How an Unprivileged User Can Bypass Netskope: Auditing Certificate Pinned Apps
How to identify and exploit misconfigured Certificate Pinned Apps in a Netskope deployment during a pentest, without needing administrative privileges.
1 contribution in the year 2026
Hi there! 👋 I’m Hilario José Bandrés Sasal.
I currently work as an SSE Solutions Expert, focused on SASE platforms such as Netskope and Zscaler. My day-to-day revolves around the design, deployment, and troubleshooting of access security solutions in corporate environments.
My main interest within cybersecurity is offensive security applied to this type of platform: understanding how they work under the hood, identifying configurations that open the door to an attacker, and documenting auditing techniques that help other professionals find the same issues. I’m also interested in Active Directory red teaming and cloud environment security.
I firmly believe in sharing knowledge and contributing to the community.
If you’d like to get in touch or follow my work, you can do so through my social media.
How to identify and exploit misconfigured Certificate Pinned Apps in a Netskope deployment during a pentest, without needing administrative privileges.
This author has not published articles yet.
If you like the content and want to support the project, you can buy me a coffee. Your support helps keep the site active and create more quality content.
Buy me a coffeeThanks for your support 🙏