<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>Security Researcher @ Datadog. 🐶 Head in the (Azure) clouds.&#xA;Sometimes blogging, always curious. Aim to be, rather than to seem. &#xA;Blogs at https://kknowl.es.</description><link>https://bsky.app/profile/siigil.bsky.social</link><title>@siigil.bsky.social - Katie Knowles</title><item><link>https://bsky.app/profile/siigil.bsky.social/post/3m3mw2w2y4k2d</link><description>😈 Copilot Studio agents are great for users... and attackers! Check out our deep-dive on why you should be careful to trust unknown agents, plus background on upcoming app consent changes that will help prevent our demo scenario.&#xA;https://securitylabs.datadoghq.com/articles/cophish-using-microsoft-copilot-studio-as-a-wrapper/</description><pubDate>20 Oct 2025 13:24 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3m3mw2w2y4k2d</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lwetageet22x</link><description>🎉 Exciting news: The Office 365 Exchange Online SP privilege escalation we documented in &#34;I SPy&#34; is no longer possible! We&#39;ve updated the post to reflect this. Thanks to Eli Guy for the tip on this one:&#xA;https://securitylabs.datadoghq.com/articles/i-spy-escalating-to-entra-id-global-admin/#appendix</description><pubDate>14 Aug 2025 17:06 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lwetageet22x</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lvbzqbc4hk2b</link><description>Excited to see folks at DEFCON next week!! Ready to see some great talks and get those conference steps in. 👟</description><pubDate>31 Jul 2025 20:59 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lvbzqbc4hk2b</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lu3ivz6n5c2y</link><description>🕵️‍♀️ Looking to escalate privileges with a first-party Microsoft app? How do federated domain backdoors work? And what&#39;s an app reg, really? All this and more in our new @securitylabs.datadoghq.com post:&#xA;https://securitylabs.datadoghq.com/articles/i-spy-escalating-to-entra-id-global-admin/</description><pubDate>16 Jul 2025 13:17 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lu3ivz6n5c2y</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lt2szijzek22</link><description>☁️ My fwd:cloudsec talk, &#34;I SPy: Rethinking Entra ID research for new paths to Global Admin&#34;, is up! Learn what a service principal is, how Microsoft&#39;s first-party apps could be backdoored, and one weird trick they haven&#39;t fixed yet:&#xA;https://www.youtube.com/watch?v=oNpwtt1TEkQ</description><pubDate>03 Jul 2025 13:20 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lt2szijzek22</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lseom56wac2t</link><description>My RSAC virtual session is up! Catch &#34;Persisting Unseen: Attacker Methods of Infesting Entra ID&#34; here: https://youtu.be/ngSFP-tgupM?si=hsI5_Q7vW2UWIeYQ&amp;t=4719&#xA;&#xA;Companion blog: https://kknowl.es/posts/defending-against-entra-id-persistence/</description><pubDate>24 Jun 2025 18:03 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lseom56wac2t</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lrsk3t2ces2u</link><description>🕵️‍♀️ I&#39;ll be presenting &#34;I SPy: Rethinking Entra ID research for new paths to Global Admin” at fwd:cloudsec June 30-July 1, alongside some fantastic other speakers: https://fwdcloudsec.org/conference/north-america/speakers.html&#xA;&#xA;If you can’t make it, talks are streamed at: www.youtube.com/@fwdcloudsec</description><pubDate>17 Jun 2025 12:54 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lrsk3t2ces2u</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lquymn6irc23</link><description>🥷 Detect &amp; defend vs Entra ID persistence! From my RSAC Cloud Summit talk, I&#39;ve shared how attackers persist through Entra ID roles, applications, and authentication... and how you can stop them: https://kknowl.es/posts/defending-against-entra-id-persistence/</description><pubDate>05 Jun 2025 18:54 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lquymn6irc23</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lor5qvfkvs2s</link><description>🌐 I&#39;ll be speaking at RSA Conference&#39;s Virtual Seminar on Cloud Security on June 5, 2025! I&#39;ll be sharing a technical overview of Entra persistence techniques for all levels. You can sign up to stop by here: https://www.rsaconference.com/library/virtual%20seminar/hds19-cloud-security&#xA;https://lnkd.in/gQ-eNuDT</description><pubDate>09 May 2025 19:25 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lor5qvfkvs2s</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lojo4jzvrk2u</link><description>👾 It&#39;s up!! Everything you ever wanted to know about Entra Administrative Unit (AU) attack paths, from my talk at @specterops.io SO-CON 😁&#xA;https://www.youtube.com/watch?v=oxD7-UhE3Nw</description><pubDate>06 May 2025 19:56 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lojo4jzvrk2u</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3lm5dgjg2q22q</link><description>Had a fantastic time at @specterops.bsky.social SO-CON and Azure training! So much to learn, and so many incredible people to meet. Feeling excited to apply all this knowledge... time to head home. 😁</description><pubDate>06 Apr 2025 11:23 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3lm5dgjg2q22q</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3llolm4idsc26</link><description>Excited to be at @specterops.bsky.social  SO-CON this week!! If you&#39;re around, I&#39;ll be presenting &#34;Abusing AUs, Confusing the SOC&#34; tomorrow bright &amp; early:</description><pubDate>31 Mar 2025 14:39 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3llolm4idsc26</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3ll7uk46gf223</link><description>🛡️ We found a bug in restricted AUs that let accounts stay restricted (forever!) without an AU, preventing containment. Glad this is fixed now! More details here: https://securitylabs.datadoghq.com/articles/creating-immutable-users-entra-id-administrative-units/</description><pubDate>25 Mar 2025 18:09 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3ll7uk46gf223</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3ldqljln67s2f</link><description>🎄Have you ever paid for a simple product and thought, &#34;Hey, I could build that&#34;? As a pre-holiday project, I tried my hand at &#34;home cooking&#34; my own web text editor with GPT Canvas: https://kknowl.es/posts/home-cooking-apps-with-ai/ &#xA;+ the results: github.com/siigil/brevity</description><pubDate>20 Dec 2024 14:22 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3ldqljln67s2f</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3ldojbo64v22a</link><description>👻 Excited to be presenting &#34;Abusing AUs, Confusing the SOC: Entra ID&#39;s Administrative Unit Attack Paths&#34; at #SOCON2025, March 31-April 1! You can register to join me with discount code SOCONSPEAKER20: ghst.ly/socon25-spkr</description><pubDate>19 Dec 2024 18:36 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3ldojbo64v22a</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3ldix4zdk7s27</link><description>🔑 Azure Key Vault Contributors can&#39;t access keys... but they CAN modify access policies! More on how this can lead to unintended data access here: https://securitylabs.datadoghq.com/articles/escalating-privileges-to-read-secrets-with-azure-key-vault-access-policies/</description><pubDate>17 Dec 2024 13:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3ldix4zdk7s27</guid></item><item><link>https://bsky.app/profile/siigil.bsky.social/post/3ldccam6nb22y</link><description>🎄 I shared a lab on reviewing Azure security with KQL + Resource Graph Explorer! My walkthrough is available as Day 14 of the Advent of Cloud Security:&#xA;❄️ Calendar, Day 14: advent.cloudsecuritypodcast.tv&#xA;❄️ Full Repo: https://github.com/siigil/azure-kql-demo</description><pubDate>14 Dec 2024 21:58 +0000</pubDate><guid isPermaLink="false">at://did:plc:orgollddhva2byrhdvkmlxml/app.bsky.feed.post/3ldccam6nb22y</guid></item></channel></rss>