Training
Get a free hour of SANS training

Experience SANS training through course previews.

Learn More
Learning Paths
Can't find what you are looking for?

Let us help.

Contact us
Resources
Join the SANS Community

Become a member for instant access to our free resources.

Sign Up
For Organizations
Interested in developing a training plan to fit your organization’s needs?

We're here to help.

Contact Us
Talk with an expert

Modern Multi-Factor Authentication Bypass Techniques: A Taste of SANS SEC660

  • Wed, Apr 2, 2025
  • 4:00PM - 5:00PM UTC
  • English
  • James Shewmaker
  • Technical Presentation
Webcast Hero

With the proliferation of multi-factor authentication, penetration testers need to apply existing tooling to manipulate even internal applications. Building attack infrastructure internally during a penetration test is resource exhausting, but modern tools like evilginx can do most of the heavy lifting for us.

This webcast will cover an excerpt from SANS SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking™, using evilginx to bypass internal application authentication.

There are many examples of public MFA bypass attacks, such as manipulating credentials from office365. Here, we will discuss and demonstrate such an attack, resulting in pivoting internally into an administrative console.

This webcast supports content and knowledge from SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking™. To learn more about this course, explore upcoming sessions, and access your FREE preview, click here.

Meet the speaker

James Shewmaker
James Shewmaker

James Shewmaker

Founder and Principal Consultant

James Shewmaker, founder of Bluenotch Corporation, has over two decades of technical experience in IT, primarily developing appliances for automation and security for broadcast radio, internet, and satellite devices.

Read more about James Shewmaker
Modern Multi-Factor Authentication Bypass Techniques: A Taste of SANS SEC660 | SANS Institute