
Attack Paths in Practice: Okta, GitHub, and Jamf with BloodHound Enterprise | SO-CON 26
Source: YouTube · SpecterOps · published Jun 4, 2026 · 31:36
This talk provides a deep dive into real-world attack paths targeting identity and cloud infrastructure, specifically focusing on Jamf, Okta, and GitHub, including lessons from recent breaches like the Trevi incident 0:00.
Key Takeaways:
• The presentation focuses on exploiting Jamf, Okta, and GitHub within actual enterprise environments, expanding on a previous morning session 0:00.
• It examines recent security events, specifically the Trevi breach, highlighting how GitHub was leveraged to connect to AWS infrastructure 0:15.
• The core concept of the session is "attack paths," which details the methodology of escalating from a single compromised identity to broader system access 0:39.
This session aims to deliver actionable insights into how attackers chain these specific platforms together during an intrusion.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
This talk is going to be all about Jamf, Okta, and GitHub. We kind of previewed some of this in our talk this morning. We're going to dive a little bit deeper and talk about some of the things that we've seen in real environments, especially attacking like Jamf and um GitHub for sure. Some of the most like more recent events like the Trevi breach that happened with um uh GitHub and connecting that to AWS. So, a little bit of a deeper dive for our morning session. For those of you here, there will be repeat content. >> Sorry, there will. >> Um who wasn't here in the morning? All right, cool. Well, this is for you. Um so, real quick before we get started, again reminder attack paths are what we're talking about. Uh it's how we go from a single identity that we might have initial like we brea…