About
Julian Catrambone
I’m a Red Team Engineer at SpecterOps, where I spend my time exploring the seams between on-prem identity and cloud platforms. I’m particularly interested in how trust, identity, and seemingly reasonable configurations can cross those boundaries to create unexpected attack paths.
Selected threads
A few places to start.
-
OneLogin, Many Issues
Following exposed credentials, signing keys, and cloud resources across the boundaries of an identity platform.
-
Your CI/CD Pipeline is My Attack Path
Graphing the path from GitHub OIDC trust to AWS access and cloud takeover.
-
From Dev to Prod
A hands-on AWS privilege-escalation lab culminating in an attack path across three accounts.
-
Attacking FreeIPA
Authentication, enumeration, lateral movement, and privilege boundaries in FreeIPA environments.
This archive
Kept for the record.
This site is the durable home for my published research, field notes, and older writing that previously lived elsewhere. The archive reaches back to 2017; the perspective and tooling have evolved, but the original work remains available in context.
Keep in touch
No algorithm required.
New research lands here first. Subscribe directly, browse the code, or connect on LinkedIn.