Senior Linux Systems Engineer
Samet Can Tasci is a Senior Linux Systems Engineer and security researcher with experience across enterprise infrastructure, cloud and hybrid environments, automation, and defensive security validation.
His research interests include web defense behavior, WAF normalization gaps, parser inconsistencies, adversary-informed testing, and practical tooling for security teams.
He is the creator of WaffleX, a research prototype selected for Black Hat USA Arsenal, which focuses on semantic consistency analysis, enforcement drift, and family-level request-variant testing across modern web application defense stacks.
10:30-11:00 PDT | Saturday, Aug 8th 2026 | DEF CON Creator Stage 3, Las Vegas Convention Center Talk
Co-presented with: Mehmet Önder Key
Modern intrusions often start with identity, not malware. Adversaries abuse IdP drift, device code flows, stale sessions, weak conditional access, helpdesk processes, SaaS integrations, and cloud role mappings. This talk presents a safe emulation framework for identity-first threat actors across AD, Entra ID, Okta-like workflows, and cloud control planes. The lab provides ATT&CK-aligned playbooks that simulate identity compromise, IdP pivoting, session abuse, and SaaS access without stealing real credentials. The focus is measurable purple-team validation: expected telemetry, detection hypotheses, failure points, and repeatable scoring.
Many adversary emulation plans still assume the intrusion begins with malware execution and endpoint persistence. That model misses a growing class of intrusions where the attacker's primary tool is identity. The path may start with a phished session, device code abuse, helpdesk manipulation, stale SaaS access, IdP synchronization drift, or cloud role assignment. The attacker may never need custom malware to reach sensitive systems.
This talk introduces an identity-first adversary emulation framework. The framework models how an attacker moves from on-prem identity to cloud identity, from IdP to SaaS, and from SaaS to cloud control plane access. The lab uses synthetic AD, Entra ID-style identity objects, Okta-like flows, SaaS app assignments, and cloud role mappings. Each emulation step includes a defensive expectation: what log should exist, what alert should fire, what identity relationship should be visible, and what evidence proves the control worked.
The playbooks are designed for purple teams, not uncontrolled attack simulation. They cover safe versions of device code flow testing, session reuse simulation, IdP drift detection, privilege assignment review, SaaS integration abuse, and cloud role pivoting. The talk maps each step to ATT&CK techniques where appropriate, but it avoids turning ATT&CK into a checkbox exercise. The emphasis is measurable coverage.
The demo shows a synthetic user moving through an identity-first path. The audience sees the identity graph, the emulation step, the generated telemetry, the expected detection, and the final coverage score. The result is a repeatable way for organizations to test whether their identity controls detect modern intrusion behavior.
Agency.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!