Session
The Unseen Secrets of the Cloud and How They Surface
This talk introduces a new way of detecting secrets in cloud environments that directly enables privilege escalation and large-scale cloud compromise.
The session reveals how secrets systematically surface across AWS, Azure, and GCP due to architectural design choices and a system-level lack of sanitization by default. While centralized logging systems are a major focus, the research goes beyond logging to cover multiple cloud-native surfaces where credentials emerge, including containers, virtual machines, serverless functions, managed services, and control-plane components.
The talk explains how attackers can abuse default access to logs from resources and telemetry after an initial foothold, why cloud-native logging architectures amplify blast radius, and how unsanitized secrets propagate across services. Attendees will see how secrets discovered through these techniques can be chained into lateral movement, privilege escalation, persistence, and full cloud compromise.
Chen Shiri
Cyber Security Researcher, Accenture Security
Tel Aviv, Israel
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top