Attack Paths in Practice: Okta, GitHub, and Jamf with BloodHound Enterprise | SO-CON 26

Attack Paths in Practice: Okta, GitHub, and Jamf with BloodHound Enterprise | SO-CON 26

Source: YouTube · SpecterOps · published Jun 4, 2026 · 31:36

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This talk provides a deep dive into real-world attack paths targeting identity and cloud infrastructure, specifically focusing on Jamf, Okta, and GitHub, including lessons from recent breaches like the Trevi incident 0:00.

Key Takeaways:
• The presentation focuses on exploiting Jamf, Okta, and GitHub within actual enterprise environments, expanding on a previous morning session 0:00.
• It examines recent security events, specifically the Trevi breach, highlighting how GitHub was leveraged to connect to AWS infrastructure 0:15.
• The core concept of the session is "attack paths," which details the methodology of escalating from a single compromised identity to broader system access 0:39.

This session aims to deliver actionable insights into how attackers chain these specific platforms together during an intrusion.

Sources:

  • 0:00 Introduction of the core topics: Jamf, Okta, and GitHub
  • 0:15 Discussion of the Trevi breach connecting GitHub to AWS
  • 0:39 Definition of "attack paths" starting from a single identity

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

This talk is going to be all about Jamf, Okta, and GitHub. We kind of previewed some of this in our talk this morning. We're going to dive a little bit deeper and talk about some of the things that we've seen in real environments, especially attacking like Jamf and um GitHub for sure. Some of the most like more recent events like the Trevi breach that happened with um uh GitHub and connecting that to AWS. So, a little bit of a deeper dive for our morning session. For those of you here, there will be repeat content. >> Sorry, there will. >> Um who wasn't here in the morning? All right, cool. Well, this is for you. Um so, real quick before we get started, again reminder attack paths are what we're talking about. Uh it's how we go from a single identity that we might have initial like we brea…