Mohamed Elsayed
Senior Red team Consultant
Google - Mandiant
Mohamed is specialized in Penetration Testing and Red Teaming engagements, protecting corporate assets. He had been acknowledged for serious application vulnerabilities, resulting in multiple CVEs
Speaker sessions
Shells Without Phish: AppSec Tactics and Zero-Day Discovery in Red Team Ops
Initial access isn’t just about phishing anymore. Modern breaches are increasingly rooted in the application layer, where logic flaws, design weaknesses, and overlooked attack surfaces can open paths to compromise.In this talk, we’ll dissect how AppSec-driven tactics can redefine red team operations. We’ll share our methodology for embedding vulnerability research into live engagements, blending code-level analysis, target hunting, and exploit chaining with traditional adversary tradecraft. This isn’t about dropping a pre-packaged exploit—it’s about building one mid-operation.Through case studies against high-profile global targets, we’ll show how this approach surfaced and chained zero-day vulnerabilities to breach external perimeters and operate effectively in mature environments. Whether you’re looking to sharpen your offensive capabilities or expand your initial access playbook, this session delivers hard-earned insights straight from the field.
- 12:30
- Thu
- 04 Dec
Stage:
Briefings 1
Sessions Type:
Presentation