Identity security has evolved far beyond simply deploying MFA or tracking domain admins. Today, organizations must understand how seemingly harmless individual permissions can chain together across complex environments to grant access to critical outcomes. With the rapid adoption of AI agents creating thousands of new non-human identities, securing the modern identity perimeter requires proactive mapping and clear prioritization. In this episode, Ashish sits down with Kay Daskalakis from SpecterOps and Andreas Fleischmann from QBS to discuss practical methods for resolving identity risks during "peacetime". They explore how security teams can utilize tools like BloodHound Enterprise to visualize attack paths, audit deep group nesting, and properly restrict service accounts before they are exploited. By addressing trust policy flaws in CI/CD pipelines and auditing legacy Active Directory setups on a quiet Tuesday afternoon, defenders can systematically take back control of their identity architecture.
Questions asked:
00:00 Introduction to Securing Identity Attack Paths
01:30 Andreas and Kay’s Backgrounds in Security and Distribution
03:00 Why Identity Security is More Than Just Single Sign-On
04:20 Spotting Red Flags: Deep Group Nesting and Stale Accounts
06:20 The Value of Fixing Attack Paths During "Peacetime"
08:50 Self-Assessment Questions for Your Identity Infrastructure
10:00 Managing the Explosion of AI Agents and Non-Human Identities
11:40 Lessons from Miasma: CI/CD Pipelines and Trust Policy Abuse
13:30 Using BloodHound Enterprise for Proactive Identity Defense
Andreas Fleischmann: [00:00:00] There are thousands of attack paths usually in customer environments
Ashish Rajan: I do single sign-on, I do MFA, my identity is done. Is that the right way to look at identity today in an AI world?
Kay Daskalakis,: A user may not be a domain admin, but they may be able to reset another account, modify a group, trigger a deployment, and individually those permissions can look harmless.
Kay Daskalakis,: In a graph, they become an attack path.
Andreas Fleischmann: We have to talk about AI because with all those agents spreading, we have all those non-human identities, and they get more and more and more. These are the potential new attack paths in the future and already today.
Kay Daskalakis,: This is a supply chain incident, and it is being presented as a malware problem, but it is fundamentally a trust policy design issue, a tool that is being used by pen testers and red teamers worldwide, but [00:01:00] unfortunately also it's being used by attackers.
Kay Daskalakis,: You can tackle the problem of an attack path on a silent Tuesday afternoon during peace time, or you can do that, uh, with an attacker in your network where you're fighting to take back your identity.
Ashish Rajan: Hello, welcome to another conversation with Cloud Security Podcast. I've got Kay and Andreas with me. Hey, guys.
Ashish Rajan: Thanks for coming on the show.
Andreas Fleischmann: Thank you for
Kay Daskalakis,: having us.
Andreas Fleischmann: Thank you.
Ashish Rajan: I'm looking forward to this conversation. Maybe to kick things off, Andreas, if you don't mind giving a, a short introduction about yourself, your professional background and what, where you're at.
Andreas Fleischmann: So I'm Andreas Fleischmann from Germany employed by QBS software distribution company.
Andreas Fleischmann: We handle a lot of vendors, uh, and I do the technic part, technically evaluation of new vendors, looking into market fit, looking into do we have the right customer s- s- uh, system houses and retailers? [00:02:00] And I occasionally, occasionally been called the truffle pig, so truffle or the mushroom, pig, the animal.
Ashish Rajan: Yeah.
Andreas Fleischmann: Thank you.
Ashish Rajan: And, uh, Kay, what about yourself, man? Just an introduction.
Kay Daskalakis,: So I'm Kay Daskalakis or Kay, difficult surname, and, uh, I'm a sales engineer for at SpecterOps. And my focus is helping organizations understand identity risk Through attack paths, how permissions, accounts, systems, cloud roles, and non-human identities interact, connect with each other into real routes an attacker can use.
Kay Daskalakis,: So I spend a lot of time with customers looking at whether their identity assumptions do not match what their environment actually allows.
Ashish Rajan: Awesome. So maybe that's a good segway into the conversation itself then. Identity and security a lot of people t- look at this, look at that as two different things.
Ashish Rajan: One is where there's a dedicated identity team, security is like this whole... Like, and identity primarily is looked at, hey, I do single [00:03:00] sign-on, I do MFA, my identity is done. Is that the right way to look at identity today in an AI world? And what are some of the conversations that you guys are hearing in the broader scheme of things between identity and security at the moment?
Kay Daskalakis,: So the conversation, I think, has shifted from, in the past couple of years from who has admin rights to who can, uh, reach a critical outcome, and, uh, it is fundamentally a very different question, isn't it? Like, a user may not be a domain admin, but they may be able to reset another account, modify a group, trigger a deployment, access a cloud role, or influence a privileged workflow, and individually, those permissions can look harmless.
