Relatively Risky: Identifying Exposures at Scale With BloodHound OpenGraph | SO-CON 26

Relatively Risky: Identifying Exposures at Scale With BloodHound OpenGraph | SO-CON 26

Source: YouTube · SpecterOps · published Jun 4, 2026 · 42:15

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

The video reflects on the evolution of cybersecurity, contrasting the graph-based thinking of attackers with the list-based mindset of defenders, while tracing the speaker's journey from early internet exploration to modern security tooling like BloodHound.

Key Takeaways:
• The speaker highlights the fundamental difference in perspective: defenders typically think in lists, whereas attackers think in graphs, a concept crucial for understanding modern threat landscapes 0:30-0:35.
• BloodHound emerged as a pivotal tool in the security industry, gaining significant traction around 2010, fundamentally changing how active directory and network attacks are visualized and executed 0:00-0:10.
• The speaker’s career began in the era of Bulletin Board Systems (BBS), war dialing, and early internet scanning, reflecting a time when security was more about raw exploration than structured frameworks 0:20-0:28.
• As the speaker ramped down traditional penetration testing, their focus shifted toward product development, exploit development, and red teaming, illustrating the industry's move toward more specialized roles 0:09-0:17.

This narrative underscores how the tools and methodologies in cybersecurity have evolved from manual scanning to complex graph-based analysis, shaping both offensive and defensive strategies today.

Sources:

  • 0:00 Introduction to BloodHound and its historical context
  • 0:30 Discussion on attacker vs. defender mental models
  • 0:20 Early days of security involving BBS and war dialing
  • 0:09 Transition from pen testing to exploit developm

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Um, I've always been a fan of BloodHound ever since it came out. Like, I guess when BloodHound released or it took off kind of in 2000s, uh, like maybe almost 2010 or so when it really started to notice it. Um, I'd already started ramping down my pen test work. I was doing more product work at that point, more exploit dev, things like that. Then then, you know, straight up red teaming and at that point. So, I kind of missed the the peak of it. Um, but going back to like the early days of like how I got into security, it's a lot of like BBSs, war dialing, scanning the internet, hack the planet, all that kind of fun stuff. And it very much was attacking, you know, there's a silly quote about, you know, you know, defenders think in lists, attackers think in graphs. No, attackers like to like …