Ahead of the Breach

Accenture's Daniel Barnes on SAML exploitation and what really matters in pentesting

34 min · 4. März 2026
Episode Accenture's Daniel Barnes on SAML exploitation and what really matters in pentesting Cover

Beschreibung

What makes a vulnerability truly shocking is simplicity, once you notice the assumption everyone else missed. In this episode, Daniel shares a memorable SAML/SSO privilege escalation from a real engagement, then zooms out into what it takes to grow as a penetration tester: handling uncertainty, collaborating through roadblocks, and building the fundamentals that make creative problem-solving possible. The conversation blends war stories with practical guidance for both aspiring testers and security leaders. We cover everything from dependency risk and real-world scoping realities to why thinking like an attacker belongs early in the SDLC, not at the end.

Kommentare

0

Sei die erste Person, die kommentiert

Melde dich jetzt an und werde Teil der Ahead of the Breach-Community!

Loslegen

2 Monate für 1 €

Dann 4,99 € / Monat · Jederzeit kündbar

  • Podcasts nur bei Podimo
  • 20 Stunden Hörbücher / Monat
  • Alle kostenlosen Podcasts

Alle Folgen

51 Folgen

Episode Gary Lobermier on Scaling Red Team Automation with AI to Run Hundreds of Real Attacks Daily Cover

Gary Lobermier on Scaling Red Team Automation with AI to Run Hundreds of Real Attacks Daily

Most security teams test their detections once a year. Gary Lobermier, Lead Adversarial Security Engineer at Northwestern Mutual, built something different: a custom automation platform that executes hundreds of MITRE ATT&CK techniques daily across Windows, macOS, Linux, and AWS, giving his team real-time signal on whether their defenses actually hold. In this episode, Gary breaks down why off-the-shelf purple team tools fall short at enterprise scale, the procedure-level gap nobody talks about in the MITRE ATT&CK framework, and what EDR vendors don't advertise about their own coverage limits. He also shares how his non-traditional path (from network admin to red teamer) shaped the way he thinks about adversary emulation and detection engineering. If you're building or scaling an offensive security program and want to know what continuous validation actually looks like in practice, this one's worth your time.

1. Mai 202631 min