JamfHound v1.1 Update: SSO Attack Paths and Okta Additions
ID: ba50ac28-79d6-5704-b1a3-61b3b67a6b69
STIX ID: report--ba50ac28-79d6-5704-b1a3-61b3b67a6b69
Feed Name: SpecterOps Blog
This report describes JamfHound v1.1 enhancements that add SSO-aware graph nodes and hybrid edges to BloodHound, enabling visibility of dangerous attack paths in JAMF Pro deployments integrated with external identity providers (e.g., Okta). The updates reveal practical privilege escalation scenarios—such as abusing the "Update SSO Settings" right to point JAMF to an attacker-controlled IDP, and leveraging Okta–JAMF device/group mappings—to achieve full admin access and cross-platform pivoting; defenders can use the collector to identify and remediate these risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
