1. X
  2. Chris Thompson
Log inSign up
Chris Thompson
516 posts
Chris Thompson profile banner
user avatar

Chris Thompson

@_Mayyhem
Senior Security Researcher @SpecterOps github.com/Mayyhem
Joined August 2015
495
Following
2,792
Followers
RepliesRepliesMediaMedia
  • Pinned
    user avatar
    Chris Thompson
    @_Mayyhem
    Aug 3
    ConfigManBearPig adds SCCM attack paths to the BloodHound graph, including all of the known hierarchy TAKEOVERs. I rewrote 2.0 in Python and added a ton of features that make it easier and more reliable to use, whether you're on offense or defense. Let me know what you find!
    user avatar
    SpecterOps
    @SpecterOps
    Aug 3
    ConfigManBearPig 2.0 is out, a full Python rewrite built on OpenHound. Faster, runs on Linux, SOCKS proxy support, better BloodHound pathfinding for SCCM attacks. ➡️ ghst.ly/3RGyETm Catch @_Mayyhem demo-ing it live at #BHUSA Arsenal TOMORROW, Tue 8/4, 5:15pm, Station 6.
  • user avatar
    Chris Thompson
    @_Mayyhem
    Jul 29
    I'm releasing a new Python rewrite of ConfigManBearPig, my BloodHound collector for SCCM, next week w/ a TON of upgrades (SOCKS, hash/kerb auth, CVE scan, threads, pathfind) and am presenting at Black Hat Arsenal next Tues. Come say hi and grab a sticker! blackhat.com/us-26/arsenal/…
  • user avatar
    Chris Thompson
    @_Mayyhem
    May 11
    Very compelling read on OpenGraph's beginnings. The content is interesting, but also I just love Brandon's writing! It makes you feel like you're there on a personal journey instead of just dumping technical info onto the page, which I tend to do and would love to improve upon.
    user avatar
    SpecterOps
    @SpecterOps
    May 8
    What does it take to build the foundation for a graph that can grow beyond Active Directory? In his latest blog post, Brandon Shearin reflects on a year building OpenGraph for BloodHound, & the work of turning ambiguity into architecture. Check it out ⤵️ ghst.ly/3QYKrvG
  • user avatar
    Chris Thompson
    @_Mayyhem
    Apr 23
    MSSQLHound runtime is down from 17 minutes to 17 seconds in my lab after rewriting the BloodHound collector in Go with Javier Azofra and added SOCKS proxying, Kerberos and NT hash auth, and pathfinding. Hope this is more useful for ops than PowerShell! Let me know how it goes!
    user avatar
    SpecterOps
    @SpecterOps
    Apr 23
    If MSSQL isn't in your attack path visibility yet, this is your sign. @Mayyhem just shipped a major MSSQLHound upgrade with Javier Azofra Ovejero (github.com/jazofra): faster, cross-platform, and pathfinding-ready in BloodHound. Check it out! ghst.ly/4cUKgtJ
  • user avatar
    Chris Thompson
    @_Mayyhem
    Apr 2
    I added an SCCM central admin site, child site, passive site server, secondary site, and remote system roles to @synzack21 and @badsectorlabs Ludus lab so you can skip the manual deployment. It's vuln to almost every technique in Misconfiguration Manager.
    Image
    Ludus SCCM Lab Expansion
    From specterops.io

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement