Loading…

arrow_back View All Dates
Saturday, September 12
 

7:00am CDT

General Conference Registration
Saturday September 12, 2026 7:00am - 7:00pm CDT

Saturday September 12, 2026 7:00am - 7:00pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

9:00am CDT

Opening Ceremonies
Saturday September 12, 2026 9:00am - 9:30am CDT

Speakers
avatar for Phoenix Fier

Phoenix Fier

Advisory Board Member, Blue Team Con
avatar for Frank McGovern

Frank McGovern

Advisory Board Chairman, Blue Team Con

avatar for Alyssa Miller

Alyssa Miller

Advisory Board Member, Blue Team Con
avatar for Becky Selzer

Becky Selzer

Advisory Board Member, Blue Team Con
avatar for Tillery

Tillery

Advisory Board Member, Blue Team Con
avatar for Stel Valavanis

Stel Valavanis

Advisory Board Vice-Chairman, Blue Team Con
Saturday September 12, 2026 9:00am - 9:30am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

9:30am CDT

Keynote Address: We Keep Us Safe
Saturday September 12, 2026 9:30am - 10:20am CDT
Who keeps us safe? We keep us safe.

It’s a rallying cry for community defenders, and for blue teams, it’s the job description. All of us are fighting uphill battles with short resources and long odds, and we have a lot to learn from each other.



How can we do our work most effectively when we can’t count on institutions to have our backs?

This talk takes lessons from neighborhood organizing and applies them to envision security that is rooted in a different kind of trust, with a shared responsibility model built on relationships and care. Attendees will leave with practical advice about what they can do to help get us there together.
Speakers
avatar for Ian Coldwater

Ian Coldwater

Security Consultant, Independent
Ian Coldwater is SIG Security Co-Chair for the Kubernetes project, a longtime community organizer, and a globally recognized expert in container and Kubernetes security. They have presented their research on hacking and hardening cloud native infrastructure at conferences such as... Read More →
Saturday September 12, 2026 9:30am - 10:20am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

10:00am CDT

CTF Village
Saturday September 12, 2026 10:00am - 6:00pm CDT
An attendee favorite at past Blue Team Con events, the Capture The Flag events are a fun and challenging way to hone your cybersecurity defense skills alongside your peers. We’re bringing back some new and different CTF experiences for 2026, brought to you by our sponsors. Check back soon, new CTF challenges will be added shortly.

Saturday September 12, 2026 10:00am - 6:00pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

10:00am CDT

Cyber Polygots Village
Saturday September 12, 2026 10:00am - 6:00pm CDT
We are a community dedicated to bridging the gap between spoken languages and cybersecurity. Our mission is to unify multilingual professionals and enthusiasts, fostering global collaboration and knowledge sharing in the infosec space.
Saturday September 12, 2026 10:00am - 6:00pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

10:00am CDT

IoT Village
Saturday September 12, 2026 10:00am - 6:00pm CDT
IoT Village advocates for advancing security in the Internet of Things (IoT) industry through bringing researchers and industry together. IoT Village hosts talks by expert security researchers, interactive hacking labs, live bug hunting in the latest IoT tech, and competitive IoT hacking contests. Over the years IoT Village has served as a platform to showcase and uncover hundreds of new vulnerabilities, giving attendees the opportunity to learn about the most innovative techniques to both hack and secure IoT. IoT Village is organized by security consulting and research firm, Independent Security Evaluators (ISE).
Follow both ISE (@ISEsecurity) and IoT Village (@IoTvillage) on Twitter for updates on talks, contests, and giveaways.


Saturday September 12, 2026 10:00am - 6:00pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

10:00am CDT

Labs Village
Saturday September 12, 2026 10:00am - 6:00pm CDT
The Lab room is a place where attendees can get an in-depth walk-through or workshop through use cases with hands-on experience using cybersecurity products developed by our sponsors. Each Lab is open for two hours, so if there is a particular company or product that you’d like to see, make note of their Lab timeslot!

Individual lab listings coming soon!
Saturday September 12, 2026 10:00am - 6:00pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

10:00am CDT

Linux Village
Saturday September 12, 2026 10:00am - 6:00pm CDT
Are you Linux Curious?

Got an older Windows computer that can't really support Windows 11 but aren't ready to spend on an upgrade?

Just done with Microsoft's "Agentic OS?"

Our Linux village is here for you with computers to test out Linux on, experts to answer your questions, and we will even install Linux Mint on your computer for you - the OS is free and so is our help! Our mission is to help you explore Linux as your ""daily driver"" OS, and show you just what you can do in a modern Linux environment. So if you've ever wondered what all the talk is about, if you're ready to take the Linux plunge, or if you're anywhere in between, stop by and talk with us, we're here to help you on your Linux journey!

Learn more here: https://www.between-two-firewalls.com/linux-village/

Saturday September 12, 2026 10:00am - 6:00pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

10:00am CDT

Wellness Village
Saturday September 12, 2026 10:00am - 6:00pm CDT
The Wellness Village will be ran by Mental Health Hackers, a 501(c)(3) organization.

The Mental Health Hacker’s (MHH) mission is to educate tech professionals about the unique mental health risks faced by those in our field – and often by the people who we share our lives with – and provide guidance on reducing their effects and better manage the triggering causes. This will be done through numerous talks and speakers conducted within the village during the conference. There will also be fun activities, crafts, coloring, and more to help you reduce stress and take a mental break from the conference activities and attendees.

MHH also aims at providing support services to those who may be susceptible to related mental health issues such as anxiety, depression, social isolation, eating disorders, etc.

Please understand that MHH does not provide counseling or therapy services.

Learn more at https://www.mentalhealthhackers.org/.

Saturday September 12, 2026 10:00am - 6:00pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

10:00am CDT

Unconference
Saturday September 12, 2026 10:00am - 11:59pm CDT
Open during the entire time (even through the night) of the conference.

The Unconference Village is an open-mic setup with a podium and a projector. No talks are selected or scheduled before the start of the conference. Once the conference opens, you can sign up for a slot to present. If your amazing talk didn’t get selected by the Blue Team Con CFP committee, this is your chance to present on your topic in a creative way. If you didn’t submit but wished you would have – here you go! If you want to do a fishbowl about knitting – have at it! The topics do not have to be cybersecurity related. It’s an Unconference!

Saturday September 12, 2026 10:00am - 11:59pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

10:30am CDT

A Standard For Investigative Playbooks
Saturday September 12, 2026 10:30am - 10:55am CDT
The Human Centered Investigation Playbook (HCIP) standard is a YAML-based syntax for writing investigation playbooks that correspond to a particular alert, artifact, or attack. The goal is to have an investigation methodology that both guides the analyst and also integrates into defensive tooling to make necessary data easily available during the investigation. I will discuss the standard, explore its purpose and use cases, and demonstrate its functionality in a free and open monitoring platform
Speakers
avatar for Matthew Gracie

Matthew Gracie

Senior Engineer, Security Onion Solutions
Matthew Gracie is a defensive security specialist with fifteen years of Blue Team experience in higher education, manufacturing, financial services, and healthcare. He is currently a Senior Engineer at Security Onion Solutions, as well as the interim director of the Cybersecurity... Read More →
Saturday September 12, 2026 10:30am - 10:55am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

10:30am CDT

Vulnerability Management: The Leadership Playbook
Saturday September 12, 2026 10:30am - 10:55am CDT
Most vulnerability programs keep teams busy without reducing risk. Mean-time-to-remediate improves quarter over quarter while the total count of unpatched vulnerabilities climbs. The program optimizes a local maximum: patching speed. This talk presents four strategies for escaping the cycle, and the leadership behaviors each strategy requires.
Strategy 1: Shrink what needs protecting. Every decommissioned environment, consolidated tool, and disabled stale account is one less thing to scan, patch, monitor, or defend. Specific targets exist in every organization: SaaS products nobody canceled after a pilot, test environments that outlived their projects, overlapping tools acquired through inertia. Zero-based security budgeting surfaces surprising candidates for elimination and reframes security from cost center to cost-reduction partner. But decommissioning requires a shared source of truth. When security counts 200 SaaS applications, finance tracks 100 with purchase orders, and IT lists 50 in systems management tools, conversations stall. Building that shared reality across departments is the prerequisite for any attack surface reduction initiative.
Strategy 2: Look beyond scanning. Scanners miss configuration drift, exposed APIs, shadow infrastructure, and short-lived cloud resources that disappear between scan cycles. Pairing vulnerability scanners with endpoint agents, cloud security posture tools, systems management software, and identity providers gives a more accurate picture of what needs attention. This section also challenges the attackers only need to be right once myth. Map it against MITRE ATT&CK: attackers must succeed at reconnaissance, initial access, persistence, lateral movement, and exfiltration. Every stage, sequentially. Defenders disrupt one step. Architectural choke points like SSO create disproportionate defensive returns. Terrain knowledge compounds over time and is impossible for an external attacker to replicate.
Strategy 3: Prioritize with context. Base CVSS scores assume worst-case conditions and mislead patching teams. Combining exploitability data such as EPSS scores and CISA's KEV catalog with environment specifics, including network exposure, compensating controls, and data sensitivity, produces rankings that reflect actual risk. A CVSS 6.5 on an internet-facing authentication server often deserves faster action than a CVSS 9.0 on an isolated test box. When patching teams see priorities grounded in their reality, they trust the process and act on it. The job of a security leader is not to maximize security but to calibrate acceptable insecurity through criteria a business colleague would understand.
Strategy 4: Apply pressure without alienating the teams who do the work. Patching teams are measured on delivery velocity, not vulnerability metrics. Earning a seat in their planning sessions starts with understanding their constraints and what they are trying to ship this quarter. Allies often sit outside security and IT: General Counsel cares about legal exposure, product management about customer trust, finance about cost reduction. Frame requests in terms of their objectives, not your risk scores. If your assessment doesn't change the state of the organization, it hasn't reduced risk.
The talk closes with metrics that measure program health rather than activity, guidance on communicating vulnerability management to boards and executives, and five diagnostic questions attendees take home to assess whether their program is reducing risk or producing reports.
Speakers
avatar for Lenny Zeltser

Lenny Zeltser

Faculty Fellow, SANS Institute
Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. He has built security products and programs from early stage to enterprise scale. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a... Read More →
Saturday September 12, 2026 10:30am - 10:55am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

