Compass Security Blog

Offensive Defense

Stealthy AD CS Reconnaissance

Introducing a certipy parse command to perform stealthy offline AD CS enumeration based on local registry data.

Continue reading

BloodHound Community Edition Custom Queries

This blog post introduces our new custom queries for BloodHound Community Edition (CE) and explains how you can use them effectively to analyze your Active Directory infrastructure. TL;DR: Check out our new BloodHound CE custom queries! Active Directory and BloodHound The majority of our customers run a Microsoft Active Directory infrastructure, either exclusively on-prem or […]

Continue reading

Hitchhiker’s Guide to Managed Security

Over the past few years, we have had the opportunity to conduct several Purple Teaming exercises together with our customers.

Particularly after Purple Teaming exercises involving external providers, we often see a mismatch between the customer’s expectations and the service provided.

This blog post attempts to summarize how to prevent the most prevalent issues with a managed security service as early as possible.

Continue reading