Jonathan Prince
Jonathan spends a large proportion of his time breaking the things enterprises trust most but understand least. He specialises in IBM z/OS and IBM i security, not because it's fashionable, but because someone has to, and the systems running your bank's core transactions deserves more than a checkbox audit.
He analyses authorization models, maps privilege escalation paths, and explains to enterprises why their carefully designed access controls are actually a roadmap for attackers. At home he runs a lab that includes two AS/400s and enough enterprise equipment to make most corporate IT departments uncomfortable, because the best way to understand how to break something is to pwn one.
His current research applies modern offensive security methodology to platforms the industry forgot to threat-model, and demonstrates that the gap between a compromised AD account and privileged access on a mainframe may be smaller, and more traversable, than anyone in your SOC wants to hear.
Session
Enterprise identity security has been transformed by graph-based attack path modeling. BloodHound changed how attackers and defenders think about Active Directory, revealing privilege escalation paths that static access reviews consistently missed. That shift never reached the mainframe.
RACF, IBM's security subsystem for z/OS, controls access to some of the most sensitive workloads in existence such as core banking, payment processing, government records, and insurance systems. Yet mainframe authorization is still primarily analyzed through flat reports and manual access list reviews, approaches that are blind to multi-step privilege escalation across users, groups, datasets, surrogate permissions, and system authorities.
RACFHound applies attack path modeling to RACF by transforming authorization data into an identity graph and integrating it into BloodHound via the OpenGraph framework. This talk demonstrates how privilege escalation paths through RACF can be systematically discovered using the same techniques now standard in Active Directory security. The mainframe becomes a first-class citizen in modern identity security analysis, and the attack paths hiding in plain sight in every large enterprise finally become visible.