BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-bristol-2026//speaker//SZPDBL
BEGIN:VTIMEZONE
TZID:Europe/London
BEGIN:DAYLIGHT
DTSTART:20250821T000000
TZNAME:BST
TZOFFSETFROM:+0100
TZOFFSETTO:+0100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T020000
RDATE:20261025T020000
TZNAME:GMT
TZOFFSETFROM:+0100
TZOFFSETTO:+0000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T020000
RDATE:20270328T020000
TZNAME:BST
TZOFFSETFROM:+0000
TZOFFSETTO:+0100
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:They Hacked Me. I Took Their Source Code. - David Rushmer
DTSTART;TZID=Europe/London:20260821T113000
DTEND;TZID=Europe/London:20260821T115000
DTSTAMP:20260812T225140Z
UID:pretalx-bsides-bristol-2026-JCEHSW@pretalx.com
DESCRIPTION:This talk walks through how a $20 piece of cloud infrastructur
 e became a fully functional threat intelligence pipeline. Starting with a 
 simple honeypot\, we capture an inbound attack\, pivot back against the at
 tacker's infrastructure using a reverse scan\, discover an open staging se
 rver\, and walk away with something most researchers only dream of — the
  actual source code behind the malware.\nNo enterprise budget. No team. No
  expensive tooling. Just cheap infrastructure\, some curiosity\, and attac
 kers with terrible opsec.\nWe'll walk through the full attack chain in rev
 erse — from the initial hit on the honeypot\, through the pivot and enum
 eration of attacker infrastructure\, to pulling the payload and source cod
 e from their own server. We'll then crack open both the binary in IDA Pro 
 and the source code side by side\, showing exactly what this bot was built
  to do and what the attacker left behind for anyone willing to look.\nThe 
 key takeaway is simple — you don't need a SOC\, a threat intel platform\
 , or a six figure budget to find real malware in the wild. Sometimes the a
 ttackers do half the work for you.
LOCATION:Track 2
URL:https://pretalx.com/bsides-bristol-2026/talk/JCEHSW/
END:VEVENT
END:VCALENDAR
