{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.3.0.dev0", "url": "https://pretalx.com"}, "schedule": {"url": "https://pretalx.com/bsides-joburg-2026/schedule/", "version": "0.5", "base_url": "https://pretalx.com", "conference": {"acronym": "bsides-joburg-2026", "title": "BSides Joburg 2026", "start": "2026-07-25", "end": "2026-07-25", "daysCount": 1, "timeslot_duration": "00:05", "time_zone_name": "Africa/Johannesburg", "colors": {"primary": "#00ccff"}, "rooms": [{"name": "Track 1", "slug": "5278-track-1", "guid": "72ab5b9d-7650-5ed5-aa34-b0ed4c25e7b1", "description": null, "capacity": null}, {"name": "Track 2", "slug": "5279-track-2", "guid": "2fd34c2d-802d-5c37-9ebc-0f13a4d1df25", "description": null, "capacity": null}], "tracks": [], "days": [{"index": 1, "date": "2026-07-25", "day_start": "2026-07-25T04:00:00+02:00", "day_end": "2026-07-26T03:59:00+02:00", "rooms": {"Track 1": [{"guid": "c4c0ef97-8e4a-5545-ba58-ed0d318e27cd", "code": "KCZJXM", "id": 103220, "logo": null, "date": "2026-07-25T09:30:00+02:00", "start": "09:30", "end": "2026-07-25T10:20:00+02:00", "duration": "00:50", "room": "Track 1", "slug": "bsides-joburg-2026-103220-goedkoop-koop-is-duur-koop-the-price-of-cheap-thinking", "url": "https://pretalx.com/bsides-joburg-2026/talk/KCZJXM/", "title": "\"Goedkoop koop is duur koop\" - the price of cheap thinking", "subtitle": "", "track": null, "type": "Keynote", "language": "en", "abstract": "Thinking is expensive: time and effort, the one budget you can't refill. So we buy discounts like heuristics, tidy stories, curated feeds, and now agents that decide for us. Every discount is rational. Every discount is also an attack surface, and for twenty years an industry has been optimizing against it: a kill chain running recon, exploit, and payload against human cognition, at machine speed, one operator per user. This talk maps that attack: who runs it, how, and why \u2014 then asks the harder question: what actually defends against it, and where those defenses could break.", "description": "Cognition is expensive, so we buy cheaper substitutes, and someone else gets to set the price.", "recording_license": "", "do_not_record": false, "persons": [{"code": "ELQZLJ", "name": "Roelof Temmingh", "avatar": "https://pretalx.com/media/avatars/CHEDEA_WUiaQpq.webp", "biography": "Roelof Temmingh has worked in cybersecurity and Open-Source Intelligence (OSINT) for more than 25 years. Trained as an engineer (B.Eng, 1995), he began his career in IT security and penetration testing, co-founding SensePost, one of the early security consultancies, which later became part of Orange Cyberdefense.\n\nHe went on to start Paterva, the company that created Maltego, widely used for data visualization and relationship mapping in OSINT investigations. More recently, he founded Vortimo and is currently building Ubikron.\n\nOver the years, Roelof has given talks and training in many countries, sharing practical approaches to security and OSINT. He is known for creating tools that emphasize usability and real-world application rather than hype.", "public_name": "Roelof Temmingh", "guid": "a7242728-4bcc-5399-9aff-a39466addb56", "url": "https://pretalx.com/bsides-joburg-2026/speaker/ELQZLJ/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/KCZJXM/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/KCZJXM/", "attachments": []}, {"guid": "c93cbc22-e58f-5413-b749-79de3564486d", "code": "MJG7ER", "id": 98029, "logo": null, "date": "2026-07-25T10:25:00+02:00", "start": "10:25", "end": "2026-07-25T11:10:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-joburg-2026-98029-the-missing-drive-proving-a-hidden-linux-hdd-through-windows-registry-forensics", "url": "https://pretalx.com/bsides-joburg-2026/talk/MJG7ER/", "title": "The Missing Drive: Proving a Hidden Linux HDD Through Windows Registry Forensics", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "A suspect was linked to online financial fraud through ISP records. The user agent data suggested that the transactions had been performed from a Linux system. Yet when the computer was examined, only a Windows hard drive was present. The original forensic examination looked for familiar Windows artefacts, found nothing of value, and concluded that the computer could not have been used.\n\nBut what if the most important evidence was not on the drive that was examined?\n\nThis talk presents a real-world forensic case study of a missing Linux hard drive, a suspected dual-boot system, and the Windows registry artefacts that helped prove what had been removed. It is a technical walk-through of how forensic reconstruction can reveal the historical presence of storage devices, expose weak assumptions, and turn apparently absent evidence into a defensible conclusion.\nThe presentation will show how careful analysis of Windows registry hives, storage artefacts, boot-related configuration, and physical indicators allowed the investigation to move from \u201cthere is no Linux drive\u201d to \u201cthere was a Linux drive, it was used in this computer, and it appears to have been removed.\u201d\n\nThis is a talk about finding the evidence that someone hoped would stay hidden.", "description": "In digital forensics, some of the most important evidence is not always the evidence that is immediately visible. Sometimes the real question is not what is present, but what is missing, why it is missing, and what traces it left behind.\n\nThis talk presents a real-world forensic case study involving a suspect alleged to have conducted online financial fraud using a Linux-based system. The transactions had been traced back to the suspect through ISP records, and user agent string data suggested that the activity had originated from a Linux environment. However, when the suspect\u2019s computer was examined, the police only considered the Windows hard drive that was present in the machine. They searched for familiar Windows artefacts, including LNK files and Shellbags, and found nothing that linked the fraud activity to that Windows installation. On that basis, they concluded that the computer could not have been used.\n\nThat conclusion was wrong.\n\nThe problem was not simply that the police had failed to find the right artefacts. The deeper problem was that they had asked the wrong forensic question. The allegation was not that the suspect had conducted the transactions from Windows. The allegation, supported by the user agent evidence, was that the activity had taken place from a Linux system. The relevant question was therefore not whether there were Windows user artefacts proving the transactions. The relevant question was whether the physical computer had also been configured to boot into, or otherwise use, a Linux system that was no longer present.\n\nThrough a detailed forensic examination of the Windows registry hives and related system artefacts, it was possible to prove the prior existence of a second physical hard drive. Further analysis established evidence consistent with the computer having been configured as a dual-boot system, with Windows on one drive and Linux on another. The digital findings were then correlated with a physical examination of the computer itself, where tool marks and other physical indicators suggested that the second drive had been removed.\n\nThis presentation will walk through the investigative reasoning and technical analysis used to move from an apparent absence of evidence to a defensible forensic conclusion. It will examine how Windows can retain traces of historical storage devices, how registry artefacts can assist in reconstructing prior system configurations, and how boot-related and storage-related evidence can be used to identify signs of a missing operating system drive. It will also consider how physical examination findings can support and corroborate digital forensic conclusions.\nThe talk is not intended as a general overview of Windows artefacts. It is a practical, technical case study about forensic reconstruction in the face of deliberate concealment. It will show why forensic practitioners must be careful not to confuse the absence of expected artefacts with the absence of relevant evidence. It will also demonstrate the importance of hypothesis-led investigation, especially in cases where a suspect may have attempted to remove or conceal the most incriminating evidence.\n\nFor the BSides Johannesburg theme of \u201cLight the Way\u201d, this case provides a very direct example of what digital forensics should do. It is about illuminating what was hidden, testing assumptions, challenging weak conclusions, and helping investigators and courts understand what really happened. In this case, the light did not come from a single artefact or a single tool. It came from methodical forensic reasoning, careful registry analysis, and the convergence of digital and physical evidence.\n\nAttendees will leave with a better understanding of how Windows registry artefacts can reveal the historical presence of missing storage devices, how dual-boot configurations may be reconstructed after a drive has been removed, and why forensic conclusions must be based on tested hypotheses rather than a narrow search for familiar artefacts.", "recording_license": "", "do_not_record": false, "persons": [{"code": "GD8DRZ", "name": "Jason Jordaan", "avatar": "https://pretalx.com/media/avatars/CHUWTE_VP5WlkE.webp", "biography": "Jason Jordaan is the Principal Forensic Scientist and Founder of DFIRLABS. As a recognised polymath, he is considered by his peers internationally to be a leading specialist in the fields of digital forensics, incident response, cybercrime investigations, and cybersecurity forensic engineering. He was one of the early pioneers in digital forensics in South Africa with his interest and activities in the field beginning in the mid 1990\u2019s. Not only does Jason lead DFIRLABS, but he remains actively involved as a practitioner in these fields and regularly testifies as an expert witness in them.\n\nHe founded DFIRLABS in 2014 after leaving the Special Investigating Unit, where he was the national head of the Cyber Forensic Laboratory. In this role, he was responsible for the development and implementation of the digital forensics capacity of the Special Investigating Unit, and in conducting digital forensics engagements on several high-profile cybercrime, fraud, and corruption cases in the South Africa public sector. Prior to joining the Special Investigating Unit in 1998, Jason served as a Detective in the South African Police Service Commercial Branch from 1992, where he conducted numerous white-collar crime investigations, with a focus on organised crime.\n\nJason is an active researcher, academic, trainer, advisor and assessor in the international digital forensics and cybersecurity communities. He is a Principal Instructor with the internationally renowned SANS Institute. In this capacity he teaches digital forensics around the world, including to some of the leading international law enforcement, intelligence, and miliary units such as the Federal Bureau of Investigations, the US Secret Service, US Special Operations Command, Scotland Yard, the UK National Crime Agency, and many others. He also has provided digital forensics and incident response training to numerous companies in the Fortune 500 list. He is also as Assistant Professor at the SANS Technology Institute. He has also taught digital forensics at the University of Cape Town, the University of Pretoria, and Rhodes University. \n\nHe currently serves on the SANS Advisory Board and on the Advisory Board of the Department of Computer Science of the University of Pretoria. He also served on the expert advisory panel for the South African Deputy Minister of Justice for cybercrime legislation and has advised the South African Police Service on the South African National Cybercrime Strategy.