{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.3.0.dev0", "url": "https://pretalx.com"}, "schedule": {"url": "https://pretalx.com/bsides-cymru-2023-2022/schedule/", "version": "1.3", "base_url": "https://pretalx.com", "conference": {"acronym": "bsides-cymru-2023-2022", "title": "Bsides Cymru 2023", "start": "2023-02-11", "end": "2023-02-11", "daysCount": 1, "timeslot_duration": "00:05", "time_zone_name": "UTC", "colors": {"primary": "#F33535"}, "rooms": [{"name": "Track 1- Dragon Suite", "slug": "1732-track-1-dragon-suite", "guid": "884d07be-21e4-500b-99fe-04f6bf3e2acd", "description": "Main Hall", "capacity": 300}, {"name": "Track 2  -  Foxhunter", "slug": "1733-track-2-foxhunter", "guid": "83bd33cf-2983-5cf7-a669-cd69f90fa664", "description": "Foxhunter Suite", "capacity": 40}, {"name": "Track 3 (TTT) - St David's Suite", "slug": "1880-track-3-ttt-st-davids-suite", "guid": "d519e35e-31ca-5efb-bb47-a3f67dcadc79", "description": "St David's Suite", "capacity": 20}, {"name": "Workshops - Glamorgan Suite", "slug": "1735-workshops-glamorgan-suite", "guid": "c96633f0-0771-5b87-acbf-7f9ac5351c8c", "description": "Glamorgan Suite", "capacity": 22}, {"name": "Workshops - ClockTower", "slug": "1734-workshops-clocktower", "guid": "e67fdeb2-15fa-5cae-8c23-186b1d94303a", "description": "Clocktower Room", "capacity": 12}, {"name": "Workshops Clocktower (more)", "slug": "2009-workshops-clocktower-more", "guid": "a4f7a4a6-0019-5f66-b72c-4f1cead60bc8", "description": null, "capacity": 12}], "tracks": [{"name": "Main Track", "slug": "3162-main-track", "color": "#0A0A0A"}], "days": [{"index": 1, "date": "2023-02-11", "day_start": "2023-02-11T04:00:00+00:00", "day_end": "2023-02-12T03:59:00+00:00", "rooms": {"Track 1- Dragon Suite": [{"guid": "5b2b6900-2cc8-5b09-ac8f-ad4fc89e7647", "code": "TXUJF3", "id": 27800, "logo": null, "date": "2023-02-11T09:00:00+00:00", "start": "09:00", "end": "2023-02-11T09:10:00+00:00", "duration": "00:10", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-27800-opening-speech", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/TXUJF3/", "title": "Opening Speech", "subtitle": "", "track": null, "type": "Pecha Kucha", "language": "en", "abstract": "Hello and Welcome!", "description": "Hello and Welcome!", "recording_license": "", "do_not_record": true, "persons": [{"code": "MR3GJU", "name": "Craig Jones, Clare Johnson + Stuart Criddle", "avatar": null, "biography": null, "public_name": "Craig Jones, Clare Johnson + Stuart Criddle", "guid": "8791c352-d2af-5547-8f6d-2cde375d8e35", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/MR3GJU/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/TXUJF3/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/TXUJF3/", "attachments": []}, {"guid": "1451a81f-bd7e-5fd8-b86c-cf89fbff3a5d", "code": "ECGZYB", "id": 27377, "logo": null, "date": "2023-02-11T09:15:00+00:00", "start": "09:15", "end": "2023-02-11T09:45:00+00:00", "duration": "00:30", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-27377-keynote-speech", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/ECGZYB/", "title": "Keynote Speech", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Keynote/Opening Speech", "description": "Keynote/Opening Speech", "recording_license": "", "do_not_record": false, "persons": [{"code": "QQLZ8N", "name": "John Shier", "avatar": "https://pretalx.com/media/avatars/QQLZ8N_2zkQdDZ.webp", "biography": "John Shier is a Senior Research Scientist at Sophos. John is a popular presenter at security events, and is well-known for the clarity of his advice, even on the most complex security topics. He has researched everything from costly ransomware to illicit dark web activity, uncovering insights needed to strengthen cybersecurity defenses.\n\nJohn is often consulted by press, and has been quoted in publications like Reuters, WIRED, The Register, Fortune, CNN, The Hill, Fast Co, Yahoo, and more. He\u2019s also a frequent speaker at industry events like RSA Conference, Infosec, GITEX, BSides and more.", "public_name": "John Shier", "guid": "8d653205-742e-579f-b470-228cd0ebb9f4", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/QQLZ8N/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/ECGZYB/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/ECGZYB/", "attachments": []}, {"guid": "306d92e4-e710-58bc-b0ab-606a1fbae678", "code": "BZQBXJ", "id": 23229, "logo": null, "date": "2023-02-11T09:50:00+00:00", "start": "09:50", "end": "2023-02-11T10:35:00+00:00", "duration": "00:45", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-23229-let-that-think-in-thought-experiments-and-their-application-to-cyber-security", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/BZQBXJ/", "title": "Let that think in: Thought experiments and their application to cyber security", "subtitle": "", "track": null, "type": "Talk - long", "language": "en", "abstract": "Thought experiments are used in many disciplines - from theoretical physics and biology to linguistics and law - to question assumptions and generate new theories. Perhaps most prominently, they are a critical tool in philosophy, where their usage goes back thousands of years to Socrates and Plato. The insights and knowledge that rigorous, carefully considered thought experiments provide have completely revolutionized thinking in various fields. And yet, in cyber security, we haven\u2019t made much use of them at all, and certainly not in any organized or formalized manner. This talk is an attempt to begin changing that.\n\nIn this session, I\u2019ll provide a primer on thought experiments, covering their definitions, types, features, construction, usage, and outputs. I\u2019ll examine some examples, discuss the drawbacks, and explore some unconventional forms which use different formats and ways of thinking.\n\nI\u2019ll then move on to argue a case for using thought experiments more widely in cyber security. I\u2019ll start by focusing on how thought experiments differ from similar activities in security \u2013 such as tabletop exercises and \u2018thinking like an attacker\u2019 \u2013 and suggest several related areas in which thought experiments have proven useful previously, such as AI and cryptography, with examples.\n\nNext, I\u2019ll outline why we need more thought experiments in cyber security, identifying several areas in which they could be used to question common assumptions and theories, and I\u2019ll present some thought experiments I\u2019ve created in these areas, which I\u2019ll invite attendees to use and build on as a starting point for further discussion and exploration.\n\nI\u2019ll then share a guide for creating thought experiments, as a first step towards encouraging their wider design and use in the field of security, and finish by calling for collaboration and cooperation to continue this.", "description": "Brief outline of the talk:\n\n1. INTRODUCTION: who I am, what I do; my interest in thought experiments; aims of the talk\n\n2. WHAT IS A THOUGHT EXPERIMENT? Competing definitions; history and examples in various fields (philosophy, physics, law); types of thought experiment (destructive, constructive, platonic); format and usage (how they're presented; unfolding of scenario; why they should be used, Kuhnian crises); outputs (models); caveats (biases, where does new knowledge come from, idealisation, imagination as a negative); unusual forms (koans, fiction)\n\n3. APPLICATIONS TO CYBER SECURITY: Background (usage, distinction vs. tabletop exercises, scenarios, 'thinking like an attacker'); why we need thought experiments (Kuhnian crisis, challenging assumptions); examples of pre-existing thought experiments in related areas (AI, cryptography, privacy); benefits; examples (adapting pre-existing thought experiments and coming up with new ones - examples include attribution, innovation, cyberweapons)\n\n4. HOW TO DESIGN A THOUGHT EXPERIMENT: destructive and constructive forms; outline of the process\n\n5. CONCLUSION: Reiterate aims; first step; call for collaboration and cooperation; references, contact details, and questions.", "recording_license": "", "do_not_record": false, "persons": [{"code": "CN8NKN", "name": "Matt Wixey", "avatar": "https://pretalx.com/media/avatars/CN8NKN_kGCAQRw.webp", "biography": "Matt Wixey is a Principal Technical Editor and Senior Threat Researcher at Sophos. He is a former penetration tester, and previously led cybersecurity R&D capabilities at both PwC UK and a specialist unit in the Metropolitan Police Service, digging into emerging attack vectors, vulnerabilities, and new technologies. Matt has spoken at national and international conferences, including Black Hat USA, DEF CON, ISF Annual Congress, BSides LDN, 44con, and BruCon.", "public_name": "Matt Wixey", "guid": "9f57518d-b3d2-5c08-8df8-53df95ebaa84", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/CN8NKN/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/BZQBXJ/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/BZQBXJ/", "attachments": []}, {"guid": "5c1e0540-5121-5456-9d27-f247ccca6061", "code": "YQR3J7", "id": 22963, "logo": null, "date": "2023-02-11T10:40:00+00:00", "start": "10:40", "end": "2023-02-11T11:10:00+00:00", "duration": "00:30", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-22963-fangxiao-a-chinese-phishing-threat-actor", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/YQR3J7/", "title": "Fangxiao, a Chinese phishing threat actor", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Fake survey sites, dating scams, shell companies, and Chinese threat actors - oh my! A walkthrough of Fangxiao, a phishing threat actor, covering their TTPs, IOCs, and how we attributed their activities.", "description": "Have you ever seen a fake survey site spready by WhatsApp? If so, you might have interacted with Fangxiao. Starting from a single phishing website, this talk will cover how we identified tens of thousands of phishing domains and de-anonymised domains behind Cloudflare. Pivoting across sites, we uncover a shady world of lead generation agencies, fake dating sites, and a frankly ridiculous number of domains. We will explain how we identified and tracked the group behind these sites and discuss their operational security failures.", "recording_license": "", "do_not_record": false, "persons": [{"code": "YQ3G7G", "name": "Emily Dennison", "avatar": null, "biography": "Emily is a CTI analyst at Cyjax and a student. In her spare time she can be found tinkering with all kinds of electronics and 3D printers, or buried in a book. She tweets from @nyxilar.", "public_name": "Emily Dennison", "guid": "c36f7f17-5d2c-5299-92bb-9f89a96eed5b", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/YQ3G7G/"}, {"code": "LST399", "name": "Alana Witten", "avatar": "https://pretalx.com/media/avatars/LST399_9zmfz9P.webp", "biography": "Hey!\n\nI'm a security enthusiast with a background in web hacking and VDPs, and an interest in OSINT investigations and threat intelligence. My CV looks like a bad game of scrabble with the amount of letters I've picked up from working with various organisations and completing certs.\n\nI've read thousands of bug reports and write synopses and other security topics in the forms of blogs (https://medium.com/@nynan) and I write bash one liners and regexes so horrific that HP Lovecraft couldn't dream of on twitter (https://twitter.com/_nynan).", "public_name": "Alana Witten", "guid": "842f5c97-4575-51b3-b178-41231e9b38e9", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/LST399/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/YQR3J7/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/YQR3J7/", "attachments": []}, {"guid": "a9d69717-f3f5-566c-a38b-fa074d65432d", "code": "YCASUH", "id": 23091, "logo": null, "date": "2023-02-11T11:15:00+00:00", "start": "11:15", "end": "2023-02-11T12:00:00+00:00", "duration": "00:45", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-23091-electryone-in-the-land-with-no-sun", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/YCASUH/", "title": "Electryone: In the land with no sun", "subtitle": "", "track": null, "type": "Talk - long", "language": "en", "abstract": "During this talk, we will see that many photovoltaic (PV) inverters suffer from typical \"rush to market\" problems that can introduce weaknesses and potentially allow a remote attacker to fully control or brick them.", "description": "Targeting an installer cloud means that a successful attack would give elevated access to the inverters , including functions not accessible to PV\u2019s owners.\n\nIn this talk we are going to review how attacking a PV installer cloud could lead to taking hundreds of thousands of inverters offline and introduce instability into countries\u2019 power grids.\n\nAll attacks are remotely exploitable and a result of logic flaws introduced by the web portals\u2019 developers. Those logic flaws vary from simple Insecure Direct Object References (IDORs) to self-promoting your user to platform admin.", "recording_license": "", "do_not_record": false, "persons": [{"code": "K8J3L9", "name": "Vangelis Stykas", "avatar": "https://pretalx.com/media/avatars/K8J3L9_hyfh2A0.webp", "biography": "Vangelis is a developer as well as Senior Penetration Tester. His research is mainly in API and web application security.\n\nHis academic research is focused on machine learning and the development of proactive web application security.\n\nDuring his free time Vangelis helps start-ups secure themselves on the internet and get a leg-up on security.\n\nDuring the past years he has published research regarding API control functions for ships, smart locks, IP cameras, EV chargers and many other IoT devices.", "public_name": "Vangelis Stykas", "guid": "32a1b099-c9fc-5f35-8790-aed534f09cd2", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/K8J3L9/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/YCASUH/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/YCASUH/", "attachments": []}, {"guid": "2828e929-81a6-5c18-a68a-c01e29b88dd8", "code": "EN7TT3", "id": 27379, "logo": null, "date": "2023-02-11T12:05:00+00:00", "start": "12:05", "end": "2023-02-11T13:05:00+00:00", "duration": "01:00", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-27379-lunch-click-for-menu", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/EN7TT3/", "title": "Lunch - Click for Menu", "subtitle": "", "track": null, "type": "Talk - long", "language": "en", "abstract": "Lunch - click for menu.", "description": "Lunch will be a buffet and cater for a spectrum of dietary requirements: \n\u2022\tSalad boxes including- \n\u2022\tGreen salads, \n\u2022\tColeslaw, \n\u2022\tMediterranean couscous \n\u2022\tTomato salad \n \n\u2022\tWith a choice of Caesar chicken, bbq chicken, teriyaki salmon, selection of cheese and then dietary appropriate options- these will be labelled for self-service and collection. \n \n\u2022\tRustic Bread roll selection\n\u2022\tAssortment of sweet treats- carrot cakes, muffins, mini cakes, cookies \n\u2022\tPackets of crisps- assorted flavours  \n\u2022\tAssortment of soft drinks \n \nAny special dietary requirements provided in advance will be labelled and accessible.", "recording_license": "", "do_not_record": true, "persons": [{"code": "MR3GJU", "name": "Craig Jones, Clare Johnson + Stuart Criddle", "avatar": null, "biography": null, "public_name": "Craig Jones, Clare Johnson + Stuart Criddle", "guid": "8791c352-d2af-5547-8f6d-2cde375d8e35", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/MR3GJU/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/EN7TT3/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/EN7TT3/", "attachments": []}, {"guid": "4ad95dfb-342a-589c-81a5-ba9106bd4658", "code": "VXJRWD", "id": 24311, "logo": null, "date": "2023-02-11T13:15:00+00:00", "start": "13:15", "end": "2023-02-11T13:45:00+00:00", "duration": "00:30", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-24311-bohemian-icedid-queen-of-loaders", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/VXJRWD/", "title": "Bohemian IcedID - Queen of Loaders", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "This talk provides an insight into Team Cymru's tracking of IcedID over the past 24 months, following its transition from banking trojan to all-round loader malware. We will demonstrate how we identify potential bot and loader C2 infrastructure through our network telemetry data, and provide confirmation of these findings through config extraction.", "description": "IcedID (also referred to as BokBot) first appeared in early 2017 as a 'traditional' banking trojan leveraging webinjects to steal financial information from victims. Since this time, it has evolved to include dropper functionality, and is now primarily used as a vehicle for the delivery of other tools, such as Cobalt Strike, and the eventual deployment of ransomware.\n\nIcedID itself is commonly delivered in phishing (spam) campaigns, leveraging an assortment of lure types and execution processes.\n\nIcedID has two stages to its initial command and control (C2) communications, prior to further tools being downloaded on the victim host. Patterns in the way these C2 communications are setup and appear in network telemetry data allow us to follow threat actor campaigns, often from a starting point of 'pre-spam' (before infrastructure is used actively in the wild).\n\nWe look forward to sharing more details in our talk!", "recording_license": "", "do_not_record": true, "persons": [{"code": "JTDXQM", "name": "Josh Hopkins", "avatar": "https://pretalx.com/media/avatars/JTDXQM_I9UKVH7.webp", "biography": "Now leading the internal S2 research team, Josh has been an analyst with Team Cymru for the past six years. Specialising in the tracking of infrastructure for a diverse target set that includes both nation state and criminal threat actors. Josh has an extensive background in law enforcement and national security investigations.", "public_name": "Josh Hopkins", "guid": "b7549956-9115-54fc-af07-6d61c312c333", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/JTDXQM/"}, {"code": "XXXBKS", "name": "Thibault Seret", "avatar": "https://pretalx.com/media/avatars/XXXBKS_n7Crxxe.webp", "biography": "Thibault Seret is a researcher on the Team Cymru Research Team. He is\ncurrently focusing on crimeware and APT analysis and research, reverse engineering\nand threat intelligence, and trying to fight against bad guys. Before joining Team\nCymru, he worked as a Threat Researcher in McAfee\u2019s ATR team, as cybercrime\nanalyst in a banking institution with the mission to improve the digital forensics\ndepartment, and as a CERT analyst at an IT services company where he tried to save\nthe world with his teammate. He participates a lot in the security community and\nCTF competitions and is a teacher for the new generation of cyber defenders. For\nthe Alliance!", "public_name": "Thibault Seret", "guid": "47a7b1be-54e1-5b3a-b05d-fcaed29e3d06", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/XXXBKS/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/VXJRWD/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/VXJRWD/", "attachments": []}, {"guid": "2d05f3f9-61f9-5398-b29b-fe698b0480b8", "code": "QVMLF3", "id": 23053, "logo": null, "date": "2023-02-11T13:55:00+00:00", "start": "13:55", "end": "2023-02-11T14:25:00+00:00", "duration": "00:30", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-23053-the-office-of-danger-a-choose-your-own-adventure-story", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/QVMLF3/", "title": "The Office of Danger: A Choose Your Own adventure story!", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Have you always wanted to know what type of decisions are required for a Social Engineering engagement but never get the opportunity to find out? Well look no further! \nThe Office of Danger: A Choose Your Own Adventure Story lets the audience make real world decisions on a social engineering engagement. \nWill you be able to bypass security and reach your target? Or will your choices get your caught as soon as you enter? \nThe choice is in your hands!", "description": "The Office of Danger: A Choose Your Own adventure story! This session will put the audience in the driving seat of a real-life social engineering engagement against a high security office building in central London. \nSimulating the high-pressure environment of a social engineering engagement, the slides will present the audience with a choice that must be made quickly to avoid detection, unlock new areas of the office and achieve their objective. \nSo, what will you do?\n\u2022\tHead for the stairs or the elevator?\n\u2022\tSweet talk the receptionist, or try and blend in with the crowd?\n\u2022\tRun as quickly as you can from Security, or hide in the toilet?\nYou are presented with two options to take each adventure in a unique direction, with over 30 different choices to be made, resulting in a different and unique presentation each time! \nThis is the first of its kind talk, which puts you in the driving seat and shows the level of quick thinking that is needed to avoid detection and reach your targets!", "recording_license": "", "do_not_record": false, "persons": [{"code": "TWAHFW", "name": "Phil Eveleigh", "avatar": "https://pretalx.com/media/avatars/TWAHFW_SXaeODJ.webp", "biography": "Phil is a professional penetration tester working in the UK.. He has been a pen tester for the past four years and has completed numerous engagements across different sectors for all sizes of clients. He has written dozens of blogs covering different areas of testing, including: introductions to hardware hacking; threat modelling; owning a company through admin password reuse; and an investigating into an anti-5G USB key which caught the attention of the mainstream media. Phil was also co-speaker at DEF CONs Aviation Village discussing hacking legacy in-flight entertainment systems in retired 747s.\n\nPhil has completed several social engineering jobs: breaking into buildings both big and small, well protected, and not so much. Forever wondering \u201cwhat is behind that door\u201d has somehow turned into a job, and a quizzical mind combined with quick thinking has allowed him to bypass some brilliant security measures and gain access into some very interesting areas.", "public_name": "Phil Eveleigh", "guid": "b3664ef4-4424-5ab9-9869-8f3ab813dbaa", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/TWAHFW/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/QVMLF3/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/QVMLF3/", "attachments": []}, {"guid": "d67e6fe0-1abc-5011-94e3-e9ea1df0c631", "code": "8JRWD9", "id": 24280, "logo": "https://pretalx.com/media/bsides-cymru-2023-2022/submissions/8JRWD9/polar_orbit_udb1MQn.png", "date": "2023-02-11T14:30:00+00:00", "start": "14:30", "end": "2023-02-11T15:00:00+00:00", "duration": "00:30", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-24280-hacking-to-defend-how-we-hacked-into-a-polar-orbit-satellite-and-managed-to-get-a-full-system-compromise", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/8JRWD9/", "title": "Hacking to defend: How we hacked into a Polar Orbit Satellite and managed to get a full system compromise", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Initial discovery was from a Discord message; Some people were talking about having access to a Polar Orbit Satellite due to it not having any authentication. We knew this was a risk in the wrong hands. We decided to research the Web Application shortly after, we were able to get a shell and escalate our privileges. While on the system we managed to identify privilege escalation vectors while also performing source code analysis where we found further command injection vulnerabilities. To ensure other hackers do not kill our shell and patch the bug to perform malicious activities, we created a backup shell for president access!", "description": "While researching a Polar Orbit Satellite we managed to identify a critical vulnerability allowing full system compromise, we managed to completely own the box within a time span of a few hours. The vulnerabilities were reported and patched.", "recording_license": "", "do_not_record": false, "persons": [{"code": "S3VMBS", "name": "James (0xJay)", "avatar": "https://pretalx.com/media/avatars/S3VMBS_9O3GVja.webp", "biography": "I am James, I am 16. I work in Cyber Security as a Junior Security Analyst and an Offensive Web Application Trainer for HackTheBox. I have a background in Offensive Hacking/Penetration Testing. I started at a young age and went down the wrong path where I was investigated and arrested by the National Crime Agency/Federal Bureau of Investigation. I am eJPT Certified and thanked by various companies for reporting vulnerabilities.", "public_name": "James (0xJay)", "guid": "ec5ebe91-10f0-5953-8f7f-92a0e5ed9658", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/S3VMBS/"}, {"code": "9KXUU9", "name": "Josh Allman", "avatar": null, "biography": "My name is Josh, I am 23. I currently work as a Threat Operations Analyst for @HuntressLabs where I am able to defend against a variety of attacks and put Defensive/Forensics techniques into practice. \nLover of all things including IoT, Offensive Sec, Threat intelligence and more.", "public_name": "Josh Allman", "guid": "a39b5192-1cfd-50b9-8bce-0c01b1103ad0", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/9KXUU9/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/8JRWD9/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/8JRWD9/", "attachments": []}, {"guid": "aa863244-4bae-547b-9974-55ebefd4eca8", "code": "FEPNNU", "id": 24143, "logo": null, "date": "2023-02-11T15:10:00+00:00", "start": "15:10", "end": "2023-02-11T15:55:00+00:00", "duration": "00:45", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-24143-bypassing-anti-virus-using-badusb", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/FEPNNU/", "title": "Bypassing Anti-Virus using BadUSB", "subtitle": "", "track": null, "type": "Talk - long", "language": "en", "abstract": "Agenda for the presentation:\n- AMSI Bypass Development\n- Execution Policy Bypass\n- Payload Runner Development\n- Deploying Attack using BadUSB\n- Post-Exploitation Persistence\n- DEMO\n- Prevention", "description": "During this presentation, we will take a look over how we can bypass most Anti-Virus detection using a payload embedded on a BadUSB device, resulting in a silver bullet for gaining initial access inside a victim network. Demo will be also included during the presentation.", "recording_license": "", "do_not_record": false, "persons": [{"code": "7JYAU8", "name": "Cristian Cornea", "avatar": "https://pretalx.com/media/avatars/7JYAU8_iBhFp74.webp", "biography": "- OSEP | OSWE | OSCP | CEH | CPTC | PenTest+ | eWPT | ECIH | CREST\n- Founder of Zerotak Security | Co-Founder of Cyber Union\n- Providing pentesting & security consultation for clients all over the world:  Australia, U.S., U.K., Middle East, Singapore, India, Central Africa, Europe.\n- Trainer for U.S. Department of Defense, Slovenian National Bureau of Investigation, Polish Military CERT\n- Speaker @ Defcamp, HEK.SI, RST Con, HackTheZone, Unbreakable\n- EC-Council Certified Ethical Hacker (CEH) Scheme Committee Member\n- InfoSec Writer on Medium", "public_name": "Cristian Cornea", "guid": "6294cf69-dc0f-5378-9e89-8bbeed2c84b6", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/7JYAU8/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/FEPNNU/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/FEPNNU/", "attachments": []}, {"guid": "933b01cc-422f-55f6-81be-8426a03e254a", "code": "BNC8W3", "id": 23077, "logo": null, "date": "2023-02-11T16:00:00+00:00", "start": "16:00", "end": "2023-02-11T16:30:00+00:00", "duration": "00:30", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-23077-needles-without-the-thread-threadless-process-injection", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/BNC8W3/", "title": "Needles Without the Thread: Threadless Process Injection", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Most process injection techniques typically involve creating remote threads within the target process.  This often exposes opportunities for EDR detection engines to pick up the malicious activity.  This talk will cover some of the existing methods used today followed by a novel technique that can inject and execute code into a remote process without some of these common indicators.", "description": "As red teamers, we always find ourselves in a cat and mouse game with the blue team.  Many Anti-virus and EDR solutions over the past 10 years have become significantly more advanced at detecting fileless malware activity in a generic way.  \n\nProcess injection, a technique used for executing code from within the address space of another process is a common method within the offensive operator\u2019s toolbox.  Commonly used to mask activity within legitimate processes such as browsers and instant messaging clients already running on the target workstation.\n\nWithin the last 2 years, tools such as Sysmon have added new detections and events for process injection along with big improvements in detections within commercial EDR space.\nWith this in mind, a new method of injection was researched that would not fall foul to the traditional methods that are often detected today. \n\nThroughout the talk we will cover some of these traditional process injection techniques followed by a technical dive into the novel method that was researched and release a corresponding open-source tool that leverages the technique.", "recording_license": "", "do_not_record": false, "persons": [{"code": "3D8NMB", "name": "Ceri Coburn", "avatar": null, "biography": "After a 20 career within the software development space I was looking for a new challenge and moved into pen testing back in 2019.  During that time I have created and contributed to several open source offensive tools such as Rubeus, BOFNET and SweetPotato and on the odd occasion contributed to projects on the defensive side too.", "public_name": "Ceri Coburn", "guid": "ce78376f-a157-5b6f-8ff6-fcab1806c7c7", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/3D8NMB/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/BNC8W3/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/BNC8W3/", "attachments": []}, {"guid": "15329746-879f-531b-9d68-1f52d752f7cd", "code": "VCTQJK", "id": 27378, "logo": null, "date": "2023-02-11T16:40:00+00:00", "start": "16:40", "end": "2023-02-11T16:40:00+00:00", "duration": "00:00", "room": "Track 1- Dragon Suite", "slug": "bsides-cymru-2023-2022-27378-closing-speech", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/VCTQJK/", "title": "Closing Speech", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Thanks and details of the afterparty", "description": "A short thanks to everyone and details of the afterparty.", "recording_license": "", "do_not_record": false, "persons": [{"code": "MR3GJU", "name": "Craig Jones, Clare Johnson + Stuart Criddle", "avatar": null, "biography": null, "public_name": "Craig Jones, Clare Johnson + Stuart Criddle", "guid": "8791c352-d2af-5547-8f6d-2cde375d8e35", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/MR3GJU/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/VCTQJK/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/VCTQJK/", "attachments": []}], "Track 2  -  Foxhunter": [{"guid": "670feeac-0e3d-5ec7-9736-c0fd26f08b11", "code": "AGYTSR", "id": 23493, "logo": null, "date": "2023-02-11T09:50:00+00:00", "start": "09:50", "end": "2023-02-11T10:35:00+00:00", "duration": "00:45", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-23493-robots-for-complete-beginners", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/AGYTSR/", "title": "Robots for Complete Beginners", "subtitle": "", "track": null, "type": "Talk - long", "language": "en", "abstract": "An introduction on how to build robots. For complete beginners.", "description": "Robots look fun, right? We'd all love to build robots... but how?\n\nThis talk is about the \"how\". Using some tools that most of us will be familiar with (Lego!!) and some that are perhaps less familiar... but easy (Arduino) we'll examine how to turn an off-the-shelf toy into something more special.", "recording_license": "", "do_not_record": false, "persons": [{"code": "73F93W", "name": "Mark Goodwin", "avatar": "https://pretalx.com/media/avatars/73F93W_3g2ruAw.webp", "biography": "Mark is a software developer turned security specialist and has worked in Application Security for almost 20 years.", "public_name": "Mark Goodwin", "guid": "83be738f-b972-581b-921c-133dff53a479", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/73F93W/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/AGYTSR/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/AGYTSR/", "attachments": []}, {"guid": "c80072d0-4cfa-51a8-ab32-192530484840", "code": "TXYBVN", "id": 23588, "logo": null, "date": "2023-02-11T10:40:00+00:00", "start": "10:40", "end": "2023-02-11T11:10:00+00:00", "duration": "00:30", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-23588-verify-then-trust", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/TXYBVN/", "title": "Verify, then Trust", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Dr Jennings presents a session on how to identify 'experts' using false credentials and accomplishments to establish their reputation.", "description": "From dummy think tanks to false academic credentials and degree mills, Dr Jennings, author of the acclaimed book on establishing false identities 'When You're Not You', presents a fascinating session on how people claim false authority. Covering everything from the principles of influence involved, to the techniques, and how to verify the claims people make.", "recording_license": "", "do_not_record": false, "persons": [{"code": "AYEWSD", "name": "Rick Jennings", "avatar": null, "biography": "Dr Rick Jennings is an acclaimed expert in the field of false identities and credential claims, and has been researching in the field for over a decade. Among other works, he is the author of the recognised authoritative text on the subject 'When You're Not You: Identity and Credential Falsification Through the Ages' and has presented keynotes at a number of globally renowned events.", "public_name": "Rick Jennings", "guid": "0c0bc549-b51d-55cf-b86b-fc2c4612ed7c", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/AYEWSD/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/TXYBVN/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/TXYBVN/", "attachments": []}, {"guid": "dc13fe30-f7e5-5761-91e6-b0e811f3cc19", "code": "QKGJMM", "id": 24683, "logo": null, "date": "2023-02-11T11:15:00+00:00", "start": "11:15", "end": "2023-02-11T11:25:00+00:00", "duration": "00:10", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-24683-extending-the-capabilities-of-dependency-modelling-for-risk-identification-in-an-ics-environment", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/QKGJMM/", "title": "Extending the capabilities of Dependency Modelling for Risk Identification in an ICS environment", "subtitle": "", "track": null, "type": "Pecha Kucha", "language": "en", "abstract": "Dependency modelling (DM) is a standardised approach proposed by the Open standard Institute as a methodology to manage risk and build trust between inter-dependent enterprises .  This approach aligns with the National Cyber Security Centre (NCSC)\u2019s advocacy of system-driven risk analysis.  measures risk as the degree of uncertainty - uncertainty that a system will be at a required (desired) state. DM is expressed as the probability of achieving the desired state of a goal and how it is impacted by things beyond the control, predictability or understanding of the system/process owner. These probabilities of events (nodes) change when the probabilities of some other events change. However, there exist limitations in the current expressions of DM that hinder its complete adaptation for risk identification in a complex environment such as ICS. This research investigates how the capability of DM could be extended to address the identified limitations and proposes additional variables to address phenomena that are unique to ICS environments. The proposed extension is built into a system-driven, ICS dependency modeller, and we present an illustrative example using a scenario of a generic ICS environment. We reflect that the proposed technique supports an improvement in the initial user data input in the identification of areas of risk at the enterprise, business process, and technology levels.", "description": "Dependency modelling (DM) is a standardised approach proposed by the Open standard Institute as a methodology to manage risk and build trust between inter-dependent enterprises .  