Kay Daskalakis,: In a graph, they become an attack path.
Ashish Rajan: And, well, Andreas, how are you seeing this? Especially, are people aware... So what Kay's example, that, uh, the attack path is probably visible or not visible, what are you seeing in terms of identity and security that maybe [00:04:00] comes across as warning signs that people should be aware of but are not aware of in that identity and security space?
Andreas Fleischmann: Yeah, so, I think we know that, or we know from Lacone the software, that there are thousands of attack paths usually in in customer environments, and those numbers scale, uh, with the amount of identities in the active directory. So, if you do not have a kind of central visibility of those identities, this is already a kind of red flag.
Andreas Fleischmann: If you have high volume of risky users or risky signs in which are well-known measures, for example, in Azure Entra ID, this is also already a red flag. If you have too many domain admins or [00:05:00] global admins in your environment, this is another, uh, red flag. If you have a lot of service accounts or if you have those, um, permissions like generic all, um, write owner, full control could be already a red flag.
Andreas Fleischmann: Another common thing is if you have deep group nestings in your uh, account, uh, in your active directory objects, especially in your groups, it's red flag. Um, stale or unused accounts, maybe you are not really aware of stale or unused accounts. Um, we can go on, uh, when it comes, for example, to the best practice.
Andreas Fleischmann: What about tiering? Do you have tier zero admins? Do you have non-privileged access workstations? Uh, and you cannot say [00:06:00] yes to those questions, then they are red flags. If you have unconstrained delegations, so You see, I have lot of examples and I can go on, go on and go on.
Ashish Rajan: Do you find the people are... is there-- 'Cause obviously identity has been there for a long time, and all of us being in cybersecurity for a while, do you feel there is more awareness for this now than before?
Ashish Rajan: Or is it more that you find that even the basics are still missing in the customers that you speak to?
Kay Daskalakis,: Yeah, sure. The basics are very, it is a contextual narrative on its own, right? What are the basics? So people, right, don't even know s- uh, where to begin with. It's fundamentally a prioritization problem that we are meeting, like, and in many cases, it's also an accountability problem.
Kay Daskalakis,: Many different teams can't, even within the same business, cannot, uh, really, uh, communicate with with each other, [00:07:00] like in a, in a manner that makes sense, sense from a risk perspective. Perhaps they can have a conversation around a business objective and achieve an outcome. But when it comes to solving a problem that crosses organizational charts, that becomes quite a problem of its own.
Kay Daskalakis,: And I think the basics there, uh, come down to prioritization, effective prioritization, knowing exactly what matters, that what we need to fix first. Because, uh, i- if anything, if what we've learned, uh, from the past, uh, five years post COVID era is that there's no such thing as perfect security. We need to live with our imperfection.
Kay Daskalakis,: And, uh, in doing so, we need to realize that time is to our advantage during the peace times. I will use this analogy, I will borrow this analogy actually from, uh, a friend of mine, Goran [00:08:00] Svetlecic, who is, uh, um, a, a very well-known practictioner, practitioner in cyber incident response at Deloitte.
Kay Daskalakis,: And he has used this, uh, analogy a, a lot of times. You can tackle the problem of an attack path on a silent Tuesday afternoon during peacetime, or you can do that with an attacker in your network under a completely stressed situation where you're fighting to take back your identity.
Ashish Rajan: Yeah. That, that would definitely put things into perspective at that particular time.
Ashish Rajan: A-Andreas, I'm curious, uh, obviously if you have some additional thoughts, but also what do you think are the areas that teams should pay more attention to, specifically when it comes to identity and security? And I mean, obviously you read out ... you spoke about all the red flags. Uh, w- was there one over the other that pe- you feel teams should pay more [00:09:00] attention to?
Andreas Fleischmann: Yes. So maybe to the first part, so that people are aware or getting aware, uh, maybe some quick self-assessment questions. And if you answer yes or I do not know, uh, to several of these, you likely have meaningful problems. So one is, can you visualize all your paths to your most critical assets? Not all, but to the most critical yes, no, maybe.
Andreas Fleischmann: Are there more than 10 to 20 permanent domain or global admins? Or do you know exactly how many non-human identities exist and who owns them, uh, them? And there, um, and from this I come to the other part where we need to maybe pay attention on [00:10:00] that in today's world we are not talking only about human identities, but we...
Andreas Fleischmann: that we are getting a lot more non-human identities especially... Yes, we have to talk about AI because, uh, with all those agents spreading, we have all those non-human identities, and they get more and more and more. And as we learned that those agents are valuable if they really have tools and access to something, so people have the motivation to give them access, and this is exactly, or maybe these are the potential new attack paths in the future and already today.
