Program

/

CODE BLUE 2026

Time Table

Pass-the-Device: Transplanting SASE/VPN Trust After Endpoint Compromise

Despite massive investments in Zero Trust, many modern SASE/VPN deployments still allow trust to be transplanted after endpoint compromise. Identity, certificates and posture checks often prove transferable rather than strictly device-bound. This talk introduces “Pass-the-Device” - a practical methodology whose core techniques proved applicable in most red-team engagements involving SASE/VPN solutions. We demonstrate how attackers can export or reissue certificates, replay sessions, abuse enrollment flows and reconstruct posture state to establish independent access from attacker-controlled hosts. We classify recurring trust-hijacking primitives across Palo Alto, Cisco, Netskope and Zscaler, explaining when each technique succeeds or fails. Attendees will learn how attackers operate beyond the original host’s EDR visibility while still leaving detectable traces across IdP, SASE and network telemetry. The talk concludes with practical mitigations and detection opportunities.

  • Location :

    • Track 1(HALL B)

  • Category :

    • Technical

  • Share :

Speakers

  • ルスラン・サイフィエフ の写真

    Ruslan Sayfiev

    ルスラン・サイフィエフ

    Ruslan Sayfiev is a Principal Consultant and Red Team Architect at Fujitsu Uvance Wayfinders, with more than a decade of experience in offensive security, adversary simulation, exploit development, and vulnerability research.

    Previously, as Director of Offensive Security at GMO Cybersecurity by Ierae, he built and led the company’s red team practice from the ground up, delivering hundreds of engagements focused on real-world adversary emulation for major enterprises in Japan.

    His work focuses on advanced post-compromise techniques, including trust transplantation in SASE and VPN environments, endpoint detection evasion, and identity-focused attacks. He is particularly interested in connecting offensive research with detection engineering, incident response, and practical improvements to enterprise security.

    Ruslan holds the OSEE, OSCE3, GXPN, and CRTL certifications. He is a former OffSec instructor, a Code Blue speaker, and has been credited with multiple CVEs affecting major vendors.