This approach aligns with the National Cyber Security Centre (NCSC)\u2019s advocacy of system-driven risk analysis.  measures risk as the degree of uncertainty - uncertainty that a system will be at a required (desired) state. DM is expressed as the probability of achieving the desired state of a goal and how it is impacted by things beyond the control, predictability or understanding of the system/process owner. These probabilities of events (nodes) change when the probabilities of some other events change. However, there exist limitations in the current expressions of DM that hinder its complete adaptation for risk identification in a complex environment such as ICS. This research investigates how the capability of DM could be extended to address the identified limitations and proposes additional variables to address phenomena that are unique to ICS environments. The proposed extension is built into a system-driven, ICS dependency modeller, and we present an illustrative example using a scenario of a generic ICS environment. We reflect that the proposed technique supports an improvement in the initial user data input in the identification of areas of risk at the enterprise, business process, and technology levels.", "recording_license": "", "do_not_record": false, "persons": [{"code": "79AJ89", "name": "Ayo Rotibi", "avatar": null, "biography": null, "public_name": "Ayo Rotibi", "guid": "016846a2-3221-55b2-8edd-1849a0478757", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/79AJ89/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/QKGJMM/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/QKGJMM/", "attachments": []}, {"guid": "4d3d0207-b23d-5358-972f-707a50f01cbd", "code": "GPH7YY", "id": 24760, "logo": null, "date": "2023-02-11T11:30:00+00:00", "start": "11:30", "end": "2023-02-11T11:40:00+00:00", "duration": "00:10", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-24760-developing-cybersecurity-curriculum-for-secondary-school", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/GPH7YY/", "title": "Developing cybersecurity curriculum for secondary school", "subtitle": "", "track": null, "type": "Pecha Kucha", "language": "en", "abstract": "Nowadays, many educational providers worldwide have started teaching cyber security courses for school students due to rising interest from students. As a result, cyber security developer programs need help building a competent cyber security curriculum that is relevant and nurturing student performance throughout their leading journey.\nIn addition, teachers at the secondary school level need more recent and up-to-date experience and need more relevant resources. \nConsequently, It is crucial to address how cyber security will be delivered within the curriculum to secondary schools. This paper analyses different computer science curricula in eight countries and the extra curriculum worldwide.\nThe analysis estimates that in many countries, cyber security educated was addressed inconsistently, embedded in various curriculum content areas. The existing curricula could have offered more support for teachers to educate the nature, aims, and pedagogical identifications of\nCyber security. Comparing the curricula raised some critical challenges faced by cyber security in secondary school. These challenges are discussed in the paper alongside the proposed way of  addressing them.", "description": "This study answers the following essential questions: (1) what the challenges of teaching cyber security between 12 to 15 are?\n(2) How is cyber security education addressed in secondary school curricula worldwide? (3) What are the issues with the existing cyber security curricula worldwide?", "recording_license": "", "do_not_record": false, "persons": [{"code": "MTWS9U", "name": "Maha Alotaibi1", "avatar": null, "biography": null, "public_name": "Maha Alotaibi1", "guid": "e0b2deff-49e6-5753-a776-51b138b1867c", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/MTWS9U/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/GPH7YY/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/GPH7YY/", "attachments": []}, {"guid": "30d32cf6-9910-5145-b26a-8dd970ae0414", "code": "RX87LC", "id": 24126, "logo": null, "date": "2023-02-11T11:45:00+00:00", "start": "11:45", "end": "2023-02-11T11:55:00+00:00", "duration": "00:10", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-24126-trust-blame-in-self-driving-cars-following-a-cyber-attack", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/RX87LC/", "title": "Trust & Blame in Self-Driving Cars Following a Cyber Attack", "subtitle": "", "track": null, "type": "Pecha Kucha", "language": "en", "abstract": "Even as our ability to counter cyber attacks improves, it is inevitable that threat actors may compromise a system through either exploited vulnerabilities and/or user error. It is therefore important to understand the factors which influence trust and blame in a self-driving car following a successful cyber attack.", "description": "One increasingly pertinent concern related to self-driving car technology (and its connected infrastructure) is the potential for it to be cyber attacked.  Should (or when) an adverse experience occurs, such an event is likely to erode human trust in the technology and potentially inhibit its uptake. It is therefore important to understand who is blamed for the attack and how/when trust is affected so that appropriate cyber security measures can be implemented (pre and post attack) to mitigate its impact on users and other stakeholders.", "recording_license": "", "do_not_record": false, "persons": [{"code": "T39DAF", "name": "Victoria Marcinkiewicz", "avatar": "https://pretalx.com/media/avatars/T39DAF_MbjNrAe.webp", "biography": "Victoria is 2nd year PhD student based in the School of Psychology, Cardiff University and is part of the Doctoral Training Program (DTP) in Cyber Security Analytics. Her main research focus is on how self-driving cars would be blamed and trusted (or not) in the event of a cyber attack, and how the initial loss of trust in such technology could be countered by the human-machine interface (HMI). \nVictoria studied Criminology as an undergraduate at the University of Lincoln and went on to complete her Masters in Criminology and Social Research \u2013 Cyber Crime and Cyber Security at the University of Surrey. Around her studies, Victoria supports a related research project and has represented this team at international conferences and workshops. Victoria is also an established Cyber Security and Information Assurance Consultant.", "public_name": "Victoria Marcinkiewicz", "guid": "68afbe23-17e2-5e19-8a2e-2ffbd08efb2e", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/T39DAF/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/RX87LC/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/RX87LC/", "attachments": []}, {"guid": "e67e0172-9e2b-5843-a7f9-44e93d1a1e62", "code": "W9PAQ8", "id": 24406, "logo": null, "date": "2023-02-11T12:00:00+00:00", "start": "12:00", "end": "2023-02-11T12:10:00+00:00", "duration": "00:10", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-24406-a-review-of-intrusion-detection-systems-in-large-scale-iot-systems-challenges-approaches-and-needs", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/W9PAQ8/", "title": "A Review of Intrusion Detection Systems in Large-scale IoT Systems: Challenges, Approaches, and Needs", "subtitle": "", "track": null, "type": "Pecha Kucha", "language": "en", "abstract": "Given the scale expansion of the Internet of Things, the design of an Intrusion Detection System (IDS) is critical to protect the future network infrastructure from intrusions. Traditional IDS base their operations on Machine Learning (ML) models trained centrally in the cloud and then distributed across multiple end devices. However, this centralised approach often suffers from network overhead and high latency, thereby resulting in slow detection of malicious traffic and unresponsiveness to attacks in the worst case. The specific characteristics of large-scale IoT systems bring new design challenges that need to be carefully considered. This paper provides a comprehensive review of current IDS for IoT systems to shed light on these issues, focusing on the types of deployment architecture. We show how traditional practices are unsuitable for large-scale IoT systems due to their inherent characteristics. The current research for IoT intrusion detection