Nullcon Goa 2025: Project Dusseldorf: Finding Out-Of-Band Vulnerabilities At Cloud Scale - Michael
About this talk
This talk introduces Project Dusseldorf, a versatile out-of-band application security platform designed to identify and analyze network requests. The speaker explains how it utilizes a built-in rule engine to create automated responses through a range of predefined payloads. Project Dusseldorf, employed by multiple red teams and application security teams at Microsoft, aims to detect various vulnerability classes such as SSRF, XXE, SSTI, and XSS, as well as generic remote code executions. The session also includes an open-source release of the code, demonstrating how attendees can leverage the platform to uncover vulnerabilities in their targets.
More from this event
See all 30 talks →
Nullcon Goa 2025: Securing the chains: Building defensive layers for software supply chains
38:14
Nullcon Goa 2025 | Large-Scale Exposure Of Orphaned Commits On Major Git Platforms by Kumar Ashwin
26:30
Nullcon Goa 2025 | Panel: Modernizing Security Architecture: Platforms or Best-of-Breed, What Works?
44:47
Nullcon Goa 2025: Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense
42:01