Manuel Melendez
I'm Manuel Melendez, originally from Chihuahua, Mexico.
Received my master's from the University of Texas at El Paso and have been working at Microsoft for almost 3 years. My work focuses on doing research on attacks, Azure infrastructure, as well as validation and investigation of the attacks.
Outside of work, I like to play videogames, spend time with my dogs, and play guitar.
Session
Azure serverless resources like Logic Apps, Function Apps, and Automation Accounts rely on managed identities to securely access Azure services without managing credentials, making them widely trusted but high-value targets. This talk shows how attackers can extract access tokens issued to managed identities, abuse them against Azure APIs, and pivot within an environment, along with practical mitigation and detection strategies.