BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-bristol-2026//talk//SL8KYV
BEGIN:VTIMEZONE
TZID:Europe/London
BEGIN:DAYLIGHT
DTSTART:20250821T000000
TZNAME:BST
TZOFFSETFROM:+0100
TZOFFSETTO:+0100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T020000
RDATE:20261025T020000
TZNAME:GMT
TZOFFSETFROM:+0100
TZOFFSETTO:+0000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T020000
RDATE:20270328T020000
TZNAME:BST
TZOFFSETFROM:+0000
TZOFFSETTO:+0100
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:The Next Internal Network: Why Your Old Playbook Doesn't Work - Du
 mi Masimini
DTSTART;TZID=Europe/London:20260821T110000
DTEND;TZID=Europe/London:20260821T114000
DTSTAMP:20260812T231611Z
UID:pretalx-bsides-bristol-2026-SL8KYV@pretalx.com
DESCRIPTION:For more than two decades\, internal penetration testing has f
 ollowed a familiar objective: compromise Active Directory and become Domai
 n Admin.\n\nOur methodologies\, tooling and even our mental models have be
 en built around this goal. Kerberoasting\, delegation abuse\, AD CS attack
 s\, DCSync and BloodHound became the playbook for understanding enterprise
  compromise.\n\nBut what happens when Domain Admin is no longer the most v
 aluable privilege in the organisation?\n\nModern enterprises are rapidly s
 hifting their trust away from traditional Windows domains. Identity provid
 ers grant access to critical business systems. SaaS platforms hold sensiti
 ve data and administrative control. Device management platforms decide whi
 ch endpoints are trusted. Cloud management planes often provide broader in
 fluence than on-premises infrastructure\, while OAuth applications and fed
 erated identity introduce entirely new attack paths.\n\nThis talk explores
  how the definition of the "internal network" is changing and why offensiv
 e security professionals need to rethink what successful compromise looks 
 like.\n\nUsing examples inspired by real penetration testing engagements\,
  we'll examine how attackers can chain together weaknesses across identity
  providers\, cloud administration\, SaaS platforms\, device management and
  federated trust to achieve objectives that traditional Active Directory-f
 ocused methodologies may never uncover.\n\nThis isn't a talk about the dea
 th of Active Directory—it remains a critical component of many enterpris
 e environments. Instead\, it's about recognising that Active Directory is 
 increasingly just one node in a much larger trust graph.\n\nWhether you're
  a penetration tester\, red teamer\, blue teamer or security leader\, you'
 ll leave with a new perspective on where enterprise trust is moving\, how 
 attackers are adapting\, and why the next generation of internal security 
 assessments must look far beyond Domain Admin.
LOCATION:Track 1
URL:https://pretalx.com/bsides-bristol-2026/talk/SL8KYV/
END:VEVENT
END:VCALENDAR
