Loading…

Type: Talk Track 3 clear filter
Saturday, September 12
 

10:30am CDT

Vulnerability Management: The Leadership Playbook
Saturday September 12, 2026 10:30am - 10:55am CDT
Most vulnerability programs keep teams busy without reducing risk. Mean-time-to-remediate improves quarter over quarter while the total count of unpatched vulnerabilities climbs. The program optimizes a local maximum: patching speed. This talk presents four strategies for escaping the cycle, and the leadership behaviors each strategy requires.
Strategy 1: Shrink what needs protecting. Every decommissioned environment, consolidated tool, and disabled stale account is one less thing to scan, patch, monitor, or defend. Specific targets exist in every organization: SaaS products nobody canceled after a pilot, test environments that outlived their projects, overlapping tools acquired through inertia. Zero-based security budgeting surfaces surprising candidates for elimination and reframes security from cost center to cost-reduction partner. But decommissioning requires a shared source of truth. When security counts 200 SaaS applications, finance tracks 100 with purchase orders, and IT lists 50 in systems management tools, conversations stall. Building that shared reality across departments is the prerequisite for any attack surface reduction initiative.
Strategy 2: Look beyond scanning. Scanners miss configuration drift, exposed APIs, shadow infrastructure, and short-lived cloud resources that disappear between scan cycles. Pairing vulnerability scanners with endpoint agents, cloud security posture tools, systems management software, and identity providers gives a more accurate picture of what needs attention. This section also challenges the attackers only need to be right once myth. Map it against MITRE ATT&CK: attackers must succeed at reconnaissance, initial access, persistence, lateral movement, and exfiltration. Every stage, sequentially. Defenders disrupt one step. Architectural choke points like SSO create disproportionate defensive returns. Terrain knowledge compounds over time and is impossible for an external attacker to replicate.
Strategy 3: Prioritize with context. Base CVSS scores assume worst-case conditions and mislead patching teams. Combining exploitability data such as EPSS scores and CISA's KEV catalog with environment specifics, including network exposure, compensating controls, and data sensitivity, produces rankings that reflect actual risk. A CVSS 6.5 on an internet-facing authentication server often deserves faster action than a CVSS 9.0 on an isolated test box. When patching teams see priorities grounded in their reality, they trust the process and act on it. The job of a security leader is not to maximize security but to calibrate acceptable insecurity through criteria a business colleague would understand.
Strategy 4: Apply pressure without alienating the teams who do the work. Patching teams are measured on delivery velocity, not vulnerability metrics. Earning a seat in their planning sessions starts with understanding their constraints and what they are trying to ship this quarter. Allies often sit outside security and IT: General Counsel cares about legal exposure, product management about customer trust, finance about cost reduction. Frame requests in terms of their objectives, not your risk scores. If your assessment doesn't change the state of the organization, it hasn't reduced risk.
The talk closes with metrics that measure program health rather than activity, guidance on communicating vulnerability management to boards and executives, and five diagnostic questions attendees take home to assess whether their program is reducing risk or producing reports.
Speakers
avatar for Lenny Zeltser

Lenny Zeltser

Faculty Fellow, SANS Institute
Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. He has built security products and programs from early stage to enterprise scale. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a... Read More →
Saturday September 12, 2026 10:30am - 10:55am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

11:00am CDT

Purple Testing Is Not Enough — Why CTEM Is the Missing Layer
Saturday September 12, 2026 11:00am - 11:25am CDT
Session Description (Abstract)
Purple testing is powerful.
It helps us validate detections, simulate attacker behavior, and expose where our defenses break. It gives us truth about our controls.
But there’s a problem.
Most teams stop at validation.
We test.
 We validate.
 We generate findings.
And then… we move on.
The same gaps show up again later—not because we didn’t find them, but because we didn’t ensure they were actually fixed. Over time, this creates what I call “validation theater”—a cycle where teams continuously prove weaknesses without reducing real exposure.
From an attacker’s perspective, that’s not a weakness.
 It’s reliability.
This talk focuses on closing that gap.
Drawing from 12 years of incident response experience and 6 years running continuous validation programs, I’ll show how to move from “we tested it” to “we fixed it—and proved it stays fixed.”
We’ll break down where purple testing delivers value—and where it falls short—and introduce Continuous Threat Exposure Management (CTEM) as the missing operational layer that connects validation to ownership, prioritization, and remediation.
Attendees will learn how to operationalize a practical CTEM loop:
 Scoping → Discovery → Prioritization → Validation → Mobilization
And more importantly, how to:
  • Assign clear ownership across teams
  • Prioritize remediation based on real risk
  • Build a repeatable process for closing gaps
  • Measure whether exposure is actually decreasing over time
This session is designed for blue team practitioners, detection engineers, and security leaders who want a practical, actionable approach to improving security effectiveness.
Because testing is not protection.
 Detection is not protection.
 Closure is.
It’s about building a repeatable system that ensures what you find… actually gets fixed.
Because if the same gaps keep coming back—so will attackers.
 
Speakers
avatar for Irina Dimitrov (Loktionova)

Irina Dimitrov (Loktionova)

Irina Dimitrov (Loktionova) is a cybersecurity professional with over a decade of hands-on experience in incident response and security operations. For 12 years, she worked on the front lines, responding to real-world attacks and seeing firsthand where security controls succeed—and... Read More →
Saturday September 12, 2026 11:00am - 11:25am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

11:30am CDT

Threat Intelligence at the Speed of Cyber Defense
Saturday September 12, 2026 11:30am - 11:55am CDT
Cyber threat intelligence (CTI) is essentially a decision support function within cybersecurity. As such, CTI that cannot enable, improve, or otherwise facilitate a security action is of questionable value. This is often evaluated in terms of CTI relevance, applicability, or accuracy, but the relationship between CTI and security actions also demands investigation of another metric: timeliness. CTI that arrives too late for the supported decisions is functionally irrelevant.


In this discussion we will explore the implications of a time-oriented view for CTI production, dissemination, and integration into operationally-focused decision making. From this we will identify a key tension at the core of CTI analysis and production: that the SPEED at which CTI is produced and disseminated is often in conflict with the QUALITY or DEPTH of the produced CTI. Organizations cannot have immediate decision support on tactically-relevant timescales while simultaneously having deep context in the current environment. As a result, tradeoffs are necessary to both recognize and navigate in developing a relevant CTI function. Furthermore, evaluating CTI becomes a question of determining audience and customer needs, purpose, and response timelines to appropriately structure CTI support for the entity or specific decision maker in question.


To conclude this discussion, we will examine the possibility of eliminating (or at least reducing) this dilemma through technical means. Particularly future progress in the field of artificial intelligence may allow CTI functions to tap into mechanisms where context or detail and timeliness are no longer in direct conflict with one another, mapping out an effective and meaningful way for AI to support CTI and broader security functions.
Speakers
avatar for Joe Slowik

Joe Slowik

Director, Cybersecurity Alerting Strategy, Dataminr
Joe Slowik has over 15 years of experience across multiple cyber domains, from threat intelligence to detection engineering to incident response. Joe currently works as director for cyber alerting strategy at Dataminr, and has previously held roles at organizations including the MITRE... Read More →
Saturday September 12, 2026 11:30am - 11:55am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

12:00pm CDT

Same Network, Different Worlds: Bridging the IT Ops and SOC Divide
Saturday September 12, 2026 12:00pm - 12:25pm CDT
A temporary service account with Domain Admin rights gets created at 11 PM to patch a legacy application. The sysadmin logs off and forgets about it. The SOC sees the account creation, flags it as authorized admin activity, and moves on. Three weeks later, that account becomes an attacker's persistence mechanism. Nobody did anything wrong. And that is exactly the problem.
IT operations and security teams share the same network but operate in fundamentally different worlds. Sysadmins speak the language of uptime, change windows, and ticket queues. SOC analysts speak the language of alerts, TTPs, and kill chains. Both teams assume the other has visibility into what is happening, and both teams are wrong. The result is a gap that does not show up in any audit report but lives quietly in every environment: misattributed alerts, forgotten service accounts, unclaimed security tasks, and legitimate admin activity that looks completely indistinguishable from an attacker who already knows your environment inside and out.
Most organizations try to solve this with better documentation, cleaner org charts, and the occasional cross team meeting. It does not work. The gap is not a process problem. It is a knowledge problem. Security analysts often do not know enough about how systems are actually administered day to day to separate noise from signal. Sysadmins often have no idea how their routine tasks appear inside a SIEM and have even less awareness of the quiet risk they are generating while doing everything by the book.
This session is built on a premise that is easy to understand but rarely acted on: the person best positioned to bridge that gap is someone who has stood on both sides of it. Drawing from hands on experience managing and securing environments across multiple client organizations at an MSSP, this talk translates the operational realities of IT administration into the detection focused language of the SOC and does the same in reverse. No theory. No vendor pitch. Just an honest look at how two teams who are supposed to be working together keep accidentally working against each other.
Attendees will work through real world scenarios that are very common between companies and industries. They will experience each scenario from the IT ops side and the SOC side to understand what happens. The audience will leave with a practical communication framework they can bring back to their organization before the next incident forces the conversation anyway. 
Whether there is a junior analyst trying understand the authenticity of alerts or a systems engineer who has never thought of how routine tasks look like from a SOC lens, this session will be inclusive of all.
Speakers
avatar for Sameer Singhal

Sameer Singhal

System Engineer II, EXOS
Sameer bridges the critical gap between infrastructure engineering and security operations. He holds a bachelor's degree in Cybersecurity from Purdue University and is currently a Systems Engineer II working his way towards a Cybersecurity Analyst I position at an MSSP, where he supports... Read More →
Saturday September 12, 2026 12:00pm - 12:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

12:30pm CDT

MDR: From Vendor Shortlist to Security Partnership
Saturday September 12, 2026 12:30pm - 12:55pm CDT
In a saturated market, how can CISOs move past monitoring volume to evaluate Managed Detection and Response (MDR) providers based on their true ability to reduce exposure and drive proactive risk reduction?


How do you build a practical evaluation framework that balances technical visibility and response capability with commercial clarity and long-term consolidation potential?


What does is the difference between a provider that wins a contract, and a partner that actually strengthens resilience before, during, and after a crisis?
Speakers
avatar for Alan Simpson

Alan Simpson

Field CISO, Rapid7
Alan Simpson is Field CISO for the UK and Ireland at Rapid7, advising CISOs and senior leaders on cyber risk, resilience, and security strategy that supports business outcomes. Before joining Rapid7, he served as Global Security Operations Manager and Acting CISO at Keyloop, where... Read More →
Saturday September 12, 2026 12:30pm - 12:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

1:00pm CDT

Game of Cones: Why Your Crisis Plan Shouldnt Melt Under Pressure
Saturday September 12, 2026 1:00pm - 1:25pm CDT
Your incident response playbook is sitting on a server. The server just got encrypted. Now what?


Most organizations invest heavily in plans they never actually test: polished documentation, detailed runbooks, maybe a shiny new SIEM. Then a real crisis hits. Ransomware. A breach notification deadline. A regulator on line one and a journalist on line two. And everyone discovers, at the worst possible moment, that having a plan and having a practiced plan are two very different things.


This session draws on 18+ years of crisis management consulting across financial services, healthcare, and critical infrastructure — and a parallel career as a court-qualified expert witness in cybersecurity matters — to make one foundational argument: you cannot exercise your way to readiness during a crisis. You have to earn it before one arrives.


We'll start by untangling two exercise types that organizations routinely conflate. Technical Tabletop Exercises are built for your engineers and incident responders: deep, system-specific scenarios that evolve with each inject, stress-testing malware analysis, containment decisions, forensic timelines, and recovery procedures. Crisis Management Exercises are built for the people making the ransom pay/no-pay call at 2 a.m., fielding questions from the board, and deciding what to tell regulators before the mandatory notification window closes. Both matter. They serve different audiences, surface different gaps, and fail in different ways when neglected.


From there, we get practical. Using concrete inject examples drawn from real engagements, we'll examine what a realistic inject sequence actually looks like, how scenarios should evolve under pressure, and how to design exercises that surface real gaps rather than validate comfortable assumptions. We'll walk through common failure patterns: the outdated playbook nobody printed, the escalation path that dead-ends at a person who left the company, the executive team that spent the first 45 minutes of a simulated breach trying to figure out who was supposed to be talking to legal.


We'll also cover the human dimension that most exercise frameworks undercount: trust. You cannot know whether the person next to you will stay calm under real pressure until you've watched them handle simulated pressure. Exercises make your colleagues' behavior predictable. That predictability: knowing who steps up, who freezes, who asks the right questions, is what separates a coordinated response from organized chaos.


Attendees will leave with a practical framework for designing and running exercises that actually move the needle, a clear model for separating leadership-track and technical-track scenarios, and concrete guidance on building post-exercise debrief processes that drive iteration rather than just generating a report nobody reads.


One durable truth ties it all together: the calmest person in the room on the worst day of the organization's life didn't get there by accident. They practiced.


So should you.
Speakers
avatar for Richard Suls

Richard Suls

US Lead, Advisory Consulting, Reversec
Richard Suls is US Lead for Security Advisory Consulting at Reversec Consulting, where he designs and delivers crisis management exercises and technical tabletops for major financial institutions, healthcare organizations, and critical infrastructure operators. He brings 18+ years... Read More →
Saturday September 12, 2026 1:00pm - 1:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

1:30pm CDT

Make the Governed Path the Apparent One
Saturday September 12, 2026 1:30pm - 1:55pm CDT
If you've ever game-mastered a tabletop campaign, you already understand AI governance: your world has rules that can't bend, your players will find every loophole you didn't think of, and saying "no" all the time loses the table. The same pattern is playing out right now in every organization handing AI agents write access to production systems, and the solution is the same: make the governed path the apparent path.


Your employees are already using AI agents to write code, modify configurations, and execute shell commands, many without understanding what they're authorizing. Traditional security controls are blind to this: EDR doesn't flag an AI agent opening a port, DLP doesn't catch a model exporting records to a temp directory, and change management doesn't have a ticket type for "the AI refactored our auth module."


The instinct is to restrict access or schedule another training. Restriction drives usage underground. Classroom training can't keep pace with adoption. But training delivered inside the tool itself, guidance at the moment of risk, maintained by AI from current documentation; actually sticks, because users encounter it when they need it, not months before.