11:00am CDT

Purple Testing Is Not Enough — Why CTEM Is the Missing Layer
Saturday September 12, 2026 11:00am - 11:25am CDT
Session Description (Abstract)
Purple testing is powerful.
It helps us validate detections, simulate attacker behavior, and expose where our defenses break. It gives us truth about our controls.
But there’s a problem.
Most teams stop at validation.
We test.
 We validate.
 We generate findings.
And then… we move on.
The same gaps show up again later—not because we didn’t find them, but because we didn’t ensure they were actually fixed. Over time, this creates what I call “validation theater”—a cycle where teams continuously prove weaknesses without reducing real exposure.
From an attacker’s perspective, that’s not a weakness.
 It’s reliability.
This talk focuses on closing that gap.
Drawing from 12 years of incident response experience and 6 years running continuous validation programs, I’ll show how to move from “we tested it” to “we fixed it—and proved it stays fixed.”
We’ll break down where purple testing delivers value—and where it falls short—and introduce Continuous Threat Exposure Management (CTEM) as the missing operational layer that connects validation to ownership, prioritization, and remediation.
Attendees will learn how to operationalize a practical CTEM loop:
 Scoping → Discovery → Prioritization → Validation → Mobilization
And more importantly, how to:
  • Assign clear ownership across teams
  • Prioritize remediation based on real risk
  • Build a repeatable process for closing gaps
  • Measure whether exposure is actually decreasing over time
This session is designed for blue team practitioners, detection engineers, and security leaders who want a practical, actionable approach to improving security effectiveness.
Because testing is not protection.
 Detection is not protection.
 Closure is.
It’s about building a repeatable system that ensures what you find… actually gets fixed.
Because if the same gaps keep coming back—so will attackers.
 
Speakers
avatar for Irina Dimitrov (Loktionova)

Irina Dimitrov (Loktionova)

Irina Dimitrov (Loktionova) is a cybersecurity professional with over a decade of hands-on experience in incident response and security operations. For 12 years, she worked on the front lines, responding to real-world attacks and seeing firsthand where security controls succeed—and... Read More →
Saturday September 12, 2026 11:00am - 11:25am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

11:00am CDT

Too Big to Review: Scaling AppSec to Zero at Fortune #1
Saturday September 12, 2026 11:00am - 11:25am CDT
As AI-powered development tools accelerate code velocity across the industry, application security programs face an existential scaling problem: the team that was once a trusted partner to engineering has become a bottleneck. Traditional human-led security review cannot keep pace with the rate of new features, services, and infrastructure being shipped; and bolting AI onto a broken process only makes it fail faster.


This talk presents a proven layered framework for scaling application security programs without proportionally scaling the security team, drawn from direct experience building and running the SHINE (Security Hub of Innovation and Efficiency) program at AWS. The framework moves through three progressive layers: Golden Paths that eliminate entire risk categories before review through secure-by-default infrastructure; Deterministic Automation that encodes repeated security decisions into binary, scalable rules; and Agentic Investigation where AI systems assemble complete application context and make judgment calls on genuinely novel problems.


In practice, this architecture reduced security review time by 30% through deterministic automation, drove 90%+ adoption rates of new applications onto secure-by-default infrastructure via CDK property injection, and enabled an Agentic Security Engineer capable of context-aware decisions that previously required senior human involvement.


In today's AI-driven world, the instinct is to reach for a model. But that instinct is wrong when applied too early: AI is not a fix for a broken foundation - it amplifies whatever is already there. Teams missing stability at the foundational layers will find that AI makes the chaos faster, not better. This talk provides a concrete, implementation-grounded roadmap for building the foundation that makes automation and eventually agentic AI actually work.
Speakers
avatar for Adam Schaal

Adam Schaal

Distinguished Engineer, AI Security, Pixee AI
Adam Schaal is a Distinguished Engineer at Pixee, where he focuses on using generative AI and automation to meaningfully change how application security is practiced at scale.
Previously, Adam created and led the SHINE team at AWS, a group tasked with rethinking how security could scale across massive development organizations without slowing builders down. Through experimentation, automation, and hands-on engineering, SHINE explored new approaches to aligning... Read More →
Saturday September 12, 2026 11:00am - 11:25am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

11:00am CDT

How We've Gone Completely Phishing-resistant (And So Can You!)
Saturday September 12, 2026 11:00am - 11:50am CDT
Phishing-resistant authentication is shifting from optional to mandatory. Not only are attackers using phishing as the primary mechanism to evade traditional forms of MFA, but they are also evolving their attacks to find ways around implementations where phishing-resistant auth is only preferred and not enforced. The road to deploying passkeys, Windows Hello for Business and Mac Platform SSO looks easy enough in the Microsoft docs, but what does it look like to implement them as mandatory across a workforce?

In this session we’ll cover how we went from a handful of FIDO2 keys to phishing-resistant authentication across our enterprise in Entra ID at breakneck speeds. We’ll explore the ins-and-outs from a technical and organizational perspective of the implementation, the gotchas we hit along the way, and how we overcame them. We’ll cover edge case scenarios, and how deploying passkeys is just part of the bigger equation to going phishing-resistant. We’ll also examine phishing attack trends we were seeing, which helped inform and shape policy so that phishing-resistant authentication isn’t an option – it’s the only option.
Speakers
avatar for Eric Woodruff

Eric Woodruff

Chief Identity Architect, Semperis
Throughout his 26-year career in the IT field, Eric has sought out and held a diverse range of roles. Currently the Chief Identity Architect for Semperis; Eric previously was a member of the Security Research and Product teams. Prior to Semperis, Eric worked as a Security and Identity... Read More →
Saturday September 12, 2026 11:00am - 11:50am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

11:00am CDT

Swag Booth Open
Saturday September 12, 2026 11:00am - 4:00pm CDT

Saturday September 12, 2026 11:00am - 4:00pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

11:30am CDT

Detection Engineering for AI Agents: Building Defenses That Work When Your Attacker Can Think
Saturday September 12, 2026 11:30am - 11:55am CDT
The bot detection playbook defenders have relied on for years — IP blocklists, rate limits, behavioral baselines, CAPTCHA — was built for a threat that no longer exists. Modern adversaries are deploying LLM-powered agents that reason, adapt, and evolve their behavior in response to detection. For defenders, this means the threat model has fundamentally changed.   This talk, drawn from production experience building bot mitigation systems at Amazon, provides blue teamers with a practical framework for detection engineering against agentic AI attackers. The session covers: how to identify the behavioral signatures of LLM-driven agents (and why they're different from both humans and traditional bots); detection signal categories that remain robust against adaptive adversaries; pipeline architecture for high-velocity threat detection at scale; and incident response workflows when an AI-powered attacker is actively evading your controls.   Critically, this talk addresses the strategic challenge defenders face: in an adversarial ML environment, your model is always at risk of being reverse-engineered and evaded. How do you build detection systems that are robust to an adversary who can iterate as fast as you can? Attendees will leave with detection engineering patterns they can apply to bot defense, fraud prevention, and automated threat response — and a realistic understanding of where current defenses still have gaps.
Speakers
avatar for Shashwat Jain

Shashwat Jain

Sr. Software Development Engineer, Amazon
Shashwat Jain is a Senior Software Development Engineer at Amazon, where he architects and deploys AI-powered bot mitigation systems protecting Amazon's global e-commerce platforms from sophisticated automated threats. With expertise spanning real-time behavioral detection engines... Read More →
Saturday September 12, 2026 11:30am - 11:55am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

11:30am CDT

Threat Intelligence at the Speed of Cyber Defense
Saturday September 12, 2026 11:30am - 11:55am CDT
Cyber threat intelligence (CTI) is essentially a decision support function within cybersecurity. As such, CTI that cannot enable, improve, or otherwise facilitate a security action is of questionable value. This is often evaluated in terms of CTI relevance, applicability, or accuracy, but the relationship between CTI and security actions also demands investigation of another metric: timeliness. CTI that arrives too late for the supported decisions is functionally irrelevant.


In this discussion we will explore the implications of a time-oriented view for CTI production, dissemination, and integration into operationally-focused decision making. From this we will identify a key tension at the core of CTI analysis and production: that the SPEED at which CTI is produced and disseminated is often in conflict with the QUALITY or DEPTH of the produced CTI. Organizations cannot have immediate decision support on tactically-relevant timescales while simultaneously having deep context in the current environment. As a result, tradeoffs are necessary to both recognize and navigate in developing a relevant CTI function. Furthermore, evaluating CTI becomes a question of determining audience and customer needs, purpose, and response timelines to appropriately structure CTI support for the entity or specific decision maker in question.


To conclude this discussion, we will examine the possibility of eliminating (or at least reducing) this dilemma through technical means. Particularly future progress in the field of artificial intelligence may allow CTI functions to tap into mechanisms where context or detail and timeliness are no longer in direct conflict with one another, mapping out an effective and meaningful way for AI to support CTI and broader security functions.
Speakers
avatar for Joe Slowik

Joe Slowik

Director, Cybersecurity Alerting Strategy, Dataminr
Joe Slowik has over 15 years of experience across multiple cyber domains, from threat intelligence to detection engineering to incident response. Joe currently works as director for cyber alerting strategy at Dataminr, and has previously held roles at organizations including the MITRE... Read More →
Saturday September 12, 2026 11:30am - 11:55am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk, Talk Track 3

12:00pm CDT

Same Network, Different Worlds: Bridging the IT Ops and SOC Divide
Saturday September 12, 2026 12:00pm - 12:25pm CDT
A temporary service account with Domain Admin rights gets created at 11 PM to patch a legacy application. The sysadmin logs off and forgets about it. The SOC sees the account creation, flags it as authorized admin activity, and moves on. Three weeks later, that account becomes an attacker's persistence mechanism. Nobody did anything wrong. And that is exactly the problem.
IT operations and security teams share the same network but operate in fundamentally different worlds. Sysadmins speak the language of uptime, change windows, and ticket queues. SOC analysts speak the language of alerts, TTPs, and kill chains. Both teams assume the other has visibility into what is happening, and both teams are wrong. The result is a gap that does not show up in any audit report but lives quietly in every environment: misattributed alerts, forgotten service accounts, unclaimed security tasks, and legitimate admin activity that looks completely indistinguishable from an attacker who already knows your environment inside and out.
Most organizations try to solve this with better documentation, cleaner org charts, and the occasional cross team meeting. It does not work. The gap is not a process problem. It is a knowledge problem. Security analysts often do not know enough about how systems are actually administered day to day to separate noise from signal. Sysadmins often have no idea how their routine tasks appear inside a SIEM and have even less awareness of the quiet risk they are generating while doing everything by the book.
This session is built on a premise that is easy to understand but rarely acted on: the person best positioned to bridge that gap is someone who has stood on both sides of it. Drawing from hands on experience managing and securing environments across multiple client organizations at an MSSP, this talk translates the operational realities of IT administration into the detection focused language of the SOC and does the same in reverse. No theory. No vendor pitch. Just an honest look at how two teams who are supposed to be working together keep accidentally working against each other.
Attendees will work through real world scenarios that are very common between companies and industries. They will experience each scenario from the IT ops side and the SOC side to understand what happens. The audience will leave with a practical communication framework they can bring back to their organization before the next incident forces the conversation anyway. 
Whether there is a junior analyst trying understand the authenticity of alerts or a systems engineer who has never thought of how routine tasks look like from a SOC lens, this session will be inclusive of all.
Speakers
avatar for Sameer Singhal

Sameer Singhal

System Engineer II, EXOS
Sameer bridges the critical gap between infrastructure engineering and security operations. He holds a bachelor's degree in Cybersecurity from Purdue University and is currently a Systems Engineer II working his way towards a Cybersecurity Analyst I position at an MSSP, where he supports... Read More →
Saturday September 12, 2026 12:00pm - 12:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

12:00pm CDT

Secrets That Survive Everything: The Shift-Right Runtime Gap Left Unguarded
Saturday September 12, 2026 12:00pm - 12:25pm CDT
A bug bounty researcher found Azure credentials in a JavaScript file and 
marked the report informational. The credentials were live production values -
four Azure AD fields sitting in a public JS bundle, enough to authenticate as 
the application itself. The frontend had documented its own backend. Full 
account takeover. The application's token had been granted the ability to 
perform user-level operations, every account in the system was reachable. 
The organization had GitLeaks in CI/CD and static secret scanning on pull 
requests. The credentials were still live.


That was one chain. A second application used CryptoJS to encrypt its 
configuration, a common pattern in SPAs where developers believe encrypting 
the config protects it. The decryption key was hardcoded in the same 
JavaScript file, three lines away from the encrypted blob. The secret to 
unlock everything was sitting next to the lock. Same credential pattern at 
the end. Same result.


Shift-left tools scan what you commit. They do not scan what you serve. 
Build-time environment injection bakes live keys into webpack bundles that 
never touch the repository. CI/CD pipeline variable substitution materializes 
secrets only in the build artifact, after every scanner has run. SSR state 
blobs injected by Next.js and Nuxt carry credentials into HTML that no 
pre-deployment scanner ever sees. Once a secret reaches production, it 
disappears from every scanner's view. Sometimes that disappearance is 
engineered, developers suppress scanner alerts on credentials the application 
genuinely requires, trading automated monitoring for a green pipeline. The 
only things finding runtime secrets are manual penetration testers, bug bounty 
researchers, and attackers. Two of those three report what they find.


This talk walks through both exploitation chains in detail, maps the full 
shift-right gap in the security tooling landscape, and closes with a live 
demo using a purpose-built intentionally vulnerable healthcare portal, a 
HIPAA-branded application exposing Twilio, SendGrid, Stripe, and Firebase 
credentials in its public JavaScript files, and leaking internal service keys 
in response headers on every single request.


The demo uses SecretSifter, a free Burp extension, browser tool, and desktop 
app built for the runtime layer to find every secret passively, without 
configuration, as traffic flows.


Security teams leave with a clear picture of where their shift-left controls 
stop, a taxonomy of the six exposure mechanisms that bypass them, and a free 
tool they can deploy against their own applications the same day.


Speakers
avatar for Hemanth Gorijala

Hemanth Gorijala

Global Penetration Testing Lead
Hemanth Gorijala is a security researcher and Global Pentest Lead at a Fortune 100 financial services company, where he leads application security assessments and reviews vulnerability reports in enterprise bug bounty programs. His work focuses on the runtime credential gap: the space... Read More →
Saturday September 12, 2026 12:00pm - 12:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

12:00pm CDT

Breaking Identity at Scale: From DPAPI & TBAL Secrets to Full Domain Compromise
Saturday September 12, 2026 12:00pm - 12:50pm CDT
Modern enterprise environments continue to rely on implicit trust within identity and credential protection mechanisms such as DPAPI, DPAPI-NG, and token-based authentication layers. While these technologies are designed to safeguard secrets, they also introduce powerful attack surfaces when combined with misconfigurations, weak privilege boundaries, and overlooked trust relationships.


This session presents a deep technical exploration of how attackers extract and abuse protected credentials at scale, moving from local access to full domain compromise. We demonstrate novel techniques for decrypting DPAPI-protected data, abusing TBAL-related key material, and chaining these with authentication protocol weaknesses such as NTLM and Kerberos to achieve lateral movement and privilege escalation.


Unlike traditional approaches that focus on single techniques, this research connects multiple layers of identity abuse into a cohesive attack path observed in real-world environments. Attendees will see how seemingly isolated weaknesses: credential storage, token handling, and protocol trust, combine into high-impact attack chains.


The session also provides defensive strategies, including detection opportunities, hardening approaches, and architectural changes to reduce reliance on implicit trust. The goal is to shift defenders from reactive detection to proactive identity security design.
Speakers
avatar for Paula Januszkiewicz

Paula Januszkiewicz

CEO and Founder, Cybersecurity Expert, CQURE
Paula Januszkiewicz is the Founder and CEO of CQURE and CQURE Academy, globally recognized organizations delivering cutting-edge cybersecurity consulting and advanced training since 2008. She is an Enterprise Security MVP, Microsoft Regional Director, and one of the world’s leading... Read More →
Saturday September 12, 2026 12:00pm - 12:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

12:30pm CDT

MDR: From Vendor Shortlist to Security Partnership
Saturday September 12, 2026 12:30pm - 12:55pm CDT
In a saturated market, how can CISOs move past monitoring volume to evaluate Managed Detection and Response (MDR) providers based on their true ability to reduce exposure and drive proactive risk reduction?


How do you build a practical evaluation framework that balances technical visibility and response capability with commercial clarity and long-term consolidation potential?


What does is the difference between a provider that wins a contract, and a partner that actually strengthens resilience before, during, and after a crisis?
Speakers
avatar for Alan Simpson

Alan Simpson

Field CISO, Rapid7
Alan Simpson is Field CISO for the UK and Ireland at Rapid7, advising CISOs and senior leaders on cyber risk, resilience, and security strategy that supports business outcomes. Before joining Rapid7, he served as Global Security Operations Manager and Acting CISO at Keyloop, where... Read More →
Saturday September 12, 2026 12:30pm - 12:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

12:30pm CDT

Your User, Their Rules: Rethinking the OS trust model for the AI-era
Saturday September 12, 2026 12:30pm - 12:55pm CDT
Operating systems solved multi-user security decades ago: files have owners, permissions enforce boundaries, and one user's processes cannot tamper with another's data. But modern developer workstations are effectively single-user machines — and every process running as that user inherits the same trust. For years, this was a footnote. Today, it is the attack surface.


The explosion of AI-powered developer tools — IDE agents, MCP servers, lifecycle hooks, autonomous coding assistants — has turned local configuration files into high-leverage control planes. These tools store security-critical state (working directories, cluster credentials, session metadata, agent memory) in files and act on them without integrity validation due to assumed trust. The OS says "same user, same trust." The AI tool says "if it's in my config, I'll execute it." The result: any process running in the user's context — a compromised npm package, a malicious browser extension, a rogue VS Code plugin — can cause havoc: silently hijack an AI agent's behavior, redirect kubectl to an attacker-controlled server, or trigger recursive deletion of arbitrary directories to name a few.


In this talk, we present a systematic analysis of this trust gap through three original vulnerability disclosures across Docker Desktop, Lens Desktop, and Claude Desktop. In each case, the attack requires no privilege escalation, no kernel exploits, and no user credentials — only the ability to write to a JSON file that the OS considers perfectly authorized. We use these as case studies to examine a broader architectural problem: the classic OS segregation model was built for a world where "same user" meant "same human." In the age of AI agents, MCP servers, and autonomous tools, "same user" now means "same human plus every autonomous process acting on their behalf" — and processes don't necessarily verify whether the others are trustworthy.


We will dissect why this pattern keeps recurring (electron-store defaults, the absence of application-level integrity checks, the gap between OS-level and application-level trust), propose a threat model for "intra-user trust boundaries," and provide concrete detection and hardening strategies for security teams who need to defend developer endpoints where the OS permission model is necessary but no longer sufficient.


Speakers
avatar for Ofir Balassiano

Ofir Balassiano

Co-Founder, Bloom Security
Ofir is an experienced security researcher turned co-founder at Bloom Security. Led the Cortex Cloud Posture Security research group at Palo Alto Networks, focusing on AI, identity, and data security. Previously led the research group at Dig Security (acquired by PANW), served as... Read More →
avatar for Golan Myers

Golan Myers

Security Researcher, Bloom Security
Golan is a security researcher at Bloom Security, with previous experience as a researcher within the Cortex Cloud Posture Security research group at Palo Alto Networks, focusing on AI, identity, and data security.
Saturday September 12, 2026 12:30pm - 12:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

1:00pm CDT

AI Failures in IR: A Field Guide to Filling the Gaps
Saturday September 12, 2026 1:00pm - 1:25pm CDT
Every security vendor is shipping AI. Every IR team is under pressure to adopt it. And in the middle of a real incident, the gap between what AI promises and what it actually delivers becomes very concrete, very fast.


This talk is a field guide to that gap. Drawing on experience as an incident responder on T-Mobile's CIRT during Salt Typhoon and on the builder side developing AI tooling for IR, I'll walk through the specific ways AI underperforms when a breach is unfolding — hallucinated IOCs and timestamps, confident wrong answers, first-hypothesis lock-in, bias toward threat explanations over innocuous ones, lost evidence chains, context windows that collapse on real forensic data, and agents that can take down your SIEM because nobody throttled them.


