Priyank Nigam

Priyank Nigam

Offensive security research and security engineering notes

I work on identity, application security, and red teaming finding the flaws, exploiting them and getting them fixed. I talk about a subset of them due to [reasons]. Conference talks and slide decks below, alongside advisories and long-form technical breakdowns.

Talks

5
2025

Beyond LSASS: Cutting-Edge Techniques for Undetectable Threat Emulation

Insomni'Hack & TROOPERS25

Entra ID credential-access tradecraft that avoids the detections built around LSASS.

Slides
2024

Advanced Techniques for Hunting and Securing User Registration Vulnerabilities

NorthSec & Security Fest

Account-registration flaws end to end: enumeration, pre-hijacking and verification bypasses.

Slides
2023

Breaking Business As Usual: Attacking Android Enterprise Solutions

BSides Las Vegas

Attacking Android enterprise management stacks, from enrollment through policy enforcement.

Slides
2023

Throw Your (App)Integrity Out the Window: Bypassing Device Integrity Checks on iOS

BSides Seattle

Defeating the jailbreak and device-integrity checks that iOS apps rely on.

Slides
2019

Reverse Engineering Mobile Transit Applications

BSides Las Vegas

The research behind the reverse engineering mobile ticketing solutions.

Slides

Writing & Advisories

4
2026

When a Version Number Becomes a Shell Command

Technical Analysis of GHSA-p89g-fcr7-p99r in QuestPDF CI
2021

CVE-2020-13956

A URI-parsing flaw in Apache HttpClient
2019

Authentication Bypass in Mobile APIs

Greyhound Road Rewards - coordinated disclosure
2019