
Okta For Good and Bad: Hybrid Attack Paths Crossing Okta Organizations | SO-CON 26
Source: YouTube · SpecterOps · published Jun 4, 2026 · 48:07
The Shadow Credentials attack against Active Directory was originally invented by Michael Grafnetter but gained significant attention only after Elad Shamir published a blog post about it 0:25.
Key Takeaways:
• Michael Grafnetter, a security researcher at SpecterOps, introduced the Shadow Credentials attack in a presentation that initially went unnoticed 0:22.
• Elad Shamir later discovered the technique and published a blog post that brought widespread recognition to the vulnerability 0:34.
• Grafnetter is also known for authoring the DSInternals PowerShell module for Active Directory security research 0:18.
This highlights how independent discovery can amplify technical findings within the cybersecurity community.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So, hello everybody. How are you doing today? >> Good. >> Yeah. So, my name is Michael Grafnetter. I work as a security researcher at SpecterOps. And previously, I did a lot of Active Directory security research. So, some of you might know me as the author of the DS Internals or Directory Services Internals PowerShell module. I originally invented the Shadow Credentials attack against Active Directory, but nobody noticed my presentation until Elad, who's sitting at in the in the back, noticed it and and published a blog post. And that blog post of his got got famous, not my not my original talk where where I where I was presenting that. Yeah, so so that's me. >> Yeah. Hello everyone. My name's Lance Cain. I'm an offensive security engineer at SpecterOps. I In a previous life, I spent about…