pushsecurity / saas-attacks

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
https://pushsecurity.com/blog/saas-attack-techniques/
Creative Commons Attribution 4.0 International
943 stars 61 forks source link

Should SAMLJacking be lateral movement as well? #31

Closed jacques- closed 10 months ago

jacques- commented 10 months ago

If you can change the configuration of an actively used app's SAML config that is legit lateral movement no?