BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Breaking the Oracle: Building an Offensive Security 
 Toolkit\n   for OCI\n   Tags: Demo đź’» | Cloud Village | Creator Talk/Pan
 el\n   When: Sunday\, Aug 9\, 11:20 - 11:50 PDT\n   Where: LVCCW Level 3 W
 313 (Cloud Village Talks) - [1]Map\n\n   Description:\n\n   Oracle Cloud I
 nfrastructure (OCI) is arguably one of the\n   lesser-explored major cloud
  platforms from an offensive security\n   perspective. While OCI shares ma
 ny familiar IAM concepts with AWS and\n   GCP\, its identity architectureâ
 €”including sentence-based IAM\n   policies\, identity domains\, dynamic g
 roups\, compartment hierarchies\,\n   and cross-tenancy permissionsâ€”crea
 tes authorization relationships\n   and privilege escalation paths that be
 nefit from OCI-specific\n   analysis.\n\n   To help tackle these challenge
 s\, I built OCInferno\, an open-source OCI\n   reconnaissance framework fo
 r offensive security assessments. Alongside\n   oci-lexer-parser\, an ANTL
 R-based parser for OCI's sentence-based IAM\n   policies\, and OCISigner\,
  a Burp Suite extension for transparently\n   signing OCI API requests\, a
  pentester/blue teamer can automate\n   enumeration\, model OCI IAM relati
 onships\, and build OpenGraph-based\n   attack paths similar to BloodHound
  to help visualize privilege\n   escalation opportunities.\n\n   This talk
  will demonstrate how to model OCI IAM relationships and\n   uncover OCI-s
 pecific attack paths that are difficult to spot from\n   policy text alone
 . It will also cover a security issue I uncovered\n   that was acknowledge
 d by Oracle in the June 2026 Critical Security\n   Patch Update under its 
 Security-in-Depth program\, illustrating how\n   offensive security resear
 ch can uncover weaknesses not only in\n   customer environments but in the
  cloud platform itself. Whether you're\n   new to OCI or already assessing
  cloud environments\, you'll leave with\n   a practical understanding of O
 CI IAM\, identity-domain-aware attack\n   path analysis\, and an open-sour
 ce toolkit for exploring OCI security.\n\n   SpeakerBio:  Scott Weston\n\n
    Originally from Southern California and now based in Minneapolis\,\n   
 Scott has six years of experience in information security. As a Labs\n   R
 esearcher at NetSPI\, he builds open-source tools and research\n   materia
 l focused on cloud security and penetration testing across AWS\,\n   GCP\,
  and OCI environments. His tools include gcpwn\, ocinferno\,\n   oci-lexer
 -parser\, and ocisigner.\n\n   In his spare time\, he enjoys being a total
 ly fair and impartial D&D\n   Dungeon Master\, and holding out hope that S
 an Diego FC will advance to\n   the MLS finals.\n\n   '\n\n   1. #LVCCW_Le
 vel3_South\n\n\n
DTEND:20260809T185000Z
DTSTART:20260809T182000Z
LOCATION:Cloud Village - LVCCW Level 3 W313 (Cloud Village Talks)
SUMMARY:Breaking the Oracle: Building an Offensive Security Toolkit for OCI
END:VEVENT
END:VCALENDAR