\n\nJason is an assessor for the Netherlands Register of Court Experts and is responsible for the assessing the competency of digital forensics practitioners testifying in court in the Netherlands. He is a Director of the Institute of Commercial Forensic Practitioners of South Africa. He has previously served as a Director of the South African Academy of Forensic Sciences, and the South African Chapter of the Association of Certified Fraud Examiners. His digital forensics, cybersecurity, and cyberlaw research has been published in textbooks and international peer-reviewed journals, and he is a frequent speaker at professional, scientific, and technical conferences internationally. He also sits on several international and local conference advisory boards.", "public_name": "Jason Jordaan", "guid": "a04d5d66-9c86-5d3c-b94c-c7ffdbde0771", "url": "https://pretalx.com/bsides-joburg-2026/speaker/GD8DRZ/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/MJG7ER/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/MJG7ER/", "attachments": []}, {"guid": "44fc96ca-7d3d-5fa2-8ce8-1752dc5d8e05", "code": "GGUMFJ", "id": 100285, "logo": null, "date": "2026-07-25T11:15:00+02:00", "start": "11:15", "end": "2026-07-25T12:00:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-joburg-2026-100285-rooting-the-wink-hub-2-finally", "url": "https://pretalx.com/bsides-joburg-2026/talk/GGUMFJ/", "title": "Rooting the Wink Hub 2 (finally)", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "The Wink Hub 2 is a 2016 multi-radio home automation hub, which was locked down using High Assurance Boot techniques. This talk will cover my efforts over a period of 3 years to finally run my own code on it - apparently the first person to do so.", "description": "The Wink Hub 2 is a 2016 multi-radio home automation hub, originally purchased by myself because of its appearance as a hardware hacking playground - multiple manufacturer radio reference implementations dotted around the board, each with their own programming interface brought out to headers. Due to how easily the prior generation Hub 1 was hacked, the company implemented Freescale/NXP High Assurance Boot v4 techniques to lock the Hub 2 down. These were effective for 10 years to the best of my knowledge - I have seen no reports of anyone else successfully executing their own code on the Hub 2.\n\nThis talk will cover my efforts to break the security of the Wink Hub 2, and the lengths to which I went over a three year period to finally execute my own code on this device.", "recording_license": "", "do_not_record": false, "persons": [{"code": "FXZR3F", "name": "Rogan Dawes", "avatar": "https://pretalx.com/media/avatars/ZAVVZL_AK3Eo4I.webp", "biography": "Rogan Dawes is a senior researcher at SensePost and has been hacking since 1998, which, coincidentally, is also the time he settled on a final wardrobe. He used the time he saved on choosing outfits to live up to his colleague\u2019s frequent joke that he has an offline copy of the Internet in his head. Rogan spent many years building web application assessment tools, and is credited as having built one of the first and most widely used intercepting proxies; WebScarab. In recent years, Rogan has turned his attentions towards hardware hacking; and these days many suspect him to be at least part cyborg. A good conversation starter is to ask him where he keeps his JTAG header.", "public_name": "Rogan Dawes", "guid": "0c129bbe-0389-57d5-959c-ef2781abea67", "url": "https://pretalx.com/bsides-joburg-2026/speaker/FXZR3F/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/GGUMFJ/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/GGUMFJ/", "attachments": []}, {"guid": "f313257d-597a-5af8-aba6-efccf391f964", "code": "VY8CVH", "id": 97937, "logo": null, "date": "2026-07-25T12:05:00+02:00", "start": "12:05", "end": "2026-07-25T12:50:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-joburg-2026-97937-stop-waiting-for-unicorns-bulding-sa-s-security-pipeline-with-3-300-interns", "url": "https://pretalx.com/bsides-joburg-2026/talk/VY8CVH/", "title": "Stop Waiting for Unicorns: Bulding SA's Security Pipeline with 3,300 Interns", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "South Africa's cybersecurity skills gap isn't a future problem, it's a present one. Demand for security experts has been outpacing supply for years, and the organisations feeling the squeeze tend to respond the same way: raise the hiring salary and wait for job-ready candidates who don't exist yet.\n\nWe decided to test a different approach. MWR launched a free virtual internship programme for any students designed to take motivated individuals and give them structured, practical security training over 16 weeks. There was no barrier to entry, but there was only one condition, if you fail 3 assignments you're out. More than 3,300 people applied. After five weeks and the simple three-strike rule, over 1,800 had already dropped off. But roughly 800 stuck it out, keeping up with assignments week on week and  demonstrating exactly the kind of persistence the industry claims it can't find.\n\nThis talk draws on data from that programme alongside experience recruiting through MWR's traditional pipelines, observing self-directed learning trends through TryHackMe, and working inside university cybersecurity programmes at the University of Pretoria and Wits. Together, these lenses reveal where the talent pipeline is breaking, where it's stronger than we think, and why the organisations waiting for the \"finished product\" are missing the point.\n\nWe'll end off  with a practical call to action to the entire cyber security community. Highlighting specific, low-barrier ways the security community, not just employers, can help widen and strengthen the pipeline. MWR can't do this alone. The data says the talent and passion is there. The question is whether our industry is willing to meet it halfway.", "description": "## Talk Overview\n\n### 1. The Gap Is Real (and Getting Louder)\nFraming the South African cybersecurity skills shortage with demand-side data and what it looks like from inside recruitment. Why the current model of \"post a job and hope\" isn't working.\n\n### 2. Four Lenses on the Pipeline\nWhat MWR recruitment (600+ applicants), TryHackMe training data, university programmes (University of Pretoria, Wits), and the virtual internship each reveal about the talent funnel. Where candidates come from, where they stall, and what accelerates them.\n\n### 3. 3,300 to 800: The Virtual Internship Experiment\nThe design and structure of the programme, the three-strike attrition model, the dropout curve over 16 weeks, and what the data tells us about motivation versus readiness. Who stayed, who left, and what separated the two groups.\n\n### 4. Where the Pipeline Breaks\nWhy traditional recruitment signals (degrees, certifications, prior experience) miss good candidates. Why \"job-ready\" expectations are unrealistic when training structures don't exist. Why formal postgraduate programmes are arriving slowly and what that means for the next few years.\n\n### 5. Where the Pipeline Is Stronger Than We Think\nThe 800 who stayed and what they demonstrated. How self-learning platforms have changed the speed of skill acquisition. What effective junior development actually looks like when organisations invest in it.\n\n### 6. The Call to Action\nConcrete, specific, low-barrier ways organisations and individuals can contribute: mentorship commitments, structured shadowing placements, open training content contributions, and hiring model adjustments that recognise non-traditional pathways. What MWR has learned about what works, and where we need the rest of the industry to step in.\n\n---\n\n## Key Takeaways\n\n1. **The bottleneck isn't motivation, it's the gap between \"interested\" and \"employable\"**.\n\n2. **Structured programmes surface committed candidates quickly**: Data from 3,300 virtual internship applicants shows that a deliberate attrition model identified 800 consistently engaged participants within five weeks.\n\n3. **Traditional recruitment signals frequently fail**: Degrees, certifications, and prior experience don't reliably predict who will succeed when given structured support and practical training.\n\n4. **Self-learning platforms have changed the game, but they're not enough**: Without industry investment in mentorship and practical pathways, the pipeline remains fragile and dependent on individual resilience.\n\n5. **Small, concrete actions from the broader community can meaningfully widen the talent stream**: This isn't a problem that requires massive budgets, just willingness to meet emerging talent halfway.", "recording_license": "", "do_not_record": false, "persons": [{"code": "F8VZXY", "name": "Tinus Green", "avatar": "https://pretalx.com/media/avatars/PDD89G_ywHasbM.webp", "biography": "Passionate about cybersecurity, helping upskill others, and generally getting involved in the cybersecurity community!", "public_name": "Tinus Green", "guid": "04985167-c634-5976-8eb3-240f8f9b302a", "url": "https://pretalx.com/bsides-joburg-2026/speaker/F8VZXY/"}, {"code": "BXUXSL", "name": "Jonathon Everatt", "avatar": "https://pretalx.com/media/avatars/HHDF3D_yYXJysS.webp", "biography": "I'm a Senior CyberSecurity consultant at MWR CyberSec. I've spoken a BSides Cape Town a few times before and some other conferences. I'm an organsior of the MWR Virtual Internship and Internship.\n\nCome say hi", "public_name": "Jonathon Everatt", "guid": "22b34c0f-df8a-5470-9173-22d477869c32", "url": "https://pretalx.com/bsides-joburg-2026/speaker/BXUXSL/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/VY8CVH/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/VY8CVH/", "attachments": []}, {"guid": "f9469184-b697-56f2-820f-d64c8bff8cf8", "code": "3FQBRW", "id": 100177, "logo": null, "date": "2026-07-25T13:30:00+02:00", "start": "13:30", "end": "2026-07-25T14:15:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-joburg-2026-100177-1-logsource-to-rule-them-all-what-dns-is-telling-you-that-you-re-not-listening", "url": "https://pretalx.com/bsides-joburg-2026/talk/3FQBRW/", "title": "1 LogSource to rule them all: What DNS Is Telling You(That You're Not Listening)", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "Every organisation on this continent is generating DNS logs right now. Very few of them are reading those logs for threats. That single oversight is letting attackers use the most trusted protocol on your network as a covert highway for command and control, data exfiltration, and long-term persistence. South Africa now faces nearly 2,000 cyberattacks per organisation per week, yet most SOCs are drowning in endpoint alerts while DNS queries whisper attacker activity in plain text, completely unread. This talk shows what a single, generally available log source reveals: C2 beaconing hidden in query frequency, data leaving your network one subdomain at a time, and malware phoning home through resolvers you trust.", "description": "**Introduction \u2014 The Log Source You Already Have**\nEvery organisation running a network has DNS. It is the first thing that fires when a device connects, the last thing that fires before data leaves, and the quiet witness to almost every stage of an attack. Yet in most African SOCs, DNS logs sit unqueried. This talk makes the case what defenders can do with less,  they need to start listening to the one witness that never goes offline. The theme of this conference is \"Light the Way.\" DNS is the flashlight that was always in your pocket.\n\n**Technical Deep Dive \u2014 Five Things DNS Sees That Your SIEM Misses**\nWe walk through five concrete attacker behaviours that leave clear, detectable traces in DNS logs alone: C2 beaconing via regular query intervals to attacker-controlled domains; DNS tunneling for covert data exfiltration encoded in subdomains; domain generation algorithms (DGAs) used by malware to find live C2 infrastructure; newly registered domain (NRD) abuse for phishing and initial access; and lateral movement fingerprinted through internal DNS resolution patterns. For each, we show the exact query patterns, the ES|QL detection rule that catches it, and what a clean alert looks like versus noise.\n\n**Real-World Relevance \u2014 What African Attackers Are Actually Doing**\nDrawing on publicly documented attack patterns from recent African incidents, including telecom breaches and ransomware campaigns active in the region in 2025, we map the DNS artifacts those attackers left behind. Ransomware groups like Qilin, Akira, and DragonForce, all confirmed active in Africa as of early 2026, rely heavily on DNS for C2 and staging. Their tradecraft is well-documented. Their DNS fingerprints are detectable.\n\n**Key Takeaways \u2014 Getting the Most Out of What You Already Have**\nDNS logs are basic. What you do with them is not. Attendees will leave knowing how to enrich raw DNS telemetry, adding context like domain lengths, TXT payload size, DNS history, threat intel enrichment, domain age, and reputation scoring to transform a plain query log into a high-signal detection source. We cover the specific attack behaviours that DNS exposes at each stage of the kill chain, the signatures that distinguish malicious DNS patterns from legitimate traffic (query length anomalies, entropy scoring for DGA detection, beaconing intervals, TXT record abuse), and the detection rules that operationalise those signatures immediately.", "recording_license": "", "do_not_record": false, "persons": [{"code": "B8VEXM", "name": "Mohammed Anas", "avatar": "https://pretalx.com/media/avatars/TT8FGB_3Fwwj8D.webp", "biography": "A seasoned security practitioner with over a decade of experience building and managing Security Operations Centres across the Middle East, Africa, and Europe. Having started on the offensive side \u2014 understanding how attackers think, move, and hide the transition to defence brought a sharper eye for what most blue teams miss. That attacker's perspective is what drives this talk: DNS isn't just a log source, it's the trail adversaries leave behind, and most defenders aren't following it yet.", "public_name": "Mohammed Anas", "guid": "91ca600d-2377-52c0-8d3c-0697aec41d5f", "url": "https://pretalx.com/bsides-joburg-2026/speaker/B8VEXM/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/3FQBRW/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/3FQBRW/", "attachments": []}, {"guid": "0333380d-0c1f-5520-927e-b9340c4d12ec", "code": "WAKEAZ", "id": 100564, "logo": null, "date": "2026-07-25T14:20:00+02:00", "start": "14:20", "end": "2026-07-25T14:40:00+02:00", "duration": "00:20", "room": "Track 1", "slug": "bsides-joburg-2026-100564-the-black-box-problem-detection-engineering-in-the-age-of-ai-agents", "url": "https://pretalx.com/bsides-joburg-2026/talk/WAKEAZ/", "title": "The Black Box Problem: Detection Engineering in the Age of AI Agents", "subtitle": "", "track": null, "type": "Lightning Talk", "language": "en", "abstract": "Detection engineering is about more than alerts and SIEM rules; it is the practice of understanding attacker behaviour and building the visibility needed to detect it. As AI becomes embedded into enterprise environments through agents, copilots, and connected ecosystems, organisations face new identity, data, and supply chain risks that are difficult to monitor using traditional approaches. This talk explores how detection engineering can help illuminate these emerging threats and asks a bigger question: if every breach contains valuable lessons, why does cybersecurity still lack an effective way to share them with the wider industry?", "description": "Many organisations invest heavily in SIEM platforms and security tooling, yet struggle to answer a simple question: what attacks can we actually detect? Detection engineering seeks to bridge that gap by focusing on visibility, telemetry, attacker behaviour, and continuous improvement rather than simply collecting logs and generating alerts.\n\nAt the same time, organisations are rapidly embedding AI into everyday business operations. AI assistants, autonomous agents, MCP servers, and AI-powered workflows are becoming trusted participants in enterprise environments. These systems are creating entirely new security challenges. AI agents increasingly operate with delegated permissions, access sensitive corporate data, and interact with critical business systems, introducing new identity risks that traditional security models were never designed to handle. The growing ecosystem of models, plugins, connectors, MCP servers, and open-source components also introduces significant supply chain risk, often with limited visibility into how these systems operate or what dependencies they rely upon.\n\nAs adoption accelerates, these challenges will inevitably contribute to new classes of security incidents, compromises, and failures. Yet cybersecurity has a problem of its own. Unlike industries such as aviation, which have mature processes for investigating accidents and sharing lessons learned, cybersecurity lacks an effective mechanism for collective learning. Breaches are often hidden behind legal agreements, reputational concerns, or private incident reports, leaving the broader community unable to benefit from the lessons they contain.\n\nThis talk explores what detection engineering is, how it extends beyond traditional SIEM deployments, and why it is becoming increasingly important as AI reshapes enterprise environments. It also examines the growing AI attack surface, the identity and supply chain risks that accompany it, and why the industry may need its own equivalent of an aviation accident investigation board if we want to stop repeating the same mistakes and start learning from each other's failures.", "recording_license": "", "do_not_record": false, "persons": [{"code": "3QSAAW", "name": "Jared Naude", "avatar": "https://pretalx.com/media/avatars/NC8LQU_LdGN9WE.webp", "biography": "Jared is the Head of Security at Synthesis, where he specializes in enterprise cloud architecture. Jared is passionate and deeply committed to guiding large organizations through the complexities of architecting, securing and operationalizing enterprise cloud environments. Beyond Jared\u2019s professional responsibilities, Jared is an enthusiastic advocate for community building, serving as the organizer of several local security events, including 0xcon, BSides Cape Town, and BSides Joburg. Jared\u2019s research focuses on cybersecurity topics that intersect with national security and foreign policy issues such as encryption, privacy, surveillance, disinformation, and nation-state activity.", "public_name": "Jared Naude", "guid": "e6f21261-d4f1-5305-954d-f40752d9fc9b", "url": "https://pretalx.com/bsides-joburg-2026/speaker/3QSAAW/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/WAKEAZ/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/WAKEAZ/", "attachments": []}, {"guid": "1a7aaffd-72f8-528d-9b6b-14b81bf40209", "code": "SCMAG7", "id": 99982, "logo": null, "date": "2026-07-25T14:40:00+02:00", "start": "14:40", "end": "2026-07-25T14:55:00+02:00", "duration": "00:15", "room": "Track 1", "slug": "bsides-joburg-2026-99982-cells-and-claws-a-mental-model-for-autonomous-ai-agents", "url": "https://pretalx.com/bsides-joburg-2026/talk/SCMAG7/", "title": "Cells and Claws: A Mental Model for Autonomous AI Agents", "subtitle": "", "track": null, "type": "Lightning Talk", "language": "en", "abstract": "\"AI agent\" has become a catch-all term that hides more than it reveals, and builders, defenders, and testers are making decisions on top of incomplete mental models. This talk builds one from first principles: starting with the base LLM and climbing seven generations to the Claw, an autonomous digital agent operating with persistent identity, tools, and goals. We then contrast the Claw with the most successful autonomous agent we know, the biological cell, and find a shared code/data problem, a shared hijack pattern (adenovirus vs. prompt injection), and one critical gap: the Claw has no immune system. Attendees leave with a working mental model of AI agents, a reasoning tool, not a checklist that drives better decisions on design, control selection, surveillance, and response.", "description": "Introduction\n\nAsk ten security professionals what an \"AI agent\" is and you will get ten different answers, most of them gesturing at something between an over-eager intern, a souped-up search engine, and an embryonic AGI. None of those models are wrong, but none of them are useful when you have to decide what to sandbox, what to log, or what to kill. As Claws, autonomous, tool-using, goal-pursuing systems with persistent identity move from labs into production, the cost of operating without a working mental model is measured in incidents. This talk is about lighting that path: building a model that is technically incomplete (all models are) but sharp enough to reason with.\n\nTechnical Deep Dive\n\nWe start at Generation 0: the base LLM as a probability distribution over tokens, demonstrated with a Galton board and grounded in a simplistic example of Karpathy's \"200 lines of Python\" microGPT. From there we climb seven generations Chat, Tool-Using, Workspace, Coding, Autonomous, Multi-Agent, and finally the Claw: a digital agent with persistent identity, file access, code execution, long-running tasks, and the ability to delegate. Along the way we look at what the industry currently uses to control these systems: sandboxing, prompt-injection guards, code / data separation attempts, and where each control breaks down at Claw scale. \n\nReal-World Relevance\n\nCells are autonomous, tool-using, self-replicating agents, and they are the best-studied agents we have. They solve the same problems Claws do, code / data confusion, identity, surveillance, shutdown \u2014 and we can take some lessons from their solutions. We build a parallel mental model of the cell, DNA as code-and-data, mRNA as instruction stream, MHC (Major Histocompatibility Complex) presentation as mandatory observability, apoptosis as self-attested shutdown, and then introduce the adenovirus as a textbook hijack: code-flow takeover by injecting foreign DNA into a system that cannot distinguish self from non-self at the molecular level. The talk will discuss comparisons of Cell vs. Claw across code / data confusion, hijack vector, surveillance, shutdown, and identity. The findings are uncomfortable: the Claw shares most of the cell's failure modes, and has none of the cell's defenses.\n\nKey Takeaways\n\nThe headline takeaway is the model itself. A useful mental model is not a list of answers, it is a reasoning tool. Once you have one for AI agents as a class, anchored by the seven-generation ladder and the cell mirror, you can think more clearly and make better decisions.", "recording_license": "", "do_not_record": false, "persons": [{"code": "GPVV3Z", "name": "Marinus van Aswegen", "avatar": "https://pretalx.com/media/avatars/ZPVEMU_Q51nvJo.webp", "biography": "Marinus is a Cyber Security professional with over 25 years of experience consulting to startups, multinationals, government, and law enforcement. He has extensive experience in building banks from the ground up and is currently focusing on AI engineering.\n\nMarinus has a background in architecture, risk management, security assessments, testing, audit, forensics, penetration testing, and development. He holds numerous international security certifications including CISSP, ISSMP, ISSAP, and CSSLP, and is a certified TOGAF 10 Enterprise Architecture Practitioner.\n\nIn 2006 he founded Telic, a specialist consulting practice that helps customers bring products and services to market by managing their security design, engineering, and implementation concerns.\n\nBefore Telic, he was a Principal Consultant at Deloitte, working with clients across Europe, Africa, Japan, and Australia.", "public_name": "Marinus van Aswegen", "guid": "6c2d965b-1db3-5f18-ba82-23c068b0aa28", "url": "https://pretalx.com/bsides-joburg-2026/speaker/GPVV3Z/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/SCMAG7/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/SCMAG7/", "attachments": []}, {"guid": "940d0211-ebd2-5484-b6db-3a0e56a95b52", "code": "YHKD9B", "id": 99006, "logo": null, "date": "2026-07-25T15:05:00+02:00", "start": "15:05", "end": "2026-07-25T15:50:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-joburg-2026-99006-pipe-dreams-escalating-to-system-via-cooler-master-masterplus", "url": "https://pretalx.com/bsides-joburg-2026/talk/YHKD9B/", "title": "Pipe Dreams: Escalating to SYSTEM via Cooler Master MasterPlus", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "Every gaming peripheral that ships to your desk comes bundled with software running silently as NT AUTHORITY\\SYSTEM. These OEM utilities are trusted, rarely audited, and almost never patched.\n\nIn this talk I walk through the discovery and exploitation of a local privilege escalation vulnerability in Cooler Master MasterPlus. A  peripheral management suite installed on millions of Windows machines. The root cause is an unauthenticated named pipe exposed by MPService.exe (SYSTEM). Any standard local user can connect, send a single JSON payload, and execute arbitrary commands as SYSTEM with no admin rights, no user interaction, and no race condition required.\n\nI'll cover the full methodology: service enumeration, pipe discovery, Ghidra static analysis, dynamic confirmation, and a working proof-of-concept.", "description": "OEM peripheral software ships trusted on millions of Windows machines, runs as SYSTEM, and almost never receives a security review. Inspired by Leon Jacobs' DEF CON 33 research, this talk applies the same methodology to a major peripheral manufacturer's management suite.\n\nMethodology:\nSystematic enumeration of SYSTEM services, IPC surface discovery, access control analysis, and binary reverse engineering. I'll cover the tooling and decision points that led from initial enumeration to a confirmed vulnerability.\n\nRoot Cause Analysis:\nStatic analysis identifies a privileged IPC handler that accepts unauthenticated connections from any local user and processes attacker-controlled input without validation. I'll walk through the decompiled code showing exactly where the trust boundary fails and why the impact is full SYSTEM code execution.\n\nDemo:\nProof-of-concept demonstrated live: standard user to NT AUTHORITY\\SYSTEM in a single step. No admin rights, no user interaction, no race condition.\n\nRemediation & Disclosure:\nVendor disclosure process including what to expect when a vendor has no dedicated PSIRT.\n\nTakeaways & Q&A:\n\nKey Takeaways\n1. A replicable methodology for auditing OEM/bloatware SYSTEM services\n2. How Windows IPC access controls are commonly misconfigured\n3. Navigating coordinated disclosure with vendors that lack a PSIRT", "recording_license": "", "do_not_record": false, "persons": [{"code": "ZZS9UN", "name": "Tyron Kemp", "avatar": "https://pretalx.com/media/avatars/RXLFHY_D3SypEa.webp", "biography": "Tyron Kemp is a cybersecurity professional with with a background spanning network engineering, penetration testing, and deception technology. He is perhaps best known for his Black Hat USA 2020 briefing, Routopsy: Modern Routing Protocol Vulnerability Analysis and Exploitation, co-presented with Szymon Ziolkowski at SensePost, where he exposed how misconfigured dynamic routing and first-hop redundancy protocols can be weaponised for person-in-the-middle attacks, releasing an open-source toolkit alongside the research.\n\nIn recent years, Tyron has worked where offensive tradecraft, detection engineering, and deception technologies overlap, helping organisations understand how attackers operate and how to reduce risk in ways that matter.\n\nIn his BSides Joburg 2026 talk, Pipe Dreams, he turns his attention to the endpoint by walking through how he escalated privileges to SYSTEM via Cooler Master's MasterPlus software, because sometimes the most dangerous vulnerabilities are hiding in the software you least expect.", "public_name": "Tyron Kemp", "guid": "9ce04129-aab3-5126-9978-e7c63a23f6a3", "url": "https://pretalx.com/bsides-joburg-2026/speaker/ZZS9UN/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/YHKD9B/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/YHKD9B/", "attachments": []}, {"guid": "645df8ec-bf33-5d71-af1a-0326d131b039", "code": "EQCAL7", "id": 99829, "logo": "https://pretalx.com/media/bsides-joburg-2026/submissions/EQCAL7/image_LpiEAax.webp", "date": "2026-07-25T15:55:00+02:00", "start": "15:55", "end": "2026-07-25T16:10:00+02:00", "duration": "00:15", "room": "Track 1", "slug": "bsides-joburg-2026-99829-shedding-light-on-mobile-trust-rethinking-ssl-pinning", "url": "https://pretalx.com/bsides-joburg-2026/talk/EQCAL7/", "title": "Shedding Light on Mobile Trust: Rethinking SSL Pinning", "subtitle": "", "track": null, "type": "Lightning Talk", "language": "en", "abstract": "**SSL pinning is not dead \u2014 it just needs a redesign.**\n\nMobile applications have traditionally relied on static SSL pinning to defend against man-in-the-middle attacks. However, static pins introduce operational challenges, including certificate rotations, application updates, and recovery from compromised trust anchors.\n\nThis talk explores an alternative approach: a protocol-driven model that enables the secure exchange and validation of SSL pins between a mobile application and backend services. By moving beyond hardcoded trust relationships, organisations can improve resilience, reduce deployment friction, and maintain strong transport security without sacrificing agility.\n\nWe will examine the threat landscape, design considerations, trust-establishment mechanisms, and practical implementation patterns for securely distributing and validating pins at runtime. Attendees will leave with a fresh perspective on mobile trust models and a roadmap for building more adaptable, future-ready SSL pinning solutions.", "description": "**Bootstrapping Trust: Secure Distribution of SSL Pins in Mobile Applications**\n\nSSL pinning has long been considered a cornerstone of mobile application security. Yet most implementations still rely on hardcoded pins embedded within applications, creating an uncomfortable trade-off between security and operational agility. Certificate rotations, emergency key replacements, backend migrations, and application release cycles often turn a security control into an operational burden.\n\nThis talk explores a different approach to establishing trust between mobile applications and backend services. Instead of shipping static trust anchors inside the application, we examine a protocol that securely bootstraps trust and dynamically distributes SSL pinning configuration to mobile clients.\n\nThe architecture leverages modern cryptographic primitives, including Ed25519 for digital signatures, asymmetric key exchange for trust establishment, and AES encryption for secure transport of sensitive configuration data. During an initial registration phase, the mobile application generates a unique device trust identity and establishes a secure cryptographic relationship with the server. Once trust has been established, the server can securely distribute and rotate SSL pinning information without requiring application updates or exposing trust material to interception.\n\nThe session walks through the protocol design, trust establishment process, cryptographic decision-making, and implementation challenges encountered while building the solution. We will discuss key rotation strategies, secure storage considerations, and how the design resists common attacks such as man-in-the-middle interception, and other pin distribution strategies.\n\nAttendees will gain practical insights into the future of mobile trust models, understand the limitations of traditional SSL pinning approaches, and leave with architectural patterns to build more resilient mobile security controls in environments where change is constant and trust cannot be hardcoded forever.", "recording_license": "", "do_not_record": false, "persons": [{"code": "L38NBQ", "name": "Christoff Jacobs", "avatar": "https://pretalx.com/media/avatars/GQ7VWT_HIrTY9B.webp", "biography": "Software Developer | Mobile Security Enthusiast", "public_name": "Christoff Jacobs", "guid": "dbe94313-5831-5d23-a192-31960ce5d576", "url": "https://pretalx.com/bsides-joburg-2026/speaker/L38NBQ/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/EQCAL7/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/EQCAL7/", "attachments": []}, {"guid": "8287c125-bdfd-5ef5-8ea4-69166831e212", "code": "WKRNMH", "id": 98263, "logo": null, "date": "2026-07-25T16:10:00+02:00", "start": "16:10", "end": "2026-07-25T16:25:00+02:00", "duration": "00:15", "room": "Track 1", "slug": "bsides-joburg-2026-98263-from-unknown-to-understood-malware-triage-in-minutes", "url": "https://pretalx.com/bsides-joburg-2026/talk/WKRNMH/", "title": "From Unknown to Understood: Malware Triage in Minutes", "subtitle": "", "track": null, "type": "Lightning Talk", "language": "en", "abstract": "Malware analysis can often feel out of reach for newer analysts, particularly when discussions move into reverse engineering and assembly. In practice, however, the earliest stages of analysis frequently provide enough information to form an initial understanding of a sample.\n\nThis talk introduces a structured \u201cfirst 10 minutes\u201d malware triage workflow, covering hashes, reputation analysis, strings extraction, and sandbox detonation. The focus is on efficiently identifying behavioural indicators and building a coherent analytical narrative from early observations, rather than immediately relying on deep reverse engineering.\n\nAttendees will leave with a repeatable and practical approach to early-stage malware analysis that supports incident response workflows, strengthens analytical confidence, and improves the ability to quickly translate unknown samples into meaningful, actionable insight.", "description": "This session is aimed at analysts who want a practical starting point for malware analysis without immediately diving into reverse engineering. Using a lightweight workflow, I will show how simple triage steps can quickly uncover useful context, suspicious behaviour, infrastructure, and attacker intent.\n\nStatic and dynamic analysis techniques are combined to show how hashes, strings, reputation data, and sandbox observations can be used together to build a clearer understanding of a sample. Along the way, we discuss the importance of treating indicators as clues rather than conclusions, and how defenders can turn scattered observations into practical, actionable insight.\n\nRather than focusing on advanced reverse engineering, this session demonstrates that meaningful analysis begins much earlier, and that newer analysts can contribute valuable findings with the right approach.\n\nKey Takeaways:\n- A simple malware triage workflow for the first 10 minutes\n- How to combine simple static and dynamic analysis effectively\n- Ways to identify useful indicators and suspicious behaviour quickly\n- How to turn technical findings into a coherent analysis story", "recording_license": "", "do_not_record": false, "persons": [{"code": "FKGNU7", "name": "Latasha Friend", "avatar": "https://pretalx.com/media/avatars/LAFLEL_rOXW0Lq.webp", "biography": "Latasha Friend is a cybersecurity consultant at Integrity 360, where she serves as technical lead of the incident response team. Having begun her career in penetration testing, she transitioned into incident response driven by a passion for digital forensics and active threat management.\n \nMalware analysis quickly stood out as a fascinating and essential piece of the incident response puzzle. Since then, she has been building her knowledge in this space, driven by a genuine curiosity about how malware works and a desire to turn that understanding into faster, sharper triage decisions. As a certified incident responder working directly in client environments, Latasha sees firsthand how critical it is to quickly make sense of a threat before it does real damage.\n \nThe excitement of untangling complex problems is what drew her to this topic and what this talk is built around.", "public_name": "Latasha Friend", "guid": "f45dc38c-aae7-5b6f-9eba-13c6f986e7a9", "url": "https://pretalx.com/bsides-joburg-2026/speaker/FKGNU7/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/WKRNMH/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/WKRNMH/", "attachments": []}, {"guid": "84e3188d-5599-5a06-abb0-2e4fbd2b6f9f", "code": "AXTUMN", "id": 100032, "logo": null, "date": "2026-07-25T16:25:00+02:00", "start": "16:25", "end": "2026-07-25T16:40:00+02:00", "duration": "00:15", "room": "Track 1", "slug": "bsides-joburg-2026-100032-using-csc-to-build-future-cyber-workforce", "url": "https://pretalx.com/bsides-joburg-2026/talk/AXTUMN/", "title": "Using CSC to build future cyber workforce", "subtitle": "", "track": null, "type": "Lightning Talk", "language": "en", "abstract": "The cyber security skills gap is a global problem, but it is acutely felt in South Africa, where access to structured, affordable, and locally relevant training remains limited. This talk draws on first-hand experience designing and building Capture the Flag (CTF) challenges for the SANReN Cyber Security Challenge (CSC) to explore how individuals and small groups can become the spark that ignites a local security community.\n\nFrom identifying the gap to building beginner-friendly challenges, running competitions, and watching participants grow into contributors. The SANReN CSC was created with the sole purpose of building up local cyber security skills but we would like to extend that goal by supporting local communities to start up their own initiatives and hacking communities.", "description": "Most cyber security training is expensive, foreign, or assumes a level of access that many South African students and practitioners simply do not have. Many South African tertiary institutions do not even offer cyber security at undergrad level, only at Honours or Masters level. Yet many of these students have immense talent. It just needs _a guiding light_.\n\nThis talk will cover the story behind building CTF challenges for the SANREN CSC, what worked, what did not, and what any motivated person or group can replicate without a large budget.\n\nPreviously a similar talk was presented at BSides Cape Town 2025, this talk has been updated and expanded for BSides Joburg with new lessons learned and a broader focus on community building beyond the CTF context.", "recording_license": "", "do_not_record": false, "persons": [{"code": "DCFSKW", "name": "Ivan Burke", "avatar": "https://pretalx.com/media/avatars/ANGEA7_znebSgh.webp", "biography": "I currently serve as the Head of Research, Development, and Innovation at BlueVision ITM, where I lead initiatives in cyber security innovation and capability development. I specifically focus on bridges the gap between theoretical research and practical application, particularly in areas like cryptography, network security, and cyber resilience.\n\nI am passionate about fostering the next generation of cyber security talent through mentorship and community engagement. As such, I contribute to various cyber security events, community gatherings and cyber security challenges throughout South Africa.", "public_name": "Ivan Burke", "guid": "6acc54a4-592f-59be-9b6d-a400f4769e72", "url": "https://pretalx.com/bsides-joburg-2026/speaker/DCFSKW/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/AXTUMN/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/AXTUMN/", "attachments": []}, {"guid": "0710ee4c-e258-5a32-9eea-2704a7014e34", "code": "3QBKMN", "id": 99879, "logo": null, "date": "2026-07-25T16:45:00+02:00", "start": "16:45", "end": "2026-07-25T17:30:00+02:00", "duration": "00:45", "room": "Track 1", "slug": "bsides-joburg-2026-99879-socvel-live-the-ciso-s-gambit", "url": "https://pretalx.com/bsides-joburg-2026/talk/3QBKMN/", "title": "SocVel Live : The CISO's Gambit", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "I don't sign off on risk waivers and I don't set the budgets. But, more often than not, I am the one who tells the CISO why their weekend plans are about to get ruined.\n\nThe CISO's Gambit is a live strategy simulation where Threat Intelligence sets the scene and the audience drives the response. Drawing on the cyber roller coaster of the past 12 months, you get put in the hot seat of the one whose weekend is now also ruined. When a critical vendor is compromised, do you halt production or do \"heightened monitoring\" and pray. When the geopolitical mess spills over into cyber, do you change vendors or duck and cover. \n\nThrough live audience voting, we track the real-world impact of your choices across key metrics. No slides. No safe paths. Just trade-offs, facepalms and high-fives through a collective decision-making experiment.", "description": "This isn't a talk about security leadership. But a look at how those decisions are made collectively. Decisions that need to get taken because someone, probably someone in this room, found something. Flagged something. Wrote the email that landed in the wrong inbox at the wrong time and suddenly it's everyone's problem. \n\nThe CISO's Gambit is the next evolution of SocVel Live, the interactive tabletop format that took home Best Speaker at BSides JHB 2025. This time, we're not hunting the threat. We're managing what comes after.\n\nWorking through scenarios grounded in real threat intelligence from the past year: each one a moment where a technical finding collides with a business reality \u2014 and someone has to make a call with incomplete information, an impatient board, and a vendor on hold. Sound familiar? \n\nThe scenarios cover the kind of things that have been quietly ruining people's Fridays since 2025. ClickFix campaigns, the AI apocalypse, geopolitical shenanigans, supply chain compromises and malicious dev tooling that handed your build pipeline over to someone called Vlad.\n\nThe audience votes on what to do at each decision point. Consequences unfold in real time. And we track the impact across three metrics: Board Confidence, Reputation, and Threat Exposure.\n\nThis session is built for techies. Because the best leadership decisions in security are only as good as the technical insight behind them. The techies are the ones who assess the new tool that is supposed to be the silver bullet, give feedback on what the blast radius of a change will be, or flag the dodgy process the entire business is running on. This simulation puts that work in context \u2014 and shows what happens when it hits the decision layer.\n\nNo single right answer. No fixed path. Just trade-offs, pressure, and the collective weight of a room that knows exactly what's at stake.\n\nHope you like awkward board meetings.", "recording_license": "", "do_not_record": false, "persons": [{"code": "EMBS3S", "name": "Jaco Swanepoel", "avatar": "https://pretalx.com/media/avatars/L7VFXK_F9PwT48.webp", "biography": "Jaco Swanepoel is a cybersecurity professional with over 15 years of experience in digital forensics, incident response, and threat intelligence. He\u2019s worked on high-profile investigations, supported law enforcement operations, and testified as an expert witness in court. Having obtained multiple SANS certifications, he has led forensic engagements across several continents. Today, he heads a threat hunting and intelligence team within one of South Africa\u2019s leading financial institutions, tracking threat actors and uncovering malicious activity. Passionate about sharing knowledge, Jaco actively works on projects designed to spark curiosity and inspire others to explore the world of cybersecurity.", "public_name": "Jaco Swanepoel", "guid": "cc879b7d-cc76-5cf6-98a0-1117f0fe5cb9", "url": "https://pretalx.com/bsides-joburg-2026/speaker/EMBS3S/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/3QBKMN/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/3QBKMN/", "attachments": []}], "Track 2": [{"guid": "b6209c45-fcca-5e7c-9411-43b252800218", "code": "EFWTWY", "id": 96042, "logo": null, "date": "2026-07-25T10:25:00+02:00", "start": "10:25", "end": "2026-07-25T11:10:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-joburg-2026-96042-gimme-gimme-your-creds-after-midnight-weaponising-veeam-credential-extraction", "url": "https://pretalx.com/bsides-joburg-2026/talk/EFWTWY/", "title": "Gimme! Gimme! Your Creds After Midnight: Weaponising Veeam Credential Extraction", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "## Abstract\n\nBackup solutions deal with incredibly sensitive data, and for ransomware to be truly effective, backups are a primary target. One of the common backup technologies we encounter during red team engagements is Veeam and it often stores highly privileged credentials needed to perform backup jobs across the environment. Domain Admin, vSphere administrator, ESXi root: all sitting in a database, encrypted with DPAPI, waiting for someone to ask nicely.\n\nIn this talk, we walk through how we went from manually extracting credentials from Veeam Backup & Replication and Veeam ONE databases to building and releasing VeeamDumper, a .NET tool and Beacon Object File (BOF) that automates the entire process. We'll cover the credential storage mechanisms and encryption differences between VBR and Veeam ONE (including the undocumented Veeam ONE entropy value we had to figure out ourselves), the DPAPI decryption chain, and how extracted credentials map to infrastructure targets for lateral movement.\n\nBeyond the tool itself, we'll break down the process of porting a .NET post-exploitation tool into a BOF including the design decisions, the pain points, and why having both gives operators flexibility across different C2 frameworks. We'll demonstrate VeeamDumper live, from enumeration through to cleartext credential extraction and target mapping.\n\nWe'll close with the defender's perspective: what makes Veeam infrastructure vulnerable, why domain-joining backup servers to your primary AD domain is asking for trouble, and practical hardening steps to stop us from doing exactly what we just showed you.\n\nVeeamDumper will be released as open-source prior to this talk.", "description": "## Talk Overview\n\n### 1. Why Attackers Love Your Backups\nThe role of backup infrastructure in targeted attacks and ransomware operations. Why Veeam servers are high-value targets and what we keep finding during real-world engagements: domain-joined backup servers, over-privileged service accounts, and credentials that unlock far more than just backup jobs.\n\n### 2. How Veeam Stores Credentials (And How We Extract Them)\nThe technical internals: how VBR and Veeam ONE store credentials in MSSQL and PostgreSQL databases, how DPAPI encryption is applied differently between the two products, and the undocumented Veeam ONE entropy value that isn't covered in Veeam's own KB articles. We'll walk through the decryption chain step by step, from encrypted database blob to cleartext password.\n\n### 3. Building VeeamDumper: From Manual Process to Automated Tooling\nHow repeated encounters with Veeam during engagements drove us to automate the extraction process. The design of VeeamDumper's modules (ENUM, AUTO, MSSQL/PSQL, MAP), why we built it as a .NET assembly for execute-assembly compatibility, and how the MAP module connects extracted credentials to specific infrastructure targets.\n\n### 4. From .NET to BOF: Porting Post-Exploitation Tooling to C\nThe process of taking a working .NET tool and porting it into a Beacon Object File. Why BOFs exist, what changes when you move from managed .NET to raw C and practical lessons for anyone building red team tooling\n\n### 5. Live Demo: VeeamDumper in Action\nLive demonstration of VeeamDumper against a lab environment: enumeration, automatic credential extraction, DPAPI decryption, and credential-to-target mapping. We'll show both the .NET execute-assembly path and the BOF execution.\n\n### 6. Securing Your Backup Infrastructure\nPractical hardening guidance: why backup servers should not be domain-joined to your primary AD domain, how to restrict access to credential stores, detection opportunities for credential extraction activity, and the questions every organisation should be asking about their backup security posture.\n\n## Key Takeaways\n\n1. **Veeam backup servers frequently store Domain Admin-level credentials** in a reversible format and once an attacker has local admin on the server, extracting them is straightforward.\n\n2. **Veeam ONE handles credential encryption differently to VBR** using an undocumented entropy value, a detail not covered in Veeam's public documentation that we had to reverse ourselves.\n\n3. **VeeamDumper automates the full extraction chain** enumeration, database identification, DPAPI decryption, and credential-to-target mapping as both a .NET assembly and a BOF, released as an open-source tool on MWR's GitHub.\n\n4. **Porting .NET post-exploitation tooling to a BOF** involves meaningful design tradeoffs of which we'll share the practical lessons for anyone building red team tools that need to operate across C2 frameworks.