Blog

Field notes on identity and cloud attacks

Practitioner breakdowns of the identity, cloud, and SaaS attacks teams actually face. How each one works, how to detect it, and how to recover. Search by keyword or filter by tag.

Latest

Insider Risk

The insider you cannot just lock out: responding to a privileged departure

For an external attacker, you contain first and scope second. For an insider with legitimate access, that reflex tips off a malicious actor, taints admissible evidence, breaks employment law, or punishes an innocent person. Here is why insider response inverts the playbook, and how to decide when to govern and when to act.

Insider Risk

The biggest insider risk is a good admin having a bad day

The insider threat that fires most often is not a spy or a thief - it is a trusted administrator making a high-blast-radius mistake. Here is why administrative error is the dominant insider risk, and why disciplining it makes your next outage worse, not less likely.

Insider Risk

Negligence is not theft: the clinician who took the charts home

A nurse exports patient records to a personal drive to finish charting from home. It is a real HIPAA incident and it is not theft. Here is why treating a well-meaning clinician as a data thief backfires, and how a corrective, just-culture response contains the breach and fixes the reason for the workaround.

Insider Risk

He has a handler: why confronting a recruited insider destroys the case

A trader is feeding pre-release deal flow to a competitor fund for money. Cutting his access and confronting him is the reflex - and it tips the handler, wipes the evidence, and loses the ring. Here is why, for a recruited insider, speed is not containment, and what a covert, coordinated response looks like.

17 posts

The spy who is a victim: responding to a coerced insiderInsider Risk

A cleared engineer is leaking controlled data to a foreign party - but the evidence says he is being coerced, not paid. Here is why pulling his clearance and referring him for espionage can tip the handler, foreclose counterintelligence, and endanger a victim, and what a covert, CI-led response looks like.

Your engineers paste secrets into AI. Banning it makes it worseInsider Risk

An engineer pastes proprietary code and customer data into a public AI chatbot to get unblocked. It is a real third-party exposure and it is not theft. Here is why treating it as data theft and banning AI drives the behavior onto personal phones where you have zero visibility, and what enabling a safe path looks like instead.

Okta support HAR session theft: when the help file hands over adminSaaS

A HAR file uploaded to support can carry a live session token. Steal it and you replay an admin session with no password or MFA needed. Here is how the Okta-style attack turns a help file into tenant takeover, why a password reset does nothing, and how to contain it.

GCP service account impersonation: borrowing identity in Google CloudGCP

In GCP, the right to generate tokens for a service account lets an attacker act as it, no key required. Here is how impersonation and key abuse chain up the IAM hierarchy toward project owner, why it is so quiet, and how to bound it.

Microsoft Teams external access: when a trusted chat is the delivery channelEntra & M365

Teams external access lets outside domains message your users directly, bypassing email security entirely. Here is how attackers abuse it to phish and exfiltrate, why users trust it more than email, and how to lock it down to an allowlist.

It was not a Snowflake breach: stolen-credential data theft explainedSaaS

The 2024 Snowflake customer data thefts used valid stolen credentials against accounts with no MFA. Here is what happened, how to detect it, and the two controls that would have stopped it.

From SSRF to stolen cloud credentials: the EC2 metadata attackAWS

An SSRF flaw can read EC2 instance-role credentials from the metadata service and replay them from anywhere. Here is the attack, the detection, and why IMDSv2 stops it.

Kerberoasting: how service account passwords get cracked, and how to stop itActive Directory

Kerberoasting lets any domain user request service tickets and crack them offline for service account passwords. Here is how it works, how to detect it, and the fix that actually holds.

When attackers unenroll your devices: Intune as an attack surfaceEntra & M365

An attacker with Intune rights can unenroll devices and disable compliance controls, stripping protection before deploying malware. Here is the technique, how to detect it, and how to lock it down.

MFA fatigue attacks: how push bombing defeats MFA, and how to stop itEntra & M365

MFA fatigue spams a user with approval prompts until one is accepted. Here is how the attack works, how to detect it, and why number matching and phishing-resistant MFA stop it.

Containment under fire: leading an identity breach in the first hourIdentity & Access

When identity itself is compromised, the first hour is about command, scope, and containment, not restoration. Here is how leadership should run it: the decisions only an executive can own, the containment tradeoff, and the record the board will ask for.

Azure Run Command: how a VM contributor becomes subscription ownerAzure

A user with Contributor on a VM can run code as the VM and borrow its managed identity. If that identity is over-privileged, it is a path to subscription owner. Here is the fix.

Business email compromise: the inbox rules you are not watchingEntra & M365

After a mailbox takeover, attackers commit fraud from a trusted account and stay hidden with inbox rules that survive a password reset. Here is why BEC outlives the password, the persistence to hunt in the Microsoft 365 audit log, and how to contain it for real.