BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Key Rotation Won't Save You: Hunting Workload Identi
 ty\n   Backdoors in AWS and GCP\n   Tags: Cloud Village | Creator Talk/Pan
 el\n   When: Saturday\, Aug 8\, 16:40 - 16:59 PDT\n   Where: LVCCW Level 3
  W313 (Cloud Village Talks) - [1]Map\n\n   Description:\n\n   Cloud incide
 nt response runbooks end with "rotate all keys and\n   credentials." AWS I
 AM Roles Anywhere and GCP Workload Identity\n   Federation were designed t
 o remove keys from the trust chain\, and that\n   design is what lets an a
 ttacker survive standard containment.\n\n   This talk shows how an attacke
 r registers their own certificate\n   authority as an AWS Roles Anywhere t
 rust anchor\, or modifies a GCP\n   Workload Identity Federation provider 
 to trust an attacker-controlled\n   identity\, and mints fresh credentials
  indefinitely. Defender content\n   has not caught up to the attack resear
 ch: Roles Anywhere trust anchor\n   and session events land in CloudTrail 
 by default\, but no published\n   hunting query traces the CreateSession b
 ack to the issuing certificate\n   authority via the hex serial recorded i
 n roleSessionName. GCP pool and\n   provider creation lands in Admin Activ
 ity logs for free\, but the\n   federated token exchange only lands in Dat
 a Access logs when\n   explicitly enabled and paid for.\n\n   The session 
 closes with the cross-cloud fingerprint: when the same\n   attacker-contro
 lled OIDC provider is registered in both clouds (as an\n   AWS OIDC identi
 ty provider and as a GCP Workload Identity Federation\n   pool provider)\,
  the same OIDC sub claim surfaces in both audit trails.\n   Extracting and
  joining on it ties one attacker to two cloud incidents.\n\n   Attendees w
 ill gain the WIF Hunting Pack: a working playbook for\n   keyless persiste
 nce in AWS and GCP\, two prevention policy templates\n   that block the at
 tack at organization scope\, and a cross-cloud\n   correlation pattern for
  OIDC-based incident response. Live demo across\n   speaker-controlled AWS
  and GCP environments. This talk is for blue\n   teamers and platform secu
 rity engineers who secure infrastructure\n   across AWS and GCP.\n\n   Spe
 akerBio:  Jie Wu\n\n   Jie is a Senior Security Engineer at Shopify based 
 in New York City\,\n   working on cloud security\, Kubernetes\, and detect
 ion engineering to\n   secure cloud infrastructure. She has spoken at Kube
 Con EU\,\n   fwd:cloudsec\, and BSides (Chicago\, Ottawa\, Montréal)\, co
 vering topics\n   from Kubernetes security at scale to non-human identity 
 accountability\n   in the cloud. Before Shopify\, she worked on cyber defe
 nse and\n   vulnerability management at Bank of America.\n\n   '\n\n   1. 
 #LVCCW_Level3_South\n\n\n
DTEND:20260808T235900Z
DTSTART:20260808T234000Z
LOCATION:Cloud Village - LVCCW Level 3 W313 (Cloud Village Talks)
SUMMARY:Key Rotation Won't Save You: Hunting Workload Identity Backdoors in
  AWS and GCP
END:VEVENT
END:VCALENDAR