This talk presents a practical approach drawn from field experience building and testing a governance framework for AI agents: make the governed path easier than the ungoverned one, and embed the education in the guardrails themselves. When your secure pipeline is less friction than the alternative AND teaches users why it matters in context, you get compliance and competence as side effects of normal usage.


We'll cover why current tooling misses AI-driven changes, a field incident where a governance system silently failed and then told the AI the failure was intentional, experiments in securing MCP, and actionable takeaways you can apply regardless of which AI tools your organization runs.
Speakers
avatar for Johnathon Rhoades

Johnathon Rhoades

Founder, (RIT) - Rhoades Institute of Technology
Johnathon Rhoades founded and operates the Rhoades Institute of Technology (RIT), where he oversees development, legal filings, outreach, event planning, and much of the organization’s day-to-day administration, as well as all current technical efforts. Before launching RIT, his... Read More →
Saturday September 12, 2026 1:30pm - 1:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

2:00pm CDT

Teaching AI to Analyze Malware: How to Encode Practitioner Expertise into an MCP Server
Saturday September 12, 2026 2:00pm - 2:25pm CDT
AI agents can reason about suspicious files, plan multi-step investigations, and write custom deobfuscation code when standard tools fall short. But generic models produce shallow, unreliable results because they lack practitioner knowledge about which tools to use and when, and access to the tools themselves.
Without domain expertise, an AI agent doesn't know that, for example, capa exit codes follow non-standard conventions, that YARA match counts require context to interpret, or that GetProcAddress appears in virtually every Windows program and is not inherently suspicious. Without tool access, it can only comment on malware but cannot investigate it.
This talk walks through my experience of building an open source MCP server, a standardized interface that connects AI agents to external tools, that bridges both gaps simultaneously. The server connects AI agents to my open source REMnux malware analysis toolkit, encoding practitioner knowledge into tool workflow sequencing and output interpretation. The server runs analysis at three depth levels, and manages context budgets when tool output exceeds approximately reasonable values by automatically switching to summary mode while preserving key findings.
The server also counteracts confirmation bias. Generic AI agents tend to label every API call as suspicious and every string as an indicator of compromise. The server's neutral framing prompts agents to consider benign explanations before concluding malicious intent. This is a critical safeguard when the AI chains dozens of tool calls without human review at each step.
Against real-world samples, the resulting system completed full investigations in about 10 minutes with 25-30 automated tool calls. In one case during my experimentation, the AI agent wrote custom Python to reconstruct a PE from file fragments. In another, it reverse-engineered a proprietary archive format and adapted when initial analysis approaches failed.
The talk covers what worked, what failed, and what surprised me. It addresses the security model required when AI agents have tool access, including prompt injection risks from malicious content in analyzed samples, container isolation as the primary security boundary, and data flow considerations.
Attendees leave with a reproducible pattern for encoding domain expertise into MCP servers, applicable to incident response, cloud forensics, network analysis, or any domain with specialized tools and practitioner workflows.
Speakers
avatar for Lenny Zeltser

Lenny Zeltser

Faculty Fellow, SANS Institute
Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. He has built security products and programs from early stage to enterprise scale. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a... Read More →
Saturday September 12, 2026 2:00pm - 2:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

2:30pm CDT

CISA’s Menu for Vulnerability Management
Saturday September 12, 2026 2:30pm - 2:55pm CDT
Hungry for better cyber defense? Pull up a chair at CISA’s café, where vulnerability management is always on the menu! This talk will serve up a full tasting of best practices, international standards, and key initiatives that help organizations defend against today’s threats and enhance their cyber resilience. From tried-and-true favorites like CVE and the Known Exploited Vulnerabilities (KEV) catalog, to innovative new flavors including CSAF and OpenEoX, discover how the vulnerability management chefs at CISA lead efforts to streamline vulnerability disclosure, automate risk decisions, and overall secure U.S. critical infrastructure. Whether picking a la carte or sampling the whole menu, you will leave this talk with tasty insights and actionable recipes to boost your organization’s cyber defense posture…no reservations required!
Speakers
avatar for Justin Murphy

Justin Murphy

Cybersecurity Vulnerability Analyst, DHS/CISA
Justin Murphy is a Vulnerability Analyst with the Cybersecurity and Infrastructure Security Agency (CISA). He helps to coordinate the remediation, mitigation, and public disclosure of newly identified cybersecurity vulnerabilities in products and services with affected vendor(s... Read More →
avatar for Julia Turkevich

Julia Turkevich

Cybersecurity Vulnerability Analyst, DHS/CISA
Julia Turkevich leads CISA's stakeholder engagement activities to recruit CVE Numbering Authority (CNA) partners that are committed to proactive and responsible vulnerability disclosure. As a member CISA's Vulnerability Management subdivision, Julia works to advance maturity across... Read More →
Saturday September 12, 2026 2:30pm - 2:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

3:00pm CDT

Beyond The Auth Artifacts: Identifying Intrusions by Correlating Identity and EDR Telemetry
Saturday September 12, 2026 3:00pm - 3:25pm CDT
In today’s landscape of sophisticated cyberattacks, EDR (Endpoint Detection and Response) is an indispensable tool, but it’s not a complete solution. We are observing a rise in sophisticated cyberattacks that are difficult to detect based solely on endpoint behavior. By initiating breaches via VPNs—which are outside the scope of EDR monitoring—and utilizing stolen credentials to blend in through LotL methods, attackers are successfully evading traditional security measures. To address these challenges, the importance of monitoring identity-based behavior generated by Active Directory (AD)—known as ID alerts—is growing by the day.


