escalation.Along the way, they discuss how attackers exploit identity relationships, why MFA and PAM don’t eliminate risk on their own, and how defenders can better prioritize remediation by understanding cross-platform attack paths.

  • S1 · E9
    March 19 · 34 min

    Episode 9: Palo Alto Networks Unit 42 with Special Guest Steve Elovitz

    In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler are joined by Steve Elovitz of Palo Alto Networks’ Unit 42, where he leads service delivery across North America. With years of incident response experience, including time at Mandiant, Steve shares what it’s like responding to hundreds of real-world security incidents each year. The conversation explores how modern adversaries operate once inside an environment and why identity has become a primary entry point for many attacks. Steve breaks down the attack patterns his team most frequently sees during incident response engagements. These often begin with identity compromise through phishing, password spraying, or social engineering, followed by lateral movement and privilege escalation. The group also discusses how attackers expand access across hybrid environments by targeting SaaS platforms, developer systems, and cloud identity providers. Along the way, they examine common misconceptions around MFA and privileged access management, and why understanding attack paths helps defenders see how adversaries actually move through complex environments.

  • S1 · E8
    Nov 24, 2025 · 45 min

    Episode 8: Ping Identity with Special Guest Bjorn Aannestad

    In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler sit down with SpecterOps Principal Product Architect Andy Robbins and Ping Identity Director of Product Management Bjorn Aannestad to discuss SpecterOps’ recent attack path research engagement with the PingOne platform. The conversation covers how the collaboration began, why gaining access to a real PingOne tenant was crucial for accurate modeling, and what stood out about Ping Identity’s documentation, design choices, and security philosophy. Andy walks through key elements of the PingOne architecture—including its RBAC model, environment structure, and controls that limit privilege escalation—while the group highlights how thoughtful design can dramatically reduce attack path complexity. They also explore the broader challenges of understanding hybrid identity systems, how cross-platform dependencies can create unexpected risk, and why validating security assumptions across interconnected services is essential for modern defenders.

  • S1 · E7
    Nov 24, 2025 · 25 min

    Episode 7: The State of APM - Community Contributions

    In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler sit down with Christopher Maddalena to explore how open-source contributions continue to shape the evolution of attack path management. Christopher breaks down how community tools have moved from raw data dumps to polished, digestible insights that plug directly into BloodHound. The team also discusses how researchers are expanding the attack graph across identity, cloud, and infrastructure systems, and how new interfaces such as OpenGraph, make analyzing complex environments faster and more accessible. Whether you're a defender or researcher, this episode highlights how open-source innovation is accelerating visibility across modern hybrid attack surfaces.

  • S1 · E6
    Nov 13, 2025 · 20 min

    Episode 6: The State of APM - Tradecraft Trends

    In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler talk with Andrew Chiles, VP of Tradecraft at SpecterOps, about the latest trends in tradecraft. Andrew breaks down how real assessment data is reshaping identity-focused attacks, why hybrid and SaaS environments create new pivot opportunities, and how browser-based session abuse is changing the game. He also shares insights on modeling emerging techniques, shortening the attacker–defender feedback loop, and what these evolving patterns mean for organizations trying to stay ahead.

  • S1 · E5
    Oct 27, 2025 · 18 min

    Episode 5: The State of APM - Graph Expansion

    In this episode of Know Your Adversary, hosts Jared Atkinson and Justin Kohler sit down with Elad Shamir, Head of Research at SpecterOps, to discuss the evolution and future of BloodHound OpenGraph. Elad shares how BloodHound has grown from a simple model into a powerful platform that maps complex attack surfaces across diverse environments. The conversation explores the challenges of modeling adversary tradecraft, the impact of hybrid paths connecting Active Directory and Entra ID, and how new capabilities like OpenGraph are accelerating innovation. Elad also introduces his philosophy of the Clean Source Principle, explaining how misaligned trust between systems often creates the very attack paths BloodHound is designed to uncover.

  • S1 · E4
    Oct 15, 2025 · 18 min

    Episode 4: The State of APM - Operationalizing Attack Path Management

    In this episode of Know Your Adversary, hosts Jared Atkinson and Justin Kohler sit down with Kate Dawson, Director of Customer Success at SpecterOps, to explore what it takes to implement a successful Attack Path Management (APM) program. Kate explains how cross-team collaboration, identity-focused strategies, and programmatic—not project-based—approaches are key to lasting success. The team draws parallels between APM and vulnerability management, emphasizing the importance of continuous improvement, policy integration, and metrics like exposure reduction and remediation speed as signs of maturity in defending against identity-based attack paths.

  • S1 · E1
    Sep 22, 2025 · 9 min

    Episode 1: Setting the Stage

    In the very first episode of Know Your Adversary by SpecterOps, Chief Product Officer Justin Kohler and Chief Technology Officer Jared Atkinson pull back the curtain on how BloodHound came to be and why attack path management is more critical than ever. They trace BloodHound’s roots from a red teamer’s Excel-driven struggle to its evolution into a revolutionary graph-theory tool that changed how defenders and adversaries alike understand identity-based attack paths. Along the way, they explain what an “attack path” really is, why attackers rarely land where they want to, and how pivoting across identities and computers creates endless opportunities for compromise.

  • S1 · E2
    Sep 22, 2025 · 27 min

    Episode 2: The State of APM - Executive Summary & Detection In Context

    In this episode of Know Your Adversary, hosts Justin Kohler and Jared Atkinson sit down with Robby Winchester, Chief Services Officer at SpecterOps, to explore the practical side of attack path management. Robby reflects on nearly a decade of SpecterOps’ consulting and training work, sharing how the newly released State of Attack Path Management Report formalizes long-standing challenges that organizations face when dealing with identity sprawl, misconfigurations, and privilege creep. Together, they discuss how identity issues scale across environments—whether Active Directory, Kubernetes, or cloud providers—and why visibility, context, and iteration are critical to managing real-world risk.

  • S1 · E3
    Sep 22, 2025 · 26 min

    Episode 3: The State of APM - Access Graphs & Identity Movement

    In this episode of Know Your Adversary, hosts Justin Kohler and Jared Atkinson break down two key theoretical concepts shaping attack path management: the distinction between access graphs vs. attack graphs and the paradigm of identities at rest vs. identities in transit. They explain why access graphs—maps of who can reach what—don’t tell the full story, and how attack graphs reveal the snowballing effect of compromised identities that accumulate control across environments. With real-world analogies and data points, the conversation highlights why environments with millions of relationships often harbor billions of potential attack paths, leaving defenders with an overwhelming challenge.

Showing 1–14 of 14 episodes