Real-World Offensive Security: Red Teaming LLMs, Microsoft Entra ID & Android

No ratings

Presented at RootCon 9 by

This hands-on offensive security training focuses on real-world attack surfaces across three modern and highly targeted areas: Large Language Models (LLMs), Microsoft Entra ID, and Android Applications. Designed for red teamers, security professionals, and tech-savvy defenders, this training combines practical theory with 20+ hands-on labs to simulate actual attack scenarios and strengthen offensive capabilities. The training begins with an introduction to LLMs, covering how they work, the data and techniques behind their training, and the real-world applications driving their rapid adoption. It also explores the security challenges associated with deploying LLMs. Participants will then dive into LLM attack simulations, gaining hands-on experience with threats like prompt injection, system prompt extraction, sensitive information disclosure, and model manipulation. The second section introduces Microsoft Entra ID (formerly Azure AD) — Microsoft’s cloud-based identity and access management solution. The session covers its architecture, key components, RBAC, licensing, and how it differs from traditional on-prem Active Directory. The practical component focuses on pentesting Entra ID, including enumeration using tools like ROADrecon and AzureHound, password spraying with MSOLSpray, token and cookie-based attacks, and exploiting misconfigurations in Entra Connect and privileged accounts. The final part of the training covers Android application pentesting, beginning with an overview of the Android architecture, common attack surfaces, and testing methodologies. Through deep-dive labs, participants will explore real-world attack scenarios such as bypassing SSL pinning and root detection, reverse engineering Flutter apps, exploiting IPC mechanisms, analyzing insecure storage, and performing advanced tampering involving Smali code and exploitation with Metasploit. By the end of the training, participants will walk away with practical red teaming techniques and offensive knowledge applicable to AI systems, cloud identity platforms, and mobile environments.