<?xml version='1.0' encoding='utf-8' ?>
<iCalendar xmlns:pentabarf='http://pentabarf.org' xmlns:xCal='urn:ietf:params:xml:ns:xcal'>
    <vcalendar>
        <version>2.0</version>
        <prodid>-//Pentabarf//Schedule//EN</prodid>
        <x-wr-caldesc></x-wr-caldesc>
        <x-wr-calname></x-wr-calname>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>RDFGC8@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-RDFGC8</pentabarf:event-slug>
            <pentabarf:title>Opening Speeches + Keynote</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T090000</dtstart>
            <dtend>20240427T093000</dtend>
            <duration>003000</duration>
            <summary>Opening Speeches + Keynote</summary>
            <description>Keynote Speaker</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/RDFGC8/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Craig Jones, Clare Johnson + Stuart Criddle</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>ANY9VY@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-ANY9VY</pentabarf:event-slug>
            <pentabarf:title>Home Renewables Security Or: How I forgot to RTFM and got Pwned by my 12 year old</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T093000</dtstart>
            <dtend>20240427T100000</dtend>
            <duration>003000</duration>
            <summary>Home Renewables Security Or: How I forgot to RTFM and got Pwned by my 12 year old</summary>
            <description>Adoption of home technologies to help reduce CO2 emissions and energy costs are on the rise as more and more people engage with the green revolution.  Whether it&#8217;s solar panels and battery technology, Electric Vehicles (EV) and their chargers or smart home heating for both conventional fossil fuel heating and electric heating such as heat pumps. 

All of these technologies are built on electronics, software, are networked and often include cloud management capabilities, as well as often being physically located outside of the home. 

This talk will explore the threat model for home renewable technology with real world examples of vulnerabilities.  It will also explore what manufacturers should be doing to support their customers to maintain the security of home renewable technologies. 

The presentation will conclude with the story of how my 12 year old took advantage of poor default security settings on a solar inverter.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/ANY9VY/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Jon Renshaw</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>8SYSTT@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-8SYSTT</pentabarf:event-slug>
            <pentabarf:title>Hurr Durr, He Wrote: That awesome time I trolled the stupidest scammer in the world</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T100500</dtstart>
            <dtend>20240427T105000</dtend>
            <duration>004500</duration>
            <summary>Hurr Durr, He Wrote: That awesome time I trolled the stupidest scammer in the world</summary>
            <description>See abstract.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Very Long Talk</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/8SYSTT/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Matt Wixey</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>XWPKYS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-XWPKYS</pentabarf:event-slug>
            <pentabarf:title>Everything online can be faked.  Here&apos;s how and here&apos;s how to spot it.</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T105500</dtstart>
            <dtend>20240427T112500</dtend>
            <duration>003000</duration>
            <summary>Everything online can be faked.  Here&apos;s how and here&apos;s how to spot it.</summary>
            <description>We discuss the ways everything online can be faked, from spoofing phone numbers to creating virtual webcams to using AI to create deepfaked voices, combined with animating an image to make it appear as if the person is talking.  Several of the ways will be shown using demonstrations</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/XWPKYS/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Wayne May</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NNLVEQ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-NNLVEQ</pentabarf:event-slug>
            <pentabarf:title>So you want to be a spy - reality is a slap in the face</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T113000</dtstart>
            <dtend>20240427T120000</dtend>
            <duration>003000</duration>
            <summary>So you want to be a spy - reality is a slap in the face</summary>
            <description>Our presentation delves into the complex world of intelligence gathering and analysis. It covers various types of intelligence, such as TECHINT (Technical Intelligence), SIGINT (Signals Intelligence), FININT (Financial Intelligence), RADINT (Radar Intelligence), OSINT (Open Source Intelligence), CYBINT/DNINT (Cyber/Digital Network Intelligence), IMINT/GEOINT (Imagery/Geospatial Intelligence), MASINT (Measurement and Signature Intelligence), and HUMINT (Human Intelligence). We will journey through All-Source Intelligence, highlighting the specific methodologies and technologies involved, as well as their applications in different contexts. The presentation showcases less known techniques as well as those popularised by Hollywood. We also explore the integration of diverse intelligence types in modern practices and tradecraft as well as the evolution and current trends in intelligence gathering and analysis.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/NNLVEQ/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Tony Gee</attendee>
            