\n\n5. **Domain-joining backup servers to your primary AD domain** creates a compounding risk that turns a single compromise into full infrastructure takeover, including the destruction of your recovery capability.", "recording_license": "", "do_not_record": false, "persons": [{"code": "PDYNLY", "name": "Stephen", "avatar": "https://pretalx.com/media/avatars/USYEDY_lWjXlz8.webp", "biography": "I am a Principal Consultant and Red Team Lead at MWR CyberSec, specialising in offensive security and  adversary simulations.", "public_name": "Stephen", "guid": "a74376d4-3142-5c81-9cec-a9c14332d051", "url": "https://pretalx.com/bsides-joburg-2026/speaker/PDYNLY/"}, {"code": "SGEHAK", "name": "Logan Kroeger", "avatar": "https://pretalx.com/media/avatars/9YMMYR_B2aeDJS.webp", "biography": "I am a computer engineer who is a self-motivated and disciplined individual impassioned by cybersecurity and technology. I'm a hard worker and willing to go the extra mile because I am ambitious, eager to succeed and always enthusiastic to learn. I take pride in what I do and see myself as being conscientious and diligent, with a good work ethic. I am proactive, innovative and \"think outside the box\".\n\nI have a passion for performing red team exercises, namely simulating real-world advanced cyberattacks where I can employ the latest tactics, techniques and procedures to execute on attacker goals whilst remaining undetected; with the aim of identifying security weaknesses and areas where change can be implemented to enhance security practices.", "public_name": "Logan Kroeger", "guid": "25db5ba5-2ac3-503b-b582-d25c75d0f444", "url": "https://pretalx.com/bsides-joburg-2026/speaker/SGEHAK/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/EFWTWY/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/EFWTWY/", "attachments": []}, {"guid": "56118aab-a8c8-5852-bfc8-0a6ea4a7859b", "code": "FJCUKR", "id": 98231, "logo": null, "date": "2026-07-25T11:15:00+02:00", "start": "11:15", "end": "2026-07-25T12:00:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-joburg-2026-98231-the-device-doesn-t-take-no-for-an-answer", "url": "https://pretalx.com/bsides-joburg-2026/talk/FJCUKR/", "title": "The Device Doesn't Take No for an Answer", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "The vendor app says \"online\" while the firewall drops every byte of outbound traffic. The voice prompt says \"router connection unsuccessful\" while the device hammers an IP it never resolved. Embedded devices lie to their owners, and most owners can't see it.\n\nThis talk is the result of putting six embedded devices through the same enforcement lab, a mix of bottom-of-market kit and units from more recognisable vendors, and measuring the gap between what they say and what they do. You walk out with a nine-phase test you can run on your own kit, a four-axis scorecard that survives a procurement meeting, and a way to tell the difference between failing safe and failing by lying.", "description": "We tell each other to \"segment the IoT device.\" Then we put it on a separate VLAN, the device gets quiet for ninety seconds, and goes back to phoning home from an IP that no DNS record ever pointed at. While the vendor app cheerfully reports \"online.\"\n\nThat gap, between what the device tells the user and what it's actually doing, is what this talk measures.\n\nThis isn't a talk about zero-days. It's about the other dodgy things these devices do on the networks they sit on: talking to hosts they shouldn't, ignoring the policy you set, lying about their own state when you ask. Still a security problem. Still mostly invisible from where most owners and network admins are standing.\n\nI built a small enforcement lab around an open-source firewall and a Pi access point, and put six embedded devices through the same nine-phase routine: an IP camera, an attendance terminal, a SOHO router, a smart plug, a video doorbell, and a Zigbee smart-home hub. The sample mixes bottom-of-market kit with units from more recognisable vendors. Part of the point is that what the scorecard catches doesn't have much to do with what you paid. Cold boot. Idle baseline. Then a sequence of restrictions: full outbound block, vendor-domain sinkhole, wildcard DNS blackhole on the vendor zone, half a second of injected latency, two seconds of latency, a UDP block. At every step I pull the packet capture, the firewall counters, and the live filter log, and score the device against a four-axis scorecard: can you segment it, does it tell you the truth when you do, who does it actually trust, and how does it fail when something breaks?\n\nThe findings are the kind of thing a typical owner can't see from the vendor app:\n\n- Devices that ignore the network's DHCP-assigned resolver and do their own DNS to a public address. Any DNS policy not fronted by a redirect rule does nothing in that case.\n- Devices that reach a long list of hardcoded public IPs that no DNS query ever resolved, across multiple cloud providers and continents, well before any user interaction.\n- Devices that ship credentials in cleartext alongside user-generated content over HTTP/80, in 2026.\n- Devices that enter sticky failure modes on a few seconds of injected latency. Only a hard power cycle gets them back.\n- Devices that announce a network failure to the user, then keep uploading at a steady rate to a hardcoded fallback for the next twenty minutes. The vendor app cheerfully reports \"online\" for minutes after the network has actually been cut.\n\nPushing a device a little past its design envelope is itself a way to surface weaknesses you wouldn't see at rest. The wedged state machines above are the clearest example. The device was never built to handle the network it found itself on, and what was meant to be measurement turned into something that looks a lot like a bug report.\n\nThe point isn't that any one of these devices is uniquely bad. The point is that for a real slice of the embedded device market, \"secure deployment\" stops being a configuration choice and becomes an architectural fact about what you bought. That conversation needs better ammunition than a feeling. This talk is an attempt to give it some.\n\nWhat you'll leave with:\n\n- A repeatable nine-phase test you can run on a device sitting on your desk, with open-source firewall and packet-analysis tools you probably already have.\n- A four-axis scorecard (segmentation viability, transparency, trust hygiene, fail posture) with worked examples you can defend with a line of packet capture per score.\n- The procurement questions that surface a hardcoded dependency on the spec sheet, not after install.\n- A concrete way to tell the difference between a device that fails safely under enforcement and a device that fails by lying to you.\n\nWhat you won't get: zero days, exploit chains, or vendor names on the slides. The talk is written for defenders and procurement people, not red teamers, though the failure modes will look familiar to both.", "recording_license": "", "do_not_record": false, "persons": [{"code": "NBDRYC", "name": "Travis More", "avatar": "https://pretalx.com/media/avatars/GF7XKZ_EPA35PW.webp", "biography": "Travis More is a penetration tester at Bitcrack Cyber Security, where his work covers traditional pentesting. On the side, he digs into hardware hacking, reverse engineering, and password attacks, and has previously spoken at BSides Las Vegas.", "public_name": "Travis More", "guid": "9cd36e70-b0f7-5012-b905-5a479aa757f0", "url": "https://pretalx.com/bsides-joburg-2026/speaker/NBDRYC/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/FJCUKR/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/FJCUKR/", "attachments": []}, {"guid": "f76a1b53-8302-54c2-bd03-4278e1f483d8", "code": "3JE8KJ", "id": 98923, "logo": null, "date": "2026-07-25T12:05:00+02:00", "start": "12:05", "end": "2026-07-25T12:50:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-joburg-2026-98923-lighting-the-way-in-the-dark-binary-only-race-detection-in-go-with-zorya-volos", "url": "https://pretalx.com/bsides-joburg-2026/talk/3JE8KJ/", "title": "Lighting the Way in the Dark: Binary-Only Race Detection in Go with Zorya-Volos", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "\"How do I find race conditions in a Go binary without being a wizard? Do any tools actually cater to real-world, off-the-shelf binaries?\" When source code is unavailable, Go\u2019s runtime acts as a dark, impenetrable black box where traditional scanners fail. Given the prevalence of Go in critical cloud infrastructure and high-stakes cryptocurrency environments, these \"invisible\" vulnerabilities represent a significant and under-addressed security risk.\n\nTo address this, we present Zorya-Volos, a specialized framework that lights the way into the obscured depths of Go runtime internals and concurrent behavior, bridging the gap between theoretical research and practical, in-depth security assessment. Zorya-Volos is built by leveraging Ghidra\u2019s P-Code intermediate representation, processed through an internally developed translation layer that interfaces directly with the Z3 SMT solver to model binary execution paths with mathematical rigor. Zorya-Volos differentiates itself from other approaches by (i) being rigorously tested on COTS binaries, (ii) fielding a hybrid race detection algorithm developed through deep binary analysis to identify both lock inconsistencies and race-able memory access, and (iii) utilizing symbolic execution for the comprehensive modelling of execution paths.\n\nExpanding on our Black Hat Asia presentation, we demonstrate how this engine maps runtime scheduler behavior to state-changing operations within the binary. We will explore the technical challenges of symbolic execution at scale, showcasing how our approach successfully identifies critical concurrency flaws and null pointer dereferences that current industry tooling and automated scanners consistently overlook in production environments.", "description": "Go\u2019s concurrency model\u2014built on the pillars of Goroutines and a sophisticated M:N scheduler\u2014offers powerful performance but introduces complex, often non-deterministic, vulnerability surfaces. Because Go is the language of the cloud, powering critical infrastructure like Kubernetes and Docker, as well as high-stakes distributed systems and cryptocurrency utilities, these vulnerabilities are widespread. When source code is unavailable, identifying race conditions in Go binaries becomes a daunting challenge for security researchers navigating in the dark.\n\nThis talk introduces Zorya-Volos, a concolic execution framework built on Rust and Ghidra\u2019s P-Code IR, designed specifically to tackle the challenges of binary-only analysis of concurrent Go programs. We will light the way into the black box of the Go runtime, examining how the scheduler orchestrates Goroutine execution and manages thread mapping under the hood.\n\nAttendees will learn how Volos leverages advanced concolic execution to lift Go binaries, track execution paths without source code, and identify race conditions by modeling memory access patterns and lock states across threads. We will conclude with a comparative look at the current tooling landscape and demonstrate why our approach to in-depth manual vulnerability assessment remains essential for uncovering the race conditions that traditional scanners miss.\n\nWhat attendees will learn:\n\n- Go Runtime Internals: A deep dive into how Go binaries launch, how the scheduler distributes tasks across P, M, and G (Processor, Machine, and Goroutine) structures, and how to track the execution state of specific Goroutines.\n- Source-less Analysis: How Zorya-Volos disassembles and lifts binary code to track execution paths and identify concurrency-impacting operations without needing access to the original Go source.\n- Race Condition Detection: A technical breakdown of the Volos engine\u2019s unique ability to correlate memory read/write operations with concurrency primitives to detect race conditions in compiled Go.\n- Tooling Landscape: A comparison of current binary analysis tools for Go, highlighting the limitations of current solutions and the unique advantages of the Zorya-Volos methodology in securing production-grade cloud and crypto infrastructure.", "recording_license": "", "do_not_record": false, "persons": [{"code": "FDAGHR", "name": "Keith Makan", "avatar": "https://pretalx.com/media/avatars/AHTHZZ_uOq1IWN.webp", "biography": "Keith Makan is an experienced cybersecurity consultant and researcher with a strong history of helping clients around the world manage information security risks. He founded Keith Makan Security Consulting (KMSEC) (Pty) Ltd, a locally owned consultancy specialized in secure code review, penetration testing, training, and engineering support to help clients achieve an industry-best standard in security engineering and performance.\n\nKeith is also a published author, having written \"The Android Application Security Cookbook\" and \"Penetration Testing with the Bash Shell.\" His security research contributions include identifying vulnerabilities in widely used software like Google Chrome, and he recently presented his concolic execution framework, Zorya-Volos, at the Black Hat Asia 2026 Arsenal in Singapore. He holds an MSc in Computer Science, focusing on automated vulnerability analysis in binary formats, and is currently advancing this research as a PhD candidate at the University of the Western Cape.", "public_name": "Keith Makan", "guid": "ded6f1b6-7fae-5f5a-b290-a7c33a7c2b6a", "url": "https://pretalx.com/bsides-joburg-2026/speaker/FDAGHR/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/3JE8KJ/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/3JE8KJ/", "attachments": []}, {"guid": "accf90e3-f98d-581c-9b53-2d8026f757ac", "code": "BRXAF8", "id": 99348, "logo": null, "date": "2026-07-25T13:30:00+02:00", "start": "13:30", "end": "2026-07-25T14:15:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-joburg-2026-99348-should-ve-could-ve-would-ve-how-organisations-drift-into-breach", "url": "https://pretalx.com/bsides-joburg-2026/talk/BRXAF8/", "title": "Should've, Could've, Would've: How Organisations Drift Into Breach", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "Cyber breaches are often portrayed as the result of sophisticated attackers, yet many incidents are enabled long before compromise occurs. Organisational behaviours such as delayed patches, recurring exceptions, ignored audit findings, security fatigue, and risk acceptance quietly create the conditions that attackers exploit. This talk examines the cultural and operational patterns that tend to precede breaches, drawing on case studies across various industries to highlight how risk normalisation and organisational drift increase exposure.", "description": "Most cyber breaches are framed as sophisticated technical attacks carried out by highly skilled threat actors. Although this might hold for certain situations, many breaches are ultimately enabled by decisions, trade-offs, and accepted risks that existed long before an attacker ever gained access.\n\nA delayed patch. A temporary exception. An ignored audit finding. A burned-out SOC team. A business decision to \u201caccept the risk.\u201d\n\nThis talk examines the organisational behaviours, decisions, and trade-offs that quietly create ideal conditions for attackers. Drawing on publicly documented breach case studies across multiple industries, it explores how risk normalisation, recurring exceptions, technical debt, security fatigue, and competing business priorities can gradually increase an organisation's exposure to cyber threats.\n\nThis discussion focuses on the often-overlooked pre-breach phase: the warning signs, decisions, and cultural patterns that frequently precede compromise. By understanding these signals, security professionals can better identify environments where cyber risk is accumulating before it manifests as a major incident.\n\nOrganisations rarely approve breaches outright, but by normalising risky conditions they unintentionally pave the way for them.\n\nTakeaways from this talk will include:\n1. Recognising organisational drift.\n2. Spotting cultural warning signs and patterns that signal rising exposure.\n3. Examining publicly documented case studies to see how organisational behaviours, not just attacker sophistication, paved the way for incidents.\n4. Gaining practical methods to detect and counteract organisational drift.", "recording_license": "", "do_not_record": false, "persons": [{"code": "7N9XA7", "name": "Kitso Moema", "avatar": "https://pretalx.com/media/avatars/3WQX7L_Pw6GCJh.webp", "biography": "I'm a Cyber Threat Intelligence professional who spends my days tracking scams, cybercrime, fraud, and other emerging threats. I'm particularly interested in understanding how criminals think, adapt, and exploit both technology and human behaviour.", "public_name": "Kitso Moema", "guid": "b93aa12b-f73d-59a0-a41c-4ed5efba2aa2", "url": "https://pretalx.com/bsides-joburg-2026/speaker/7N9XA7/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/BRXAF8/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/BRXAF8/", "attachments": []}, {"guid": "067d4047-af73-5e16-84f0-c20b38115192", "code": "KVU7J3", "id": 100322, "logo": null, "date": "2026-07-25T14:20:00+02:00", "start": "14:20", "end": "2026-07-25T14:55:00+02:00", "duration": "00:35", "room": "Track 2", "slug": "bsides-joburg-2026-100322-a-journey-through-cybersecurity-regulation-in-practice", "url": "https://pretalx.com/bsides-joburg-2026/talk/KVU7J3/", "title": "A journey through Cybersecurity Regulation in practice", "subtitle": "", "track": null, "type": "Short Talk", "language": "en", "abstract": "Join us on a journey through the OT cybersecurity of a fictitious chemical plant in Germany where everything seems under control - until the regulators arrive. The IT team has done its best, the engineers trust their safety systems, and everyone is fairly confident that \u201cnothing serious can happen here.\u201d But as new regulatory demands start landing on the desk, the plant is forced to confront an uncomfortable question: is the plant actually secure, or merely hoping for the best?\n\nIn this session, we follow a chemical plant as it navigates real European and German cybersecurity regulations, including KAS-51, TRBS 1115-1, and the EU Cyber Resilience Act. Along the way we explore OT risk assessments, safety instrumented systems, hazardous incident reporting and a lot more!\n\nFinally, we bring the lessons home to South Africa. As our own regulatory environment continues to develop, what should we copy, what should we avoid, and what should we design differently from the start? Attendees will leave with a practical, story-driven view of how cybersecurity regulation moves from policy documents into control rooms, engineering workshops, audit reports, and national resilience.", "description": "**Introduction to the topic**\nSouth Africa\u2019s cybersecurity landscape largely relies on best-effort security practices, often without strong regulatory enforcement to drive consistency and accountability. While this approach allows flexibility, it can make it difficult to achieve baseline security maturity across industries. In contrast, many international environments operate under detailed, enforceable cybersecurity regulations that actively shape how organisations build, operate, and maintain their security programs. Understanding how these regulations work in practice is key to evaluating how similar approaches could strengthen local cybersecurity outcomes.\n\n**Technical Deep Dive**\nThis talk will explore a selection of modern cybersecurity regulations, including the Cyber Resilience Act (CRA), Germany\u2019s KAS-51 and TRBS 1115-1. For each, we will examine:\n\n- Who is in scope and why\n- How the regulation is structured and applied\n- The role of regulators and oversight bodies\n- What organisations are concretely required to implement\n\nThe focus will not be on legal text, but on translating regulatory requirements into actionable security practices - covering areas such as risk management, incident reporting, security controls, and audit readiness.\n\n**Real-World Relevance**\nTo ground the discussion, the talk will include practical case studies drawn from implementing the CRA, KAS-51, and TRBS 1115-1 in real environments. These will cover:\n- How requirements were interpreted and operationalised\n- How audits and assessments were conducted in practice\n- Where the regulations drove meaningful improvements in security posture\n- Where challenges emerged, particularly around administrative burden and compliance-driven approaches\n\nThese examples will provide a realistic view of both the strengths and limitations of regulatory-driven security.\n\n**Key Takeaways**\nAttendees will leave with:\n- A clear understanding of how modern cybersecurity regulations function in practice\n- Insight into the implementation realities behind major frameworks like the CRA\n- An appreciation of both the benefits and pitfalls of regulatory-driven security\n- Practical ideas for how similar approaches could be adapted to the South African context to support stronger, more effective cybersecurity outcomes", "recording_license": "", "do_not_record": false, "persons": [{"code": "N99FGZ", "name": "Dietmar Marggraff", "avatar": "https://pretalx.com/media/avatars/9GHPG8_1mciggu.webp", "biography": "Dietmar Marggraff is a cybersecurity consultant at blueflare Consulting, specialising in Operational Technology (OT) cybersecurity. He focuses on delivering pragmatic, real\u2011world solutions that organisations can implement today. He has authored several practical guides on airport and OT cybersecurity, as well as penetration testing, and brings a grounded, actionable perspective to cybersecurity.", "public_name": "Dietmar Marggraff", "guid": "bcaf7e08-dbfa-5893-9c82-3019a78703ac", "url": "https://pretalx.com/bsides-joburg-2026/speaker/N99FGZ/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/KVU7J3/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/KVU7J3/", "attachments": []}, {"guid": "a5a2cbb2-067d-52d5-ac65-5b66375f42d6", "code": "HWSVHB", "id": 98701, "logo": null, "date": "2026-07-25T15:05:00+02:00", "start": "15:05", "end": "2026-07-25T15:50:00+02:00", "duration": "00:45", "room": "Track 2", "slug": "bsides-joburg-2026-98701-turning-roadkill-into-braai-vibesdlc", "url": "https://pretalx.com/bsides-joburg-2026/talk/HWSVHB/", "title": "Turning Roadkill into braAI-VibeSDLC", "subtitle": "", "track": null, "type": "Standard Talk", "language": "en", "abstract": "Anyone got a light? When the CEO or product people send you a zip or github project do we burn or braai? Corporate and enterprise level AI enabled development is another beast in of itself. This talk reflects 3-6 months of rolling out claude code enterprise to 200+ engineers securely, turning agentic roadkill into a product with AI-SDLC and how you can shine the light in the generative darkness. \n\nOften the discussions start with a solution seeking a problem. Ample opportunity to search for problems that kill the project. Who is this for? Why? How much will it cost? Saving $3000 a year on SAAS licence can often translate into $30000 engineering time and fines way above that when you vibe-exfiltrate your company's data.", "description": "Remember that scene where Grommit lays out the track while the train is going down an unbuilt section in Wallace & Grommit. Well thats what enterprise, AI coding agents and AI productivity tools rollouts are like in 2026. CTO says we need AI agents yesterday, MDM reports everyone has had it for a year anyway and your CISO says what are our controls.\n\nThis is the war stories of a SOC and DevSecOps team rolling out agentic controls as we figure things out. This is a pro-active vs reactive story of all the disucssions, policy work, controls and incident response over the period. \n\nThe talk will cover the following topics:\n\n- Rolling out claude code enterprise\n- AI agent controls\n- Sandboxing\n- MDM and EDR\n- OTEL for Agents\n- Costs: economic, incident, cognitive load\n- SDLC in the agentic era.\n- When automation goes wrong.\n- Security team leading the way with the torch of controls, education and setting the standard.\n- Opportunities for security team to use the tools for creating tools, vuln discovery.\n- Security validation testing on these controls\n\nTakeaways:\n\n- Agents, LLMs, etc pros and cons.\n- Infosec, Dev, Devops, Infra, etc have always been early adopters. Better they debug tech than the general public debugs medical answers.\n- SDLC is still relevant, might need tweaks\n- Ownership is key, claude doesn\u2019t own your code, your responsibility remains\n- Trust but verify\n- Sandboxing is back\n- Enterprise is king ($$$$)\n- Manage risk, enable efficiency\n- Lead by example, get devs interested and involved.", "recording_license": "", "do_not_record": false, "persons": [{"code": "TLFKSG", "name": "Christo Goosen", "avatar": "https://pretalx.com/media/avatars/PKFGFH_7K09g3q.webp", "biography": "DevSecOps Lead, AI/ML. Hacker, tinkerer, builder, breaker.