Solutions  ·  2026-08-14

SpecterOps open-sources Blacklight, an AI-agent endpoint artifact discovery toolkit

SolutionsMedium impactGlobal
SpecterOps published (Aug 12, 2026) Blacklight, an open-source research toolkit that discovers and analyzes local AI-agent artifacts (auth tokens, credentials, session transcripts, config) left behind by Codex, Claude Code, Cursor, and Antigravity CLI on developer endpoints, released on GitHub with operator and defender guidance.
First widely-published, purpose-built tooling to treat local coding-agent state (session transcripts, cached tokens) as a post-exploitation target class analogous to browser-profile/shell-history harvesting, giving defenders inventory and detection guidance for a previously under-monitored endpoint surface.
Red teams and blue teams securing developer endpoints that run AI coding agents; security engineering teams should inventory and monitor the artifact paths Blacklight identifies now.
SpecterOps BlogGitHub
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →