Session

How I Accidentally Helped Hack 80,000 EntraID Accounts

Back in 2022, I released TeamFiltration to help defenders test their Microsoft 365 security. In early 2025, Proofpoint and others reported that attackers had weaponized it in large-scale password-spraying campaigns, targeting over 80,000 Entra ID accounts worldwide. This talk dives into how my red-team tool was abused in the wild, why it became headline news across outlets like Proofpoint, The Hacker News, and SecurityWeek, and what the TeamFiltration saga reveals about the double-edged nature of open-source offensive tooling.

Melvin Langvik

Senior Security Consultant at TrustedSec

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top