Katie Knowles
@siigil.bsky.social
1.1K followers
85 following
34 posts
Security Researcher @ Datadog. 🐶 Head in the (Azure) clouds.
Sometimes blogging, always curious. Aim to be, rather than to seem.
Blogs at https://kknowl.es.
Posts
Media
Videos
Starter Packs
Reposted by Katie Knowles
Nick Frichette
@frichetten.com
· Aug 19
Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer | Datadog Security Labs
Discover how attackers could quietly enumerate AWS resources via Resource Explorer, and how Datadog and AWS worked together to close the visibility gap.
securitylabs.datadoghq.com
Katie Knowles
@siigil.bsky.social
· Aug 14
Katie Knowles
@siigil.bsky.social
· Aug 14
I SPy: Escalating to Entra ID's Global Admin with a first-party app | Datadog Security Labs
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led...
securitylabs.datadoghq.com
Reposted by Katie Knowles
Hope Walker
@1cemoon.bsky.social
· Aug 13
Katie Knowles
@siigil.bsky.social
· Jul 31
Katie Knowles
@siigil.bsky.social
· Jul 28
Katie Knowles
@siigil.bsky.social
· Jul 16
I SPy: Escalating to Entra ID's Global Admin with a first-party app | Datadog Security Labs
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led...
securitylabs.datadoghq.com
Katie Knowles
@siigil.bsky.social
· Jun 25
Katie Knowles
@siigil.bsky.social
· Jun 24
Katie Knowles
@siigil.bsky.social
· Jun 17
fwd:cloudsec 2025 Speaker Bios & Abstracts | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
fwdcloudsec.org
Katie Knowles
@siigil.bsky.social
· Jun 5
Persisting Unseen: Defending against Entra ID persistence
I recently presented “Persisting Unseen: Attacker Methods of Infesting Entra ID” at RSAC’s virtual Cloud Security seminar. This session introduced some methods attackers may use now or in the near fut...
kknowl.es
Reposted by Katie Knowles
Greg Foss
@gregfoss.com
· May 19
fwd:cloudsec 2025 Speaker Bios & Abstracts | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
fwdcloudsec.org
Reposted by Katie Knowles
Reposted by Katie Knowles
Katie Knowles
@siigil.bsky.social
· Mar 28
Katie Knowles
@siigil.bsky.social
· Mar 25
Creating immutable users through a bug in Entra ID restricted administrative units | Datadog Security Labs
Imagine trying to disable a malicious user in your Azure environment, only to find it can't be modified! We recently identified a timing-based bug in Entra ID's restricted administrative units (AUs) t...
securitylabs.datadoghq.com
Katie Knowles
@siigil.bsky.social
· Mar 11