For each failure mode, we'll cover why it happens, how to recognize it in tools you're evaluating or already running, and what mitigations actually hold up under incident pressure. Attendees will leave with a taxonomy of AI failure modes in IR, a set of sharp questions to ask any vendor (or internal build team) claiming to solve them, recommendations for how to solve them, and a clearer picture of how AI can augment responders versus where it quietly creates new risks.
Speakers
avatar for Alex Thomson

Alex Thomson

Incident Response Specialist, Spacewalk.ai
Alex has over 30 years of professional experience in cybersecurity, including building and leading SOCs and other secops teams. Most recently, he served on T-Mobile's CIRT — including during the Salt Typhoon intrusion — before joining Spacewalk, where for the past 1.5 years he's... Read More →
Saturday September 12, 2026 1:00pm - 1:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

1:00pm CDT

Game of Cones: Why Your Crisis Plan Shouldnt Melt Under Pressure
Saturday September 12, 2026 1:00pm - 1:25pm CDT
Your incident response playbook is sitting on a server. The server just got encrypted. Now what?


Most organizations invest heavily in plans they never actually test: polished documentation, detailed runbooks, maybe a shiny new SIEM. Then a real crisis hits. Ransomware. A breach notification deadline. A regulator on line one and a journalist on line two. And everyone discovers, at the worst possible moment, that having a plan and having a practiced plan are two very different things.


This session draws on 18+ years of crisis management consulting across financial services, healthcare, and critical infrastructure — and a parallel career as a court-qualified expert witness in cybersecurity matters — to make one foundational argument: you cannot exercise your way to readiness during a crisis. You have to earn it before one arrives.


We'll start by untangling two exercise types that organizations routinely conflate. Technical Tabletop Exercises are built for your engineers and incident responders: deep, system-specific scenarios that evolve with each inject, stress-testing malware analysis, containment decisions, forensic timelines, and recovery procedures. Crisis Management Exercises are built for the people making the ransom pay/no-pay call at 2 a.m., fielding questions from the board, and deciding what to tell regulators before the mandatory notification window closes. Both matter. They serve different audiences, surface different gaps, and fail in different ways when neglected.


From there, we get practical. Using concrete inject examples drawn from real engagements, we'll examine what a realistic inject sequence actually looks like, how scenarios should evolve under pressure, and how to design exercises that surface real gaps rather than validate comfortable assumptions. We'll walk through common failure patterns: the outdated playbook nobody printed, the escalation path that dead-ends at a person who left the company, the executive team that spent the first 45 minutes of a simulated breach trying to figure out who was supposed to be talking to legal.


We'll also cover the human dimension that most exercise frameworks undercount: trust. You cannot know whether the person next to you will stay calm under real pressure until you've watched them handle simulated pressure. Exercises make your colleagues' behavior predictable. That predictability: knowing who steps up, who freezes, who asks the right questions, is what separates a coordinated response from organized chaos.


Attendees will leave with a practical framework for designing and running exercises that actually move the needle, a clear model for separating leadership-track and technical-track scenarios, and concrete guidance on building post-exercise debrief processes that drive iteration rather than just generating a report nobody reads.


One durable truth ties it all together: the calmest person in the room on the worst day of the organization's life didn't get there by accident. They practiced.


So should you.
Speakers
avatar for Richard Suls

Richard Suls

US Lead, Advisory Consulting, Reversec
Richard Suls is US Lead for Security Advisory Consulting at Reversec Consulting, where he designs and delivers crisis management exercises and technical tabletops for major financial institutions, healthcare organizations, and critical infrastructure operators. He brings 18+ years... Read More →
Saturday September 12, 2026 1:00pm - 1:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

1:00pm CDT

Defending the Hypervisor: Using Offensive Tooling to Validate vSphere Security
Saturday September 12, 2026 1:00pm - 1:50pm CDT
VMWare (Broadcom) represents the most commonly used enterprise Hypervisors.  This means a compromised vCenter or ESXi host gives attackers access to every virtual machine and credential in your my environment. Defenders often lack visibility into what a post-exploitation attack against the hypervisor layer looks like. So, I built a tool to find out.
  In this session, I'll walk through the real-world attack chains that threat actors use against VMware vSphere environments: extracting Kerberos keytabs and credential caches from ESXi  hosts, decrypting stored VPX database passwords to pivot across every managed host, dumping JVM heap memory from vCenter to harvest SAML tokens, and forging certificates using stolen VMCA private keys. These are the techniques behind campaigns and APT operations targeting virtualization infrastructure today.
The core of this talk is a live demo of VEXED (vSphere EXploitation Extraction and Detection), an open-source tool I developed to automate these attack chains against vCenter and ESXi. Starting from a single SSH session, I'll show how VEXED chains credential extraction through VPX password decryption to automatically pivot across an entire vSphere cluster — mirroring the lateral movement patterns we as defenders need to detect and prevent.
But I didn't build this as a red team tool. I built it to answer a blue team question: what should I be looking for? For each attack chain I demonstrate, I'll map the corresponding detection opportunities: what logs are generated, what telemetry to forward to your SIEM, and what hardening controls actually break the chain. I'll cover VEXED's built-in hardening audit module, which checks over 20 security configurations across ESXi and vCenter, giving you a repeatable way to validate vSphere security posture. I'll also walk through the interactive attack graph output that visualizes the relationships between compromised credentials, certificates, and pivot paths… something I've found quite useful when communicating to leadership.
 Attendees will leave with:
  - A clear understanding of the most critical vSphere post-exploitation attack chains and how to detect them
  - Practical SIEM detection logic for credential extraction, memory dumping, and lateral movement across vSphere infrastructure
  - A hardening checklist validated against real attack tooling, not just vendor best practices
  - An open-source tool you can run in your own lab to validate defenses before an attacker does
 
  This session is for SOC analysts, infrastructure security teams, and anyone responsible for defending virtualized environments. No prior vSphere security experience is required. Just a desire to understand what happens when the hypervisor layer is compromised and how to stop it.
Speakers
avatar for Darryl Baker (DFIRDeferred)

Darryl Baker (DFIRDeferred)

Senior Staff Security Researcher, Netwrix
Darryl Baker is a Senior Staff Security Researcher at Netwrix, where he focuses on identity security and emerging attack techniques targeting enterprise authentication systems. With a background spanning security research, consulting, and adversary simulation, he specializes in uncovering... Read More →
Saturday September 12, 2026 1:00pm - 1:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

1:30pm CDT

email.telemetry.normalized: Detection Engineering Beyond the Inbox in Healthcare
Saturday September 12, 2026 1:30pm - 1:55pm CDT
Email continues to be the most common initial access vector in healthcare environments, yet many organizations still rely primarily on email security gateways for detection and protection. While gateways provide an important first layer of defense, they often create visibility gaps once messages reach user inboxes. Attackers routinely exploit these gaps through techniques such as executive impersonation, credential harvesting, and business email compromise (BEC).


This session explores how extending email security beyond the inbox can significantly improve detection and response capabilities in healthcare environments. Based on real-world operational experience, the talk focuses on integrating third-party email security telemetry into a centralized SIEM using custom connectors and normalized log pipelines. By ingesting and analyzing this telemetry alongside other security signals, defenders gain deeper visibility into attacker behavior that may otherwise go unnoticed.


Healthcare environments present unique challenges compared to other industries. Clinical workflows, external vendor communication, patient interactions, and regulatory requirements often limit how aggressively organizations can block or restrict email activity. These constraints create opportunities for attackers who understand how healthcare communication patterns differ from traditional enterprise environments. This talk highlights several real-world attack scenarios observed in healthcare networks, including executive impersonation attempts targeting leadership staff and phishing campaigns leveraging newly registered domains or fake authentication portals.


Attendees will see how detection engineering techniques can be applied to email telemetry once it is normalized within a SIEM. Instead of relying solely on static gateway signatures, defenders can build behavioral detections based on patterns such as suspicious sender reputation, missing email authentication controls (DMARC, DKIM, SPF), domain anomalies, and abnormal message characteristics. Lightweight Sigma-style logic will be used to illustrate how these detection patterns can be implemented in a platform-agnostic way.


Beyond detection, the session will also demonstrate how SOAR workflows integrated with SIEM detections can automate investigation and response actions. Automated enrichment, alert triage, domain blocking, and credential reset workflows can significantly reduce analyst fatigue while improving response speed and consistency in high-volume healthcare environments.


This talk is grounded entirely in real-world incidents and production security operations rather than theoretical frameworks or vendor marketing. The goal is to provide practical guidance on how healthcare defenders can implement a defense-in-depth strategy for email security by combining gateway protections, SIEM-based detection engineering, and automated response workflows.


Attendees will leave with actionable ideas for improving email visibility, building stronger detection logic, and operationalizing email telemetry to better defend healthcare environments against modern phishing and impersonation attacks.
Speakers
avatar for Akash Parasumanna Sridhar

Akash Parasumanna Sridhar

Security Engineer, Campbell Clinic
Akash Parasumanna Sridhar is a cybersecurity professional working in healthcare environments, specializing in detection engineering, incident response, and security automation. He has hands-on experience designing SIEM-driven detections, integrating third-party security telemetry... Read More →
Saturday September 12, 2026 1:30pm - 1:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

1:30pm CDT

Life After Tier 1: Rebuilding the SOC When Triage Is Outsourced
Saturday September 12, 2026 1:30pm - 1:55pm CDT
For many medium-sized enterprises, outsourcing Tier 1 triage to an MSSP is positioned to reduce workload, provide 24/7 coverage, and improve efficiency. In practice, it fundamentally reshapes how a SOC operates—and introduces new challenges that many teams are unprepared for.


Outsourcing Tier 1 doesn’t eliminate work—it redistributes it in ways most SOCs are not designed to handle.


This talk examines what happens after Tier 1 is removed. Organizations place significant trust in third-party providers, yet alert volume may decrease while investigation complexity increases. Context is often lost at handoff boundaries, and traditional metrics lose meaning, while new measures—such as mean time to confirm and escalation quality—become critical for understanding performance. Teams that fail to adapt quickly often find themselves with fewer alerts, but greater uncertainty and slower response.


Operational gaps also emerge when systems do not align with MSSP onboarding models. Custom telemetry sources, delayed parser development, and the gap between deployment and monitoring readiness introduce risk that must be actively managed.


Drawing on real-world experience leading a SOC through this transition, this session focuses on how to redesign operations for a post–Tier 1 model. We will explore how analyst roles must evolve from queue processors to investigators, why detection fidelity becomes the most important metric, and how to build feedback loops that continuously improve detection quality.


Attendees will leave with a practical framework for restructuring workflows, redefining success metrics, and improving detection precision.
This talk is designed for SOC leaders, detection engineers, and analysts navigating MSSP integration or considering outsourcing triage functions and aligns with both the Management/Leadership and Security Operations tracks.
Speakers
avatar for Stuart Fairchild

Stuart Fairchild

Senior Manager, Cybersecurity, C Spire
Stuart Fairchild is a Senior Manager of Cybersecurity at a regional telecommunications provider, where responsibilities include leading security monitoring, incident response, and security awareness programs supporting infrastructure for over one million customers. Work focuses on improving detection... Read More →
Saturday September 12, 2026 1:30pm - 1:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk, Talk Track 2

2:00pm CDT

Learning How to Pop Champagne Bottles: How Leaders Should Reframe Cyber Wins and Losses
Saturday September 12, 2026 2:00pm - 2:25pm CDT
Moments after the Oklahoma City Thunder won their first Championship, the team had a problem.   None of the team’s young stars knew how to open a champagne bottle.  Normally, after winning, we would see videos of players popping champagne bottles and celebrating.  But the Thunder needed a little help, and backup guard Alex Caruso, who won an NBA championship in 2020, had to teach his teammates how to celebrate. In the world of cybersecurity, it often feels like you are always down 17 points chasing to catch up with new threats and vulnerabilities.  But every day, employees are successful in making the right cybersecurity decisions.   According to Harvard Business Review, we should be celebrating these small wins because they create “momentum that will propel you toward your bigger goals." Likewise, every cyber crisis contains both the seeds of success and the roots of failure. This presentation will explore how leaders should reframe their companies' views of success and failure to make their organizations safer.  By first exploring current cybersecurity trends. Next, we will discuss the importance of small wins and the challenges that success can pose for organizations.   Then we will examine the lessons from failure and how failure is the first step for growth.  Finally, the presentation will provide ways for leaders to reframe how they view success and failure and how embracing both can help their teams secure a championship. 
Speakers
avatar for Anthony Hendricks

Anthony Hendricks

Director and Chair of Cybersecurity, Crowe & Dunlevy
Anthony Hendricks is a legal problem solver and litigator at Crowe & Dunlevy, one of Oklahoma’s largest and oldest firms. At Crowe & Dunlevy, Anthony serves as founder and chair of the firm’s Cybersecurity and Data Privacy Practice Group. His legal practice focuses on data privacy... Read More →
Saturday September 12, 2026 2:00pm - 2:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

2:00pm CDT

Teaching AI to Analyze Malware: How to Encode Practitioner Expertise into an MCP Server
Saturday September 12, 2026 2:00pm - 2:25pm CDT
AI agents can reason about suspicious files, plan multi-step investigations, and write custom deobfuscation code when standard tools fall short. But generic models produce shallow, unreliable results because they lack practitioner knowledge about which tools to use and when, and access to the tools themselves.
Without domain expertise, an AI agent doesn't know that, for example, capa exit codes follow non-standard conventions, that YARA match counts require context to interpret, or that GetProcAddress appears in virtually every Windows program and is not inherently suspicious. Without tool access, it can only comment on malware but cannot investigate it.
This talk walks through my experience of building an open source MCP server, a standardized interface that connects AI agents to external tools, that bridges both gaps simultaneously. The server connects AI agents to my open source REMnux malware analysis toolkit, encoding practitioner knowledge into tool workflow sequencing and output interpretation. The server runs analysis at three depth levels, and manages context budgets when tool output exceeds approximately reasonable values by automatically switching to summary mode while preserving key findings.
The server also counteracts confirmation bias. Generic AI agents tend to label every API call as suspicious and every string as an indicator of compromise. The server's neutral framing prompts agents to consider benign explanations before concluding malicious intent. This is a critical safeguard when the AI chains dozens of tool calls without human review at each step.
Against real-world samples, the resulting system completed full investigations in about 10 minutes with 25-30 automated tool calls. In one case during my experimentation, the AI agent wrote custom Python to reconstruct a PE from file fragments. In another, it reverse-engineered a proprietary archive format and adapted when initial analysis approaches failed.
The talk covers what worked, what failed, and what surprised me. It addresses the security model required when AI agents have tool access, including prompt injection risks from malicious content in analyzed samples, container isolation as the primary security boundary, and data flow considerations.
Attendees leave with a reproducible pattern for encoding domain expertise into MCP servers, applicable to incident response, cloud forensics, network analysis, or any domain with specialized tools and practitioner workflows.
Speakers
avatar for Lenny Zeltser

Lenny Zeltser

Faculty Fellow, SANS Institute
Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. He has built security products and programs from early stage to enterprise scale. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a... Read More →
Saturday September 12, 2026 2:00pm - 2:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

2:00pm CDT

The Second Front: Detecting LOTL Off the Endpoint
Saturday September 12, 2026 2:00pm - 2:50pm CDT
Living-off-the-land (LOTL) isn't what it used to be. Blue teams have spent years tuning detections for the classic playbook - LOLBins, malicious macros, WMI abuse, PowerShell, etc. - and endpoint tooling has gotten pretty good at catching it. So, attackers moved.
LOTL is now operating across a second front: the identity and management plane, which spans hundreds (if not thousands) of SaaS apps and authorizations in an enterprise. Stolen session tokens, abused OAuth flows, device code phishing, and browser-native credential harvesting let adversaries operate entirely within sanctioned tools and legitimate traffic. 
Scattered Spider, and more recent evolutions like Scattered Lapsus$ Hunters, operate inside victim environments using legitimate SaaS APIs and identity tooling: SSO, MFA bypass via social engineering and post-auth attacks, and direct access to cloud management planes. In every case, the attackers aren’t hiding from EDR; they’re operating in the browser context where EDR doesn't see.
This “missing middle” is a structural gap: EDR owns the endpoint, and the IdP owns authentication events. But the space in between - the authenticated browser session, the OAuth token, the SaaS API call from a legitimate identity - belongs to no tool and appears on no dashboard. It’s a second front for LOTL, and most blue teams don't have a strategy for it because they don't have visibility into it.
This talk maps the evolution of LOTL techniques from endpoint to identities and SaaS, walks through the attack patterns that define the second front (AitM session hijacking, OAuth abuse, infostealer-to-IAB pipelines, MFA-resilient phishing infrastructure), and describes a practical detection framework that addresses both fronts simultaneously. We'll look at what telemetry sources actually exist for in-browser and identity-plane activity, how to build detection logic when you're pattern-matching against legitimate behavior rather than malicious binaries, and how SOC teams can prioritize coverage across two active fronts without exponentially increasing analyst workload.
Attendees will leave with a mental model for how these two LOTL fronts interact, a framework for evaluating their own detection coverage gaps, and concrete starting points for building detection programs that account for the full attack surface - not just the stuff that shows up in endpoint logs!
Speakers
avatar for Mark Orlando

Mark Orlando

Field CTO, Push Security
Mark is the Field CTO at Push Security, where he advances detection and response for in-browser threats. With 25 years of experience building and leading security operations teams at the White House, the Pentagon, the Department of Energy, and Fortune 500 companies, Mark has investigated... Read More →
Saturday September 12, 2026 2:00pm - 2:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

2:30pm CDT

CISA’s Menu for Vulnerability Management
Saturday September 12, 2026 2:30pm - 2:55pm CDT
Hungry for better cyber defense? Pull up a chair at CISA’s café, where vulnerability management is always on the menu! This talk will serve up a full tasting of best practices, international standards, and key initiatives that help organizations defend against today’s threats and enhance their cyber resilience. From tried-and-true favorites like CVE and the Known Exploited Vulnerabilities (KEV) catalog, to innovative new flavors including CSAF and OpenEoX, discover how the vulnerability management chefs at CISA lead efforts to streamline vulnerability disclosure, automate risk decisions, and overall secure U.S. critical infrastructure. Whether picking a la carte or sampling the whole menu, you will leave this talk with tasty insights and actionable recipes to boost your organization’s cyber defense posture…no reservations required!
Speakers
avatar for Justin Murphy

Justin Murphy

Cybersecurity Vulnerability Analyst, DHS/CISA
Justin Murphy is a Vulnerability Analyst with the Cybersecurity and Infrastructure Security Agency (CISA). He helps to coordinate the remediation, mitigation, and public disclosure of newly identified cybersecurity vulnerabilities in products and services with affected vendor(s... Read More →
avatar for Julia Turkevich

Julia Turkevich

Cybersecurity Vulnerability Analyst, DHS/CISA
Julia Turkevich leads CISA's stakeholder engagement activities to recruit CVE Numbering Authority (CNA) partners that are committed to proactive and responsible vulnerability disclosure. As a member CISA's Vulnerability Management subdivision, Julia works to advance maturity across... Read More →
Saturday September 12, 2026 2:30pm - 2:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

2:30pm CDT

Vibe Check: Scaling AppSec in an AI-Driven World
Saturday September 12, 2026 2:30pm - 2:55pm CDT
Scaling an AppSec program is hard enough in a traditional environment, but it gets exponentially more difficult when Sonny from Accounting decides to vibe code their own full-stack internal tool over the weekend and announces it in the company All Hands on Monday. The "Shift Left" movement promised to get in front of security breaches by thinking about security early in the development lifecycle, but AI has thrown that idea out the window. How do we shift left when teams are deploying demos in the time that it used to take to agree on basic design principles? Teams are shipping code faster than it can be reviewed and in an era when anyone who can write a mostly coherent thought can pump out an application, vibe coders are spinning up unreviewed shadow apps overnight.


The modern AppSec program has to adapt and scale without becoming a bottleneck. We have to focus on:

Automated Guardrails: Leveraging AI to secure the code that AI creates

Democratized Security: Extending AppSec to the vibe coding masses through self-service tooling.

Maintaining Quality at Speed: Using risk-based prioritization when the codebase is growing exponentially.

AppSec programs need to stop policing every line of code and start building resilient ecosystems where everyone, not just traditional software engineers, can build safely regardless of how they write their code.
Speakers
avatar for Cory Roop

Cory Roop

Security Engineering Manager, Garner Health
Cory leads the Security Engineering function at Garner Health. He’s a veteran engineer and leader who has scaled security programs for both healthcare firms and hyper-growth SaaS startups. He balances a "big picture" leadership style with a genuine love for the technical weeds of... Read More →
Saturday September 12, 2026 2:30pm - 2:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

3:00pm CDT

Beyond The Auth Artifacts: Identifying Intrusions by Correlating Identity and EDR Telemetry
Saturday September 12, 2026 3:00pm - 3:25pm CDT
In today’s landscape of sophisticated cyberattacks, EDR (Endpoint Detection and Response) is an indispensable tool, but it’s not a complete solution. We are observing a rise in sophisticated cyberattacks that are difficult to detect based solely on endpoint behavior. By initiating breaches via VPNs—which are outside the scope of EDR monitoring—and utilizing stolen credentials to blend in through LotL methods, attackers are successfully evading traditional security measures. To address these challenges, the importance of monitoring identity-based behavior generated by Active Directory (AD)—known as ID alerts—is growing by the day.


In this session, we will share the “realities” of ID alert analysis from the front lines of a managed SOC that monitors and analyzes environments comprising tens of thousands of devices—primarily for major Japanese enterprises—24 hours a day, 365 days a year. Monitoring identity-based behavior in large-scale enterprise environments is a “headache” for operators due to vast amounts of noise and a lack of context. We will introduce our initiatives for utilizing correlation analysis and threat hunting to address these ID alerts. Attendees will learn “correlation analysis logic” and “hypothesis-based hunting” using Sigma rules—techniques that can be immediately applied in SOC operations the very next day—while filtering out the noise specific to large-scale environments.
Speakers
avatar for Shogo Hayashi

Shogo Hayashi

SOC Analyst, NTT Security
Shogo Hayashi is a SOC analyst at NTT Security (Japan) KK. He has been working in cybersecurity as a member of the Blue Team for 15 years. He specializes in responding to EDR and AD detections, developing detection rules, malware analysis, and cyber threat research. He has spoken... Read More →
avatar for Teruki Yoshikawa

Teruki Yoshikawa

Security Analyst, NTT Security
Teruki Yoshikawa is a security analyst at NTT Security (Japan) KK. He is responsible for monitoring NW/EDR alerts, while also being involved in malware analysis. He is actively engaged in security research. He has spoken at JSAC, NorthSec and has co-authored several white papers... Read More →
Saturday September 12, 2026 3:00pm - 3:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

3:00pm CDT

It Started with an Employee. It Ended Inside Your AI: The Exposure Chain You Need to Understand
Saturday September 12, 2026 3:00pm - 3:25pm CDT
AI didn't just speed up reconnaissance. It connected dots that were never supposed to connect and most blue teams haven't caught up yet.
 
This talk walks through a single, end-to-end exposure chain so defenders can finally see what they're up against, and know exactly where to break it.
It starts with people. AI-powered OSINT pipelines aggregate and correlate employee data across LinkedIn, GitHub, forums, and breach databases in minutes, building behavioral profiles precise enough to generate hyper-targeted phishing lures at scale. But the exposure doesn't stop at individuals. The same reconnaissance that maps employees also maps the company: infrastructure, misconfigured services, and increasingly API endpoints leaked during LLM deployments. Production AI tools calling internal services, chatbots inadvertently surfacing internal documentation, LLM APIs left exposed during staging, these aren't edge cases, they're patterns blue teams are consistently missing.
 
From there, the path in is shorter than most teams think. Either a well-profiled employee gets phished into opening the door, or an exposed AI-connected service was never meant to be public in the first place. And once an attacker reaches an internal LLM: a security chatbot, an AI-assisted SIEM, an LLM-integrated IR tool, prompt injection becomes the final piece. Your AI doesn't know the difference between a legitimate query and a crafted instruction. Your analyst might not either.
 
We'll demonstrate each stage, then flip the lens entirely covering how defenders can map their AI exposure, harden LLM-integrated tooling, and break the chain before it completes.
 
Attendees will leave with:
  • Visibility into how AI-powered recon pivots from employees to exposed infrastructure
  • Awareness of LLM deployment patterns that unintentionally surface internal services
  • A framework for identifying prompt injection risks in security tooling
  • Actionable steps to audit and defend their AI attack surface
Speakers
avatar for Derick Johnson

Derick Johnson

Derick Johnson is a cybersecurity graduate student and practitioner specializing in the intersection of AI, large language models, and offensive security. His research focuses on two converging threats: how AI-powered tools are transforming open-source intelligence and reconnaissance... Read More →
Saturday September 12, 2026 3:00pm - 3:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

3:00pm CDT

Entra the Dragon: Entra ID Red vs Blue
Saturday September 12, 2026 3:00pm - 3:50pm CDT
Entra ID is the identity & access management system for the Microsoft cloud. Microsoft continues to add new features to Entra ID and many of these features provide attack capability. There are many moving parts and regular updates that requires attention to stay secure. This talk covers the latest attacks against the Microsoft cloud from phishing to account take-over to persistence as well as the best ways to defend against them. So go beyond Secure Score and level up your cloud security!
Speakers
avatar for Sean Metcalf

Sean Metcalf

Identity Security Architect, TrustedSec
Sean Metcalf  (@PyroTek3) is an Identity Security Architect with TrustedSec. He is one of about 100 people in the world who holds the Microsoft Certified Master Directory Services (MCM) Active Directory certification and is a former Microsoft MVP. Sean has presented on Active Directory... Read More →
Saturday September 12, 2026 3:00pm - 3:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

3:30pm CDT

Beyond the SIEM: Critical Governance and Architecture Decisions for Modern SOCs
Saturday September 12, 2026 3:30pm - 3:55pm CDT
Modern Security Operations Centers (SOCs) have evolved from basic technical hubs into essential engines for risk management. Success requires a disciplined alignment of governance, architecture, and talent to ensure every action remains resilient and defensible. This session presents a structured methodology to balance high-level technical capability with fiscal responsibility and regulatory mandates. By evaluating SOC evolution through the lens of financial and legal risk, organizations can build a function that is both highly effective and accountable to the board of directors.


We begin by discussing why governance must precede tooling to avoid embedding technical debt into the center’s foundation. This involves identifying critical assets, defining precise operational scope, and mapping risks driven by regulatory frameworks and customer contracts. Once these boundaries are set, we explore how to design a technical backbone that eliminates unnecessary complexity. We will evaluate a tiered log strategy where a security data lake handles high-volume telemetry while the primary analytics engine is reserved for real-time, high-fidelity alerting. This strategic approach prevents cost escalation while providing the depth required for advanced automated workflows.


We also address workforce modeling, demonstrating how technology choices dictate staffing requirements. By examining the mathematical rule of five, we evaluate the requirements for sustainable 24/7 coverage while preventing analyst burnout. The session concludes by reviewing how these elements create a living function that leverages automated triage and standardized playbooks to reduce manual effort by 60–80%. Attendees will learn to formalize critical escalation paths and measure performance through a trinity of operational, contractual, and compliance metrics, ultimately validating defenses through structured training to maintain a proactive, intelligence-driven posture.
Speakers
avatar for Bart Stump (Stumper)

Bart Stump (Stumper)

Managing Principal, Coalfire
Bart Stump is a Managing Principal on the Threat Discovery Services team at Coalfire with over 19 years of experience. He specializes in identifying defensive gaps through threat hunting, cyber threat intelligence, and security tool gap analysis to implement robust defensive measures. For... Read More →
avatar for Jeremy Croghan

Jeremy Croghan

Director, Coalfire
Jeremy Croghan is a seasoned cybersecurity leader and Director of Business Resiliency at Coalfire with over 20 years of experience, including U.S. Marine Corps service. He specializes in aligning the complex regulatory requirements of any industry with organizational policies to ensure... Read More →
Saturday September 12, 2026 3:30pm - 3:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

3:30pm CDT

Paving the Road for AI-Driven Security Teams
Saturday September 12, 2026 3:30pm - 3:55pm CDT
We are not a traditional SOC. Notion’s Detection and Response Team (DART) is a small group of engineers and incident responders. We build the systems our own team runs on, and we own them end to end.
AI changed how we work. Our answer has been to pave the road for agentic security work: an internal platform of harnesses, CLI tools, review steps, and guardrails that makes AI workflows predictable enough to run during a real incident, and safe enough for other security teams to build on top of.
We will cover three things:
  1. Setting up AI agents for triage and investigations in a way we actually trust
  2. The boring stuff that makes it work. Harnesses, CLI tools, and review steps so agent runs are repeatable and we can actually check what happened
  3. What that paved road unlocks, using security automations as the example. DART owns and runs the platform, so other security teams can ship new automations on top of it without having to learn the underlying infra
You’ll leave with the guardrails we actually use, patterns for making agent workflows deterministic, and the lessons we picked up scaling our automation and observability work.
Speakers
avatar for Britton Hayes

Britton Hayes

Detection and Response Engineer, Notion
Britton is a detection and response engineer building tools to keep security simple. Currently at Notion focusing on incident response, security automation, and detection engineering. Previously, he architected observability pipelines at Fortune 500 scale and secured Kubernetes infrastructure... Read More →
avatar for Joakim Pedersen

Joakim Pedersen

Detection and Response Engineer, Notion
Joakim is a Detection and Response engineer at Notion, focusing on detection engineering, incident response, and observability. With a background in offensive security, he brings an attacker mindset to defending cloud infrastructure at a global scale.
Saturday September 12, 2026 3:30pm - 3:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

4:00pm CDT

Finding SOCKS with ProxyWatch
Saturday September 12, 2026 4:00pm - 4:25pm CDT
Attackers increasingly use SOCKS proxies on intrusions to pivot through compromised networks and to keep their tools away from EDR. C2 frameworks like Sliver, Cobalt Strike, and Mythic make it simple to turn one callback into a gateway for the entire network. 


As defenders, we looked at existing guidance to find SOCKS proxies and found detections too narrowly focused on specific tools, or advice too difficult to implement for every possible technique an attacker could run through SOCKS. We looked at how to identify behaviors when a process acts as a SOCKS proxy, from endpoint and network telemetry, and created ProxyWatch, a tool to find SOCKS. This talk will cover our research process into how SOCKS works, why attackers choose to use SOCKS, ways to potentially identify SOCKS behaviors in your data, and introduce ProxyWatch as a tool that implements the signals we found. 


If you’re a defender, detection engineer, incident responder, or anyone curious about how these attacks work, we invite you to join in and learn how ProxyWatch can help you find SOCKS proxies.
Speakers
avatar for Brian Reitz

Brian Reitz

SpecterOps
Brian Reitz is a consultant for SpecterOps for the Adversary Detection team, working on detection engineering for a variety of clients. He previously worked in detection and response in healthcare, and pentesting, red team, and defensive work for public-sector and commercial clie... Read More →
avatar for John Wotton

John Wotton

Consultant, SpecterOps
John Wotton is a Consultant at SpecterOps specializing in adversary simulation, Active Directory, Physical Security, and EDR evasion. He focuses on custom tooling, offensive and defensive research, and helping organizations defend against advance persistent threats.
Saturday September 12, 2026 4:00pm - 4:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

4:00pm CDT

The End is Just the Beginning of Better Security: Enhancing Vulnerability Management with OpenEoX
Saturday September 12, 2026 4:00pm - 4:25pm CDT
Persistent cyber campaigns continue to threaten both public and private sectors, with outdated, unsupported edge devices emerging as a prime target for Nation-state adversaries. End-of-Life/End-of-Support (EoL/EoS) technologies create enduring exposure across our Nation's critical infrastructure, prompting CISA's February 2026 Binding Operational Directive (BOD) 26-02 requiring federal agencies to identify and replace EoS edge devices, maintain current software, and patch known vulnerabilities when immediate replacement is not feasible. The presentation will also introduce OpenEoX, a new open source, machine-readable standard, developed by OASIS Open, that streamlines the exchange of product lifecycle data across software, hardware, services, and AI models, and explains how it enables automated, timely detection of EoL/EoS assets and seamless integration with existing tools and standards such as Software Bills of Material (SBOMs) and the Common Security Advisory Framework (CSAF). It will detail the benefits for government agencies, vendors and open source maintainers, downstream users, and the broader ecosystem, and show how OpenEoX adoption supports transparency and consistency at scale. The session will also outline actions to operationalize OpenEoX, such as publishing OpenEoX data publicly, integrating OpenEoX into scanners and asset platforms, and updating workflows to drive proactive replacement, patching, and upgrades for unsupported devices. The goal is coordinated adoption that reduces risk and strengthens security through a standardized, transparent, and automated lifecycle management framework.
Speakers
avatar for Justin Murphy

Justin Murphy

Cybersecurity Vulnerability Analyst, DHS/CISA
Justin Murphy is a Vulnerability Analyst with the Cybersecurity and Infrastructure Security Agency (CISA). He helps to coordinate the remediation, mitigation, and public disclosure of newly identified cybersecurity vulnerabilities in products and services with affected vendor(s... Read More →
Saturday September 12, 2026 4:00pm - 4:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

4:00pm CDT

Trusted, But Dangerous: Identity Abuse Through First-Party Apps in Entra
Saturday September 12, 2026 4:00pm - 4:50pm CDT
Microsoft Entra environments rely heavily on implicit trust in Microsoft first-party applications, yet most defenders have limited visibility into how expansive that trust boundary truly is. With more than 4,000 Microsoft first-party app IDs, many operate as “ghost” applications: active in authentication and token issuance, but not clearly represented in enterprise application views or routinely monitored by defenders. This creates a significant blind spot in identity security.
This session explores how these trusted applications can be abused through Resource Owner Password Credentials (ROPC), Family of Client IDs (FOCI), and token issuance behaviors that extend access beyond what defenders typically expect. Rather than focusing on generic anomalous sign-ins, the talk centers on capability: the delegated scopes these applications request, the permissions they inherit, and how those access paths can be leveraged to persist and expand access within a tenant. These behaviors can be executed through standard Graph API interactions and demonstrate how ROPC can be leveraged to obtain tokens without interactive authentication and, in many real-world environments aligned with historical Microsoft guidance, results in effective MFA bypass conditions.
Attendees will learn how ROPC remains relevant in modern identity attacks, how first-party application trust complicates Conditional Access enforcement, and why policy evaluation differs between interactive and non-interactive authentication paths. The session also examines token lifecycle in depth, including how refresh tokens can persist for extended periods, how Continuous Access Evaluation (CAE) impacts enforcement, and why resetting user credentials does not necessarily revoke active access without additional token invalidation steps.
From a defensive perspective, this talk provides practical, immediately usable guidance. It includes KQL queries specifically designed to identify ROPC authentication activity, enumerate first-party application usage, and help defenders understand which client applications are requesting access and with what scope. It also covers Conditional Access policy considerations, validation techniques, and response actions to take during identity incidents involving token abuse.
A companion GitHub repository is included with ready-to-use KQL queries, detection logic, and example configurations. Attendees will leave with a concrete understanding of how first-party application trust can be abused, where visibility and enforcement gaps exist, and how to build effective identity-focused detection and response workflows in Microsoft Entra.
Speakers
avatar for Jon Haas

Jon Haas

Threat Hunter, Nationwide
Jon Haas is a Threat Hunter at Nationwide specializing in identity security, cloud detection engineering, and adversary tradecraft in modern SaaS environments. His work focuses on uncovering gaps in authentication controls, including OAuth abuse, first party application behavior... Read More →
Saturday September 12, 2026 4:00pm - 4:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

4:30pm CDT

It Wasn’t Spoofed: Investigating Authenticated Email Abuse in Real Environments
Saturday September 12, 2026 4:30pm - 4:55pm CDT
Not every incident starts with an alert.

Sometimes it starts with a confident assumption.

In this case, a suspicious email spread internally. The user reported they did not send it, and the client confidently assessed the message as spoofing.

It wasn’t.

Email header analysis revealed the message originated from within the organization (AuthAs: Internal) using legacy SMTP AUTH (AuthMechanism: 04), an authentication pathway that does not enforce MFA. Valid credentials were used, no alerts were generated, and the activity appeared legitimate.

With limited visibility, the investigation required correlating endpoint and infrastructure telemetry. Pivoting on domains associated with file retrieval revealed additional impacted systems beyond those initially reported.

The incident exposed gaps in both detection and control coverage. Mailbox forwarding rules enabled data exfiltration and were managed reactively rather than preventively, while authentication-based detection failed due to legitimate credential use. When questions arose around credential origin, validation had to be guided within the client’s own environment while maintaining privacy and access boundaries.

This talk provides practical guidance for defenders, including how to:
  • distinguish spoofed emails from authenticated internal activity using header analysis
  • identify authentication pathways where MFA is not enforced
  • pivot on DNS and endpoint telemetry to expand incident scope
  • detect and reduce risk from mailbox forwarding rules
  • validate potential credential exposure within appropriate privacy and access boundaries
  • investigate effectively when activity appears legitimate and generates no alerts
Attendees will leave with practical approaches for identifying and responding to attacks that bypass traditional detection by blending into expected behavior.
Speakers
avatar for Kelsey O'Connell (w0mbat)

Kelsey O'Connell (w0mbat)

Tier II MDR Analyst, WWT (World Wide Technology)
Kelsey (w0mbat) is a cybersecurity analyst focused on detection, investigation, and response, with an emphasis on cases where activity appears legitimate but is not. Her work spans endpoint, identity, and email telemetry, specializing in identifying subtle indicators of compromise... Read More →
Saturday September 12, 2026 4:30pm - 4:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk, Talk Track 3

4:30pm CDT

Zero Trust After the Breach: Lessons from Real-World Incident Response
Saturday September 12, 2026 4:30pm - 4:55pm CDT
When a breach hits, the instinct is clear: shut everything down. But is that always necessary and what does it cost the business?
In the face of increasingly sophisticated attacks, perimeter-based defences often collapse once compromised. This session explores how Zero Trust changes that equation, not during the breach itself, but in how organisations recover and rebuild securely.
Drawing on real-world incident response in large enterprises, the talk shows how to turn reactive recovery into long-term resilience. It highlights what actually works in practice: reducing lateral movement, limiting blast radius, and maintaining essential services while addressing practical challenges.
This includes rapid onboarding of tens of thousands of users under crisis conditions, enabling secure third-party access for recovery teams, and implementing segmentation across workforce, datacentre, branch, and OT environments.
Breaches create a rare window to enforce least-privilege access and accelerate Zero Trust adoption.
Speakers
avatar for Andrea

Andrea

Sr Solutions Consultant, Zscaler
Andrea Ibiassi is a cybersecurity professional with 10+ years of experience, having worked at Cisco, Zscaler and Snyk. She specialises in Zero Trust and cloud security. She has supported major European and UK organisations adopting zero trust and through high-impact cyber incidents... Read More →
Saturday September 12, 2026 4:30pm - 4:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

5:00pm CDT

Defending the Credential Reset Process
Saturday September 12, 2026 5:00pm - 5:25pm CDT
Some of the most noteworthy cybersecurity incidents that have occurred in the past 5 years have involved attacks on the credential lifecycle. Credentials are targeted by threat actors when they are initially issued at employee onboarding, when they are used everyday to login, and when they are lost and need to be reset. According to Microsoft’s 2025 Digital Defense Report, credential based attacks were the initial access vector used in 80% of attacks by access brokers. 


One of the most well known credential related incidents targeted MGM and Caesar’s Casinos in the summer of 2023. To target MGM, the criminals reportedly identified employee profiles on Linkedin, and learned enough about one employee in particular to call up MGM’s IT Helpdesk and successfully convince them to reset that person’s multi-factor authentication. These attacks prompted many organizations to take a closer look at how they handle credential reset.


One of the drivers behind these attacks is the increasing popularity of remote work. It is no longer reasonable in many cases to tell employees to just “drop by the office” if they loose access to the network. Organizations need ways to validate the identity of people remotely, and this is a lot harder than it sounds. SIM swapping, deepfakes, and breach data provide lots of ways to overcome various controls that organizations are trying to put in place. 


This talk will dissect the credential lifecycle and describe different attacks that target it and controls that can be put in place. We will focus specifically on credential reset workflows and show how attackers can subvert different countermeasures. We’ll then discuss how organizations can leverage what they know about their own employees to build robust defenses against these kinds of attacks.
Speakers
avatar for Tom Cross

Tom Cross

Head of Threat Research, GetReal Security
Tom Cross is the Head of Threat Research at GetReal Security, where he tracks threat actors and attack activity involving deepfake social engineering and impersonation. His career in cybersecurity has spanned three decades, and numerous roles, including CoFounder and CTO of Drawbridge... Read More →
Saturday September 12, 2026 5:00pm - 5:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

5:00pm CDT

Superposition, not Superstition
Saturday September 12, 2026 5:00pm - 5:25pm CDT
SUPERPOSITION WITHOUT SUPERSTITION
Why the foreseeable state of quantum computing is not a nightmare for security practitioners


In this illuminating talk, we’ll cut through the quantum hype to reveal why security professionals can approach quantum computing with informed confidence rather than panic.