will need to move in a different direction to develop an optimised solution for these types of networks.", "description": "In this talk, I will present a comprehensive review of current intrusion detection systems for IoT systems to shed light on the challenges and associated solutions.", "recording_license": "", "do_not_record": false, "persons": [{"code": "X7VFTC", "name": "Othmane Belarbi", "avatar": null, "biography": null, "public_name": "Othmane Belarbi", "guid": "c161cf27-a2f5-5bb1-90ab-ff53894425db", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/X7VFTC/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/W9PAQ8/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/W9PAQ8/", "attachments": []}, {"guid": "7a9a8ba3-e502-5b0a-af69-e652524b79a6", "code": "WCL8S7", "id": 24423, "logo": null, "date": "2023-02-11T12:15:00+00:00", "start": "12:15", "end": "2023-02-11T12:25:00+00:00", "duration": "00:10", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-24423-why-critical-thinking-is-not-the-answer-to-misinformation", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/WCL8S7/", "title": "Why critical thinking is not the answer to misinformation", "subtitle": "", "track": null, "type": "Pecha Kucha", "language": "en", "abstract": "Incorrectly assessing digital information has many repercussions for users: from downloading malicious code in open-source software repositories, to becoming a victim of misinformation. Study 1 was a systematic review (N = 63 studies) of the digital symbols and signals that communicate trust when assessing digital information. The results suggested trust signals and symbols were grouped into three themes of social proof, verification to reduce variance of risk, and expectancy violation theory. Study 2 (N = 20 participants) was a thematic analysis exploring whether expertise influences the use of trust signals and symbols in open-source software libraries. Results indicated that differences exist between expert and lay users when utilising trust cues to assess digital information. The implications for these studies are that ways in which people use trust cues create vulnerabilities for malicious actors to exploit through a range of possibilities. Researching which digital trust signals and symbols are utilised by users (when assessing the trustworthiness of digital information) may help to inform how to mitigate said vulnerabilities.", "description": "This presentation focuses on how the interaction of the digital environment and a user\u2019s psychology may lead to incorrectly evaluating the trustworthiness of online information. The two studies aim to demonstrate how asking users to critically think when assessing digital information overlooks how the digital environment may increase psychological biases to distort our ability to successfully evaluate the trustworthiness of digital information. The first study reviews the current evidence for digital trust cues that increase a user\u2019s perception of trustworthy information. The second study focuses on how trust cues are used to make judgements over the trustworthiness of information within open-source software libraries.", "recording_license": "", "do_not_record": false, "persons": [{"code": "KJVVQX", "name": "Rob Peace", "avatar": "https://pretalx.com/media/avatars/KJVVQX_uK6ot1Q.webp", "biography": "Rob is a final year PhD student in psychology at the university of Bath. He is part of the centre for doctoral training in trust, identity, security, and privacy in large scale infrastructures (a collaboration between the universities of Bath and Bristol). His research focuses on gaining further understanding of how trust is exploited online (including open-source software attacks, mis/disinformation, and how to increase trust in honeypots).", "public_name": "Rob Peace", "guid": "14af78da-77d6-5eec-93e9-d28d74c041c2", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/KJVVQX/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/WCL8S7/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/WCL8S7/", "attachments": []}, {"guid": "5d3bc3d8-d17d-557e-9a6a-fb556db85a37", "code": "FHP3U9", "id": 24463, "logo": null, "date": "2023-02-11T12:30:00+00:00", "start": "12:30", "end": "2023-02-11T12:40:00+00:00", "duration": "00:10", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-24463-vulnerability-management-sucks", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/FHP3U9/", "title": "Vulnerability Management Sucks.", "subtitle": "", "track": null, "type": "Pecha Kucha", "language": "en", "abstract": "It seems simple enough... or at least till you start scaling. Take a dive through the wonderful world of the vulnerability management extravaganza and some examples I've faced when trying to make sense of the data soup.", "description": "This talk aims to highlight some of the issues that seem to be a common headache. The task of combining the varying vulnerability management solutions you may have and presenting it back to relevant stakeholders in a neat package, all while trying to properly understand what data matters. Not forgetting the varying compliance and certification requirements that need meeting....\n\nThere is a larger focus on traditional infrastructure vulnerability management in this talk.", "recording_license": "", "do_not_record": false, "persons": [{"code": "MASVQA", "name": "Luke Jones", "avatar": "https://pretalx.com/media/avatars/MASVQA_5CScltk.webp", "biography": "Blue security person with interests from DFIR to Infrastructure as Code, with a current focus on building cool solutions for various security challenges.", "public_name": "Luke Jones", "guid": "5d9aebb2-5a46-5225-8320-9247fb8da34c", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/MASVQA/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/FHP3U9/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/FHP3U9/", "attachments": []}, {"guid": "db80b0db-ff4e-5643-83de-a6ab72bc7d73", "code": "CK9QSG", "id": 27380, "logo": null, "date": "2023-02-11T12:45:00+00:00", "start": "12:45", "end": "2023-02-11T13:45:00+00:00", "duration": "01:00", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-27380-lunch-click-for-menu", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/CK9QSG/", "title": "Lunch - Click for Menu", "subtitle": "", "track": null, "type": "Talk - long", "language": "en", "abstract": "lunch - click for menu", "description": "Lunch will be a buffet and cater for a spectrum of dietary requirements: \n\u2022\tSalad boxes including- \n\u2022\tGreen salads, \n\u2022\tColeslaw, \n\u2022\tMediterranean couscous \n\u2022\tTomato salad \n \n\u2022\tWith a choice of Caesar chicken, bbq chicken, teriyaki salmon, selection of cheese and then dietary appropriate options- these will be labelled for self-service and collection. \n \n\u2022\tRustic Bread roll selection\n\u2022\tAssortment of sweet treats- carrot cakes, muffins, mini cakes, cookies \n\u2022\tPackets of crisps- assorted flavours  \n\u2022\tAssortment of soft drinks \n \nAny special dietary requirements provided in advance will be labelled and accessible.", "recording_license": "", "do_not_record": true, "persons": [{"code": "MR3GJU", "name": "Craig Jones, Clare Johnson + Stuart Criddle", "avatar": null, "biography": null, "public_name": "Craig Jones, Clare Johnson + Stuart Criddle", "guid": "8791c352-d2af-5547-8f6d-2cde375d8e35", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/MR3GJU/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/CK9QSG/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/CK9QSG/", "attachments": []}, {"guid": "04dfa2fa-0ed6-59f3-b989-536325b451d5", "code": "P8FVTA", "id": 23708, "logo": null, "date": "2023-02-11T13:50:00+00:00", "start": "13:50", "end": "2023-02-11T14:20:00+00:00", "duration": "00:30", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-23708-ioc-what-you-mean", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/P8FVTA/", "title": "IOC What You Mean", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Using analytical techniques to build a high fidelity escalator up the pyramid of pain", "description": "The Pyramid of Pain made by David Bianco and popularised by MITRE et al. It is ultimately a conceptual model to increase the adversaries operational cost via the effective use of Cyber Threat Intelligence.