In this session, we will share the “realities” of ID alert analysis from the front lines of a managed SOC that monitors and analyzes environments comprising tens of thousands of devices—primarily for major Japanese enterprises—24 hours a day, 365 days a year. Monitoring identity-based behavior in large-scale enterprise environments is a “headache” for operators due to vast amounts of noise and a lack of context. We will introduce our initiatives for utilizing correlation analysis and threat hunting to address these ID alerts. Attendees will learn “correlation analysis logic” and “hypothesis-based hunting” using Sigma rules—techniques that can be immediately applied in SOC operations the very next day—while filtering out the noise specific to large-scale environments.
Speakers
avatar for Shogo Hayashi

Shogo Hayashi

SOC Analyst, NTT Security
Shogo Hayashi is a SOC analyst at NTT Security (Japan) KK. He has been working in cybersecurity as a member of the Blue Team for 15 years. He specializes in responding to EDR and AD detections, developing detection rules, malware analysis, and cyber threat research. He has spoken... Read More →
avatar for Teruki Yoshikawa

Teruki Yoshikawa

SOC Analyst, NTT Security
Teruki Yoshikawa is a SOC analyst at NTT Security (Japan) KK. He is responsible for monitoring NW/EDR alerts, while also being involved in malware analysis. He is actively engaged in security research. He has spoken at JSAC, NorthSec and has co-authored several white papers.
Saturday September 12, 2026 3:00pm - 3:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

3:30pm CDT

Beyond the SIEM: Critical Governance and Architecture Decisions for Modern SOCs
Saturday September 12, 2026 3:30pm - 3:55pm CDT
Modern Security Operations Centers (SOCs) have evolved from basic technical hubs into essential engines for risk management. Success requires a disciplined alignment of governance, architecture, and talent to ensure every action remains resilient and defensible. This session presents a structured methodology to balance high-level technical capability with fiscal responsibility and regulatory mandates. By evaluating SOC evolution through the lens of financial and legal risk, organizations can build a function that is both highly effective and accountable to the board of directors.


We begin by discussing why governance must precede tooling to avoid embedding technical debt into the center’s foundation. This involves identifying critical assets, defining precise operational scope, and mapping risks driven by regulatory frameworks and customer contracts. Once these boundaries are set, we explore how to design a technical backbone that eliminates unnecessary complexity. We will evaluate a tiered log strategy where a security data lake handles high-volume telemetry while the primary analytics engine is reserved for real-time, high-fidelity alerting. This strategic approach prevents cost escalation while providing the depth required for advanced automated workflows.


We also address workforce modeling, demonstrating how technology choices dictate staffing requirements. By examining the mathematical rule of five, we evaluate the requirements for sustainable 24/7 coverage while preventing analyst burnout. The session concludes by reviewing how these elements create a living function that leverages automated triage and standardized playbooks to reduce manual effort by 60–80%. Attendees will learn to formalize critical escalation paths and measure performance through a trinity of operational, contractual, and compliance metrics, ultimately validating defenses through structured training to maintain a proactive, intelligence-driven posture.
Speakers
avatar for Bart Stump (Stumper)

Bart Stump (Stumper)

Managing Principal, Coalfire
Bart Stump is a Managing Principal on the Threat Discovery Services team at Coalfire with over 19 years of experience. He specializes in identifying defensive gaps through threat hunting, cyber threat intelligence, and security tool gap analysis to implement robust defensive measures. For... Read More →
avatar for Jeremy Croghan

Jeremy Croghan

Director, Coalfire
Jeremy Croghan is a seasoned cybersecurity leader and Director of Business Resiliency at Coalfire with over 20 years of experience, including U.S. Marine Corps service. He specializes in aligning the complex regulatory requirements of any industry with organizational policies to ensure... Read More →
Saturday September 12, 2026 3:30pm - 3:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

