[Speakers]
Adversary Village at
DEF CON 34

Mehmet Önder Key

Cyber Security Consultant

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.

Emulating the Identity-First Threat Actor: Automated Playbooks for IdP Hijacking

10:30-11:00 PDT | Saturday, Aug 8th 2026 | DEF CON Creator Stage 3, Las Vegas Convention Center
Talk

Co-presented with: Samet Can Tasci

Abstract

Modern intrusions often start with identity, not malware. Adversaries abuse IdP drift, device code flows, stale sessions, weak conditional access, helpdesk processes, SaaS integrations, and cloud role mappings. This talk presents a safe emulation framework for identity-first threat actors across AD, Entra ID, Okta-like workflows, and cloud control planes. The lab provides ATT&CK-aligned playbooks that simulate identity compromise, IdP pivoting, session abuse, and SaaS access without stealing real credentials. The focus is measurable purple-team validation: expected telemetry, detection hypotheses, failure points, and repeatable scoring.

Talk outline

Many adversary emulation plans still assume the intrusion begins with malware execution and endpoint persistence. That model misses a growing class of intrusions where the attacker's primary tool is identity. The path may start with a phished session, device code abuse, helpdesk manipulation, stale SaaS access, IdP synchronization drift, or cloud role assignment. The attacker may never need custom malware to reach sensitive systems.


This talk introduces an identity-first adversary emulation framework. The framework models how an attacker moves from on-prem identity to cloud identity, from IdP to SaaS, and from SaaS to cloud control plane access. The lab uses synthetic AD, Entra ID-style identity objects, Okta-like flows, SaaS app assignments, and cloud role mappings. Each emulation step includes a defensive expectation: what log should exist, what alert should fire, what identity relationship should be visible, and what evidence proves the control worked.


The playbooks are designed for purple teams, not uncontrolled attack simulation. They cover safe versions of device code flow testing, session reuse simulation, IdP drift detection, privilege assignment review, SaaS integration abuse, and cloud role pivoting. The talk maps each step to ATT&CK techniques where appropriate, but it avoids turning ATT&CK into a checkbox exercise. The emphasis is measurable coverage.


The demo shows a synthetic user moving through an identity-first path. The audience sees the identity graph, the emulation step, the generated telemetry, the expected detection, and the final coverage score. The result is a repeatable way for organizations to test whether their identity controls detect modern intrusion behavior.

Agency.


Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!