Ashish Rajan: Are there any current, uh, attack paths or known pu- uh, even public ones that you have seen organizations... Uh, and maybe Andreas, you can start with this one for you. Uh, [00:11:00] are there any current attacks on organizations that have led to more awareness of thi- these things that you may have seen?
Andreas Fleischmann: I think it's logically if you if you create more accounts for all those agents, and that means because before I said the number of attack paths scales not linearly, I would not...
Andreas Fleischmann: Maybe someone could argue exponentially, but everything between with the number of accounts. So that means the number of attack paths arises, and that means the risk of being attacked and successfully attacked mathematically increases.
Kay Daskalakis,: I do agree I do agree with, with Andreas a lot, like, uh, just to make it, like, even more specific here.
Kay Daskalakis,: We have heard about miasma, right? Or miasma, like, it's a Greek word, by the way unfortunately for us. But the, the, the, this is a supply chain incident, right? And it is [00:12:00] being presented as a malware problem, as a compromise, like downstream compromise of poisoning the repos and all of that. But it is fundamentally a, a trust policy design issue because this all started upstream by someone managing to compromise the entire pipeline.
Kay Daskalakis,: So even, uh, frameworks like SLSA, which is DAST provenance attestation, uh, just up- said, "Yeah, this is fine. This is the expected workflow." Uh, OpenID Connect said, "Yeah, this is fine. This is the token that we should allow," right? In this case. But we still, uh, managed to, to see what fundamentally is an attack path, but in a very different setting.
Kay Daskalakis,: The setting there is, uh, a developer environment and a developer's organization. It is supply chain. It is, uh, affecting [00:13:00] CICD trust and the publishing authority. But this kind of trust relationship abuse It's not point specific, it's not asset specific. It is from many different systems together and its context the business did not anticipate.
Ashish Rajan: Mm. Wait, is this where, I think when we spoke about this at InfoSec Europe, we were talking about BloodHound being that attack paths discovery, for lack of a better word. Is that, is that a way to find out what is, what the gaps in identity may be? And obviously it's open source as well, so, is that something where BloodHound helps?
Kay Daskalakis,: It does. Uh, I mean, wear the cap, like, "Trust me, I'm an expert," but, eh, look, SpecterOps, uh, has fundamentally focused too much and since the, since the dawn of it, or of itself as a company, like into solving a problem for ourselves, as [00:14:00] in red teamers trying to solve, uh, a red offensive identity-driven tradecraft problem, as in how do...
Kay Daskalakis,: are we more successful in our offensive engagements? We created tools to support those engagements, and BloodHound is a fundamentally a tool that is being used by pentesters and red teamers worldwide, but unfortunately also it's being used by attackers. The first time that I experienced BloodHound being used in the wild was, uh, in 2017 as part of a cyber incident response, uh, engagement with one of the Big Four where I found it as a forensic artifact.
Kay Daskalakis,: So today, BloodHound Enterprise, the enterprise version of BloodHound, it doesn't just focus on the shortest path, it focuses on all the paths across different and identity schemas, identity [00:15:00] organizations, let's say, and shows you how a small decision that you made that on its own is absolutely fine, thumbs up, right?
Kay Daskalakis,: Can become a, a problem that could haunt you during, uh, the wartime, during the time where you had an incident and it's per- actually, uh, extending to become an impactful one
Ashish Rajan: Yep. And,, I guess that's most of the questions I had, but where can people get in touch with you guys? I don't know, maybe LinkedIn or something, I guess, where we can share, uh, what's the best place for people to reach out to you for what they would like to... when they wanna know more about information about SpecterOps or the work that you guys are doing. Maybe Andreas, what's the best way to reach out to you, man? Uh, is LinkedIn the best?
Andreas Fleischmann: Absolutely. So I'm on LinkedIn. You find me with, uh, my real name, Andreas Fleischmann, also with QBS the company, and formerly Preemptal the company.
Andreas Fleischmann: Yeah.
Ashish Rajan: Awesome. And, uh, Kay, for yourself, man.
Kay Daskalakis,: The same for me, it's LinkedIn. But also if you probably get a [00:16:00] demo out of the website of SpecterOps, you might end up with me. Uh, I don't know if that's good news for you, but, um, we'll certainly, uh, try to be as very helpful as possible. Um, and, uh, again, thank you so much for having us, Ashish.
Andreas Fleischmann: Yeah. Thank you for your day, both your times as well, Andreas and Kay. Thank you so much, and thank you everybody for tuning in.
Ashish Rajan: Thank you for listening or watching this episode of Cloud Security Podcast. This was brought to you by techriot.io. If you are enjoying episodes on cloud security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple, Spotify.
Ashish Rajan: In case you are interested in learning about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security. Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at Cloud Security Podcast.
Ashish Rajan: You can check that out on cloudsecuritynewsletter.com. I'll see you next episode.
Ashish Rajan: Peace.

.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)


.png)


.png)



