Sign in

Katie Knowles

@siigil.bsky.social
1.1K followers 85 following 35 posts

Security Researcher @ Datadog. 🐶 Head in the (Azure) clouds. Sometimes blogging, always curious. Aim to be, rather than to seem. Blogs at kknowl.es.

PostsRepliesMedia
Reposted by Katie Knowles
Datadog Security Labs @securitylabs.datadoghq.com · 28/10/2025
CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing securitylabs.datadoghq.com/articles/cop... by @siigil.bsky.social
securitylabs.datadoghq.com
CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing | Datadog Security Labs
Copilot Studio links look benign, but they can host content to redirect users to arbitrary URLs. In this post, we document a method by which a Copilot Studio agent's login settings can redirect a user...
032
Katie Knowles @siigil.bsky.social · 20/10/2025
😈 Copilot Studio agents are great for users... and attackers! Check out our deep-dive on why you should be careful to trust unknown agents, plus background on upcoming app consent changes that will help prevent our demo scenario. securitylabs.datadoghq.com/articles/cop...
securitylabs.datadoghq.com
CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing | Datadog Security Labs
Copilot Studio links look benign, but they can host content to redirect users to arbitrary URLs. In this post, we document a method by which a Copilot Studio agent's login settings can redirect a user...
041
Reposted by Katie Knowles
Nick Frichette @frichetten.com · 19/08/2025
Old and busted: Cloud attackers making noisy List/Describe calls. New hotness: Laundering enumeration calls through an AWS service silently. Or at least, that used to work, until @datadoghq.com partnered with AWS to close this gap. Read more here: securitylabs.datadoghq.com/articles/enu...
securitylabs.datadoghq.com
Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer | Datadog Security Labs
Discover how attackers could quietly enumerate AWS resources via Resource Explorer, and how Datadog and AWS worked together to close the visibility gap.
0104
Katie Knowles @siigil.bsky.social · 14/08/2025
🎉 Exciting news: The Office 365 Exchange Online SP privilege escalation we documented in "I SPy" is no longer possible! We've updated the post to reflect this. Thanks to Eli Guy for the tip on this one: securitylabs.datadoghq.com/articles/i-s...
securitylabs.datadoghq.com
I SPy: Escalating to Entra ID's Global Admin with a first-party app | Datadog Security Labs
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led...
1111
Reposted by Katie Knowles
Hope Walker @1cemoon.bsky.social · 13/08/2025
Check out my new blog on nested app authentication.
065
Katie Knowles @siigil.bsky.social · 31/07/2025
Excited to see folks at DEFCON next week!! Ready to see some great talks and get those conference steps in. 👟
020
Katie Knowles @siigil.bsky.social · 16/07/2025
🕵️‍♀️ Looking to escalate privileges with a first-party Microsoft app? How do federated domain backdoors work? And what's an app reg, really? All this and more in our new @securitylabs.datadoghq.com post: securitylabs.datadoghq.com/articles/i-s...
securitylabs.datadoghq.com
I SPy: Escalating to Entra ID's Global Admin with a first-party app | Datadog Security Labs
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led...
040
Reposted by Katie Knowles
Nick Frichette @frichetten.com · 09/07/2025
Join my team! We’re looking for a Senior Security Researcher specializing in Generative AI. You’ll have the opportunity to be a part of one of the leading security research organizations in the industry and shape Datadog’s security products! A 🧵 careers.datadoghq.com/detail/70312...
careers.datadoghq.com
Senior Security Researcher - GenAI | Datadog Careers
We're building a platform that engineers love to use. Join us, and help usher in the future.
146
Katie Knowles @siigil.bsky.social · 03/07/2025
☁️ My fwd:cloudsec talk, "I SPy: Rethinking Entra ID research for new paths to Global Admin", is up! Learn what a service principal is, how Microsoft's first-party apps could be backdoored, and one weird trick they haven't fixed yet: www.youtube.com/watch?v=oNpw...
youtube.com
I SPy: Rethinking Entra ID research for new paths to Global Admin
YouTube video by fwd:cloudsec
050
Reposted by Katie Knowles
Eric Woodruff @ericonidentity.com · 25/06/2025
At @wearetroopers.bsky.social I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable SaaS applications. The attack is still alive and well. You can read all about it here: #Entra #M365 #infosec www.semperis.com/blog/noauth-...
semperis.com
New nOAuth Abuse Alert: Entra Cross-Tenant Saas Apps at Risk
Think nOAuth abuse is old news? We wish. Our recent testing shows that nearly 10% of apps in the Microsoft Entra Gallery remain vulnerable.
021
Katie Knowles @siigil.bsky.social · 24/06/2025
My RSAC virtual session is up! Catch "Persisting Unseen: Attacker Methods of Infesting Entra ID" here: youtu.be/ngSFP-tgupM?... Companion blog: kknowl.es/posts/defend...
youtu.be
Traditional Sessions: RSAC Virtual Seminar: Cloud Security
YouTube video by RSA Conference
020
Katie Knowles @siigil.bsky.social · 17/06/2025
🕵️‍♀️ I'll be presenting "I SPy: Rethinking Entra ID research for new paths to Global Admin” at fwd:cloudsec June 30-July 1, alongside some fantastic other speakers: fwdcloudsec.org/conference/n... If you can’t make it, talks are streamed at: www.youtube.com/@fwdcloudsec
fwdcloudsec.org
fwd:cloudsec 2025 Speaker Bios & Abstracts | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
051
Katie Knowles @siigil.bsky.social · 05/06/2025
🥷 Detect & defend vs Entra ID persistence! From my RSAC Cloud Summit talk, I've shared how attackers persist through Entra ID roles, applications, and authentication... and how you can stop them: kknowl.es/posts/defend...
kknowl.es
Persisting Unseen: Defending against Entra ID persistence
I recently presented “Persisting Unseen: Attacker Methods of Infesting Entra ID” at RSAC’s virtual Cloud Security seminar. This session introduced some methods attackers may use now or in the near fut...
011
Reposted by Katie Knowles
Greg Foss @gregfoss.com · 19/05/2025
Excited to speak at @fwdcloudsec.org in Denver on June 30 with Anthony Randazzo! We’ll share lessons from a year of cloud threat hunting. Don’t miss other @securitylabs.datadoghq.com talks from @siigil.bsky.social on EntraID escalation and @sethsec.bsky.social on AMI name confusion as well!
fwdcloudsec.org
fwd:cloudsec 2025 Speaker Bios & Abstracts | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
071
Katie Knowles @siigil.bsky.social · 09/05/2025
🌐 I'll be speaking at RSA Conference's Virtual Seminar on Cloud Security on June 5, 2025! I'll be sharing a technical overview of Entra persistence techniques for all levels. You can sign up to stop by here: www.rsaconference.com/library/virt...
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
000
Reposted by Katie Knowles
fwd:cloudsec @fwdcloudsec.org · 07/05/2025
The CFP for fwd:cloudsec Europe is now open! We're looking for practitioner-focused cloud security content, and we encourage all practitioners to submit, whatever your role or level of experience. The CFP is open until July 11th. Read more: fwdcloudsec.org/conference/e...
fwdcloudsec.org
CFP | EU 2025 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
055
Katie Knowles @siigil.bsky.social · 06/05/2025
👾 It's up!! Everything you ever wanted to know about Entra Administrative Unit (AU) attack paths, from my talk at @specterops.io SO-CON 😁 www.youtube.com/watch?v=oxD7...
youtube.com
Abusing AUs, Confusing the SOC: Entra ID's Administrative Unit Attack Paths | SO-CON 2025
YouTube video by SpecterOps
031
Reposted by Katie Knowles
SpecterOps @specterops.io · 08/04/2025
In our latest blog post, @xpnsec.com breaks down how SQL Server Transparent Data Encryption works, shares new methods for brute-forcing database encryption keys, & reveals a default key used by ManageEngine's ADSelfService product backups. Read more 👉 ghst.ly/4iXFTyF
0115
Katie Knowles @siigil.bsky.social · 06/04/2025
Had a fantastic time at @specterops.bsky.social SO-CON and Azure training! So much to learn, and so many incredible people to meet. Feeling excited to apply all this knowledge... time to head home. 😁
040
Katie Knowles @siigil.bsky.social · 31/03/2025
Excited to be at @specterops.bsky.social SO-CON this week!! If you're around, I'll be presenting "Abusing AUs, Confusing the SOC" tomorrow bright & early:
1157
Katie Knowles @siigil.bsky.social · 25/03/2025
🛡️ We found a bug in restricted AUs that let accounts stay restricted (forever!) without an AU, preventing containment. Glad this is fixed now! More details here: securitylabs.datadoghq.com/articles/cre...
securitylabs.datadoghq.com
Creating immutable users through a bug in Entra ID restricted administrative units | Datadog Security Labs
Imagine trying to disable a malicious user in your Azure environment, only to find it can't be modified! We recently identified a timing-based bug in Entra ID's restricted administrative units (AUs) t...
0105
Reposted by Katie Knowles
Datadog Security Labs @securitylabs.datadoghq.com · 26/02/2025
The Datadog Security Digest is a monthly, practitioner-focused newsletter. Don't miss our February edition going live tomorrow! securitylabs.datadoghq.com/newsletters/...
054
Reposted by Katie Knowles
Datadog Security Labs @securitylabs.datadoghq.com · 12/02/2025
We discovered a pattern in the way many projects retrieve Amazon Machine Images (AMIs), allowing attackers to publish AMIs with specially crafted names and gain code execution within vulnerable accounts. securitylabs.datadoghq.com/articles/who... by @sethsec.bsky.social
securitylabs.datadoghq.com
whoAMI: A cloud image name confusion attack | Datadog Security Labs
Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.
185
Reposted by Katie Knowles
SpecterOps @specterops.io · 15/01/2025
Check out this new blog post from @andyrobbins.bsky.social discussing the fundamental components & mechanics that enable the emergence of critical Attack Paths in Microsoft's increasingly popular Intune product. ghst.ly/3Cd5cwH
ghst.ly
Intune Attack Paths — Part 1
Intune is an attractive system for adversaries to target…
064
Katie Knowles @siigil.bsky.social · 20/12/2024
🎄Have you ever paid for a simple product and thought, "Hey, I could build that"? As a pre-holiday project, I tried my hand at "home cooking" my own web text editor with GPT Canvas: kknowl.es/posts/home-c... + the results: github.com/siigil/brevity
kknowl.es
Home cooking apps with AI assistance
This is a reflective end-of-year post on using AI to make our app wishes come true. Happy holidays! ❄️
010
Katie Knowles @siigil.bsky.social · 19/12/2024
👻 Excited to be presenting "Abusing AUs, Confusing the SOC: Entra ID's Administrative Unit Attack Paths" at #SOCON2025, March 31-April 1! You can register to join me with discount code SOCONSPEAKER20: ghst.ly/socon25-spkr
140
Reposted by Katie Knowles
Datadog Security Labs @securitylabs.datadoghq.com · 17/12/2024
"Escalating privileges to read secrets with Azure Key Vault access policies" by @siigil.bsky.social securitylabs.datadoghq.com/articles/esc...
securitylabs.datadoghq.com
Escalating privileges to read secrets with Azure Key Vault access policies | Datadog Security Labs
Azure Key Vault Contributors are not allowed access to Key Vault keys, certificates, and secrets. But did you know they can still gain access to this sensitive data? This post will cover a privilege e...
0157
Katie Knowles @siigil.bsky.social · 17/12/2024
🔑 Azure Key Vault Contributors can't access keys... but they CAN modify access policies! More on how this can lead to unintended data access here: securitylabs.datadoghq.com/articles/esc...
securitylabs.datadoghq.com
Escalating privileges to read secrets with Azure Key Vault access policies | Datadog Security Labs
Azure Key Vault Contributors are not allowed access to Key Vault keys, certificates, and secrets. But did you know they can still gain access to this sensitive data? This post will cover a privilege e...
045
Katie Knowles @siigil.bsky.social · 14/12/2024
🎄 I shared a lab on reviewing Azure security with KQL + Resource Graph Explorer! My walkthrough is available as Day 14 of the Advent of Cloud Security: ❄️ Calendar, Day 14: advent.cloudsecuritypodcast.tv ❄️ Full Repo: github.com/siigil/azure...
github.com
GitHub - siigil/azure-kql-demo: Demo: Review your Azure security with the power of Resource Graph + KQL!
Demo: Review your Azure security with the power of Resource Graph + KQL! - siigil/azure-kql-demo
0123
Reposted by Katie Knowles
SpecterOps @specterops.io · 13/12/2024
Check out the kickoff to @hotnops.bsky.social's multi-part blog series on attacker tradecraft around the syncing mechanics between Active Directory & Entra. In this first part, he shows how complete control of an Entra user is equal to compromise of the on-premises user. ➡️ ghst.ly/3Bu19eW
ghst.ly
Attacking Entra Metaverse: Part 1
This is part one in a two (maybe three…) part series regarding attacker tradecraft around the syncing mechanics between Active Directory…
041
Reposted by Katie Knowles
Dirk-jan @dirkjanm.io · 12/12/2024
Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph 😃
34520
Reposted by Katie Knowles
Datadog Security Labs @securitylabs.datadoghq.com · 11/12/2024
"Tales from the cloud trenches: Unwanted visitor" securitylabs.datadoghq.com/articles/tal... This post describes an attacker that we've observed in the wild, including a malicious AWS account ID used to create a backdoor IAM role.
0206
Katie Knowles @siigil.bsky.social · 06/12/2024
We talk about Obsidian as a second brain, but I prefer the joy it can spark as a "second braincell". Wikipedia will never love your banter the same way you do:
010
Katie Knowles @siigil.bsky.social · 04/12/2024
If you've ever wanted to add "Stratus Red Team Contributor" to your list of titles! 😉
010
Reposted by Katie Knowles
Christophe Tafani-Dereeper @christophetd.fr · 04/12/2024
Stratus Red Team v2.20.0 is now available, with great contributions from @flekyy90.bsky.social allowing you to reproduce AWS TTPs seen in the wild! ➔ Use GetFederationToken to generate temporary credentials ➔ Use SendSerialConsoleSSHPublicKey to pivot to EC2 instances github.com/DataDog/stra...
1149
Reposted by Katie Knowles
Tracebit @tracebit.bsky.social · 25/11/2024
Our Founding Engineer Michael has been in the weeds of Azure logging for the past few months. Some of the details discovered may surprise you... tracebit.com/blog/azure-d...
tracebit.com
Azure Detection Engineering: Log idiosyncrasies you should know about
We share a few inconsistencies found in Azure logs which make detection engineering more challenging.
082
Katie Knowles @siigil.bsky.social · 08/11/2024
🌤️ Happy Friday!! Wondering what's in Entra ID's Free tier for your lab experiments? I recently found out this moved to a Microsoft Learn page, instead of its previous home on the sales page: learn.microsoft.com/en-us/entra/...
learn.microsoft.com
Microsoft Entra licensing - Microsoft Entra
This article documents licensing requirements for Microsoft Entra features.
0172
Katie Knowles @siigil.bsky.social · 04/11/2024
Hello! 👋 I'm still getting set up, & will be exploring the next few days.
040