\n\nBSIDES Cape Town organiser.", "public_name": "Christo Goosen", "guid": "20cb7c89-d27c-5f8f-aa42-556407a8f1be", "url": "https://pretalx.com/bsides-joburg-2026/speaker/TLFKSG/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/HWSVHB/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/HWSVHB/", "attachments": []}, {"guid": "14eb8546-d512-5b67-9bfc-d01334d97878", "code": "QV988R", "id": 95657, "logo": null, "date": "2026-07-25T15:55:00+02:00", "start": "15:55", "end": "2026-07-25T16:10:00+02:00", "duration": "00:15", "room": "Track 2", "slug": "bsides-joburg-2026-95657-illuminating-the-underground-how-infostealers-are-bypassing-mfa", "url": "https://pretalx.com/bsides-joburg-2026/talk/QV988R/", "title": "Illuminating the Underground : How Infostealers are Bypassing MFA", "subtitle": "", "track": null, "type": "Lightning Talk", "language": "en", "abstract": "Traditional security perimeters are failing because attackers are no longer hacking in, they are logging in. Stolen credentials are now the top initial access vector, involved in 88% of basic web application attacks\n\n- As Infostealer Malware-as-a-Service operations industrialize, the dark web and illicit messaging apps are flooded with valid credentials and active session tokens\n- This presentation \"lights the way\" by exposing the hidden mechanics of the modern stealer log ecosystem. We would explore how malware variants like RedLine and Vidar harvest session cookies to seamlessly bypass Multi-Factor Authentication (MFA), granting adversaries instant access to centralized environments like Microsoft Entra ID.\n- Attendees will leave with a clear understanding of this unseen underground economy and practical strategies for Identity Exposure Management (IEM) to illuminate their blind spots, validate exposures, and neutralize threats before exploitation.", "description": "This talk perfectly embodies the \"Light The Way\" theme by shining a spotlight on the hidden risks and emerging threats lurking in the darkest corners of the internet, specifically, dark web markets and the tens of thousands of illicit Telegram channels where cybercrime thrives\n\nBy exposing the mechanics of how attackers monetize infostealer infections to bypass modern defenses like MFA, this session shares critical knowledge that empowers the community. It guides defenders out of the dark, equipping them with the insights needed to illuminate their external attack surface and proactively protect their organizations against the unseen dangers of identity compromise.\n\n**Topic Outline:**\n- The Shift in the Threat Landscape: A data-driven look at how the barrier to entry for cybercrime has plummeted. We will review how malware-as-a-service operations distribute tools for as little as $200/month (R3500/Month), resulting in over 50 million breached identities traded weekly\n\n- Anatomy of a Stealer Log: Illuminating what attackers actually see when a device is infected. We'll break down the contents of a stealer log, which includes saved passwords, browser autofill data, system fingerprints, and most critically, active session cookies\n\n- The Death of Traditional MFA: A technical walkthrough of how active session cookies allow attackers to hijack authenticated sessions without needing a password or triggering an MFA prompt\n\n- The Enterprise Impact: Analysis of recent 2025/2026 data revealing that over 1 in 10 infostealer infections now contain enterprise Single Sign-On (SSO) or Identity Provider (IdP) credentials, with Microsoft Entra ID appearing in 79% of enterprise identity logs\n\n- We will discuss the trajectory that suggests 1 in 5 infections could yield enterprise credentials by Q3 2026\n\n- Proactive Defense and Remediation: How to transition from reactive alert fatigue to proactive defense. We will discuss the principles of Identity Exposure Management (IEM), focusing on how to rapidly ingest intelligence, map the \"blast radius\" of an exposed user, and close the loop through automated validation and instant session revocation (Short 5 Min Max on how Flare Fits into this)\n\n**Key Takeaways (What Attendees Will Learn):**\n\n- The Cybercrime Supply Chain: How initial access brokers and automated Telegram bots distribute stolen credentials and stealer logs within hours of an infection\n\n- The Mechanics of Session Hijacking: Why traditional perimeter defenses and MFA are insufficient against session cookie theft, and how attackers leverage this data for rapid account takeover\n\n- Threat Forecasting: Real-world insights and statistical trends showing the rapid acceleration of enterprise identity compromise and the increasing targeting of centralized IdPs\n\n- Practical Defense Strategies: Actionable frameworks for implementing continuous monitoring and automated remediation (such as forcing password resets or terminating active sessions) to shrink an attacker's window of opportunity from days to seconds", "recording_license": "", "do_not_record": false, "persons": [{"code": "KYKKQK", "name": "Drystan Govender", "avatar": "https://pretalx.com/media/avatars/JT7VYZ_LnFSB0h.webp", "biography": "Drystan Govender serves as the Chief Technology Officer at Cyber Retaliator Solutions (CRS), where he is responsible for defining the company's technology vision and ensuring the delivery of secure, scalable cybersecurity solutions.\n\nDrawing on a robust background in pre-sales engineering and extensive hands-on field experience, Drystan excels at translating complex client challenges into practical, strategic technology solutions. He works intimately with a diverse network of partners, resellers, Managed Service Providers (MSPs), and customers to implement tailored solutions that meet their unique operational needs.\n\nDrystan is passionate about building resilient security architectures, optimizing processes, and supporting sustainable growth. His overarching goal is to make technology work seamlessly for clients while aggressively advancing CRS\u2019s mission to deliver trusted, highly effective cybersecurity defenses.", "public_name": "Drystan Govender", "guid": "e1d03dcf-e412-5a8e-8cb0-4c41cb0c303e", "url": "https://pretalx.com/bsides-joburg-2026/speaker/KYKKQK/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/QV988R/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/QV988R/", "attachments": []}, {"guid": "ffe134a6-38e7-5345-bd17-ba83e5a305f6", "code": "VJYQQB", "id": 98795, "logo": null, "date": "2026-07-25T16:10:00+02:00", "start": "16:10", "end": "2026-07-25T16:40:00+02:00", "duration": "00:30", "room": "Track 2", "slug": "bsides-joburg-2026-98795-lighting-the-way-to-the-server-room", "url": "https://pretalx.com/bsides-joburg-2026/talk/VJYQQB/", "title": "Lighting the Way to the Server Room", "subtitle": "", "track": null, "type": "Short Talk", "language": "en", "abstract": "Physical penetration testing is often reduced to lockpicks, cloned badges, and dramatic stories of breaking into buildings. The reality is far less glamorous and far more interesting.\n\nA successful physical penetration test begins long before anyone approaches a target facility. It starts with reconnaissance, understanding human behaviour, identifying operational weaknesses, navigating legal boundaries, and developing believable pretexts that exploit human trust rather than technology.", "description": "Physical penetration testing is often portrayed as lockpicks, badge cloning, and dramatic break-ins. In reality, those activities represent only a small part of a successful engagement. The true challenge lies in understanding how physical security, human behaviour, operational processes, and technical controls intersect to either stop or enable an attacker.\n\nThis talk provides a practical walkthrough of a real-world physical penetration test from start to finish. Attendees will follow the complete engagement lifecycle: defining scope and legal boundaries, conducting reconnaissance, developing social engineering pretexts, gaining access to facilities, operating within a target environment, and ultimately reporting findings back to the client.\n\nDrawing from real assessments and industry experience, the session focuses on the decision-making process behind physical testing rather than sensationalized lockpicking demonstrations. We will explore how attackers identify opportunities through open-source intelligence, exploit predictable human behaviours, leverage environmental weaknesses, and navigate physical spaces while balancing operational risk.\n\n**Presentation Outline**:\n\n**Introduction**\n\n* What physical penetration testing actually is and why it remains one of the most effective methods of assessing organisational security.\n* Common misconceptions surrounding physical security assessments.\n* Understanding how physical, human, and digital security controls overlap.\n\n**Scoping and Legalities**\n\n* Defining rules of engagement, success criteria, and operational constraints.\n* Authorisation requirements, legal considerations, and jurisdiction-specific concerns.\n* Planning for contingencies, escalation paths, and engagement safety.\n\n**Reconnaissance**\n\n* How attackers and physical testers build target intelligence before arriving on site.\n* Using publicly available information to identify entrances, staff routines, security technologies, and potential attack paths.\n* Translating reconnaissance findings into actionable engagement plans.\n\n**Breaching the Boundary**\n\n* Common access vectors including tailgating, piggybacking, pretexting, and badge-related weaknesses.\n* Understanding why social engineering remains one of the most effective physical attack techniques.\n* How human psychology influences security outcomes.\n* Building your own toolkit, (custom WIFI Pineapple, custom badge cloner, cheap gadgets to build a bigger toolkit) \n\n**Operating Once Inside**\n\n* Prioritising objectives after gaining access.\n* Identifying high-value targets such as boardrooms, network infrastructure, server rooms, and unattended workstations.\n* Leveraging C2 frameworks and Internal Attacks (MITM, ADCS, LLMNR, PTK)\n* Understanding the relationship between physical access and broader cyber compromise opportunities.\n\n**Contingency and \u201cWhat If You're Caught?\u201d**\n\n* Managing encounters with security personnel, facilities staff, or law enforcement.\n* Documentation, communication procedures, and safe disengagement strategies.\n* Lessons learned from real-world physical testing incidents.\n\n**Reporting and Debrief**\n\n* Converting observations into meaningful security findings.\n* Demonstrating impact without creating unnecessary risk.\n* Delivering remediation guidance that improves both physical and organisational security.\n\nThis talk combines practical field experience, social engineering concepts, and physical security assessment methodologies to provide attendees with a realistic understanding of how physical penetration tests are planned, executed, and reported.\n\n**Key Takeaways**:\n\n**Understanding Physical Attack Methodology**\nAttendees will gain a clear understanding of how professional physical penetration tests are conducted from initial planning through final reporting.\n\n**Recognising Security Weaknesses Beyond Technology**\nThe session demonstrates how human behaviour, organisational processes, and environmental design often create opportunities that technical controls alone cannot prevent.\n\n**Improving Defensive Readiness**\nSecurity practitioners, facilities teams, and business leaders will learn practical ways to identify and address weaknesses before they are discovered by real adversaries.", "recording_license": "", "do_not_record": false, "persons": [{"code": "LHQ3WW", "name": "Aaron Van Den Berg", "avatar": "https://pretalx.com/media/avatars/VFQRZV_FNUFXn3.webp", "biography": "I break into networks, applications, and infrastructure to find the critical flaws that automated scanners miss. By simulating real-world adversary tactics, I help organizations see their environment through an attacker's eyes, demonstrating actual risk and providing the blueprint to fix it.", "public_name": "Aaron Van Den Berg", "guid": "335953bc-8d00-5edc-a5b6-543395f10d01", "url": "https://pretalx.com/bsides-joburg-2026/speaker/LHQ3WW/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-joburg-2026/talk/VJYQQB/feedback/", "origin_url": "https://pretalx.com/bsides-joburg-2026/talk/VJYQQB/", "attachments": []}]}}]}}}