The OpenGraph diary: Attack path management applied to Ansible

Back to the list of Speakers and Sessions
Watch the stream

This presentation will focus on AnsibleHound, a collector that adds Ansible WorX and Ansible Tower attack paths to BloodHound. Additionally, we will conduct a thorough exploration of Ansible exploitation and abuse through attack path management. This will enable both attackers and defenders to identify hybrid attack paths.

Our presentation will provide you with three key takeaways:

  1. Discovery and offensive knowledge for Ansible exploitation
  2. Integrate Ansible in the identity surface using AnsibleHound
  3. Hybrid attack paths exploitation between Active Directory, Ansible and Github

Charl-alexandre Le Brun Senior Penetration Tester, Desjardins

Charl-Alexandre is a dedicated member of the information security community. With several years of experience as a penetration tester, he is driven by a strong passion for developing innovative tools and techniques that advance the field and contribute to the broader community.

Simon Lachkar Offensive Team Lead, Desjardins Group

Simon leads the full-scope penetration testing team at Desjardins Group, one of Canada's largest financial institutions. Previously, he worked as a technical team leader and penetration tester in Canada and France. Simon has recently been involved in developing the AnsibleHound project.