Critical SaaS, Critical Blind Spots: A Detection Engineers Field Guide to SaaS Attacks @FIRSTdotorg
Critical SaaS, Critical Blind Spots: A Detection Engineers Field Guide to SaaS Attacks  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 1 hour ago
Julie Agnes Sparks (Datadog, US), Greg Foss (Datadog, US)

What do you know about the visibility and threats in your critical SaaS applications? Come join us to learn about what you can see, what you’re missing, and the most common attack paths we are observing in the wild.

This technical deep‑dive talk will provide details on emerging SaaS attack trends across critical third‑party applications, such as case studies into Salesforce, GitHub, and GitLab attacks. Common behaviors include weak authentication methods, malicious or compromised third‑party applications, lateral movement within cloud infrastructure, and enumeration and exfiltration of critical data.

Leave this session with a guide on the next threat detections to develop and queries to use for threat hunts in your environment.

---

Julie Agnes Sparks is a security engineer specializing in threat detection, threat hunting, and incident response with over 7 years defending organizations. She is currently working under Security Research at Datadog to develop novel detections and hunting opportunities on critical SaaS applications and cloud infrastructure. She was previously on Detection & Response teams at Brex and Cloudflare. In her spare time, she focuses on community building and mentorship for those in security operations.

Greg Foss is a seasoned cybersecurity leader with over 15 years of experience spanning threat research, security operations, and offensive security. As the Engineering Manager of Threat Detection Engineering at Datadog, he leads a team of elite threat hunters and detection engineers, developing cutting-edge defenses against sophisticated cloud-native intrusions by nation-state and criminally motivated adversaries.
Critical SaaS, Critical Blind Spots: A Detection Engineers Field Guide to SaaS AttacksThe Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?The SOC Of The Future… The Future Is NowOne SOC, The Whole SOC, and Nothing But The SOC, So Help MeEiffel: A Tool to Oversee Incident Response From the HeightsProtecting Customers Through Smarter OSS ManagementOperationalizing AIBOMs: Extending Vulnerability Management to AI Models and DatasetsMalice in the Modules - How NPM Became a Supply-Chain Battleground?One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?Improving Security Across Nations with FIRST: Sametria McKinney, FIRST MemberClimbing Toward the Summit of Defense: Practical Methods for Strengthening CSIRT OrganizationsMonday Keynote: Perseverance, Growth and Success. The Sunburst Story from the CISO perspective.
FIRST |

Critical SaaS, Critical Blind Spots: A Detection Engineer's Field Guide to SaaS Attacks

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER