BSides Cleveland 2026
- Date:
- Saturday, September 26
- Location:
- Case Western Reserve University, Cleveland, OH
BSides Cleveland returns to Tinkham Veale University Center on the Case Western Reserve University campus for a full day of community-driven talks across red team, blue team, and hardware hacking tracks. The 2026 event kicks off Cleveland Tech Week, with day-of CTFs, hands-on villages, and a lineup built by and for the local infosec crowd.
David Garlak, Senior Security Consultant at Bishop Fox, takes the Red Team stage to dig into AWS attack paths that go beyond IAM misconfigurations. Known in the community as vexance, David specializes in cloud and application penetration testing with a focus on AWS pathfinding and privilege escalation.
For more details, visit: BSides Cleveland 2026
Kickin' Graphs and Takin' ARNames: Mapping Avenues of Attack in AWS
Speaker: David Garlak, Senior Security Consultant, Bishop Fox
Abstract: Most documented attack paths in AWS focus on dangerous combinations of IAM permissions, but these permissions are not necessarily a complete picture of possible cloud attack chains. While several tools exist that help identify known privilege escalation paths stemming from IAM permissions, understanding the interconnectedness of AWS resources remains a significant challenge. In this session, we'll discuss attacks through the lens of improving one's position against identity, network, and resource boundaries. After discussing core attack primitives, we'll walk through new principal compromise paths we've discovered in other AWS services, showing identification steps and sample code snippets where necessary to exfiltrate IAM role credentials. The session will contain visualizations depicting attack graph patterns covered by an upcoming tool release.