Offense for Defense

Thursday, April 30, 2026 | 8:00AM–8:45AM PT | California Ballroom B, Second Floor
Session Type: Breakout Session
Delivery Format: Presentation/Panel
Budgets are tight in education, and you can't often afford penetration testing or read teaming. This presentation focuses on how information security defenders can use simmple offensive security techniques and tools to quickly identify real-world security weaknesses without relying on costly third-party consultants. Blue teamers and defenders can safely "play red" to uncover common, high-impact issues targeted by threat actors. In this presentation, Tim will cover topics such as credential abuse (password reuse, credential-stuffing, weak passwords, Kerberoasting, and MFA gaps), Active Directory (AD) misconfigurations, excessive permissions, insecure file shares, and common AD Certificate Services (AD CS) misconfigrations. The talk demonstrates practical, defender-friendly tools such as Snaffler, PowerView, Hahcat, MFASweep, BloodHound, PingCastle, and Certipy/Cerify/Certi to rapidly identify and confirm these issues. Although perfect security is the goal, any incremental increase is good, even if that step doesn't 100% mitigate the issue. By testing common attack paths and identifying weak spots themselves, blue teams can harden environments, improve visibility, and detect attackers sooner—achieving meaningful defensive gains with minimal cost and effort.

Presenters

  • Tim Medin

    CEO, Red Siege

Resources & Downloads

  • Offense For Defense Tim Medin Red Siege

    Updated on 4/30/2026