Extending Attack Path Management into Okta, GitHub, and Mac Environments

Extending Attack Path Management into Okta, GitHub, and Mac Environments

Source: YouTube · SpecterOps · published May 18, 2026 · 50:15

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

SpecterOps announces new enterprise extensions for BloodHound Enterprise, enabling cross-platform attack path analysis across GitHub, Okta, and Jamf to identify complex privilege escalation vectors 0:08.

Key Takeaways:
• Justin Kohler (CPO) and Jared Atkinson (CTO) introduce extensions for GitHub, Okta, and Jamf, highlighting the "messy middle" of interconnected identity systems 0:18
• Attackers leverage cross-platform dependencies (e.g., AD to GitHub) to bypass siloed security controls, with 70% of privileged identities often exposed via attack paths 10:23
• New enterprise features include automated findings, remediation tracking, and Environment Targeted Access Control (EAC) to manage risks across multiple environments 35:45

BloodHound Enterprise empowers defenders to visualize and remediate these cross-platform risks before they are exploited, with official collectors releasing in mid-April.

Sources:

  • 0:08 Introduction of speakers and topic overview
  • 10:23 Discussion on attack path prevalence and cross-platform pivoting
  • 35:45 Details on enterprise features and release timeline

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, Jared, I think we're two minutes after. We could probably get started. Um, >> yep. >> So, uh, we're really excited to talk to you about some new extensions and announcements in Blood Hound Enterprise today. U, my name is Justin Kohler. I'm the chief product officer at Spectre Ops. >> And I'm Jared Atinson. I'm chief technology officer. Maybe a way to distinguish between Justin and I, I'm mostly in charge of our research and development team. And so if you have issues with the graph model or the collector, that's probably in my domain. If you have uh kudos or concerns or thoughts about the actual application and the way that you interact with it, that's uh kind of more in Justin's domain. So just kind of opening ourselves up for uh that feedback, whether it's positive or negative…