Rahul Vashisht
Rahul is a seasoned Red Team Operator with years of experience executing high-stakes offensive security engagements against hardened global enterprises—from breaching physical perimeters to dismantling cloud-native EDR solutions. As a key player at a top-tier cybersecurity firm, he specializes in crafting undetectable attack chains, weaponizing novel evasion techniques, and developing custom tooling that bypasses industry-standard defenses for clients in banking, telecom, and critical infrastructure. His mission? Hack first, hunt harder.
Session
Phishing defenses assume the attack comes from outside the trusted set: a lookalike domain, a domain registered last week, a sender with no history. Your cloud Provider's own infrastructure breaks that assumption, and this talk covers how far that goes.
B2B guest invitations produce real, Signed mail carrying a redirection target the attacker influences. Open redirects across Trusted Cloud Provider-owned domains supply the pivot, and chaining them keeps the trusted origin intact through to the payload. I'll demo forced POST parameter injection, image and context injection that pulls the target's own tenant branding into the lure, and end-to-end credential and MFA capture. The address bar stays your favorite Provider's the whole way.