Priyank Nigam

Priyank Nigam

Offensive security research and security engineering notes

I work on identity, application security, and red teaming finding the flaws, exploiting them and getting them fixed. I talk about only a subset of them due to [reasons]. Conference talks and slide decks below, alongside advisories and long-form technical breakdowns.

Talks

7
2026

Open Relays in 2026: Red Team Initial Access Vectors

BSides Las Vegas

Red Team Initial-access TTPs built on open and trusted email relays.

Slides
2026

Modern HTML Injection Exploitation

LayerOne

Turning HTML injection into impact against current browser and framework defences.

Slides
2025

Beyond LSASS: Cutting-Edge Techniques for Undetectable Threat Emulation

Insomni'Hack & TROOPERS25

Entra ID credential-access tradecraft that avoids the detections built around LSASS.

Slides
2024

Advanced Techniques for Hunting and Securing User Registration Vulnerabilities

NorthSec & Security Fest

Account-registration flaws end to end: enumeration, pre-hijacking and verification bypasses.

Slides
2023

Breaking Business As Usual: Attacking Android Enterprise Solutions

BSides Las Vegas

Attacking Android enterprise management stacks, from enrollment through policy enforcement.

Slides
2023

Throw Your (App)Integrity Out the Window: Bypassing Device Integrity Checks on iOS

BSides Seattle

Defeating the jailbreak and device-integrity checks that iOS apps rely on.

Slides
2019

Reverse Engineering Mobile Transit Applications

BSides Las Vegas

The research behind the reverse engineering mobile ticketing solutions.

Slides

Published Papers

1

Writing & Advisories

4
2026

When a Version Number Becomes a Shell Command

Technical Analysis of GHSA-p89g-fcr7-p99r in QuestPDF CI
2021

CVE-2020-13956

A URI-parsing flaw in Apache HttpClient
2019

Authentication Bypass in Mobile APIs

Greyhound Road Rewards - coordinated disclosure
2019