BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: AzProwl: Prowling the Azure Attack Surface\n   Tags:
  DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team |\n   Offens
 e/Red Team | Purple Team | DEF CON Demo Labs\n   When: Friday\, Aug 7\, 14
 :00 - 14:45 PDT\n   Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - 
 [1]Map\n\n   Description:\n\n   Cloud environments aren’t being breached
  through\n   zero-days—they’re being traversed through identity\,\n   
 misconfigurations\, and overlooked data paths. Azure is no exception.\n\n 
   This talk introduces AzProwl\, an offensive-focused tool designed to\n  
  emulate how real attackers enumerate and chain together access across\n  
  Azure environments. Rather than stopping at surface-level enumeration\,\n
    AzProwl maps identity relationships\, token abuse opportunities\, and\n
    data plane exposure to uncover realistic attack paths.\n\n   We’ll wa
 lk through how attackers move from initial access to\n   meaningful impact
  using Azure-native mechanisms—leveraging identity\n   roles\, service p
 rincipals\, tokens\, and storage access. Attendees will\n   see how seemin
 gly low-risk permissions compound into high-impact\n   compromise.\n\n   W
 hether you’re red team\, blue team\, or somewhere in between\, this\n   
 session will provide practical insight into how Azure environments are\n  
  actually attacked—and how to detect and defend against it.\n\n   Speake
 rs:Jared "GonePhishing402" Graff\,Jeff Daniels\n\n   SpeakerBio:  Jared "G
 onePhishing402" Graff\n\n   I’m a Lead Incident Response Analyst at Targ
 et with experience\n   spanning red team operations\, blue team defense\, 
 and incident\n   response. My background working in Azure cloud security a
 t Microsoft\n   helped shape my approach to understanding and defending mo
 dern cloud\n   environments and ultimately inspired the development of thi
 s training.\n\n   I specialize in analyzing and emulating real-world attac
 k paths across\n   cloud identities\, authentication tokens\, and data pla
 nes to uncover\n   gaps in detection and response capabilities. My work fo
 cuses on Azure\n   identity compromise\, token abuse\, cloud persistence t
 echniques\, and\n   understanding how adversaries actually operate within 
 cloud\n   environments—not just how we assume they do.\n\n   I’m passi
 onate about bridging the gap between offensive and\n   defensive security\
 , translating attacker tradecraft into actionable\n   detection strategies
 \, and developing hands-on labs that help defenders\n   better understand 
 cloud threats. My goal is to make complex attack\n   techniques accessible
 \, practical\, and directly applicable to\n   real-world security operatio
 ns.\n\n   SpeakerBio:  Jeff Daniels\n\n   Jeff Daniels is a Senior Cloud S
 olution Architect at Microsoft Federal\n   specializing in cloud security\
 , threat intelligence\, and red team\n   operations. With a background in 
 military cyber operations\, he brings\n   real-world offensive experience 
 to designing detection strategies\,\n   Zero Trust architectures\, and lar
 ge-scale SOC capabilities. Jeff\n   focuses on translating adversary trade
 craft into actionable security\n   outcomes for government customers and i
 s actively involved in red team\n   tooling\, adversary emulation\, and AT
 T&CK-aligned training.\n\n   Links:\n       GitHub - [2]https://github.com
 /GonePhishing402/azprowl\n   '\n\n   1. #LVCCW_Level1_Hall3\n   2. https:/
 /github.com/GonePhishing402/azprowl\n\n\n
DTEND:20260807T214500Z
DTSTART:20260807T210000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)
SUMMARY:AzProwl: Prowling the Azure Attack Surface
END:VEVENT
END:VCALENDAR
