Red Team Training Starts 24 October
Technical Talk
Dead Assets Walking : Two Silent Roads Into a Billion-Dollar Enterprise
DATE
27 October 2026
LOCATION
Hilton EGL, Bangalore
TIME
10:45 - 11:30
Abstract
A Fortune-level cybersecurity company. Twelve weeks. One router nobody had touched since an acquisition three years prior.
That router had SSH host keys. Those keys had a path into the internal network. That network had an SCCM misconfiguration, a Jenkins server with stolen deploy tokens, AWS keys sitting in home directories, and an Entra ID sync server whose credentials nobody had rotated. We walked every step of it - undetected.
Two Active Directory domains. Five AWS accounts. GitLab, Jenkins, and the entire CI/CD pipeline. Azure Global Admin. All of it, chained from a single edge device the security team had forgotten existed.
The router wasn't even the only way in. A second, completely independent road ran through the front door: public single-page-app bundles leaking Cognito identity-pool configuration, open self-registration on production, a browser signup that converted into live AWS credentials, and a single over-scoped IAM permission that escalated to full administrator across the tenant.
Two roads, opposite ends of the stack, the same crown jewels. The defenders saw neither.
This talk is the full picture of both kill chains: every technique, every mistake, every detection opportunity the defenders missed - and the checklist that would have stopped us at each stage. We close with where AI accelerates attack paths like these, and what the shrinking window between initial access and total compromise means for defenders. The irony of owning a cybersecurity company's entire estate through forgotten infrastructure and an over-trusting identity layer isn't lost on us.
MEET THE INSTRUCTOR
Venkatraman Kumar

Security Researcher
I am Venkatraman Kumar, a seasoned security researcher, red teamer, and conference speaker with over 5 years of industry experience in information security and programming. My main areas of expertise include network penetration testing, red teaming exercises, adversary simulation, and active directory attacks. I have had the privilege of presenting at notable security conferences such as LeHack, BSides, and SecurityFest.
Beyond my professional endeavors, I am an avid problem solver, constantly immersed in solving CTFs, Hackthebox Labs, and conducting independent research. Currently, I am employed as a red team lead at Securin. Additionally, I serve as the lead of OWASP Chennai, organizing meetups for security communication. I am also a core team member of the Tamil Nadu Cyber Security Council.
About AltSecCON
AltSecCON is an in-person Red Team training initiative focused on instructor-led delivery, enterprise-aligned labs, and practical offensive security execution.
© AltSecCON. An Altered Security initiative.
contact@alteredsecurity.com
Information
Training Programs
Follow Us
Conference
Event
© 2026 AltSecCON. All rights reserved.