4:00pm CDT

The End is Just the Beginning of Better Security: Enhancing Vulnerability Management with OpenEoX
Saturday September 12, 2026 4:00pm - 4:25pm CDT
Persistent cyber campaigns continue to threaten both public and private sectors, with outdated, unsupported edge devices emerging as a prime target for Nation-state adversaries. End-of-Life/End-of-Support (EoL/EoS) technologies create enduring exposure across our Nation's critical infrastructure, prompting CISA's February 2026 Binding Operational Directive (BOD) 26-02 requiring federal agencies to identify and replace EoS edge devices, maintain current software, and patch known vulnerabilities when immediate replacement is not feasible. The presentation will also introduce OpenEoX, a new open source, machine-readable standard, developed by OASIS Open, that streamlines the exchange of product lifecycle data across software, hardware, services, and AI models, and explains how it enables automated, timely detection of EoL/EoS assets and seamless integration with existing tools and standards such as Software Bills of Material (SBOMs) and the Common Security Advisory Framework (CSAF). It will detail the benefits for government agencies, vendors and open source maintainers, downstream users, and the broader ecosystem, and show how OpenEoX adoption supports transparency and consistency at scale. The session will also outline actions to operationalize OpenEoX, such as publishing OpenEoX data publicly, integrating OpenEoX into scanners and asset platforms, and updating workflows to drive proactive replacement, patching, and upgrades for unsupported devices. The goal is coordinated adoption that reduces risk and strengthens security through a standardized, transparent, and automated lifecycle management framework.
Speakers
avatar for Justin Murphy

Justin Murphy

Cybersecurity Vulnerability Analyst, DHS/CISA
Justin Murphy is a Vulnerability Analyst with the Cybersecurity and Infrastructure Security Agency (CISA). He helps to coordinate the remediation, mitigation, and public disclosure of newly identified cybersecurity vulnerabilities in products and services with affected vendor(s... Read More →
Saturday September 12, 2026 4:00pm - 4:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

4:30pm CDT

It Wasn’t Spoofed: Investigating Authenticated Email Abuse in Real Environments
Saturday September 12, 2026 4:30pm - 4:55pm CDT
Not every incident starts with an alert.

Sometimes it starts with a confident assumption.

In this case, a suspicious email spread internally. The user reported they did not send it, and the client confidently assessed the message as spoofing.

It wasn’t.

Email header analysis revealed the message originated from within the organization (AuthAs: Internal) using legacy SMTP AUTH (AuthMechanism: 04), an authentication pathway that does not enforce MFA. Valid credentials were used, no alerts were generated, and the activity appeared legitimate.

With limited visibility, the investigation required correlating endpoint and infrastructure telemetry. Pivoting on domains associated with file retrieval revealed additional impacted systems beyond those initially reported.

The incident exposed gaps in both detection and control coverage. Mailbox forwarding rules enabled data exfiltration and were managed reactively rather than preventively, while authentication-based detection failed due to legitimate credential use. When questions arose around credential origin, validation had to be guided within the client’s own environment while maintaining privacy and access boundaries.

This talk provides practical guidance for defenders, including how to:
  • distinguish spoofed emails from authenticated internal activity using header analysis
  • identify authentication pathways where MFA is not enforced
  • pivot on DNS and endpoint telemetry to expand incident scope
  • detect and reduce risk from mailbox forwarding rules
  • validate potential credential exposure within appropriate privacy and access boundaries
  • investigate effectively when activity appears legitimate and generates no alerts
Attendees will leave with practical approaches for identifying and responding to attacks that bypass traditional detection by blending into expected behavior.
Speakers
avatar for Kelsey O'Connell (w0mbat)

Kelsey O'Connell (w0mbat)

Tier II MDR Analyst, WWT (World Wide Technology)
Kelsey (w0mbat) is a cybersecurity analyst focused on detection, investigation, and response, with an emphasis on cases where activity appears legitimate but is not. Her work spans endpoint, identity, and email telemetry, specializing in identifying subtle indicators of compromise... Read More →
Saturday September 12, 2026 4:30pm - 4:55pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

5:00pm CDT

Defending the Credential Reset Process
Saturday September 12, 2026 5:00pm - 5:25pm CDT
Some of the most noteworthy cybersecurity incidents that have occurred in the past 5 years have involved attacks on the credential lifecycle. Credentials are targeted by threat actors when they are initially issued at employee onboarding, when they are used everyday to login, and when they are lost and need to be reset. According to Microsoft’s 2025 Digital Defense Report, credential based attacks were the initial access vector used in 80% of attacks by access brokers. 


One of the most well known credential related incidents targeted MGM and Caesar’s Casinos in the summer of 2023. To target MGM, the criminals reportedly identified employee profiles on Linkedin, and learned enough about one employee in particular to call up MGM’s IT Helpdesk and successfully convince them to reset that person’s multi-factor authentication. These attacks prompted many organizations to take a closer look at how they handle credential reset.


One of the drivers behind these attacks is the increasing popularity of remote work. It is no longer reasonable in many cases to tell employees to just “drop by the office” if they loose access to the network. Organizations need ways to validate the identity of people remotely, and this is a lot harder than it sounds. SIM swapping, deepfakes, and breach data provide lots of ways to overcome various controls that organizations are trying to put in place. 


This talk will dissect the credential lifecycle and describe different attacks that target it and controls that can be put in place. We will focus specifically on credential reset workflows and show how attackers can subvert different countermeasures. We’ll then discuss how organizations can leverage what they know about their own employees to build robust defenses against these kinds of attacks.
Speakers
avatar for Tom Cross

Tom Cross

Head of Threat Research, GetReal Security
Tom Cross is the Head of Threat Research at GetReal Security, where he tracks threat actors and attack activity involving deepfake social engineering and impersonation. His career in cybersecurity has spanned three decades, and numerous roles, including CoFounder and CTO of Drawbridge... Read More →
Saturday September 12, 2026 5:00pm - 5:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

5:30pm CDT

So You Want to Be a Forensicator....
Saturday September 12, 2026 5:30pm - 6:00pm CDT
Imagine starting your first day on the job with a single clue: a five-second gap in the logs that absolutely shouldn’t exist.  No flashy “zoom to enhance,” no instant answers—just you, a timestamp, and the question every forensicator lives for: What happened in the missing moment? This talk uses that small but mysterious anomaly to illustrate the real heart of digital forensics: quiet puzzles hidden inside ordinary data.


From that opening mystery, we’ll transition into the practical realities of entering the field. Attendees will learn how people actually break into computer forensics and the skills that matter more than pedigree. We’ll examine the core personality traits that make someone effective in this career, including the ability to clearly communicate what the evidence does (and does not) prove.


The session also sets realistic expectations for daily work in digital forensics. By the end, attendees will understand not only what it takes to become a forensicator, but what it feels like to think, work, and solve problems like one—no TV magic required, just skill, patience, and a passion for uncovering the truth hidden in the data.


Speakers
avatar for Dr. Catherine J. Ullman

Dr. Catherine J. Ullman

Sr. Information Security Forensic Analyst, University at Buffalo
Dr. Catherine J. Ullman is the Principal Technology Architect, Security at the University at Buffalo. She is a contributor to O’Reilly’s 97 Things Every Information Professional Should Know, the author of Wiley’s The Active Defender, and has presented at many infosec/hacker... Read More →
Saturday September 12, 2026 5:30pm - 6:00pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3
 
Sunday, September 13
 

10:00am CDT

Active Directory Post-Mortem: Assumptions vs Reality
Sunday September 13, 2026 10:00am - 10:50am CDT
Active Directory Domain Services has been around for 26 years, making it far from a young technology - yet it is not going anywhere anytime soon. Most companies still rely on Active Directory as their primary identity provider and management solution. One might assume that after all these years we have already mastered securing Active Directory with best practices. However, the reality is often the opposite: many AD environments are still poorly secured, which keeps them a common target for attackers.
In this talk, I will demonstrate three important vulnerabilities that still exist in Active Directory and are either unknown or not discussed enough. We will challenge a few assumptions along the way:
  • If an account is locked out, can you still brute-force its password?
  • If a user is in Protected Users, is the NT hash truly out of reach?
  • When you use RDP (MSTSC), does it cache more than just fragments of your screen?
By the end of the session, you will learn that some common assumptions are wrong and that you must always test and verify security controls in practice. You will also leave with practical mitigations and best practices to secure your environment against these vulnerabilities and reduce their impact.
Speakers
avatar for David Horak

David Horak

Security Engineer & Founder, Horizon Secured
David Horák is a System Security Engineer and Team Leader with 8+ years of experience securing Windows infrastructures and Active Directory. He has delivered 30+ security assessments across SMB, enterprise, and critical infrastructure, giving him a strong perspective on what security... Read More →
Sunday September 13, 2026 10:00am - 10:50am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

11:00am CDT

Slaying the Sprawl: A Hero’s Guide to Building (or Re-Forging) a Cloud Security Program Without a 20-Person Guild
Sunday September 13, 2026 11:00am - 11:50am CDT
Whether you are standing before a pristine, untouched Cloud Kingdom or inherited a crumbling fortress held together by "Native Tooling" duct tape and hope, the quest remains the same: How do you defend the realm without hiring an army you can’t afford? 


In this 40-minute campaign, we aren’t just looking at the map, we’re looking at the scars. Building a cloud security program from scratch is one thing; evolving an established one while the dragons are already circling is another. Drawing from real-world lessons learned in the DevOps trenches, this session explores the "Day 0" decisions and the "Year 2" regrets of choosing between Native Security Tooling and a unified CNAPP.


We’ll sit around the tavern table to discuss the hard-won truths of cloud defense:


- The "Free" Sword’s Hidden Cost: Real-life tales of how "built-in" tools led to siloed alerts, requiring a 20-person "manual correlation guild" just to find a single critical risk.
- Re-Forging the Armor: For those with established programs—how to transition from a "Franken-stack" of point tools to a unified platform without breaking the kingdom’s production.
- The "Agentless" Treaty: Lessons learned from the "Agent Wars." How moving to agentless visibility (the Rogue's Cloak) saved our DevOps relationships and gave us 100% visibility in hours, not months.
- The Multi-Cloud Map: Navigating the treacherous terrain of AWS, Azure, and beyond without losing your mind or your budget to "Console Swapping" fatigue.


Whether you are a Solo Adventurer starting a new program or a War-Weary Veteran trying to consolidate a sprawling one, you’ll leave with a battle-tested blueprint for a security program that scales with your magic, not your headcount, HUZZAH!
Speakers
avatar for Steve Turner

Steve Turner

Cloud Security Architect, Zelis Healthcare
Steve leads cloud security at Zelis Healthcare. He started his career through the trial by fire that is MSP life. He pivoted to securing everything from waste facilities and transportation infrastructure to huge financial services organizations and even mixed in some industry analysis... Read More →
Sunday September 13, 2026 11:00am - 11:50am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

12:00pm CDT

From Hours to Minutes With StealerLens: LLM-Accelerated Infostealer IR for Overwhelmed SOCs
Sunday September 13, 2026 12:00pm - 12:50pm CDT
Information stealer malware has quietly become one of the most consequential threats facing modern SOCs, with over 50 million stealer logs posted on underground channels in the last year alone. Each log is a comprehensive digital dossier on a single victim, and the sheer volume has created an analysis bottleneck that is impossible to address at scale.
This session opens with a technical deep dive into what an infostealer actually is and the strange artifact that is a stealer log. Beyond the obvious credentials and session cookies, stealer logs contain things defenders rarely expect: browser password manager extension data (BitWarden, Dashlane, KeePassXC), local KeePass vaults exfiltrated from disk, TOTP secrets leaked from Chrome extensions bypassing MFA, cryptocurrency wallet data, personal documents, and desktop screenshots captured at the exact moment of compromise. We will walk through the full attack surface and show why modern stealers are far more dangerous than "just a credential dump".
Buried inside each log are also forensic breadcrumbs left by the malware itself: execution paths, active processes, installed software, browser history, clipboard contents. These artifacts can reconstruct the infection vector and reveal the malware's behavior, but analyzing them manually takes hours per log. For an overwhelmed SOC triaging a steady stream of incidents, this analysis simply does not happen.
Building on our BlackHat USA 2025 work on LLM-based infection screenshot analysis ("Hackers Dropping Mid-Heist Selfies"), we introduce StealerLens, an LLM-powered forensic tool that collapses this workflow from hours to minutes. StealerLens uses a layered architecture where each log artifact (system info, software inventory, processes, browser history, clipboard, screenshots) is analyzed by a dedicated prompt. A final master prompt correlates the outputs into a cohesive infection narrative: likely source of infection, delivery vector, blast radius of exposed information, and pointing to the supporting evidence so the analyst can verify at a glance.
We will share the full prompt architecture, walk through real anonymized cases, discuss the limits we encountered across our test corpus. Attendees leave with a concrete blueprint for industrializing infostealer log analysis — and making room for the strategic work their SOC actually needs to do.
Speakers
avatar for Olivier Bilodeau

Olivier Bilodeau

Principal Cybersecurity Researcher, Flare
Olivier Bilodeau, a principal researcher at Flare, brings 15+ years of cutting-edge infosec expertise in honeypot operations, binary reverse-engineering, RDP interception and, more recently, fighting information stealer malware. Passionate communicator, Olivier spoke at conferences... Read More →
Sunday September 13, 2026 12:00pm - 12:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 3

1:00pm CDT

Why Incident Response Plans Fail Under Pressure
Sunday September 13, 2026 1:00pm - 1:50pm CDT
Most incident response plans do not fail because the document is missing. They fail because people do. Under pressure, some teams panic and abandon strategy. Others choke, overanalyze, and freeze. In both cases, the plan may be technically sound, but human performance and cross-functional coordination break down.
 
This session explores why comprehensive IR plans still collapse in real incidents, even in organizations with mature security programs and well-documented procedures. Through breach case studies and practical lessons from high-pressure performance, we will examine what traditional tabletop exercises and compliance-driven training rarely test: legal pressure, executive escalation, media scrutiny, conflicting incentives, and the absence of pre-authorized decisions.
 
Attendees will leave with a practical framework for making incident response more resilient. We will cover how to reduce panic through cognitive offloading and automation, how to reduce choking through pre-authorized response paths and role clarity, and how to design adaptive simulations that force teams to make decisions under realistic pressure. We will also discuss how blameless postmortems turn failure into better instincts for the next crisis.
 
The goal is not a better-looking incident response plan. The goal is a response culture that still works when the facts are incomplete, the stakes are high, and every minute counts.
Speakers
avatar for Ron Dilley

Ron Dilley

CISO, Reflex Security
Ron Dilley works at Reflex Security as the Field CISO, focusing on technical evangelism, channel management, and community presence, while pushing the boundaries of what's possible in technology to deliver exceptional value for clients. He is also on the IANS Research Faculty, a speaker... Read More →
Sunday September 13, 2026 1:00pm - 1:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
 
Blue Team Con 2026
From $0.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.