While headlines scream about the imminent apocalypse of our cryptographic systems, reality paints a dramatically different picture. This presentation delivers a refreshingly sober analysis of quantum computing’s actual security implications, replacing fear with facts.


Key Insights:
Reality Check on Timelines
The horizon for practical cryptographically relevant quantum computers stretches far beyond sensationalist coverage, likely years or even decades before systems capable of breaking RSA or ECC at a meaningful scale materialize. Even then, these systems will initially be massive research facilities accessible primarily to nation-states, not everyday threat actors.


“Unless you’re a high-priority target for these select few actors with nation-state resources, should quantum computing really keep you up at night?”


Technical Hurdles That Won’t Disappear Overnight
We’ll dissect the substantial challenges quantum computing still faces, comparable to nuclear fusion energy, where “breakthrough announcements” often represent minimal progress in the greater journey. Error correction requirements, qubit coherence limitations, and scaling challenges aren’t merely engineering problems but fundamental physics puzzles requiring revolutionary solutions.


The Quantum Security Advantage
Discover how quantum technologies themselves offer robust security benefits through innovations like Quantum Key Distribution (QKD). Learn how the security community’s decades of preparation have yielded practical post-quantum cryptographic standards and hybrid approaches that organizations can implement today as part of sensible transition strategies.


Practical Preparation
Walk away with actionable insights on how to approach quantum-resistant security planning without overinvesting or underestimating. Learn which threats are real, which are exaggerated, and how to communicate quantum risks accurately to stakeholders and executives.


Join us for a reality-based assessment that replaces quantum superstition with quantum understanding, providing security practitioners with a practical perspective on this fascinating technological frontier. 

This session is ideal for CISOs, security architects, and security practitioners who need to separate quantum computing fact from fiction.
Speakers
avatar for Johnny Xmas

Johnny Xmas

Global Head of Offensive Security, Fortune 150 Food & Bev Manufacturer
Johnny Xmas, a prominent figure in the Information Security community since 2002, is a board member of both Chicago's famous BurbSec community, as well as its BSides312 conference. He's most notably recognized for his pivotal role in exposing the American TSA Master Key leaks (2014-2018... Read More →
Saturday September 12, 2026 5:00pm - 5:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

5:00pm CDT

Behaviour-Driven Detection for Software Supply Chain Exploitation
Saturday September 12, 2026 5:00pm - 5:50pm CDT
Abstract
Modern software development depends on an intricate ecosystem of open‑source libraries, third‑party services, CI/CD workflows, container registries, package repositories, and cloud‑native infrastructure. As organizations accelerate development velocity, their applications increasingly rely on components they neither wrote nor control. This creates a supply chain environment where the weakest external link becomes the attacker’s easiest entry point. While Application Security (AppSec) teams focus on code reviews, SAST/DAST, SCA results, and secure SDLC controls, many of the most dangerous threats originate outside their visibility. These include malicious dependency updates, compromised package maintainers, poisoned CI/CD pipelines, hijacked SDKs, and third‑party API breaches—risks that traditional AppSec tooling isn’t designed to detect.
At the same time, Cyber defence teams track adversary activity, ecosystem‑level manipulation, suspicious code commits, dark‑web chatter, targeted campaigns against popular libraries, and exploitation of software supply chain dependencies. They see indicators and emerging threats far earlier than any automated scanner—but this intelligence rarely makes its way into AppSec decision‑making. As a result, AppSec teams continue to approve dependencies with no CVEs, unaware that the maintainer was compromised; security testing pipelines approve builds even though TI has already flagged one of the upstream components; and organizations ship production code containing malicious logic that no scanner will ever detect because the code behaves "as designed"—just not by your design.
This talk presents a unified model for bridging these gaps—delivering a strategic approach through supply chain defence. Attendees will learn how real‑world supply chain attacks unfold, why they bypass traditional AppSec controls, and how integrating cyber defence changes the defender’s perspective. We break down practical detection methods for ecosystem‑level anomalies, maintainer compromise signals, malicious package patterns, CI/CD infiltration attempts, and signs of upstream component manipulation. Through real attack examples and defensive case studies, we show how organizations can fuse AppSec findings (SCA results, dependency mapping, SBOM data) with cyber defence to build an adaptive, intelligence‑driven supply chain protection strategy.
Key Takeaways
  • Why AppSec alone cannot detect supply chain compromise — and the specific blind spots hidden inside package ecosystems, CI/CD pipelines, and third‑party integrations.
  • A practical integration model where AppSec and Cyber defence team jointly monitor, validate, and block risky dependencies or services before they reach production.
  • Field-tested workflows for real-time supply chain monitoring using SBOM enrichment, threat feeds, dependency risk correlation, and behaviour-based anomaly detection.
  • A blueprint for building an enterprise supply chain defence program that continuously adapts to attacker evolution, ecosystem shifts, and vendor risks.
Why This Talk Is Important
Supply chain attacks are now a preferred strategy for both state-sponsored and financially motivated threat actors. They exploit trust relationships between developers, automation systems, and ecosystem maintainers—areas where AppSec with cyber defence team lacks visibility with limited operational influence. This session provides a practical, actionable roadmap for bringing both teams together to defend the modern software supply chain—before adversaries weaponize it.
Speakers
avatar for Niladri Sekhar Hore

Niladri Sekhar Hore

Lead Engineer - Threat Detection and Automation, StoneX Group
Niladri Sekhar Hore is a Lead Engineer at StoneX Group in Threat Detection and Automation. He builds data-driven detection systems and security automation frameworks across cloud and hybrid environments, focusing on operationalizing  security intelligence into measurable runtime... Read More →
avatar for Anurag Mathur

Anurag Mathur

Staff Engineer - Application Security, StoneX group
Anurag Mathur is a Staff Engineer in Application Security, specializing in secure architecture design, vulnerability research, and threat modelling for modern application ecosystems. He works closely with engineering teams to identify business logic weaknesses, harden authentication and authorizatio... Read More →
Saturday September 12, 2026 5:00pm - 5:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

5:30pm CDT

Building the Human Firewall: Why Security Awareness Must Precede the Workplace
Saturday September 12, 2026 5:30pm - 5:55pm CDT
Cybersecurity conversations often begin inside corporate boardrooms and Security Operations Centers but by then, the foundation for risk is already set. In a world where digital native generations are entering the workforce, the strongest "human firewall" must be established long before an employee receives their first corporate login.
This session reframes cybersecurity education as a foundational life skill rather than a purely technical discipline. By shifting the focus from corporate compliance to early digital awareness, organizations can significantly reduce their long-term enterprise risk. We will explore how early exposure to core concepts like digital hygiene, social engineering, and the psychology of trust can create a culture of security that naturally extends into professional environments.
Drawing on practical insights from incident response and governance, risk, and compliance (GRC) frameworks, this talk will demonstrate the direct correlation between proactive digital literacy and a resilient defensive posture. Attendees will leave with a new perspective on training strategies that move beyond "checking the box" and toward a more intuitive, security-first mindset. This session is ideal for security leaders, educators, and anyone interested in the intersection of human behavior and defensive strategy.
Speakers
avatar for Nousheen Begum

Nousheen Begum

Cybersecurity Leader | GRC & AI Security | CISSP | VP, WiCyS Wisconsin | Board Member, ISACA Milwaukee & ISC2 Wisconsin, WiCyS Wisconsin
Nousheen Begum is a seasoned cybersecurity professional with over 10 years of experience in Security Operations (SOC), Incident Response, and GRC. She holds an M.S. in Cybersecurity from the University of Illinois Springfield and is a CISSP and CEH certified professional. Currently... Read More →
Saturday September 12, 2026 5:30pm - 5:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

5:30pm CDT

Security vs Product: A Professional Identity Crisis
Saturday September 12, 2026 5:30pm - 5:55pm CDT
For years, my instinct was to fix things. See an alert, chase the threat. Find a gap, build a detection. Witness an incident, contain and remediate. After a career built on DFIR, detection engineering, incident response, and sysadmin work, I was trained to be a solution machine, and I was good at it.


Then I became a Product Manager.
Everything broke.


Suddenly the job wasn't to solve the problem in front of me, it was to figure out whether I even had the right problem. The skills that made me dangerous in a SOC were quietly working against me in a product role. I was writing requirements that looked suspiciously like runbooks. I was treating user research like a post-incident review, assuming I knew the problems because I've been there before. Jumping straight to the five whys without sitting in the discomfort of not knowing yet.


This talk is the honest story of my first year as a Product Manager and what a decade in security taught me. Both the gifts and the baggage.
The gifts were real: I understood the users deeply because I was the user. I could cut through technical ambiguity, earn credibility with engineering teams fast, and spot when a "product problem" was actually an architecture problem in disguise. Threat modeling translated almost directly into risk prioritization frameworks. Log analysis taught me how to find signal in noisy customer feedback.


But the baggage was heavy too. Security work rewards decisive, fast, technical action. Product work rewards patience, ambiguity tolerance, and ruthless problem definition. The pivot from solution-first thinking to problem-first thinking didn't happen naturally, it had to be unlearned, deliberately and sometimes painfully.


In this session, I'll walk through the mental model shift that changed how I approach product decisions, the specific security habits that carried over (and why), the ones I had to consciously kill, and how I'm still learning to bridge both worlds. Whether you're a security professional curious about PM roles, a PM trying to work with security-minded engineers, or someone navigating a major career pivot, this talk is for you.
Speakers
avatar for Amanda Berlin (Infosystir)

Amanda Berlin (Infosystir)

Sr. Product Manager, Cybersecurity, Blumira
Amanda Berlin is the Sr. Product Manager of Cybersecurity at Blumira, where she leads product initiatives focused on XDR and response capabilities as well as incident detection engineering initiatives.
An accomplished author, speaker, and podcaster, Amanda is known for her ability to communicate complex technical concepts in a way that is accessible and engaging for audiences of all backgrounds. She co-authored an O’Reilly Media book Defensive Security Handbook: Best Practices... Read More →
Saturday September 12, 2026 5:30pm - 5:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk, Talk Track 3
 
Blue Team Con 2026
From $0.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -