Labs
Cloud & SaaS Tradecraft
Living off the cloud, not the land.
Attackers don’t need custom implants to be dangerous in 2025. They need OAuth consent,
a few mis-scoped roles, access to “just one” mailbox, or a misconfigured automation flow.
This lab focuses on how real intrusions play out in Microsoft 365, Google Workspace,
and critical SaaS—and how to turn that knowledge into opinionated defenses.
M365, Entra ID & Azure AD
Google Workspace & OAuth apps
SaaS persistence & identity abuse
The goal isn’t to catalog every trick—it’s to understand durable patterns that defenders
can reliably detect, block, or make prohibitively expensive.