Katie Knowles
@siigil.bsky.social
1.1K followers 85 following 34 posts
Security Researcher @ Datadog. 🐶 Head in the (Azure) clouds. Sometimes blogging, always curious. Aim to be, rather than to seem. Blogs at https://kknowl.es.
Posts Media Videos Starter Packs
Reposted by Katie Knowles
siigil.bsky.social
I think @dirkjanm.io may have initiated the extra pressure this one needed. 😁 Still excited about the outcome!
Reposted by Katie Knowles
1cemoon.bsky.social
Check out my new blog on nested app authentication.
specterops.io
Why should Microsoft's Nested App Authentication (NAA) should be on your security team's radar? @1cemoon.bsky.social breaks down NAA and shows how attackers can pivot between Azure resources using brokered authentication. ghst.ly/45h2Zw3
Going for Broke(ring) – Offensive Walkthrough for Nested App Authentication - SpecterOps
In depth walkthrough for using nested app authentication (NAA), or BroCI, for offensive engagements to access information and resources.
ghst.ly
siigil.bsky.social
Excited to see folks at DEFCON next week!! Ready to see some great talks and get those conference steps in. 👟
siigil.bsky.social
Congrats!! Sounds like a fun (& wild!) opportunity.
Reposted by Katie Knowles
frichetten.com
Join my team! We’re looking for a Senior Security Researcher specializing in Generative AI. You’ll have the opportunity to be a part of one of the leading security research organizations in the industry and shape Datadog’s security products! A 🧵
careers.datadoghq.com/detail/70312...
Senior Security Researcher - GenAI | Datadog Careers
We're building a platform that engineers love to use. Join us, and help usher in the future.
careers.datadoghq.com
siigil.bsky.social
☁️ My fwd:cloudsec talk, "I SPy: Rethinking Entra ID research for new paths to Global Admin", is up! Learn what a service principal is, how Microsoft's first-party apps could be backdoored, and one weird trick they haven't fixed yet:
www.youtube.com/watch?v=oNpw...
I SPy: Rethinking Entra ID research for new paths to Global Admin
YouTube video by fwd:cloudsec
www.youtube.com
Reposted by Katie Knowles
ericonidentity.com
At @wearetroopers.bsky.social I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable SaaS applications. The attack is still alive and well.

You can read all about it here:

#Entra #M365 #infosec

www.semperis.com/blog/noauth-...
New nOAuth Abuse Alert: Entra Cross-Tenant Saas Apps at Risk
Think nOAuth abuse is old news? We wish. Our recent testing shows that nearly 10% of apps in the Microsoft Entra Gallery remain vulnerable.
www.semperis.com
siigil.bsky.social
Enjoy! ☀️ Ignore my drooling over here. :)
siigil.bsky.social
My RSAC virtual session is up! Catch "Persisting Unseen: Attacker Methods of Infesting Entra ID" here: youtu.be/ngSFP-tgupM?...

Companion blog: kknowl.es/posts/defend...
Traditional Sessions: RSAC Virtual Seminar: Cloud Security
YouTube video by RSA Conference
youtu.be
siigil.bsky.social
Excited to watch these! roadoidc was great to play with, thank you for adding it. Been eagerly waiting to hear the full story on this, EAM, and FICs. 😁
siigil.bsky.social
🌐 I'll be speaking at RSA Conference's Virtual Seminar on Cloud Security on June 5, 2025! I'll be sharing a technical overview of Entra persistence techniques for all levels. You can sign up to stop by here: www.rsaconference.com/library/virt...
LinkedIn
This link will take you to a page that’s not on LinkedIn
lnkd.in
Reposted by Katie Knowles
fwdcloudsec.org
The CFP for fwd:cloudsec Europe is now open! We're looking for practitioner-focused cloud security content, and we encourage all practitioners to submit, whatever your role or level of experience.

The CFP is open until July 11th. Read more: fwdcloudsec.org/conference/e...
CFP | EU 2025 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
fwdcloudsec.org
Reposted by Katie Knowles
specterops.io
In our latest blog post, @xpnsec.com breaks down how SQL Server Transparent Data Encryption works, shares new methods for brute-forcing database encryption keys, & reveals a default key used by ManageEngine's ADSelfService product backups.

Read more 👉 ghst.ly/4iXFTyF
siigil.bsky.social
Had a fantastic time at @specterops.bsky.social SO-CON and Azure training! So much to learn, and so many incredible people to meet. Feeling excited to apply all this knowledge... time to head home. 😁
siigil.bsky.social
Excited to be at @specterops.bsky.social SO-CON this week!! If you're around, I'll be presenting "Abusing AUs, Confusing the SOC" tomorrow bright & early:
siigil.bsky.social
Enjoy that 2m repeater net gossip! Good + weird memories. 🥹