c0c0n 2026

c0c0n is a 19 years old platform that is aimed at providing opportunities to showcase, educate, understand and spread awareness on Information Security, data protection, and privacy...

Venue & Date

c0c0n 3-Day Professional Training

Practical Offensive Recon for Modern Attack Surfaces

Workshop Objective

Modern organizations expose thousands of assets across cloud, SaaS, APIs, mobile applications, AI platforms, and third-party services. This hands-on training teaches participants how to perform attacker-grade reconnaissance against modern organizations.

Students will learn practical techniques to discover internet-facing assets, map complex attack surfaces, identify AI-related exposures, collect actionable intelligence, and build realistic attack paths using real-world targets and enterprise-scale datasets.

The course combines manual tradecraft with automation and AI-assisted workflows to help participants perform faster, more effective reconnaissance while reducing noise.

By the end of the workshop, participants should be able to
  • Build an attacker-centric map of a modern organization's external footprint.
  • Perform structured and scalable reconnaissance across domains and internet-facing infrastructure.
  • Discover cloud, API, SaaS, mobile and third-party assets.
  • Identify source-code, CI/CD and software supply-chain exposures.
  • Collect and correlate intelligence from multiple public and security-data sources.
  • Identify leaked secrets, configuration and development artifacts.
  • Discover modern AI infrastructure and AI-related exposures.
  • Use automation and AI-assisted analysis to process large reconnaissance datasets.
  • Separate useful signals from reconnaissance noise and false positives.
  • Correlate seemingly unrelated assets into meaningful relationships.
  • Build realistic attack paths from discovered exposures.
  • Produce actionable reconnaissance suitable for penetration testing, red teaming, security research, CTEM and Attack Surface Management.

Course Content

Day 1 - Mapping the Modern External Attack Surface
  • Modern reconnaissance methodology and attacker mindset
  • Organization, domain, subdomain and infrastructure discovery
  • DNS, certificate, ASN and historical infrastructure intelligence
  • Technology and service fingerprinting
  • Identifying staging, development and forgotten infrastructure
  • Asset enrichment, validation and prioritization
  • Building an initial external attack-surface map
  • Hands-on reconnaissance exercises
Day 2 - Discovering Hidden Enterprise Exposures
  • Cloud attack-surface discovery across AWS, Azure and GCP
  • Identifying exposed storage, cloud services and development infrastructure
  • API discovery and mapping
  • SaaS, shadow IT and third-party infrastructure discovery
  • GitHub and source-code intelligence
  • CI/CD and software supply-chain exposures
  • Container registries and development artifacts
  • Credential, secret and configuration exposure
  • Correlating development, cloud and production infrastructure
  • Hands-on exercises
Day 3 - Chaining Exposures into Real-World Attacks
  • Turning reconnaissance findings into actionable attack hypotheses
  • Identifying high-value entry points across cloud, APIs, SaaS and exposed infrastructure
  • Credential attacks including password spraying, credential stuffing and targeted brute-force scenarios
  • Authentication weaknesses, weak access controls and exposed administrative interfaces
  • Chaining leaked credentials, tokens and configuration artifacts into access paths
  • Attacking exposed cloud services, storage and development infrastructure
  • API abuse and authentication-related attack paths
  • Source-code, CI/CD and software supply-chain attack scenarios
  • Exploiting exposed secrets and developer artifacts
  • Attacking exposed AI applications, inference endpoints and supporting infrastructure
  • Identifying and attacking weaknesses in RAG systems, vector databases, agent infrastructure and MCP servers
  • Chaining multiple low-severity exposures into higher-impact compromises
  • Prioritizing attack paths based on exploitability, access gained and business impact
  • Hands-on attack scenarios
Final Capstone Exercise

Participants will apply the techniques covered across all three days against a realistic simulated organization. Starting with minimal information, they will discover and map the organization's external footprint, identify hidden and emerging attack surfaces, correlate exposures across different platforms, and develop a prioritized set of attack paths and findings.

Pre-requisite
  • Basic understanding of networking and web technologies
  • Familiarity with Linux command line
  • Basic knowledge of penetration testing methodologies

The workshop is suitable for beginner-to-intermediate practitioners, while experienced penetration testers and security researchers should also benefit from the modern attack-surface.

Participant's Requirements
  • Laptop capable of connecting to WiFi without restrictive corporate proxies
  • At least 8 GB RAM (16 GB recommended)
  • Modern web browser
Who Should Attend
  • Penetration Testers
  • Red Teamers
  • Security Researchers
  • Bug Bounty Hunters
  • Attack Surface Management teams
  • CTEM teams
  • Security Engineers
  • Cloud Security Engineers
  • Application Security Engineers
  • Threat Intelligence Analysts
  • OSINT Practitioners
  • Security Consultants
What Not to Expect
  • A basic introduction to using search engines.
  • A course consisting primarily of slides or theory.
  • A tool-by-tool walkthrough with no underlying methodology.
  • A vulnerability-scanner training course.
  • An exploit-development or malware-development course.
  • A course focused only on AI security.
  • Guaranteed vulnerabilities against real organizations.

Anyone responsible for understanding what an attacker can discover about an organization from outside its perimeter will benefit from the workshop.

Trainers

Kumar Ashwin

Security Engineer

RedHunt Labs

PARTNERS