When the IAM admin is the threat: tales from battling with insiders

No ratings

Presented at BSides San Diego 2025 by

A real-world insider attack and its implications: a member of the IAM team leveraged their privileges to start disabling accounts in Active Directory. The implicit trust bypassed multiple security controls; this attack is an example of multiple other related pathways that can be exploited. The talk is full of real world insights gained from defending against stealthy threats.