About

Julian Catrambone

I’m a Red Team Engineer at SpecterOps, where I spend my time exploring the seams between on-prem identity and cloud platforms. I’m particularly interested in how trust, identity, and seemingly reasonable configurations can cross those boundaries to create unexpected attack paths.

Selected threads

A few places to start.

  1. Research · 2025

    OneLogin, Many Issues

    Following exposed credentials, signing keys, and cloud resources across the boundaries of an identity platform.

  2. Talk · 2026

    Your CI/CD Pipeline is My Attack Path

    Graphing the path from GitHub OIDC trust to AWS access and cloud takeover.

  3. Workshop · 2026

    From Dev to Prod

    A hands-on AWS privilege-escalation lab culminating in an attack path across three accounts.

  4. Research series · 2019–2020

    Attacking FreeIPA

    Authentication, enumeration, lateral movement, and privilege boundaries in FreeIPA environments.

This archive

Kept for the record.

This site is the durable home for my published research, field notes, and older writing that previously lived elsewhere. The archive reaches back to 2017; the perspective and tooling have evolved, but the original work remains available in context.

Keep in touch

No algorithm required.

New research lands here first. Subscribe directly, browse the code, or connect on LinkedIn.