NOAuth, no problem. How hard can it be?
Handling auth for offensive security
Authentication determines how much of an application an offensive security assessment can actually reach. Critical vulnerabilities such as IDOR, privilege escalation, and cross-tenant data leakage often emerge only after login, but authentication itself is frequently why assessments pause, lose coverage, or leave targets out of scope.
Join Brendan and Vincent on Wednesday, September 2 at 12pm ET / 9am PT for a practical conversation about:
Why auth matters: The highest-value application behavior often sits behind identity and permission boundaries.
Why auth is hard: SSO redirects, MFA challenges, short-lived tokens, session timeouts, passwordless flows, account lockouts, and more.
How autonomous agents approach it: Establishing and maintaining identity long enough to test the authorization boundaries behind it.
Speakers
AI Researcher @ XBOW
AI Researcher @ XBOW