\n\nIs the Pyramid of Pain too high to climb without very expensive vendor support? In this talk we'll slice up the pyramid of pain using analytical techniques, to reveal how you can prioritise and effectively reduce the permutations of each indicator type via the use of open-source tooling. This will result in  tailored 'byte' sized high fidelity chunks for respective courses of action.", "recording_license": "", "do_not_record": false, "persons": [{"code": "7WGVBL", "name": "Darren Kingsnorth", "avatar": null, "biography": "Darren runs the Threat Intelligence function at Admiral Group. Having previously worked as a tester of pens his alumni includes ECSC, NCC Group, CGI and Symantec, he routinely combines defensive and adversarial capabilities to ensure attackers don't win.", "public_name": "Darren Kingsnorth", "guid": "515259fe-3573-5fc2-8786-40b83e1f8e58", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/7WGVBL/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/P8FVTA/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/P8FVTA/", "attachments": []}, {"guid": "4cf937fa-caaa-523c-97d5-dfd69e6961be", "code": "E9HTYX", "id": 23537, "logo": null, "date": "2023-02-11T14:30:00+00:00", "start": "14:30", "end": "2023-02-11T15:00:00+00:00", "duration": "00:30", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-23537-when-diplomats-send-beacon-a-retrospective-view-of-apt29-malicious-phishing-campaigns", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/E9HTYX/", "title": "When diplomats send Beacon - A retrospective view of APT29 malicious phishing campaigns", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "In 2022, Mandiant identified spear-phishing activity targeting government entities, diplomatic missions, and international organizations in Europe and North America. The threat actors were using a variety of techniques and newly identified malware families that ultimately lead to disseminating BEACON malware payloads.\n \nThe extensive email phishing operations were performing covert cyber espionage, using CobaltStrike BEACON implant, which Mandiant publicly exposed in the blog \u201cTrello From the Other Side: Tracking APT29 Phishing Campaigns\u201d and attributed these campaigns to APT29; a Russian-nexus threat actor that\u2019s also been attributed to the SolarWinds supply chain intrusions.\n \nIn this talk, Mathias will provide:\n- A deeper overview of the various novel phishing campaigns they\u2019ve observed since February 2021\n- Any changes in APT29 phishing campaigns since the publication of findings in April 2022\n- Showcase the malware utilized to gain a foothold into a victim's network.\n- Provide recommendations for defenders to mitigate risks", "description": "(happy to write a description if needed)", "recording_license": "", "do_not_record": false, "persons": [{"code": "AC37QB", "name": "Mathias Frank", "avatar": "https://pretalx.com/media/avatars/AC37QB_Eebi3zY.webp", "biography": "Mathias is a Senior Incident Response Consultant at Mandiant and delivers emergency response services for clients facing security breaches. He specialises in providing enterprise-scale incident response operations for sophisticated network intrusions. \nMathias has led organisations and government bodies in responding to breaches by highly sophisticated adversaries such as nation-state sponsored espionage actors and cyber criminals aiming to extort or ransom victim organisations.", "public_name": "Mathias Frank", "guid": "8c507cb5-1eb0-59f8-aead-78c01b4a6e04", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/AC37QB/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/E9HTYX/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/E9HTYX/", "attachments": []}, {"guid": "e457cc46-c751-5b14-9df8-5a22f04577f4", "code": "CBQJRN", "id": 24342, "logo": null, "date": "2023-02-11T15:10:00+00:00", "start": "15:10", "end": "2023-02-11T15:40:00+00:00", "duration": "00:30", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-24342-getting-in-initial-access-in-2023", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/CBQJRN/", "title": "Getting In: Initial Access in 2023", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "The pathway to initial access in 2023 is far from an easy one. This talk will lift the lid on all the recent TTPs we have been using to gain access, giving you techniques you can implement in your own assessment. But what about defence? For all you blue teamers out there, we will show you how to prevent all the attacks we discuss! Sit back and enjoy all the fun!", "description": "The days of initial access being a case of sending a basic phishing email and get creds are long gone. With email filters so much more effective, end user training more frequent, corporate procedures enhanced, phishing is no longer trivial. We need to think differently, we need to be creative. That is what this talk is all about. Showing you the TTPs we ave developed over the years to evade or even bypass corporate controls and trick staff into giving us access. We will reveal less used TTPs that we have developed over time, showing how they can be leveraged. This is much more than phishing, this is full spectrum initial access, from OSINT led exploits, to in person SE, to creative remote social engineering, providing the many ways of getting in and gaining initial access in 2023.\nAre you a blue teamer? Don't worry we will show you all the ways you can stop our attacks, using your defensive onion to make the bad guys cry!", "recording_license": "", "do_not_record": true, "persons": [{"code": "88T3NC", "name": "Tony Gee", "avatar": "https://pretalx.com/media/avatars/88T3NC_9whAgy3.webp", "biography": "For 15 years, Tony's job has been either trying to break technology or defend it from attack.  This he has done everywhere from banks to mass transport systems.  He specialises in open source intelligence and recon, providing intelligence and understanding, helping clients understand their exposure and providing insight and recon for red and purple teams. He also speaks the world over at technology and cybersecurity events about how anything from children's toys to cars, planes and ships can be hacked.  He has spoken at PCI events in Europe and Asia, at the ISC2 Congress, ISACA CSX Europe, SANS Awareness Conference, WIRED Smarter, technical conferences such as 44Con and BSides. Most notably, he has spoken to US Congress and the European Central Bank about how the underlying digital theories and systems which modern life relies on, are vulnerable to attack.", "public_name": "Tony Gee", "guid": "04bc1cc0-d689-5a5f-bd10-7858ddfa583f", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/88T3NC/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/CBQJRN/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/CBQJRN/", "attachments": []}, {"guid": "7db044a6-0d68-533f-bba8-3eb4bea20dbb", "code": "NWWJHM", "id": 27659, "logo": null, "date": "2023-02-11T15:45:00+00:00", "start": "15:45", "end": "2023-02-11T16:30:00+00:00", "duration": "00:45", "room": "Track 2  -  Foxhunter", "slug": "bsides-cymru-2023-2022-27659-evse-ecosystems-connected-vehicle-privacy", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/NWWJHM/", "title": "EVSE Ecosystems & Connected Vehicle Privacy", "subtitle": "", "track": null, "type": "Talk - long", "language": "en", "abstract": "EVSE Ecosystems & Connected Vehicle Privacy", "description": "EVSE Ecosystems & Connected Vehicle Privacy", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/NWWJHM/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/NWWJHM/", "attachments": []}], "Track 3 (TTT) - St David's Suite": [{"guid": "1e16c455-14a0-5dd2-9119-54be9d15fb5b", "code": "SSNZU8", "id": 24084, "logo": "https://pretalx.com/media/bsides-cymru-2023-2022/submissions/SSNZU8/Tech-tent_Tbim6EE.png", "date": "2023-02-11T09:00:00+00:00", "start": "09:00", "end": "2023-02-11T17:00:00+00:00", "duration": "08:00", "room": "Track 3 (TTT) - St David's Suite", "slug": "bsides-cymru-2023-2022-24084-trans-tech-tent-talks-begin-at-10-am-click-for-schedule-of-talks", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/SSNZU8/", "title": "Trans Tech Tent - (Talks begin at 10 am) Click for Schedule of talks", "subtitle": "", "track": null, "type": "Village", "language": "en", "abstract": "Hack hardware, hack software, hack social situations, hack careers, hack gender, hack biology, hack society, hack the planet, hack everything!", "description": "The Trans Tech Tent is a Welsh organisation that started out as a community repairs group for queer people in the Cardiff area. Two years later, we hack everything, fix everything, and have a global support community.\n\nCome visit us for talks, chats, and workshops throughout the day on every topic we could reasonably fit into a security BSides event!\n\nSee https://pretalx.c3voc.de/trans-tech-tent-2023/schedule/ for current schedule\n\n10:00\nAM\n30min\nRisky Business - using risk-based analysis to detect bad things\nJaime McCallion\n\n10:35 AM 30min\nGiving you the ICK - Industrial Cyber Knowledge for n00bs\nJamie Grant\n\n11:10 AM 45min\nBiohacking in the 21st Century - A guide to transition\nAbby\n\n1:00 PM 30min\nReimplementing game servers for fun and giggles\nEva Lauren Kelly (thejsa)\n\n1:35 PM 30min\nReversing UK mobile rail tickets\neta\n\n2:10 PM 30min\nSmart Watches are dumber than you think\nJune Fleetwood\n\n2:45 PM 30min\nWhy Don't I Know Kung Fu Yet?