Beyond the Checklist: Adversary Simulation for Proactive Insecure Design Discovery track 2 @OWASPGLOBAL
Beyond the Checklist: Adversary Simulation for Proactive Insecure Design Discovery track 2  @OWASPGLOBAL
Uploaded April 2026 | Updated September 2026, 1 week ago
Standard penetration tests often focus on implementation bugs, but the most critical breaches stem from Insecure Design (OWASP Top 10 A04:2021). This session, presented from the perspective of an active red teamer and adversary simulation specialist, dives into the gap between theoretical threat modeling and real-world attack path exploitation. We will explore how to translate high-level adversary tactics (like those in MITRE ATT&CK) into proactive design reviews and custom attack scenarios. Learn to move beyond surface-level vulnerabilities by building and leveraging custom tooling and simulation techniques that specifically target design flaws, authentication/authorization logic, and chained architectural weaknesses in modern application environments (e.g., Cloud, Serverless). Attendees will leave with a clear methodology for leveraging an offensive mindset to uncover design-level risks early in the Planning and Design phase, drastically improving the security-by-design posture of their applications.

Tomiwa Falade
Offensive Security Engineer

Tomiwa is an Offensive Security Engineer with a passion for exploring how attackers think, build, and operate. His work spans red teaming, adversary simulation, and security research, where he experiments with modern techniques for bypassing defenses and uncovering real-world attack paths. With experience designing custom tools, running offensive security labs, and translating complex concepts into clear insights, he helps both technical and non-technical audiences understand the evolving threat landscape. He has spoken on topics ranging from ethical hacking and malware trends to practical steps for building resilient applications and infrastructure. Beyond offensive security, he is a strong advocate for knowledge-sharing across the wider tech community whether engaging with developers on secure coding practices, or contributing to open discussions on the future of cybersecurity.
-

Managed by the OWASP® Foundation
owasp.org
Beyond the Checklist: Adversary Simulation for Proactive Insecure Design Discovery track 2German OWASP Day HighlightThreat Modeling in the Age of AI - Susanna CoxTwo Paths to Security Upskilling: Startup and EnterpriseTransparency Exchange API: How Do You Find the SBOM for a Smart Light Bulb?OWASP Top 10 Risks for Open Source Software - George Apostolopoulos“The Developer First Security Mindset”   Making Security a Product Feature, Not a BlockerEveryone Can Play! Building CTFs for Non-Security FolksLLMs in AppSec: Why They Still Need a ChaperoneAI Goat: A Damn Vulnerable AI Infrastructure - Ofir Yakobi & Shir SadonThe History of the OWASP Developer GuideOWASP AI Exchange experts on the future of security for AI - Panel hosted by Chloé Messdaghi
OWASP Foundation |

Beyond the Checklist: Adversary Simulation for Proactive Insecure Design Discovery track 2

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER