Trends in Identity Attack Path Management

Trends in Identity Attack Path Management

Source: YouTube · SpecterOps · published Jul 8, 2025 · 1:00:19

Identity & Access Management
No ratings yet Log in to rate
Transcript Available
Description

Spectre Ops and OMIDIA surveyed 500+ security leaders on identity attack path management, revealing critical gaps in visibility and strategy 1:01.

Key Takeaways:
• Organizations struggle with fragmented identity data, making it difficult to map attack paths effectively 1:30.
• There is a significant gap between the perceived risk of identity attacks and the actual resources allocated to mitigate them 2:15.
• Traditional perimeter defenses are insufficient; defenders must prioritize identity-centric threat modeling to detect lateral movement 3:00.
• Automation and continuous monitoring are essential for real-time identification of compromised credentials and anomalous behavior 4:10.

Addressing identity-centric risks requires a shift from static perimeter security to dynamic, behavior-based monitoring to protect critical assets.

Sources:

  • 1:01 Introduction of the joint research study with OMIDIA.
  • 1:30 Discussion on challenges in mapping identity attack paths.
  • 2:15 Analysis of the gap between risk perception and resource allocation.
  • 3:00 The necessity of identity-centric threat modeling.
  • 4:10 The role of automation in detecting compromised credentials.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right. Uh good morning, good afternoon, good evening uh to those of you joining us wherever you may be. Uh thank you for joining Spectre Ops for our presentation on trends in identity attack path management today. Uh my name is Luke Luckett, director of product marketing here at Spectre Ops. And I am pleased to be joined by Justin Kohler, our chief product officer, and Jared Atkinson, our chief technology officer. And what we wanted to talk with you about today is uh is sharing some research that we worked on with analyst firm OMDIA uh earlier this year to survey more than 500 senior cyber security decision makers on how they think and feel about attack path management especially as it comes to identities. Uh next slide please. I'm going to quickly go over a couple of key findings befo…