Jordan Bonagura
Modern enterprise environments have shifted beyond traditional network perimeters, with SaaS applications and identity providers becoming the primary attack surface. However, a significant portion of this still remains unmanaged or invisible commonly referred as Shadow SaaS.
This session explores Shadow SaaS from an attacker’s perspective, demonstrating how adversaries can identify, evaluate, and abuse unmanaged SaaS applications to gain initial access and maintain persistence within target environments.
Rather than focusing on inventory or governance, this talk reframes Shadow SaaS as an offensive opportunity. It highlights how implicit trust relationships, and third-party SaaS connections expand the attack surface beyond traditional security visibility.
Using the Shadow SaaS Surface Scanner, we demonstrate how attackers can uncover hidden SaaS exposure and leverage it as a foothold into enterprise environments.
Jordan Bonagura
Senior Security Consultant and Researcher
Senior Security Consultant at Secure Ideas Researcher in Information Security Stay Safe Podcast Founder Computer Scientist Post Graduated in Business Strategic Management, Innovation and Teaching Founder - Vale Security Conference - Brazilian Conference Consultant Member - Brazilian Comission of High Tech Crime (OAB / SP) Coordinator and Teacher in IT area SJC Hacker Space President Speaker (DefCon, Hack Space Con, Hack Red Con, Hack Miami, Triangle InfoSec, AppSec California, GrrCon, BalCCon2k14, BSides Augusta, H2HC, Angeles Y Demonios, Silver Bullet, Seginfo, ITA, INPE, etc)