
Compromising Workspace from Windows, AD & EntraID | SO-CON 2025
Source: YouTube · SpecterOps · published May 6, 2025 · 50:34
Carlos Palop presents novel techniques for compromising Google Workspace from Windows Active Directory, highlighting an under-researched attack surface that red teams can leverage 0:05.
Key Takeaways:
• The core topic explores how to bridge on-premises Windows Active Directory compromises into Google Workspace environments 0:05.
• While AWS and Azure dominate cloud security research, Google Workspace remains relatively under-examined 0:27.
• This lack of widespread focus provides an opportunity for pentesters and red teams to discover and apply new exploitation tricks 0:34.
This talk aims to equip security professionals with fresh methodologies to assess and secure hybrid environments utilizing Google Workspace 0:40.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Music] So today we are going to be talking about how to compromise Google Workspace from Windows Active Directory and InD. So which of you use Google Workspace work in a company that use Google Workspace or has pentest or red team and a scenario where Google workspace was involved? Anyone can drop the hands. Okay. Okay. We have a few. uh I know that this is not the most common cloud being used. I know that AWS and Azour is much more used but this was also the reason why I did this research and it's because well nobody else was almost looking at this. So I think that uh you're going to be uh exceeding this talk with some nice new tricks to compromise Google from uh Windows environments. So I am Carlos Palop. Currently I am principal of chain security team lead in Halbour. I do pentesting, …