            <attendee>Hugo Page-Turner</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>WCFQVU@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-WCFQVU</pentabarf:event-slug>
            <pentabarf:title>Admiral Community CTF</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T120500</dtstart>
            <dtend>20240427T125000</dtend>
            <duration>004500</duration>
            <summary>Admiral Community CTF</summary>
            <description>Admiral CTF which will be accessible via phone and open to all.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Very Long Talk</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/WCFQVU/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JCDCGE@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JCDCGE</pentabarf:event-slug>
            <pentabarf:title>I Don&apos;t Care about Domain Admin</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T133000</dtstart>
            <dtend>20240427T140000</dtend>
            <duration>003000</duration>
            <summary>I Don&apos;t Care about Domain Admin</summary>
            <description>Presentation outline
1)	Common pentesting goals
In the opening of the talk, we discuss that some common goals for clients engaging pentesters is the identification of vulnerabilities, and that testers have their own goals of being able to break all security, achieve a data breach and escalate privileges (Domain Admin FTW)
2)	Traditional vs Modern penetraiton testing
This section talks about how clients are starting to see that security needs to be thought of as a big picture issue and that testing very small areas of a network or single applications don&#8217;t realistically improve security.  Modern testing is moving toward continual vulnerability assessments and more scenario/red team style testing.  However testers still want to get to DA and prove their skills
3)	Real world incidents that didn&#8217;t follow traditional playbooks
A review of the Alphv/BlackCat attack against MeridianLink and how they posted a picture of themselves reporting MeridianLink to the USA SEC in an attempt to get them to pay a ransom
4)	GDPR
A review of the types of data that are deemed valuable in the EU (PII) and how companies have been hit with fines after databreaches
5)	Weaponising GDPR for the greater good
A discussion on how in 2024 cyber security is still not where it should be and that perhaps if we embrace non-technical ramifications of an attack we can convince clients to take action.  Discussing how some clients have little idea what the impact of whoami command showing system access but can definitely understand comments such as &#8220;the last company that had this much data exposed in a breach payed &#163;X millions in fines&#8221;
6)	How to find the flaws
The release of a new tool FileFinder that searches network for file sharing locations and points pentesters to areas of interest.
7)	How a single file doomed an organsation&#8217;s attempt at being secure
A case study of a real world penetration test against an organisation that took data security seriously was doomd due to an  NFS share hosting a file with an excessive amount of passwords on it.  It would have been significantly harder to break security without these credentials.
8)	Conclusion
Summing up how pentesters can still view technical exploits and network compromise as a fantastic goal to achieve. But that we can also add steps to highlight areas that can cause real impact to clients.

Attendee Takeaway
1)	Attendees will learn about pentesting concepts and how testers target networks
2)	Attendees will learn about how regulation impacts their clients and that 1 hacking group has already threatened to use this against their victims
3)	Attendees see a new tool that can be used to map files of interest across a network.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/JCDCGE/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Dan Cannon</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>ZXC9NE@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-ZXC9NE</pentabarf:event-slug>
            <pentabarf:title>Out of the Frying Pan Into the Cloud: A Red Teamer&apos;s View of Your Cloud Estate</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T140500</dtstart>
            <dtend>20240427T143500</dtend>
            <duration>003000</duration>
            <summary>Out of the Frying Pan Into the Cloud: A Red Teamer&apos;s View of Your Cloud Estate</summary>
            <description>Initial Access: 
- Is password spraying back!? Max and his red team are leveraging intelligent password spraying and common gaps in MFA to breach orgs reliant on o365. This particular attack chain has recently been abused by Russian threat group Midnight Blizzard to compromise Microsoft themselves https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/
- The renaissance of web application compromise. Metadata services and rich cloud APIs have taken the impact of SSRF and RCE on app servers and functions to new levels. Gone are the days of popping a low-privileged service account, restricted to the webroot on a web server, in the DMZ...
- Users will always be a target...but out with the old (implants) and in with the new (post-MFA session tokens) 

Lateral Movement / Privilege Escalation:
- Every cloud environment we have red teamed to date has some level of overly privileged accounts, and its not a surprise when IT administrators are now expected to understand the granular differences between 100s of different IAM roles 
- Targeting the right identities/service principals/etc is often easier and better opsec than going for superusers
- Generally speaking there are so many misconfigurations or abusable default configurations that there is less a focus on &apos;exploitation&apos; as there is on &apos;leveraging&apos; what is there. 
- Persistence is now about maintaining access to valid session tokens, not repeatedly executing an implant.

Data Mining / Actions on Objectives:
- Data mining is an absolute goldmine in the cloud, and Max and his team have abused this to skip massive chunks of the traditional cyber attack kill chain and cause catastrophic business impact
- Actions on objectives largely remain the same from on-prem to cloud red teams, but the means change dramatically.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/ZXC9NE/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Max Corbridge</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>9N3LA7@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-9N3LA7</pentabarf:event-slug>
            <pentabarf:title>Navigating Cloud Frontiers: A War Story of Cloud Purple Teaming</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T144000</dtstart>
            <dtend>20240427T152500</dtend>
            <duration>004500</duration>
            <summary>Navigating Cloud Frontiers: A War Story of Cloud Purple Teaming</summary>
            <description>Attendees will gain actionable insights into the intricacies of Cloud Purple Teaming, from navigating the cloud landscape to mastering incident response in cloud environments. The war story format will provide tangible lessons applicable to diverse cloud security challenges.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Very Long Talk</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/9N3LA7/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Hani Momeninia</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MC3RN9@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MC3RN9</pentabarf:event-slug>
            <pentabarf:title>Ohhhh365 - How to (Quite) Reliably Hack into Microsoft 365, And What to Do Afterwards</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T153500</dtstart>
            <dtend>20240427T160500</dtend>
            <duration>003000</duration>
            <summary>Ohhhh365 - How to (Quite) Reliably Hack into Microsoft 365, And What to Do Afterwards</summary>
            <description>## Introduction

M365 accounts have never been *mere* email inboxes; they are the linchpins of internal communications and data repositories. An attacker&apos;s access to such accounts often leads to sensitive internal data exposure and facilitates lateral movement within an organization, especially in hybrid or cloud-native environments.

## Initial Access Methodologies
We dive into the methodologies tested and refined in red team operations in our consultancy, to infiltrate Microsoft 365, which include:

- **Revival of Password Spraying**: The password spraying technique is revisited, utilizing AWS API Gateway proxying to bypass Microsoft&apos;s Smart Lockout. This innovative approach enables us to exploit often-seen gaps in multi-factor authentication (MFA) setups, which got us into highly-sophisticated clients. Microsoft&apos;s security team reported in January 2024 that one of their own tenants were compromised by a threat group using a similar approach.

- **MitM Phishing Via Productivity Apps**: Tools like Microsoft Teams can be leveraged for phishing, effectively circumventing traditional email controls. Our social engineering methodology employs Man-in-the-Middle (MitM) tactics to hijack post-MFA access tokens. We will outline key steps in readily setting up a believable front that gets past web filters.

## Post-Compromise

Our Tactics, Techniques, and Procedures (TTPs) for data mining, persistence and lateral movement within Office 365 are highlighted, and thereby the potential business impact too. Threat actors, and by extension attack simulations target M365 more and more for a reason, and it&apos;s not just about breaking into accounts.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/MC3RN9/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Sunny Chau</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NAUZ9Y@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-NAUZ9Y</pentabarf:event-slug>
            <pentabarf:title>Okta Terrify - Persistence in a Passwordless World</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T161000</dtstart>
            <dtend>20240427T164000</dtend>
            <duration>003000</duration>
            <summary>Okta Terrify - Persistence in a Passwordless World</summary>
            <description>We will take a deep dive into one of these solutions, the Okta Verify application and it&apos;s FastPass feature.  We will first cover how Okta Verify and FastPass works followed by a demonstration of persistence vectors available to attackers when an endpoint is compromised that is running Okta Verify.  A new tool will be demonstrated that will also be released to the community later in the summer.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/NAUZ9Y/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
            <attendee>Ceri Coburn</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>SN8EC7@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-SN8EC7</pentabarf:event-slug>
            <pentabarf:title>Closing Speeches</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T164500</dtstart>
            <dtend>20240427T171500</dtend>
            <duration>003000</duration>
            <summary>Closing Speeches</summary>
            <description>Closing speeches and prize giving</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/SN8EC7/</url>
            <location>Main Room (Ballroom) - Track 1</location>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>DY8SWE@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-DY8SWE</pentabarf:event-slug>
            <pentabarf:title>Decoding Neurodiversity: Spectrums aren&apos;t just for RF</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T092500</dtstart>
            <dtend>20240427T101000</dtend>
            <duration>004500</duration>
            <summary>Decoding Neurodiversity: Spectrums aren&apos;t just for RF</summary>
            <description>Through personal experience and awkward audience participation, be prepared for an exploration of the misconceptions surrounding neurodiversity, coupled with practical tips on fostering inclusivity. Discover how each of us can contribute to creating a more understanding and welcoming environment for individuals with diverse neurological profiles. This session promises to be both informative and enjoyable, as we delve into the complexities of neurodiversity with a  personal touch.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Very Long Talk</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/DY8SWE/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Illyana Mullins</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>AC9KGJ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-AC9KGJ</pentabarf:event-slug>
            <pentabarf:title>Whatever you do, don&apos;t pull the plug!</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T101500</dtstart>
            <dtend>20240427T104500</dtend>
            <duration>003000</duration>
            <summary>Whatever you do, don&apos;t pull the plug!</summary>
            <description>Whatever you do, don&apos;t pull the plug!

A ticket has been logged, users are unable to open files and then you discover the ransom notes, and start seeing files changing before your eyes - what next? Isolate the hosts, pull the power, pray or go and make a cuppa?

This talk will cover a real life experience when someone did exactly that and pulled the power out of a storage array - with the best of intentions to prevent further damage, unbeknown that this would actually cripple the network! 

From stopping the attack, uncovering the lack of DR and backups, to reconstructing the environment and travelling across London with a server in the back of a black cab and then rebuilding. This is a real life tale about how a lack of incident response planning and knee jerk reactions can make things worse!</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/AC9KGJ/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Pete G</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>9WGWWS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-9WGWWS</pentabarf:event-slug>
            <pentabarf:title>SOC Analyst&#8217;s Arsenal: Essential Tools, Tips and Tricks for Effective Investigations</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T105000</dtstart>
            <dtend>20240427T112000</dtend>
            <duration>003000</duration>
            <summary>SOC Analyst&#8217;s Arsenal: Essential Tools, Tips and Tricks for Effective Investigations</summary>
            <description>We will begin with an OPSEC warning after which we will explore SOC analyst tools that form the foundation of a SOC analyst&apos;s toolkit and highlight the most valuable functionalities. Main areas that will be covered:

- Reputation engines and related info
- Quick sandboxing
- Analysis of EVTX and malware
- Other useful tools

Additionally, we will share battle-tested tips and tricks used by experienced SOC analysts in the field. These insights will cover a range of topics, including:

- OSINT gathering
- Log manipulation and transformation
- Scripting and automation opportunities

Moreover, we will mention the importance of collaboration and knowledge sharing among the SOC analysts and propose ways to leverage gamified tabletop exercise to ignite conversation and teamwork.

We will conclude the session with a few minutes for questions from the audience / suggestions of other tools or tricks they like.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/9WGWWS/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Samuel Kavaler</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NTWYXY@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-NTWYXY</pentabarf:event-slug>
            <pentabarf:title>Practical security challenges posed by AI adoption: Code Quality and Threat Modeling</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T112500</dtstart>
            <dtend>20240427T121000</dtend>
            <duration>004500</duration>
            <summary>Practical security challenges posed by AI adoption: Code Quality and Threat Modeling</summary>
            <description>1. INTRODUCTION - whomi
2. AI IN SOFTWARE ENGINEERING - How software engineers apply AI in their day to day job
3. LLM USE CASES - and few thoughts about the security cost
4. SECURITY FRAMEWORKS AND BEST PRACTICES - Latest improvements in the field
5. DEMO
6. CLOSING REMARKS</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Very Long Talk</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/NTWYXY/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Balazs Greksza</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>A8YPE3@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-A8YPE3</pentabarf:event-slug>
            <pentabarf:title>Automating Binary Analysis With Machine Learning&#8230; and a bunch of scripts</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T121500</dtstart>
            <dtend>20240427T124500</dtend>
            <duration>003000</duration>
            <summary>Automating Binary Analysis With Machine Learning&#8230; and a bunch of scripts</summary>
            <description>*Reverse engineering, vulnerability research, binary analysis - all of these approaches and disciplines require skill and take time. This talk dives into supporting the latter, by covering what we can do to automate and accelerate approaches to binary analysis and in getting results, identifying findings, and spotting bugs and vulnerabilities quicker.*

During this talk we&#8217;ll cover a collection of approaches for accelerating binary analysis, covering a rage of areas from onboarding new binaries, diffing code, and identifying vulnerabilities/ similar code using ML. This will include:

- Quick wins you can implement right now to accelerate your manual analysis
- Approaches to developing your own automated approaches to binary analysis
- Where machine learning fits into this, and a collection of ML automation tooling</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/A8YPE3/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>James Stevenson</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GB9VVT@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GB9VVT</pentabarf:event-slug>
            <pentabarf:title>Securing Online Transactions: How to Keep Your Money Safe about IDOR vulnerability</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T133000</dtstart>
            <dtend>20240427T140000</dtend>
            <duration>003000</duration>
            <summary>Securing Online Transactions: How to Keep Your Money Safe about IDOR vulnerability</summary>
            <description>I need only HDMI</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/GB9VVT/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Ilkin Javadov</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>PTKKCJ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-PTKKCJ</pentabarf:event-slug>
            <pentabarf:title>Dr. Strangequeries or: How I Learned to Stop Worrying and Write Better BloodHound Queries</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T140500</dtstart>
            <dtend>20240427T143500</dtend>
            <duration>003000</duration>
            <summary>Dr. Strangequeries or: How I Learned to Stop Worrying and Write Better BloodHound Queries</summary>
            <description>BloodHound is one of the most well-known tools in the hacker&apos;s arsenal when it comes to Active Directory exploitation. It offers the user a convenient way of visualising relationships within AD in order to find interesting attack paths. BloodHound even comes with pre-made queries that you can use to find quick-wins throughout the chosen domain. Unfortunately, these pre-made queries do not offer the full scope of paths you may wish to try in AD and may not do exactly what you want them to. 

Since BloodHound relies on Cypher queries against a neo4j database, one can simply write raw queries for use in the BloodHound GUI and neo4j web console in order to better query the AD datasets...if they can figure out the syntax that is...

This talk will (attempt to) demystify Cypher without assuming any prior knowledge of either it or BloodHound. The following will be covered:

- A very brief introduction into BloodHound, how it works and how it is used, aimed at those new to the tool
- Limitations of only using the pre-made scripts in BloodHound and how these can be solved with custom queries and the neo4j web console
- A more detailed look at Cypher syntax and how to write queries (with examples), alongside some common pitfalls
- Some example custom queries that I have found useful, including those I have used in engagements
- How to save custom queries and import them into BloodHound for later use

The need to cannibalise Cypher queries and build better queries came from the sometimes lax number of appropriate pre-built queries in stock BloodHound. Indeed, without the ability to restructure and write one&apos;s own, the risk of missing the next novel attack path is more apparent. Sometimes it&apos;s not that &apos;BloodHound did not find anything&apos;, it&apos;s that you, the user, failed to ask BloodHound the correct question.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/PTKKCJ/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Harry Williams</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>SHNKCJ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-SHNKCJ</pentabarf:event-slug>
            <pentabarf:title>Client-Side Attacks in a Post-XSS World</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T144000</dtstart>
            <dtend>20240427T151000</dtend>
            <duration>003000</duration>
            <summary>Client-Side Attacks in a Post-XSS World</summary>
            <description>With the evolution of web frameworks and browsers, Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) have become increasingly rare. In response, new classes of client-side vulnerabilities have emerged - DOM clobbering, XS-Leaks and client-side path traversals are just a few examples.

In this talk, we will explore the merits and potential pitfalls of various protections against XSS and CSRF, newer classes of client-side attacks and some real-world examples of their applications.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/SHNKCJ/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Zeyu (Zayne) Zhang</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>HTZTKW@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-HTZTKW</pentabarf:event-slug>
            <pentabarf:title>I Know What You Did Last Summer</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T151500</dtstart>
            <dtend>20240427T154500</dtend>
            <duration>003000</duration>
            <summary>I Know What You Did Last Summer</summary>
            <description>Thought provoking look at how much personal information we share and exploratory look at how this can be used in targeted campaigns. 

During the talk attendees will learn what type of personal information is attainable by OSINT.

Workflow of an investigation into a target (using myself as an example)
  
Scenarios of how threat actors could utilise this data with real world examples.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk - Long</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/HTZTKW/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Sam Macdonald</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>AE99SK@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-AE99SK</pentabarf:event-slug>
            <pentabarf:title>Is the biggest cyber security risk the lack of diversity?</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T155000</dtstart>
            <dtend>20240427T160500</dtend>
            <duration>001500</duration>
            <summary>Is the biggest cyber security risk the lack of diversity?</summary>
            <description>The trials and tribulations of a career path, which never played into the stereotypes.
A truly honest picture of what risks can be remediated by a team which is more than just what&apos;s on paper to go further for ultimate diversity.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk  - Short</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/AE99SK/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Becky Hall</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>3PYQUV@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-3PYQUV</pentabarf:event-slug>
            <pentabarf:title>Modern Vehicle Sabotage</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T161000</dtstart>
            <dtend>20240427T162000</dtend>
            <duration>001000</duration>
            <summary>Modern Vehicle Sabotage</summary>
            <description>In this 10-minute talk, we will explore the critical role of the Controller Area Network (CAN-bus) in modern vehicles and its susceptibility to security vulnerabilities. Despite its age, the CAN-bus lacks essential security features, rendering it vulnerable to cyber threats in today&apos;s connected vehicle landscape. While efforts have been made to address these vulnerabilities, little attention has been given to assessing the potential impact of security measures on other vehicle components, particularly the Event Data Recorder (EDR). We will discuss the implications of this oversight and the importance of conducting comprehensive security assessments to ensure the integrity and functionality of connected vehicles. Through simulation based experiments, we will underscore the need for holistic approaches to CAN-bus security and highlight avenues for future research and development in the field. Join us as we navigate between security features and vehicle functionality, aiming to pave the way for safer and more resilient connected vehicles.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Very Short Talk</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/3PYQUV/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Muhammad Yusuf Bambang</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GQ93WH@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GQ93WH</pentabarf:event-slug>
            <pentabarf:title>Pocket-Sized Powerhouses: Exploring IDSs on Microcontrollers</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T163000</dtstart>
            <dtend>20240427T164500</dtend>
            <duration>001500</duration>
            <summary>Pocket-Sized Powerhouses: Exploring IDSs on Microcontrollers</summary>
            <description>The ESPRESSIF family of devices, particularly the ESP32, is among the most popular microcontrollers used in the Internet of Things (IoT) domain. The ESP32 is a dual-core system, that can run tasks independently of each other. This dual-core architecture is leveraged to enhance the efficiency of IDSs implemented on these devices.

In a typical scenario, one core is dedicated to identifying potential threats or malicious activities, while the other core is responsible for sending telemetry data or alerts about these threats to a central system. This division of labour between the two cores ensures a seamless transition from threat detection to alert generation, enhancing the overall responsiveness and effectiveness of the IDS.

To further enhance the functionality of the device while ensuring it operates as intended, techniques like protothreading are employed. This means that the device can perform multiple tasks simultaneously, such as monitoring network traffic, analysing data for potential threats, and sending alerts, without any significant impact on performance.
However, implementing such a sophisticated IDS on a microcontroller does come with certain trade-offs, the most notable of which is increased power consumption. The additional processing required for threat detection and telemetry transmission can lead to higher energy usage, which can be a concern for battery-operated devices.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk  - Short</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/GQ93WH/</url>
            <location>Sophia Room - Track 2</location>
            
            <attendee>Vasilis Ieropoulos</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>U379K8@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-U379K8</pentabarf:event-slug>
            <pentabarf:title>Exploring the socio-technical challenge: What even are human factors?! and why should I care?</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T093000</dtstart>
            <dtend>20240427T133000</dtend>
            <duration>040000</duration>
            <summary>Exploring the socio-technical challenge: What even are human factors?! and why should I care?</summary>
            <description>Our lineup of speakers brings together experts from various disciplines, offering insights into psychological processes, economic investment, political landscapes, and industrial perspectives, all relating to cybersecurity. From the importance of habit in positive security behaviours to the economics of security investments, each talk promises a nuanced exploration of the human element in cybersecurity.
To complement the talks, multiple activities await attendees, including &quot;Technology, Threats, and Tradeoffs&quot;, an innovative research board game designed to immerse players in the dynamic environment of digital healthcare startup development. With a focus on cybersecurity and business investments, this game challenges players to navigate the complexities of strategic decision-making, as well as provides additional interactive sessions aimed at unravelling the essence of human factors.
Concluding the session, a panel of experts will tackle the fundamental questions surrounding human factors in cybersecurity, inviting discourse on the challenges, vulnerabilities, and future directions for human factors. Join us as we navigate the socio-technical terrain, striving to answer the critical question: What even are the human factors of cybersecurity?!