\nMisha Whitney\n\n3:20 PM 30min\nWandering wombs - A History of Medical Misogyny\nRaven Gough\n\n3:55 PM 30min\nit's borked - programming was a mistake\nMaya\n\n5:00 PM 15min\nClosing Statement\nAbby", "recording_license": "", "do_not_record": false, "persons": [{"code": "ZZYNEG", "name": "a[gk]i|ab+y", "avatar": "https://pretalx.com/media/avatars/ZZYNEG_ldTperc.webp", "biography": "Director of the Trans Tech Tent and Sr. CIRT Analyst, fixing what other people broke for [REDACTED] years!", "public_name": "a[gk]i|ab+y", "guid": "32c49e46-8cfe-57b9-954e-1d698cc9a219", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/ZZYNEG/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/SSNZU8/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/SSNZU8/", "attachments": []}], "Workshops - Glamorgan Suite": [{"guid": "1720087f-e1c2-5472-ac6c-3f3b6adfee31", "code": "JMZHJM", "id": 23015, "logo": null, "date": "2023-02-11T09:30:00+00:00", "start": "09:30", "end": "2023-02-11T13:00:00+00:00", "duration": "03:30", "room": "Workshops - Glamorgan Suite", "slug": "bsides-cymru-2023-2022-23015-introduction-to-geoint", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/JMZHJM/", "title": "Introduction to GEOINT", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "GEOINT is a component of OSINT where a physical location is discovered from clues in media, from still photographs to videos and even sound. The practice requires a selection of skills and knowledge about resources which may be as diverse as power grids, architecture and physics. A successful identification of a location may seem to be almost magical and, at the same time, scary.", "description": "A workshop describing the techniques to identify important parts of an image or video that could be used to locate it (and also when location may not be possible). It will descend into the geekery of sites that can identify various aspects of an image.\n\nIt is designed to be fully interactive. It will demonstrate the art of locating through examples and practice. Common search engines and Internet resources will be used to aid in this.\n\nAttendees are encouraged to bring their own images with them so that they can be used in the workshop to practice their own skills. They are also encouraged to share databases or knowledge that other attendees may not know about.", "recording_license": "", "do_not_record": false, "persons": [{"code": "MKS7MP", "name": "David Lodge", "avatar": "https://pretalx.com/media/avatars/MKS7MP_RZ2I4Lb.webp", "biography": "Is too boring for a biography.", "public_name": "David Lodge", "guid": "746e613d-7db1-5cc7-89ff-8522750bb4e4", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/MKS7MP/"}, {"code": "88T3NC", "name": "Tony Gee", "avatar": "https://pretalx.com/media/avatars/88T3NC_9whAgy3.webp", "biography": "For 15 years, Tony's job has been either trying to break technology or defend it from attack.  This he has done everywhere from banks to mass transport systems.  He specialises in open source intelligence and recon, providing intelligence and understanding, helping clients understand their exposure and providing insight and recon for red and purple teams. He also speaks the world over at technology and cybersecurity events about how anything from children's toys to cars, planes and ships can be hacked.  He has spoken at PCI events in Europe and Asia, at the ISC2 Congress, ISACA CSX Europe, SANS Awareness Conference, WIRED Smarter, technical conferences such as 44Con and BSides. Most notably, he has spoken to US Congress and the European Central Bank about how the underlying digital theories and systems which modern life relies on, are vulnerable to attack.", "public_name": "Tony Gee", "guid": "04bc1cc0-d689-5a5f-bd10-7858ddfa583f", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/88T3NC/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/JMZHJM/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/JMZHJM/", "attachments": []}, {"guid": "6e53cbac-2eca-5712-9550-7b401899b2a7", "code": "QEQ7G9", "id": 23088, "logo": null, "date": "2023-02-11T13:00:00+00:00", "start": "13:00", "end": "2023-02-11T17:00:00+00:00", "duration": "04:00", "room": "Workshops - Glamorgan Suite", "slug": "bsides-cymru-2023-2022-23088-mastering-android-application-reverse-engineering", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/QEQ7G9/", "title": "Mastering Android Application Reverse Engineering", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "**Extract, reverse, and exploit Android applications.**\n\nCome to this workshop if you're new to offensive security, want to develop your skills in reverse engineering, or if you're interested in Android application internals. During the four hours we'll dive into:\n- The fundamentals of the Java programming language\n- How Android applications are developed\n- How to reverse Android application's and identify common security misconfigurations\n- How to patch and dynamically instrument Android applications for security testing", "description": "# Summary\nThis workshop will be broken down into three sections,: an introduction and talk on the fundamentals, a guided challenge / exercise, followed by free-form challenges and activities. By the end of this workshop you'll be able to develop simple Android applications, reverse Android applications to both Java and SMALI, and apply other dynamic techniques to your reverse engineering efforts such as using Frida and Patching. \n\n# Prerequisites \n- A foundation knowledge of Linux CLI use\n- A laptop that can run a virtual machine (with VMWare Player or equivalent installed)\n- An Android Phone with ADB enabled or Android Studio installed with an emulator (please check the emulator works before hand).\n\n# About James\nJames is a vulnerability researcher focusing on the Android system and applications. James has over five years experience in the industry and has worked in a variety of roles from startups to global organizations.", "recording_license": "", "do_not_record": false, "persons": [{"code": "RRVMA9", "name": "James Stevenson", "avatar": "https://pretalx.com/media/avatars/RRVMA9_4P8dtvf.webp", "biography": "I\u2019m a Software Engineer and Security Researcher, with a background of over five years in the computer security industry. These days I\u2019m working at an offensive security start-up, as well as working on a range of other side projects.", "public_name": "James Stevenson", "guid": "d0816df3-9133-55e7-bd81-90161708ce11", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/RRVMA9/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/QEQ7G9/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/QEQ7G9/", "attachments": []}], "Workshops - ClockTower": [{"guid": "aaa46356-527b-5596-bb55-7fc53ceb8dd5", "code": "XPKMPQ", "id": 24399, "logo": null, "date": "2023-02-11T09:00:00+00:00", "start": "09:00", "end": "2023-02-11T17:00:00+00:00", "duration": "08:00", "room": "Workshops - ClockTower", "slug": "bsides-cymru-2023-2022-24399-ics-village-opens-at-9-45", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/XPKMPQ/", "title": "ICS Village (Opens at 9.45)", "subtitle": "", "track": null, "type": "Village", "language": "en", "abstract": "Interested in seeing how industrial control systems work and how secure they are? The ICS Village run by the University of Bristol's Cyber Security Group includes live demos of various attacks against ICS devices using our mobile demonstration units.", "description": "Industrial control systems, such as those controlling many aspects of critical infrastructure including energy, water and manufacturing, are increasingly the target of sophisticated cyber attacks.  At the ICS village you can see practical attack demonstrations against real ICS devices, including demonstrations of attack scenarios which can cause physical processes to go wrong. Demonstrations include reconnaissance of ICS devices, the exploitation of programmable logic controllers and password cracking of human machine interfaces.", "recording_license": "", "do_not_record": false, "persons": [{"code": "3TBYTJ", "name": "Joe Gardiner", "avatar": "https://pretalx.com/media/avatars/3TBYTJ_YecsSMS.jpg", "biography": "Joe Gardiner is a Lecturer in Cyber Physical Systems Security in Bristol Cyber Security Group, the University of Bristol. His primary area of research is the security of industrial control systems.", "public_name": "Joe Gardiner", "guid": "75c33ba0-6f84-52a8-838e-53244adc10b3", "url": "https://pretalx.com/bsides-cymru-2023-2022/speaker/3TBYTJ/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/XPKMPQ/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/XPKMPQ/", "attachments": []}], "Workshops Clocktower (more)": [{"guid": "73bad200-c7c8-5aa8-adde-5952ebc27ce7", "code": "CVFVFM", "id": 27795, "logo": null, "date": "2023-02-11T09:00:00+00:00", "start": "09:00", "end": "2023-02-11T17:00:00+00:00", "duration": "08:00", "room": "Workshops Clocktower (more)", "slug": "bsides-cymru-2023-2022-27795-battle-bots-opens-at-9-45", "url": "https://pretalx.com/bsides-cymru-2023-2022/talk/CVFVFM/", "title": "Battle Bots (Opens at 9.45)", "subtitle": "", "track": null, "type": "Village", "language": "en", "abstract": "Mini Battle Bots!", "description": "Mini Battle Bots!", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/CVFVFM/feedback/", "origin_url": "https://pretalx.com/bsides-cymru-2023-2022/talk/CVFVFM/", "attachments": []}]}}]}}}