This will be an in-depth talk for novice/advanced/expert level as we take a step through the rainbow (red/purple/blue) teams focusing on session-based attacks for SaaS based systems. This goal of this talk is to level up a novice/advanced/expert with different attack methods that they can utilize on how to execute attacks and build a stronger defense in their environment to enhance security. This talk will go deeper than phishing and pass-the-cookie attacks, but look into other methods of hygiene that attackers can exploit. In this talk you will: Learn how attackers execute these attacks Learn how red/purple teams conduct test exercises Learn how blue teams manage/monitor these events Understand methods to enhance design/architecture to mitigate or prevent attacks