Karim El-Melhaoui
karimscloud.bsky.social
Karim El-Melhaoui
@karimscloud.bsky.social
Principal Security Architect & Partner at http://o3c.no, CloudSec Researcher, Microsoft Security MVP, CSA Norway Board Member
My first bounty
May 15, 2025 at 6:24 PM
.. You'd also have to first elevate yourself in order to remove another principal. It's interesting how a Global Admin has an invisible access to the Root scope.
May 3, 2025 at 6:59 AM
If you were to remove any of the users previously, it had to be done through the REST API, as the permission is inherited on the Tenant Root Group visible in the portal
May 3, 2025 at 6:59 AM
Reposted by Karim El-Melhaoui
We’re also happy to announce our Europe scholarship program. Through this initiative, we hope to give a limited number of students or those looking to make a career change a chance to attend the conference, through a complimentary ticket and a stipend to cover travel expenses..
fwd:cloudsec | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
fwdcloudsec.org
April 20, 2025 at 6:49 AM
or the common "hey how are you" to derail conversation before it has even started
April 10, 2025 at 10:48 AM
Thanks for sharing! Had this discussion over a few beers with a TAM yesterday that had heard of similar cases
April 8, 2025 at 1:30 PM
Given this is the second time I look into an AWS Solutions product and find something interesting, with no AppSec background - I have a strong feeling there's more to be found..
February 19, 2025 at 7:32 AM
Rather than maintaining a poorly written niche tool, we hope that the functionality will be adopted by more prevalent and widely adopted tools such as BloodHound or commercial offerings such as Wiz Code.
February 18, 2025 at 3:28 PM