
Episode #16
Episode 16: Special Guests Daniel Heinsen and Julian Catrambone
In this episode of Know Your Adversary , Jared Atkinson and Justin Kohler are joined by Daniel Heinsen and Julian Catrambone to discuss bringing AWS attack paths into BloodHound. Daniel and Julian share how their work evolved from manually analyzing complex AWS policies to mapping relationships across accounts, identities, and resources to better understand where exposure actually exists. The conversation explores why AWS permissions and trust relationships become so difficult to reason about at scale, how seemingly isolated configurations can combine into attack paths with significant downstream impact, and what the team has learned from testing this approach in real-world environments. They also dig into third-party trust, cross-platform attack paths spanning technologies like GitHub and AWS, and why understanding paths to critical resources matters just as much as identifying paths to privileged identities.

