[Speakers]
Adversary Village at
DEF CON 34

Jordan Bonagura

Senior Security Consultant and Researcher

Senior Security Consultant at Secure Ideas
Researcher in Information Security
Stay Safe Podcast Founder
Computer Scientist
Post Graduated in Business Strategic Management, Innovation and Teaching
Founder - Vale Security Conference - Brazilian Conference
Consultant Member - Brazilian Comission of High Tech Crime (OAB / SP)
Coordinator and Teacher in IT area
SJC Hacker Space President
Speaker (DefCon, Hack Space Con, Hack Red Con, Hack Miami, Triangle InfoSec, AppSec California, GrrCon, BalCCon2k14, BSides Augusta, H2HC, Angeles Y Demonios, Silver Bullet, Seginfo, ITA, INPE, etc)

Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence

15:30-15:55 PDT | Friday, Aug 7th 2026 | Adversary Village Hands-on Activity Area, Las Vegas Convention Center
Tool Demo

Abstract

Modern enterprise environments have shifted beyond traditional network perimeters, with SaaS applications and identity providers becoming the primary attack surface. However, a significant portion of this still remains unmanaged or invisible commonly referred as Shadow SaaS.


This session explores Shadow SaaS from an attacker’s perspective, demonstrating how adversaries can identify, evaluate, and abuse unmanaged SaaS applications to gain initial access and maintain persistence within target environments.


Rather than focusing on inventory or governance, this talk reframes Shadow SaaS as an offensive opportunity. It highlights how implicit trust relationships, and third-party SaaS connections expand the attack surface beyond traditional security visibility.


Using the Shadow SaaS Surface Scanner, we demonstrate how attackers can uncover hidden SaaS exposure and leverage it as a foothold into enterprise environments.

Tool demo outline

1. Adversary Context: SaaS as the Modern Attack Surface


We begin by framing SaaS and identity ecosystems as the new perimeter. From an adversary perspective, unmanaged SaaS applications and implicit trust relationships create blind spots that are not typically covered by endpoint or network defenses.


2. Discovery: Enumerating Shadow SaaS
We demonstrate the use of the tool in a controlled environment to identify SaaS applications associated with a target organization.


This phase shows how attackers expand reconnaissance beyond traditional asset inventories.


3. Targeting: Identifying High-Value SaaS Integrations
From the discovered surface, we analyze and prioritize potential targets based on attacker-relevant signals.
This step demonstrates how attackers filter noise into actionable entry points.


4. Tool Overview
We briefly explain the role of the Shadow SaaS Surface with:
* Automated discovery and enrichment of SaaS exposure
* Mapping relationships between domains, identities, and third-party applications
* Extensible design for additional SaaS providers and environments


5. Key Takeaways and Q&A


* How attackers approach SaaS environments for initial access
* Why Shadow SaaS represents a significant blind spot in enterprise security
* Practical implications for both offensive and defensive security practitioners

Agency.


Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!