Skip to content

Security: SpecterOps/Nemesis

Security

.github/SECURITY.md

Community of SpecterOps - Creators of BloodHound

🔒 Security Policy

If you discover a security vulnerability in this project, we appreciate your help in disclosing it to us responsibly.

📧 Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.
Instead, please report security vulnerabilities using one of the following methods:

  1. Email SpecterOps Security Team
    You can email us at security[@]specterops.io.

  2. GitHub Private Vulnerability Reporting If this repository offers GitHub Private Vulnerability Reporting, use the Report a vulnerability button in the repository's Security tab.

  3. Private Maintainer Contact If Private Vulnerability Reporting is unavailable or you do not receive a timely response, contact a repository maintainer through a private channel, such as a direct Slack message. Do not share vulnerability details in public Slack channels.

✏️ What to Include

When reporting a vulnerability, please include:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any suggested fixes (if applicable)

🔰 Disclosure Policy

  • We request that you do not publicly disclose the vulnerability until we have had a chance to address it
  • Once a fix is available, we will coordinate with you on the timing of public disclosure
  • We will credit you for the discovery (unless you prefer to remain anonymous)

🚧 Supported Versions

Unless stated otherwise, only the latest version is supported. Refer to this project's documentation for more information about supported versions.

There aren't any published security advisories