Skip to main content
Community Manager
August 31, 2026
Sticky

Monthly Buzz - August - Endpoint Privilege Management

  • August 31, 2026
  • 0 replies
  • 20 views

How We Got Admin Access to Every Copilot Studio Agent Sandbox on Earth
 

The rise of AI agents has been accompanied by an equally rapid rise in sandboxes.  Upload a spreadsheet, let the agent write and run some Python and get an answer back.  What could possibly go wrong?  Surely the sandbox would keep you protected right?

At Phantom Labs, we’ve come to believe that many of these sandboxes offer guardrails more than real security boundaries.  They may introduce friction for attackers, but with enough patience and a little creativity the cracks often begin to show.  We believe this represents a broader security challenge for the AI industry, which is why we’ve been evaluating the security boundaries of agent sandboxes, including AWS AgentCore, OpenAI Codex and Dataverse Plugins.

Starting with a stock agent that any licensed maker can build, with nothing but the “code interpreter” toggle flipped on, we escaped the Python sandbox, talked its AI guardrail into approving our own exploit, read the sandbox’s source code straight off the box, and walked away with its TLS private key, environment variables, and a hardcoded list of 140 EU institutions. Then, we reused a password we had cracked during earlier research and got local administrator on the box.  

As far as we can tell, this static Administrator credential works across every Copilot Studio code interpreter sandbox. One half of the attack relied on a modern technique by bypassing an LLM, while the other relied on a technique as old-school as it gets: a dictionary attack. 
 

Click HERE to continue reading.
 

Customer Case Study
ivision: How ivision Simplifies and Scales Identity Security with BeyondTrust  

 

Latest Available Versions
EPM for Windows and Mac (Cloud and Pathfinder)  v26.2.1697 – June 2026
EPM for Windows 26.2.1 - June 2026
EPM for Mac v26.2.1 – June 2026
 

BeeKeepers Community

CrowdStrike Next-Gen SIEM PUSH for EPM Win & Mac – Step-by-step guide
Overview: BeyondTrust Endpoint Privilege Management for Windows and Mac (EPM-WM) can export audit, activity, and authorization-request events directly to an Amazon S3 bucket. This guide walks through a validated, end-to-end configuration that lands those events in CrowdStrike Falcon Next-Gen SIEM (built on Falcon LogScale), using CrowdStrike's generic Amazon S3 Data Connector and its purpose-built beyondtrust-endpointprivilegemanagement parser.
 

Two SIEM formats are available on the EPM side — CIM (Common Information Model) and ECS (Elastic Common Schema). This guide uses ECS, because CrowdStrike's own field taxonomy and its published EPM parser are both built on ECS. CIM has no native meaning inside Next-Gen SIEM and would be ingested unmapped.
 

Scope: This walkthrough uses a self-managed S3 bucket and SQS queue — not CrowdStrike Falcon Data Replicator (FDR), which is a different, CrowdStrike-managed pipeline for different data types.

Click HERE to continue reading.
 

Click here for the most popular discussions in BeeKeepers

Upcoming and In Case You Missed It Webinars

On-Demand Webinar: Endpoint Privilege Management User Group
Tech Talk Tuesday: Beyond the Endpoint: Where Privilege Went Next and How Entitle Follows
Road Map: Endpoint Privilege Management Unix & Linux and Active Directory Bridge – September 1, 2026
User Group: Q3-Americas EPM

Upcoming Webinars:

How Attackers Get In Without Hacking Your Password (Part 1) – September 3, 2026
Securing Critical National Infrastructure - September 15, 2026
Removing Ransomware’s Favorite Foothold in Education – September 16, 2026
The Fastest Path to Administrative Control (Part 2) – September 16, 2026
Monitoring, Threat Hunting and Detection of Privilege Abuse (Part 3) – September 29, 2026
Podcast: Adventures of Alice & Bob

This topic has been closed for replies.