Uploaded August 2026 | Updated September 2026, 1 hour ago
Julie Agnes Sparks (Datadog, US), Greg Foss (Datadog, US)
What do you know about the visibility and threats in your critical SaaS applications? Come join us to learn about what you can see, what you’re missing, and the most common attack paths we are observing in the wild.
This technical deep‑dive talk will provide details on emerging SaaS attack trends across critical third‑party applications, such as case studies into Salesforce, GitHub, and GitLab attacks. Common behaviors include weak authentication methods, malicious or compromised third‑party applications, lateral movement within cloud infrastructure, and enumeration and exfiltration of critical data.
Leave this session with a guide on the next threat detections to develop and queries to use for threat hunts in your environment.
---
Julie Agnes Sparks is a security engineer specializing in threat detection, threat hunting, and incident response with over 7 years defending organizations. She is currently working under Security Research at Datadog to develop novel detections and hunting opportunities on critical SaaS applications and cloud infrastructure. She was previously on Detection & Response teams at Brex and Cloudflare. In her spare time, she focuses on community building and mentorship for those in security operations.
Greg Foss is a seasoned cybersecurity leader with over 15 years of experience spanning threat research, security operations, and offensive security. As the Engineering Manager of Threat Detection Engineering at Datadog, he leads a team of elite threat hunters and detection engineers, developing cutting-edge defenses against sophisticated cloud-native intrusions by nation-state and criminally motivated adversaries.
Julie Agnes Sparks (Datadog, US), Greg Foss (Datadog, US)
What do you know about the visibility and threats in your critical SaaS applications? Come join us to learn about what you can see, what you’re missing, and the most common attack paths we are observing in the wild.
This technical deep‑dive talk will provide details on emerging SaaS attack trends across critical third‑party applications, such as case studies into Salesforce, GitHub, and GitLab attacks. Common behaviors include weak authentication methods, malicious or compromised third‑party applications, lateral movement within cloud infrastructure, and enumeration and exfiltration of critical data.
Leave this session with a guide on the next threat detections to develop and queries to use for threat hunts in your environment.
---
Julie Agnes Sparks is a security engineer specializing in threat detection, threat hunting, and incident response with over 7 years defending organizations. She is currently working under Security Research at Datadog to develop novel detections and hunting opportunities on critical SaaS applications and cloud infrastructure. She was previously on Detection & Response teams at Brex and Cloudflare. In her spare time, she focuses on community building and mentorship for those in security operations.
Greg Foss is a seasoned cybersecurity leader with over 15 years of experience spanning threat research, security operations, and offensive security. As the Engineering Manager of Threat Detection Engineering at Datadog, he leads a team of elite threat hunters and detection engineers, developing cutting-edge defenses against sophisticated cloud-native intrusions by nation-state and criminally motivated adversaries.










