
Mapping GitLab Attack Paths into BloodHound with OpenGraph | SO-CON 26
Source: YouTube · SpecterOps · published Jun 4, 2026 · 44:11
Modern DevOps platforms, particularly GitLab, serve as critical infrastructure for identity-driven attack vectors, making them essential targets for both defenders and attackers 0:06.
Key Takeaways:
• The speaker argues that GitLab and similar DevOps platforms are cornerstones of modern attack paths due to their central role in identity management 0:14.
• An open graph collector tool for GitLab is introduced to visualize these complex identity-driven attack paths 0:24.
• The talk is designed to be relevant for both defensive security professionals and offensive attackers 0:18.
Understanding the security implications of DevOps platforms is vital for securing modern software development pipelines.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Thanks for attending my talk. During the next 45 minutes, I'm hopefully going to convince you that modern DevOps platform, especially GitLab in this context, are important cornerstones for modern identity-driven attack paths. So, whether you're a defender or an attacker, you should pay attention to them. And hopefully, you will be able to use my open graph collector for GitLab to visualize some of these attack paths. A couple of words to for myself. I'm from Switzerland. I have a former computer science background where I got a glimpse into modern operating system research. I'm a former participant of Google Summer of Code and currently working professionally at Swiss uh medium-sized Swiss company Compass Security, where I'm also doing red teaming engagements. And in the aftermath of such …