Conference record

Talks

Workshops, recorded presentations, slides, demos, and supporting research.

Black Hat USA Workshop

From Dev to Prod: AWS Cross Account Privilege Escalation

A hands-on journey through AWS attack paths, from individual escalation primitives to a capstone spanning three accounts and conditional access controls.

Black Hat USA 2026 workshop card for From Dev to Prod, presented by Julian Catrambone and Daniel Heinsen on Wednesday, August 5 at 2:30 PM.
Delivered with Daniel Heinsen at the SpecterOps Kennel Club during Black Hat USA 2026.

About the workshop

The lab covers IAM, EC2, SSM, EKS, CloudFormation, KMS, Lambda, and S3, then brings the pieces together in a cross-account attack-path exercise. Participants use AWSHound to analyze the environment and identify the paths an attacker could follow.

SO-CON SpecterOps

Your CI/CD Pipeline is My Attack Path: Graphing GitHub OIDC to Cloud Takeover

How attackers move from a GitHub fork to AWS access through misconfigured OIDC trust policies—and how defenders can graph these cross-platform identity chains before they become breach paths.

About the session

No credentials to steal? No problem. This talk walks through the UNC6426 and Trivy Actions compromises, then connects GitHub Actions, OIDC federation, and AWS trust policy mistakes into attack paths defenders can discover with BloodHound collectors and OpenGraph.