Hacking from Cloud to Endpoint (and vice versa)

Hacking from Cloud to Endpoint (and vice versa)

Source: YouTube · John Hammond · published Oct 2, 2024 · 30:07

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The BloodHound team introduces new cross-platform attack path detection capabilities that identify security risks between on-prem Active Directory and Azure/Entra ID environments 0:04. These features reveal dangerous user synchronization vulnerabilities where attackers can pivot between on-prem and cloud systems 2:15-2:27.

Key Takeaways:
• Attackers are moving beyond password changes to token theft techniques to bypass MFA and conditional access protections 8:00-8:16
• 100% of analyzed environments had synced privileged roles between on-prem AD and Azure, with 70% syncing Global Admin roles 23:00-23:20
• Hybrid attack paths can span multiple domains and trust relationships, creating complex attack surfaces 24:48-25:06

These new capabilities in BloodHound Community Edition help organizations identify and mitigate dangerous cross-platform attack paths that adversaries are actively exploiting 22:00-22:30.

Sources:

  • 0:04 Introduction to cross-platform attack path features
  • 2:15-2:27 Explanation of user synchronization vulnerabilities
  • 8:00-8:16 Attack techniques focusing on token theft
  • 23:00-23:20 Statistics on synced privileged roles
  • 24:48-25:06 Complex multi-domain attack path examples
  • 22:00-22:30 Real-world adoption and availability

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Al righty well goodness hey thank you all so much for tuning in and look I'm ecstatic I'm a little excited we're in for a bit of a treat today uh hanging out with some of my good friends over at Spectre Ops and my goodness uh Justin Andy you will know that I am a fanboy uh and I hope a friend uh but really loving all the incredible stuff you up to with blood hound uh Blood Hound Enterprise and I think everyone tuning in just absolutely knows hey that is the go-to tool for digging into active directory environments but it's not just that right we've expanded even Beyond uh on premise instances but I'd love for you to do a little bit of show and tell if you're willing uh on all the sweet stuff that it's up to and hey please just fill in the gaps hey who the heck you are what you're up to uh …