BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Establishing a Beachhead: Post-Exploitation in Azure
  DevOps\n   Tags: Adversary Village | Creator Talk/Panel\n   When: Sunday\
 , Aug 9\, 10:00 - 10:25 PDT\n   Where: LVCCW Level 1 Hall 2 602 (Adversary
  Village) Hands-on Activity\n   Area - [1]Map\n\n   Description:\n\n   You
  phished a token\, found a leaked PAT\, or popped a single\n   low-privile
 ge identity. Now you're staring at an Azure DevOps\n   organization wonder
 ing what's actually within reach. This is the part\n   that never makes th
 e breach report: what an operator does in the hours\n   after initial acce
 ss.\n\n   Azure DevOps is a pivot that most defenders overlook. It's a CI/
 CD\n   plane wired straight into the cloud tenant it deploys to. It's full
  of\n   secrets and standing trust nobody watches. We'll walk a full\n   p
 ost-exploitation chain the way real intrusion sets run it:\n   enumeration
 \, credential harvesting\, privilege escalation\, and\n   OPSEC-aware exfi
 ltration. You'll see secrets pulled out of pipeline\n   variables and vari
 able groups\, a misconfigured repo turned into\n   lateral movement\, and 
 service connections abused until one forgotten\n   environment variable br
 idges a single project into tenant-wide\n   control.\n\n   All of it runs 
 on Beachhead\, an open-source toolkit we're releasing at\n   the talk. It 
 takes "I wonder what this does" on one resource and turns\n   it into a fo
 othold across the whole tenant.\n\n   This isn't offense for its own sake.
  It's adversary emulation. Every\n   technique gets mapped to the groups a
 lready using it in the wild and\n   paired with the telemetry it generates
 . Red teamers get a playbook\n   they can actually reuse. Defenders get th
 e detection side: what every\n   step looks like in the logs.\n\n   Speake
 rs:Jared Dobbelaer\,Jon Rhodes\n\n   SpeakerBio:  Jared Dobbelaer\n\n   Ja
 red Dobbelaer (Fr13ndz) is an Adversarial Engineer at Blackbaud\,\n   cond
 ucting Red Team engagements and Penetration Testing in the Cloud.\n\n   Fr
 13ndz enjoys creative solutions that both help targets with\n   organizati
 onal needs and requirements\, while also borrowing their\n   bearer tokens
 .\n\n   SpeakerBio:  Jon Rhodes\n\n   Jon Rhodes is an Adversarial Enginee
 r at Blackbaud and a member of the\n   Synack Red Team (when he needs extr
 a cash for new farm equipment).\n\n   Links:\n       adversaryvillage.org/
 adversary-events/DEFCON-34/Jared-Dobbelaer/ -\n   [2]https://adversaryvill
 age.org/adversary-events/DEFCON-34/Jared-Dobbelaer/\n   '\n\n   1. #LVCCW_
 Level1_Hall2\n   2. https://adversaryvillage.org/adversary-events/DEFCON-3
 4/Jared-Dobbelaer/\n\n\n
DTEND:20260809T172500Z
DTSTART:20260809T170000Z
LOCATION:Adversary Village - LVCCW Level 1 Hall 2 602 (Adversary Village) H
 ands-on Activity Area
SUMMARY:Establishing a Beachhead: Post-Exploitation in Azure DevOps
END:VEVENT
END:VCALENDAR