Talks
0930 - Start of HF village (Roath room) - opening remarks
0940 - Tobi Weickert (University of Bath) - Secure by Habit: Exploring the Role of Routine in Cybersecurity.
0955 - Mordecai Otter (Cardiff University) - Why human factors matter when designing digital defences.
1010 - George Raywood-Burke (Cardiff University) - Applying Theory to Practice: How Decision Making can be influenced in Cyber-Security.
1025 - Chris Locke (Admiral) - Agile Security Delivery
1040 - Elizabeth Kolade (University of Bristol) - Why is Cybersecurity a geopolitical issue?
1055 - Rob - Cross cultural differences in the perceived trustworthiness of online information.

Activities
1110 - Oishee Kundu, Tobi Weickert - Threats and trade-offs board game
&#8194;&#8194;&#8194;&#8194;&#8194;&#8194;Victoria Marcinkiewicz - OSINT challenge
&#8194;&#8194;&#8194;&#8194;&#8194;&#8194;Rob Peace/Chris Locke - Disinformation challenge
&#8194;&#8194;&#8194;&#8194;&#8194;&#8194;General HF discussion - everyone/anyone

Panel - Exploring the socio-technical challenge: What even are human factors?! and why should I care?
1230 - Prof Phil Morgan (Cardiff University)
&#8194;&#8194;&#8194;&#8194;&#8194;&#8194; Dr Oishee Kundu (University of Bath)
&#8194;&#8194;&#8194;&#8194;&#8194;&#8194; Stephen Donovan (Admiral)
&#8194;&#8194;&#8194;&#8194;&#8194; &#8194;Victoria Marcinkiewicz (Cardiff University)

End of track - 1330</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Village</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/U379K8/</url>
            <location>Roath Room</location>
            
            <attendee>Victoria Marcinkiewicz</attendee>
            
            <attendee>Rob Peace</attendee>
            
            <attendee>Oishee Kundu</attendee>
            
            <attendee>Alicia Cork</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>XP3JZU@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-XP3JZU</pentabarf:event-slug>
            <pentabarf:title>Lockpicking Village</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T093000</dtstart>
            <dtend>20240427T163000</dtend>
            <duration>070000</duration>
            <summary>Lockpicking Village</summary>
            <description>The combined TOOOL UK and UKLOCKSPORT.CO.UK team which last year provided the Lockpicking Village at BSides Brsitol 23 and Bsides London 23 would like to run a lockpick village at Bsides Cymru 24.  

We are proposing all the usual Lockpicking village content including skills transfer and maybe a competition or two.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Village</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/XP3JZU/</url>
            <location>Bute Room - Lockpicking village</location>
            
            <attendee>Rik Kershaw-Moore</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>RJCAYC@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-RJCAYC</pentabarf:event-slug>
            <pentabarf:title>ICS Village</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T093000</dtstart>
            <dtend>20240427T163000</dtend>
            <duration>070000</duration>
            <summary>ICS Village</summary>
            <description>Industrial control systems, such as those controlling many aspects of critical infrastructure including energy, water and manufacturing, are increasingly the target of sophisticated cyber attacks. At the ICS village you can see practical attack demonstrations against real ICS devices, including demonstrations of attack scenarios which can cause physical processes to go wrong. Demonstrations include reconnaissance of ICS devices (and how Nmap can kill devices), the exploitation of programmable logic controllers and password cracking of human machine interfaces.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Village</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/RJCAYC/</url>
            <location>Sponsors Hall</location>
            
            <attendee>Joe Gardiner</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>DWALNA@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-DWALNA</pentabarf:event-slug>
            <pentabarf:title>BattleBots</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20240427T093000</dtstart>
            <dtend>20240427T163000</dtend>
            <duration>070000</duration>
            <summary>BattleBots</summary>
            <description>BattleBots</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Village</category>
            <url>https://pretalx.com/bsides-cymru-2024/talk/DWALNA/</url>
            <location>Mezzanine</location>
            
            <attendee>Craig Jones, Clare Johnson + Stuart Criddle</attendee>
            
        </vevent>
        
    </vcalendar>
</iCalendar>
