Jiun-Ming (Jimmy) Su
CyCraft, Senior Security Researcher
Actions
Jimmy Su currently working at CyCraft as a Senior Security Researcher, holds a master’s degree in Information Security from National Tsing Hua University (NTHU). His work focuses on attacks involving Active Directory, Cloud, and identity-related security. Jimmy holds certifications including eJPT, CRTO, ARTA, and GRTA. He has presented at conferences such as CyberSec, HITCON 101, SECCON, SO-CON, OAIC, and co-authored a talk at ROOTCON. He has also delivered technical training and workshops, and shared his expertise with various organizations, including government agencies, ISPs, and academic institutions in Taiwan.
Links
WOOF! Sniffer Dog Off the Leash: Automating Active Directory Attacks with MCP
Building on our research from SO-CON 2025, this talk extends our Active Directory graph analysis framework. For OAIC, we pivot from defender-oriented use cases to an attacker's perspective. Still, our goal remains to think like both the attacker and the defender, to provide functionality to make everyone’s lives easier.
Our framework operationalizes the attacker's OODA loop within AD. The crucial Orient and Decide phases are automated by our enhanced algorithm, which uses linear programming to analyze the graph and select optimal attack paths based on a set of user-defined criteria, including attack difficulty and OPSEC.
This decision is then passed to the Model Context Protocol (MCP), which drives the Act phase. The MCP enables our agent, "Off-Leash Sniffer Dog," to execute a suite of offensive capabilities, including:
- Initial Access: Discovering plaintext passwords, Kerberoastable/AS-REP Roastable accounts, legacy machine account with fix password, and attacker self-defined compromised account
- Attack Execution: Automating attacks such as DACL abuse, RBCD, DCSync, AD CS escalation, and NTLM relays.
The MCP also supports flexible command generation using user-supplied tool lists or auto-detected binaries available on the host machine. Whether you’re an operator reducing analysis time, a defender exploring "what-if" scenarios, or an attacker seeking to automate attacks, this talk will show how to turn identity graphs into a fully functional OODA loop that covers the entire process from analysis to action.
Woof, Woof! Meet Sniffer BloodHound: An Algorithm-Driven Framework for Attack Path Analysis
Analyzing attack paths with BloodHound can become challenging in large-scale environments due to graph complexity and difficulty in prioritizing critical edges for mitigation or defining unblockable edges.
To address these issues, we introduce Sniffer BloodHound, an algorithm-driven framework seamlessly integrated into BloodHound. Based on the algorithm proposed by Mingyu Guo in AAAI 2023, which already supports critical edge identification and self-defined unblockable edges, we further refined and extended its capabilities.
Our enhancements focus on automating attack path prioritization, enabling self-defined Tier 0 asset analysis, and supporting multi-destination analysis to accommodate diverse attack scenarios.
Fully integrated within the BloodHound UI, Sniffer BloodHound significantly reduces analysis time and improves accuracy, empowering red and blue teams to efficiently detect and disrupt attack paths.
Offensive AI Con Sessionize Event
SO-CON 2025 Sessionize Event
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top