Hack.lu 2026

Six Degrees of RACF SPECIAL - Mainframe Attack Paths

Enterprise identity security has been transformed by graph-based attack path modeling. BloodHound changed how attackers and defenders think about Active Directory, revealing privilege escalation paths that static access reviews consistently missed. That shift never reached the mainframe.
RACF, IBM's security subsystem for z/OS, controls access to some of the most sensitive workloads in existence such as core banking, payment processing, government records, and insurance systems. Yet mainframe authorization is still primarily analyzed through flat reports and manual access list reviews, approaches that are blind to multi-step privilege escalation across users, groups, datasets, surrogate permissions, and system authorities.
RACFHound applies attack path modeling to RACF by transforming authorization data into an identity graph and integrating it into BloodHound via the OpenGraph framework. This talk demonstrates how privilege escalation paths through RACF can be systematically discovered using the same techniques now standard in Active Directory security. The mainframe becomes a first-class citizen in modern identity security analysis, and the attack paths hiding in plain sight in every large enterprise finally become visible.


Modern red team and identity security tooling has largely ignored the mainframe. This is not because mainframes are secure, it is because the platform has historically been inaccessible to the wider research community, and security through obscurity has filled the gap. RACF configurations in large enterprises have often gone unaudited in any meaningful sense for years. The permissions are there. The escalation paths are there. Nobody has been looking.
This talk introduces RACFHound, a tool that models RACF authorization data as an attack graph and integrates with BloodHound using the OpenGraph framework. RACF entities are mapped to a graph model, and how attack primitives specific to z/OS emerge from that structure: SURROGAT permission chains, write access to APF-authorized libraries, escalation through UNIX System Services, and paths to the SPECIAL and OPERATIONS attributes. Live demonstration using BloodHound shows how paths that would require hours of manual RACF report analysis become instant graph queries.
The goal is to bring the analytical shift that BloodHound brought to Active Directory to an environment that handles more sensitive data, faces less scrutiny, and has fewer defenders who know what to look for.

Jonathan Prince

Jonathan spends a large proportion of his time breaking the things enterprises trust most but understand least. He specialises in IBM z/OS and IBM i security, not because it's fashionable, but because someone has to, and the systems running your bank's core transactions deserves more than a checkbox audit.
He analyses authorization models, maps privilege escalation paths, and explains to enterprises why their carefully designed access controls are actually a roadmap for attackers. At home he runs a lab that includes two AS/400s and enough enterprise equipment to make most corporate IT departments uncomfortable, because the best way to understand how to break something is to pwn one.
His current research applies modern offensive security methodology to platforms the industry forgot to threat-model, and demonstrates that the gap between a compromised AD account and privileged access on a mainframe may be smaller, and more traversable, than anyone in your SOC wants to hear.