--- title: "Followup links for All You Need Is Guest RSAC 2024" description: "Guest access escalation research and tools—because we learned that sometimes all you really need is guest." categories: - Blog tags: - RSAC --- Assorted links for All You Need Is Guest @ RSAC 2024: 1. [Power Platform DLP Bypass via Copy & Paste](https://www.mbgsec.com/blog/power-platform-dlp-bypass-via-copy-and-paste/) 2. [OWASP No-Code / Low-Code Top 10](https://owasp.org/www-project-top-10-low-code-no-code-security-risks/) 3. [powerpwn](https://github.com/mbrg/power-pwn) 4. [Microsoft docs on EntraID multitenant sharing options](https://learn.microsoft.com/en-us/entra/identity/multi-tenant-organizations/overview) Other talks ([slides and source code](https://mbgsec.com/talks)) 1. [All You Need is Guest @ BlackHat USA 2023](https://www.blackhat.com/us-23/briefings/schedule/index.html#all-you-need-is-guest-32647) 2. [Sure, Let Business Users Build Their Own. What Could Go Wrong? @ BlackHAt USA 2023](https://www.blackhat.com/sector/2023/briefings/schedule/#sure-let-business-users-build-their-own-what-could-go-wrong-36063) 3. [Low Code High Risk: Enterprise Domination via Low Code Abuse @ DEFCON30](https://www.youtube.com/watch?v=D3A62Rzozq4) 4. [No-Code Malware: Windows 11 At Your Service @ DEFCON30](https://www.youtube.com/watch?v=e8PEIOa6W9M)