{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.3.0.dev0", "url": "https://pretalx.com"}, "schedule": {"url": "https://pretalx.com/bsides-tallinn-2024/schedule/", "version": "0.7", "base_url": "https://pretalx.com", "conference": {"acronym": "bsides-tallinn-2024", "title": "BSides Tallinn 2024", "start": "2024-09-19", "end": "2024-09-19", "daysCount": 1, "timeslot_duration": "00:05", "time_zone_name": "Europe/Tallinn", "colors": {"primary": "#3aa57c"}, "rooms": [{"name": "Stage 1", "slug": "3421-stage-1", "guid": "a7be260a-2ec4-54ed-a55a-0b3c643a0750", "description": "Main stage", "capacity": null}, {"name": "Workshops", "slug": "3423-workshops", "guid": "d4205c3a-f4c3-556f-88e0-79a81a493bf9", "description": "Hands-on workshops", "capacity": 50}, {"name": "Stage 2", "slug": "3422-stage-2", "guid": "ac002ccc-dc91-5365-8bbd-1d8c96f895b6", "description": null, "capacity": 100}], "tracks": [{"name": "Stage 1", "slug": "4776-stage-1", "color": "#0FA268"}, {"name": "Workshops", "slug": "4777-workshops", "color": "#C11040"}, {"name": "Stage 2", "slug": "4983-stage-2", "color": "#245DDB"}], "days": [{"index": 1, "date": "2024-09-19", "day_start": "2024-09-19T04:00:00+03:00", "day_end": "2024-09-20T03:59:00+03:00", "rooms": {"Stage 1": [{"guid": "9a86b91c-7264-56c4-99d1-a719a688ff64", "code": "9QNXX7", "id": 54424, "logo": null, "date": "2024-09-19T10:30:00+03:00", "start": "10:30", "end": "2024-09-19T11:15:00+03:00", "duration": "00:45", "room": "Stage 1", "slug": "bsides-tallinn-2024-54424-web-security-is-fun-or-how-i-stole-your-google-drive-files", "url": "https://pretalx.com/bsides-tallinn-2024/talk/9QNXX7/", "title": "Web security is fun (or how I stole your Google Drive files)", "subtitle": "", "track": "Stage 1", "type": "Main track", "language": "en", "abstract": "This talk is about a vulnerability in Google Drive. But it's also a talk about web security concepts, how services can be made to interact in unintended ways, and how a few seemingly harmless flaws can be chained to defeat security boundaries.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "F3KBJ3", "name": "Lyra Rebane", "avatar": "https://pretalx.com/media/avatars/F3KBJ3_RC4jsBb.webp", "biography": "I like to play around with the web and browsers for fun. Sometimes I find bugs. 7 CVEs in Chrome.\nhttps://lyra.horse/blog/", "public_name": "Lyra Rebane", "guid": "a3d31182-5647-5da5-b232-f260aa0cc2e4", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/F3KBJ3/"}], "links": [{"title": "Slides", "url": "https://docs.google.com/presentation/d/10LlimFowOJ_noDrJsv4CnRgU8XoUKRAa6YjTeJFrs70/edit", "type": "related"}, {"title": "Blogpost", "url": "https://lyra.horse/blog/2024/09/using-youtube-to-steal-your-files/", "type": "related"}], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/9QNXX7/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/9QNXX7/", "attachments": []}, {"guid": "03099d61-a269-52d4-8299-f9cfd1d19a96", "code": "93WTWU", "id": 54985, "logo": null, "date": "2024-09-19T11:15:00+03:00", "start": "11:15", "end": "2024-09-19T12:00:00+03:00", "duration": "00:45", "room": "Stage 1", "slug": "bsides-tallinn-2024-54985-keynote-iceman", "url": "https://pretalx.com/bsides-tallinn-2024/talk/93WTWU/", "title": "KEYNOTE: Iceman", "subtitle": "", "track": "Stage 1", "type": "Main track", "language": "en", "abstract": "TBD", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "SD7MN9", "name": "Christian Herrmann", "avatar": "https://pretalx.com/media/avatars/SD7MN9_nJqMbmA.webp", "biography": "Christian Herrmann, better known throughout the hacker community as \u201cIceman\u201d, is a co-founder of RRG and helped produce many of the most common RFID research tools available today including the Proxmark3 RDV4, and Chameleon Mini. He is an RFID hacking and Proxmark3 evangelist, serving the RFID community as both forum administrator and major code-contributor alongside other community developers since 2013. He has spoken at hacker conferences around the world including DEF CON, NullCon, Pass-the-Salt,  BlackAlps and SaintCon\n\nHe has provided bespoke software development services for over 14 years specializing in .NET platforms, and is a Certified MCPD Enterprise Architect.\n\nChristian Hermann has nearly unmatched knowledge of Proxmark3 architecture and a variety of RFID technologies, and was an instructor for the Red Team Alliance (RTA) during which also included Black Hat trainings.", "public_name": "Christian Herrmann", "guid": "886ba09b-deca-5c33-bf18-63f8be17201e", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/SD7MN9/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/93WTWU/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/93WTWU/", "attachments": []}, {"guid": "f63f431c-16ac-584e-ba75-4c7696b13431", "code": "NZZYQY", "id": 53360, "logo": null, "date": "2024-09-19T12:00:00+03:00", "start": "12:00", "end": "2024-09-19T12:30:00+03:00", "duration": "00:30", "room": "Stage 1", "slug": "bsides-tallinn-2024-53360-staying-legal", "url": "https://pretalx.com/bsides-tallinn-2024/talk/NZZYQY/", "title": "Staying legal", "subtitle": "", "track": "Stage 1", "type": "Main track", "language": "en", "abstract": "Security-related tools tend to be dual use, habit of editing URI bar to navigate a website may have surprising results and reporting a vulnerability while hinting a bounty sounds like ransom note.\n\nSounds like introspection of a security researchers? Could be also cybercriminal building their alibi. Or cybercrime police trying to tell the two apart. I'll talk about intel gathering, investigation and prosecution as process, explaining where we try to draw the line between good and evil - and how to make everybody's life easier by really appearing on the side of line you have chosen, illustrated by real life cases that can be discussed at the time of presentation.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "TWAF7C", "name": "Peeter Marvet", "avatar": "https://pretalx.com/media/avatars/TWAF7C_IXtNyIv.webp", "biography": "Peeter wanted to become a scientist when everybody else wanted to be firefighters and policemen. That was at the end of kindergarten. His previous positions were strategy and web development in a digital advertising agency, resident hacker at large web hosting provider and security evangelist in company building e-commerce experiences for major brands.\n\nCurrently intel analyst in C3EE, spending free time sailing and participating in marine SAR - so basically police & firefighting, but also working with people having fancy titles like data scientist.", "public_name": "Peeter Marvet", "guid": "f7b075b5-2a39-538f-aef6-8fc93cb5c746", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/TWAF7C/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/NZZYQY/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/NZZYQY/", "attachments": []}, {"guid": "add9d91c-8c2e-55ab-9763-39580271413a", "code": "FWUPHS", "id": 52085, "logo": null, "date": "2024-09-19T13:30:00+03:00", "start": "13:30", "end": "2024-09-19T14:15:00+03:00", "duration": "00:45", "room": "Stage 1", "slug": "bsides-tallinn-2024-52085-action-anomalies-a-hackers-guide-to-github-actions", "url": "https://pretalx.com/bsides-tallinn-2024/talk/FWUPHS/", "title": "Action Anomalies: A hackers guide to Github Actions", "subtitle": "", "track": "Stage 1", "type": "Main track", "language": "en", "abstract": "In the DevOps era of frequent releases, CI tools such as Github actions are powerful platforms to enable secure and rapid software releases, but what additional attack surface do these often privileged components come with? This talk covers a recent research project from Snyk Security Labs to understand Github actions in depth and how they can be attacked to leak cloud environment access tokens, arbitrary secrets and result in a full compromise of the repository. Security engineers, pentesters and bug hunters alike will come away knowing the threat landscape for Githubs CI platform, and through case studies of high impact vulnerabilities we have uncovered, be equipped to exploit and secure Github actions.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "CALY7J", "name": "Elliot Ward", "avatar": "https://pretalx.com/media/avatars/CALY7J_q04mGfC.webp", "biography": "Elliot is a senior security researcher at software security company Snyk. He has a background in software engineering and application security.", "public_name": "Elliot Ward", "guid": "5071634e-5fe2-5811-9bda-90b4087f1d96", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/CALY7J/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/FWUPHS/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/FWUPHS/", "attachments": []}, {"guid": "1b8cdc62-73bf-5bc1-a087-1483e35c1bd4", "code": "ERTU3A", "id": 54423, "logo": null, "date": "2024-09-19T14:15:00+03:00", "start": "14:15", "end": "2024-09-19T15:00:00+03:00", "duration": "00:45", "room": "Stage 1", "slug": "bsides-tallinn-2024-54423-there-s-nothing-new-except-forgotten-old-abusing-email-and-defending-against-it", "url": "https://pretalx.com/bsides-tallinn-2024/talk/ERTU3A/", "title": "There's nothing new except forgotten old: Abusing email and defending against it", "subtitle": "", "track": "Stage 1", "type": "Main track", "language": "en", "abstract": "Email is a ubiquitous part of everyday life, yet its inner workings and future developments often remain distant. Things being overlooked has left plenty of opportunities for abuse. It's up to us to pay a little bit of attention to more than just deliverability.\n\nAnd even though email is being described on Wikipedia as something that \"was conceived in the late\u201320th century\", it's still constantly evolving to better adapt to the 21st century. There are both old and new approaches available that help make things more (in)secure.\n\nThis talk covers recent larger vulnerabilities involving DKIM, DMARC and BIMI, currently available methods for improving email security and teases of what's being planned for the future.\n\nSome parts of this talk are also partially covered here: https://www.zone.ee/blogi/2024/05/17/bimi-and-dmarc-cant-save-you/", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "USFKRR", "name": "Taavi Eom\u00e4e", "avatar": "https://pretalx.com/media/avatars/USFKRR_imSJRfk.webp", "biography": "Enthusiast trying to improve (email) security for everyone at night, Cybersecurity specialist at Zone Media O\u00dc during day. Recently worked on remediating large-scale issues with DKIM, (Associate) Member of CA/Browser Forum's S/MIME working group, proud discoverer of vulnerabilities such as CVE-2023-40440 in Apple Mail.", "public_name": "Taavi Eom\u00e4e", "guid": "47ab5537-ed1a-5a28-8249-33d91279cba8", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/USFKRR/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/ERTU3A/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/ERTU3A/", "attachments": []}, {"guid": "54becdd1-49d9-57b9-a158-6e53b9b1c387", "code": "7WESKU", "id": 54247, "logo": null, "date": "2024-09-19T15:30:00+03:00", "start": "15:30", "end": "2024-09-19T16:15:00+03:00", "duration": "00:45", "room": "Stage 1", "slug": "bsides-tallinn-2024-54247-deepfake-technology-in-offensive-security-operations", "url": "https://pretalx.com/bsides-tallinn-2024/talk/7WESKU/", "title": "Deepfake Technology in Offensive Security Operations", "subtitle": "", "track": "Stage 1", "type": "Main track", "language": "en", "abstract": "The current threat landscape has seen an exponential increase in synthetic media use (deepfake technology). These tools can be leveraged against systems that automatically verify one's identity, or even be used in social engineering attacks against business processes and people in order to appear as a different person. Threat actors are using this more and more in their business-as-usual, so how can assessors test these attacks in an ethical, legal and non-impactful way? This presentation will hopefully shed a light on how we developed our approach.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "7TVZWA", "name": "Sebastian Stanici", "avatar": "https://pretalx.com/media/avatars/7TVZWA_oAUDsbX.webp", "biography": "I work at a large US-based company and have worked in the cyber security industry for the last four years.", "public_name": "Sebastian Stanici", "guid": "373f503f-661f-522e-b7c4-dad3e75552a5", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/7TVZWA/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/7WESKU/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/7WESKU/", "attachments": []}, {"guid": "236e7612-ee0a-5cda-90bc-8f987a759ac3", "code": "FC8Z33", "id": 50600, "logo": null, "date": "2024-09-19T16:15:00+03:00", "start": "16:15", "end": "2024-09-19T17:00:00+03:00", "duration": "00:45", "room": "Stage 1", "slug": "bsides-tallinn-2024-50600-saturday-night-phishing-show", "url": "https://pretalx.com/bsides-tallinn-2024/talk/FC8Z33/", "title": "Saturday Night Phishing Show", "subtitle": "", "track": "Stage 1", "type": "Main track", "language": "en", "abstract": "Join Jarrad Pemberton and Tormi Tuuling, SOC Engineers at Wise, as they walk through how threat actors can leverage verified advertising services to phish your customers. They'll be discussing the tactics of these threat actors, and the Ads transparency movement in today's advertising focused internet landscape.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "NQLUAK", "name": "Jarrad Pemberton", "avatar": "https://pretalx.com/media/avatars/NQLUAK_AqiTgBJ.webp", "biography": "Jarrad is a SOC Engineer at Wise and has been working in IT for over 5 years, ranging from IT support, IAM, and Security Engineering. Outside of work he's a cat dad, powerlifter, and TTRPG expert.", "public_name": "Jarrad Pemberton", "guid": "27cf5a33-3192-56bf-ad46-c62e4899f4f7", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/NQLUAK/"}, {"code": "RPFYNM", "name": "Tormi Tuuling", "avatar": "https://pretalx.com/media/avatars/RPFYNM_KVVDHK8.webp", "biography": "Security enthusiast who leaves no stone unturned. Likes rock music and occasionally finds nasty bugs under stones.", "public_name": "Tormi Tuuling", "guid": "251f786e-6d1a-59f7-9d9f-6ff2d06f124a", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/RPFYNM/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/FC8Z33/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/FC8Z33/", "attachments": []}], "Stage 2": [{"guid": "535da302-d1e1-5858-b518-db7538508f1b", "code": "G7B8KQ", "id": 52156, "logo": null, "date": "2024-09-19T10:30:00+03:00", "start": "10:30", "end": "2024-09-19T11:15:00+03:00", "duration": "00:45", "room": "Stage 2", "slug": "bsides-tallinn-2024-52156-sigma-decoding-the-future-of-detection", "url": "https://pretalx.com/bsides-tallinn-2024/talk/G7B8KQ/", "title": "Sigma: Decoding the Future of Detection", "subtitle": "", "track": "Stage 2", "type": "Main track", "language": "en", "abstract": "Sigma detections have been a way for blue teams to share malicious behavior for over 7 years. Since then, the core team have been working extremely hard on bringing brand new features \u2013 like correlations, filtering, & meta rules, sweeping documentation uplifts, as well as bringing a new suite of tools and ecosystem changes that's designed to be as modern as the SIEMs we use today.\n\nCome explore these advancements as we unlock some of new exciting possibilities of what Security Teams can now do with Sigma and the v2 Specification.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "CYG7SB", "name": "Alex Sinnott", "avatar": "https://pretalx.com/media/avatars/CYG7SB_KfnNBjY.webp", "biography": "Alex is a Security Engineer working within Wise' (ex. Transferwise) Security Operations Team. He's had over 7 years of experience working in Security Operation Centres across 2 continents working mostly on Detection Engineering.\n\nAlex also works alongside the core Sigma team writing proposals & documentation and working on the challenges of improving the overall user-experience of the Sigma ecosystem for all incoming and incumbent security professionals.", "public_name": "Alex Sinnott", "guid": "8577a1e9-81c1-5979-a0cd-a4ba6fa4e5a3", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/CYG7SB/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/G7B8KQ/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/G7B8KQ/", "attachments": []}, {"guid": "ef4887d0-f648-5248-8849-70fa9d932fd7", "code": "V7RVTB", "id": 53378, "logo": null, "date": "2024-09-19T12:00:00+03:00", "start": "12:00", "end": "2024-09-19T12:30:00+03:00", "duration": "00:30", "room": "Stage 2", "slug": "bsides-tallinn-2024-53378-threat-modelling-for-ai-ml-based-healthcare-systems", "url": "https://pretalx.com/bsides-tallinn-2024/talk/V7RVTB/", "title": "Threat Modelling for AI/ML-based Healthcare Systems", "subtitle": "", "track": "Stage 2", "type": "Main track", "language": "en", "abstract": "A huge amount of data is generated by electronic health records, various biosensors and other means. To receive benefits like more effective detection of diseases from these enormous amounts of data, Artificial Intelligence (AI) and Machine Learning (ML) systems are becoming more widely used. With this technological progress comes the potential for new or previously overlooked security threats. Because of the nature of the system, the security issues within healthcare systems could bear devastating consequences. This study identifies the threats opposed to AI/ML-based healthcare systems by conducting comprehensive threat modelling and threat analysis. The model captures all the characteristics of a modern healthcare system that utilizes the usage of an AI/ML component with an in-house development approach. The model has different ways to gather data and interact with patients and doctors. The threat modelling is conducted based on the STRIDE methodology. In addition, STRIDE-based attack trees are used to further identify all the relevant threats that could endanger a modern healthcare system. As a result, a comprehensive list of identified threats is provided for all the components that are used in a modern healthcare AI/ML-based system. The threat list consists of conventional and AI/ML-specific threats. For AI/ML-specific threats to be successful, they need some form of a conventional attack to be carried out beforehand. The model itself and the threats identified are validated by various experts from the cybersecurity and AI/ML field. This study aims to contribute to the safe and effective implementation of AI/ML technologies in healthcare settings.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "WV8YRX", "name": "Janno Jaal", "avatar": "https://pretalx.com/media/avatars/WV8YRX_AD7Tjr0.webp", "biography": "Cyber Security Engineer at Cybernetica. Graduated in June 2024 from the Cybersecurity MSc programme at TalTech and the University of Tartu.", "public_name": "Janno Jaal", "guid": "e5023968-a35c-573e-b96e-182f6cfb1823", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/WV8YRX/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/V7RVTB/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/V7RVTB/", "attachments": []}, {"guid": "6e25050a-d0cd-568b-b48d-c49e9e7dd851", "code": "VRDDGE", "id": 50744, "logo": null, "date": "2024-09-19T13:30:00+03:00", "start": "13:30", "end": "2024-09-19T14:15:00+03:00", "duration": "00:45", "room": "Stage 2", "slug": "bsides-tallinn-2024-50744-managing-cybersecurity-incidents-a-journey-through-cause-effect-and-response", "url": "https://pretalx.com/bsides-tallinn-2024/talk/VRDDGE/", "title": "Managing Cybersecurity Incidents: A Journey through cause, effect, and response", "subtitle": "", "track": "Stage 2", "type": "Main track", "language": "en", "abstract": "In this talk, we delve into the world of Digital Forensics and Incident Response (DFIR). We will cover the basics, such as the process and terminology, and examine four distinct incidents. For each incident, I will explain the \u2018what\u2019 and \u2018how\u2019 of the attack, the lessons learned, and the often overlooked human aspect of incident response.\n\nBusiness Email Compromise (BEC) Incident: We\u2019ll explore a case where an adversary exploited a user and maintained persistence for a month to extract money.\n\nRansomware Incident: We\u2019ll examine a company\u2019s third ransomware incident, all of which happened within a span of 2 years, where the victim attempted to pay the ransom. We\u2019ll discuss what went wrong during the recovery process\n\nWiper Incident: We\u2019ll delve into a rare hacktivism attack where 95% of the victim\u2019s infrastructure and data, including backups and logs, were deleted.\n\nFailed Attempt: Sometimes, attackers have bad days too. We\u2019ll look at an incident where the attackers gained access to the company\u2019s infrastructure but failed to deploy or exfiltrate anything.\n\nBy sharing my experiences, I hope to help attendees with the knowledge to stay proactive against cyber attacks and, in the event of an incident, respond more effectively.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "A8JWRN", "name": "Denes Fodor", "avatar": "https://pretalx.com/media/avatars/A8JWRN_puzq0j5.webp", "biography": "With over ten years of experience in IT security and systems engineering, I am a passionate and versatile CSIRT Manager / IT Security Researcher at White Hat IT Security, a leading company in defensive and offensive security. I enjoy collaborating with my team and other IT professionals, and I always strive to learn new skills and technologies. I spend most of my free time tackling RE and PWN challenges, conducting malware research, and, as a big fan of information sharing, writing blog posts on a monthly basis.", "public_name": "Denes Fodor", "guid": "4e291a9b-2385-5435-8578-66d9534e6361", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/A8JWRN/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/VRDDGE/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/VRDDGE/", "attachments": [{"title": "Presentation", "url": "/media/bsides-tallinn-2024/submissions/VRDDGE/resources/Denes_Fodor_Managing_CyberSecurity_Inci_hqyp9MV.pdf", "type": "related"}]}, {"guid": "b78f9c3d-46af-5ad9-ab75-19f97d0764fb", "code": "PTU7BZ", "id": 52506, "logo": null, "date": "2024-09-19T14:15:00+03:00", "start": "14:15", "end": "2024-09-19T15:00:00+03:00", "duration": "00:45", "room": "Stage 2", "slug": "bsides-tallinn-2024-52506-tales-from-a-cloud-csirt-let-s-deep-dive-into-a-kubernetes-k8s-infection", "url": "https://pretalx.com/bsides-tallinn-2024/talk/PTU7BZ/", "title": "Tales From a Cloud CSIRT- Let\u2019s deep dive into a Kubernetes (k8s) Infection", "subtitle": "", "track": "Stage 2", "type": "Main track", "language": "en", "abstract": "Kubernetes (k8s) is an orchestration system for automating software deployment, scaling and management, and if you don\u2019t know\u2026 this is really hot right now.\n\nWhen implemented in a cloud environment, it allows a service to grow almost limitless, because the k8s Cluster can create and destroy servers at will, based on the load of the containers running. Imagine what can go wrong when attackers get to own this power for themselves\u2026 you are right, lightspeed growth equals a lot of destruction power.\n\nIn this talk, we are going to analyze a real example of an AWS Kubernetes cluster infection through a software development supply chain compromise. The attackers were able to get AWS credentials from a DevOps workstation and use them to introduce a poisoned docker image into a kubernetes cluster. It allowed them to move laterally within the cluster and to the cloud provider, retrieving secrets, passwords, tokens, and a bunch of other data.\n\nLuckily, we were able to detect them just in time, as they had retrieved secrets that would have allowed them to move laterally to other companies or execute a new docker image with nastier results.\n\n\nWe are going to present the examples using a real-time lab, offering examples for incident responders and malware analysts to understand how to investigate these techniques, getting through the cyber kill chain and explaining what went wrong and what could have been done better.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "WJWN3S", "name": "Santi Abastante", "avatar": "https://pretalx.com/media/avatars/WJWN3S_6vTFBNt.webp", "biography": "Ex-Police Officer from Argentina, Cloud Incident Responder and Security Engineer with 10+ years of IT experience.", "public_name": "Santi Abastante", "guid": "2af26a36-51c8-5ccd-8258-41a8b3e55fb9", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/WJWN3S/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/PTU7BZ/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/PTU7BZ/", "attachments": []}, {"guid": "95d40613-2d35-5b88-9fab-b7885a88ef63", "code": "ZUZZ8D", "id": 54354, "logo": null, "date": "2024-09-19T15:30:00+03:00", "start": "15:30", "end": "2024-09-19T16:15:00+03:00", "duration": "00:45", "room": "Stage 2", "slug": "bsides-tallinn-2024-54354-get-high-as-a-threat-actor-rootkits-and-kernel-security", "url": "https://pretalx.com/bsides-tallinn-2024/talk/ZUZZ8D/", "title": "Get high as a Threat Actor - Rootkits and Kernel security", "subtitle": "", "track": "Stage 2", "type": "Main track", "language": "en", "abstract": "This talk delves into Threat Actors' tactics for infiltrating Windows systems at a Kernel level. We analyze Kernel security features and weak spots used in real-world exploitation to understand the mechanisms that Threat Actors use to bypass protections and what capabilities they gain in the process.\nWe conclude with some security recommendations to help organizations strengthen their defenses against these evolving threats.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "UMA3J9", "name": "Marcelo Toran", "avatar": "https://pretalx.com/media/avatars/UMA3J9_bjcZ4B0.webp", "biography": "Marcelo is a seasoned Red Teamer, with experience in conducting advanced operations to challenge and improve organizational defenses. When not breaking stuff you might find him rolling down some sketchy trails with his bike.", "public_name": "Marcelo Toran", "guid": "253bfc2c-8a44-50bc-8537-a1d0f7c0e870", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/UMA3J9/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/ZUZZ8D/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/ZUZZ8D/", "attachments": []}, {"guid": "ee791eb4-177a-59cf-b859-955df6f26ee2", "code": "YDU7GX", "id": 50178, "logo": null, "date": "2024-09-19T16:15:00+03:00", "start": "16:15", "end": "2024-09-19T17:00:00+03:00", "duration": "00:45", "room": "Stage 2", "slug": "bsides-tallinn-2024-50178-ivy-haul-an-analysis-of-a-pro-russian-disinformation-actor-online", "url": "https://pretalx.com/bsides-tallinn-2024/talk/YDU7GX/", "title": "IVY HAUL: An Analysis of A Pro-Russian Disinformation Actor (online)", "subtitle": "", "track": "Stage 2", "type": "Main track", "language": "en", "abstract": "In April 2023, Sarah Bils was revealed to be one of the main people behind the DonbassDevushka social media \"personality,\u201d posting pro-Russian propaganda to a variety of social media accounts since 2014.  One of the main accounts, the PeImeniPusha Twitter account has been active since 2015, with a huge uptick in activity concurrent with the Russian invasion of Ukraine.  Ms. Bils has claimed that there was a team of at least a dozen people responsible for the Donbass Devushka personality.\n\nWith a group of people all writing under the same \u201cpersonality\u201d can we detect patterns that might reveal shifts in authorship of tweets?  I used a number of open and closed source tools, along with original methodology and tools, to analyze text and metadata collected from the PeImeniPusha Twitter account and several other sources. Primary areas of research and analysis include identification of potential authorship clusters, analysis of trends in content posted, and network analysis of people affiliated with the Donbass Devushka personality. This session will build significantly upon research first presented to a standing room only crowd at the DEF CON 31 Misinformation Village, and will present additional research and analysis for the first time.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "XFMRT9", "name": "Shea Nangle", "avatar": "https://pretalx.com/media/avatars/XFMRT9_FdpI6jk.webp", "biography": "Shea has over 25 years of experience in security consulting, malware campaign investigations, compliance, and technology. He also co-founded a venture-backed knowledge management startup. Shea has presented both domestically and internationally on a wide range of topics including disinformation, OPSEC, application security, and compliance. Shea\u2019s areas of research include elicitation, disinformation, open-source intelligence, and crisis management.", "public_name": "Shea Nangle", "guid": "a4b6f51e-9285-5104-a496-2788054797d6", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/XFMRT9/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/YDU7GX/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/YDU7GX/", "attachments": []}], "Workshops": [{"guid": "e0ce9592-b8c8-5494-8086-1862136b683b", "code": "ZE8G7Z", "id": 54477, "logo": null, "date": "2024-09-19T10:30:00+03:00", "start": "10:30", "end": "2024-09-19T11:15:00+03:00", "duration": "00:45", "room": "Workshops", "slug": "bsides-tallinn-2024-54477-abuse-the-b-sides-of-bluetooth-peripherals", "url": "https://pretalx.com/bsides-tallinn-2024/talk/ZE8G7Z/", "title": "Abuse the B-sides of Bluetooth peripherals", "subtitle": "", "track": "Workshops", "type": "Main track", "language": "en", "abstract": "A paired Bluetooth device is authorized to use any function specified in the agreed-upon Bluetooth profiles. A mouse utilizes the human interface device profile, similar to a keyboard. If you lose a paired wireless mouse, the finder can convert it into a keyboard that remains paired with your computer. In this hands-on workshop, you will extract the encryption key from a physical Bluetooth mouse and use it to emulate a keyboard.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "K7CUKR", "name": "Mait Peekma", "avatar": "https://pretalx.com/media/avatars/K7CUKR_F98q4VF.webp", "biography": "If you read this, you probably get paid to build or protect stuff on a daily basis. Mait does the opposite, but has so far avoided jail time.", "public_name": "Mait Peekma", "guid": "43eefd3e-8ebd-5b2e-bb26-d7b435506f95", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/K7CUKR/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/ZE8G7Z/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/ZE8G7Z/", "attachments": []}, {"guid": "10cfc2e1-f312-5dc0-8e3b-f9fdf9f6298a", "code": "T8NBSL", "id": 54410, "logo": null, "date": "2024-09-19T12:00:00+03:00", "start": "12:00", "end": "2024-09-19T12:30:00+03:00", "duration": "00:30", "room": "Workshops", "slug": "bsides-tallinn-2024-54410-doh-down-the-rabbit-hole", "url": "https://pretalx.com/bsides-tallinn-2024/talk/T8NBSL/", "title": "DoH Down the Rabbit Hole", "subtitle": "", "track": "Workshops", "type": "Main track", "language": "en", "abstract": "DNS over HTTPS (DoH) is a protocol that emerged in 2018 and has since seen some adoption. This educational talk will provide a brief overview of DoH from the perspectives of network admins and cybersecurity experts. It will  give overview the current state of its implementation, and how it is supported by browsers, operating systems, and DNS server software. Additionally, the talk will address how DoH can be controlled, detected, and how its  being used. in diverse network setup  It will also include a short overview of the split-horizon problem with  offering practical insights.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "ECDJ8N", "name": "Toomas Lepik", "avatar": "https://pretalx.com/media/avatars/ECDJ8N_1R1eEHr.webp", "biography": "Information security analyst with a background in digital forensics,\n experienced in incident handling.", "public_name": "Toomas Lepik", "guid": "32713cad-9901-55c3-8470-774a5e485208", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/ECDJ8N/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/T8NBSL/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/T8NBSL/", "attachments": []}, {"guid": "8a146bd1-d5cd-5c8a-b94c-9ef71c1b57a4", "code": "P33HW3", "id": 54062, "logo": null, "date": "2024-09-19T13:30:00+03:00", "start": "13:30", "end": "2024-09-19T14:15:00+03:00", "duration": "00:45", "room": "Workshops", "slug": "bsides-tallinn-2024-54062-practical-hacking-llms-hands-on-workshop", "url": "https://pretalx.com/bsides-tallinn-2024/talk/P33HW3/", "title": "Practical Hacking LLMs - Hands-on Workshop", "subtitle": "", "track": "Workshops", "type": "Main track", "language": "en", "abstract": "Last year, at BSides Tallinn, we demonstrated how to make ChatGPT your b*tch.\n\nThis year, we'll dive deeper into real-world LLM vulnerabilities.\n\nNowadays everybody is talking about AI and large language models.\n\nLet's talk about to break them.\n\nIn this workshop we'll target some LLMs and exploit the h$ll out of them.\n\nGet your laptop ready for this hands-on workshop delivered by OWASP Lead Stefano Amorelli.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "YDHFCD", "name": "Stefano Amorelli", "avatar": "https://pretalx.com/media/avatars/YDHFCD_G8uXTQi.webp", "biography": "Stefano Amorelli, Staff Software Engineer for a FinTech unicorn, security engineer, and leading Estonia's first OWASP chapter.", "public_name": "Stefano Amorelli", "guid": "38fded64-94c3-51c2-9faf-ed616d7fcc13", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/YDHFCD/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/P33HW3/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/P33HW3/", "attachments": []}, {"guid": "aea87aec-ffa9-5083-8a63-1a5492d682c7", "code": "T7HQ7Y", "id": 54293, "logo": null, "date": "2024-09-19T14:15:00+03:00", "start": "14:15", "end": "2024-09-19T15:00:00+03:00", "duration": "00:45", "room": "Workshops", "slug": "bsides-tallinn-2024-54293-no-edrs-were-harmed-while-making-this-talk", "url": "https://pretalx.com/bsides-tallinn-2024/talk/T7HQ7Y/", "title": "No EDRs were harmed while making this talk", "subtitle": "", "track": "Workshops", "type": "Main track", "language": "en", "abstract": "In this talk we'll explore how Red Teams can and do evade Endpoint Detection and Response (EDR) systems.\n\nFirst, we'll look at how EDRs are set up and used in various environments. We'll break down their components and how they work & communicate. Next, we'll dive into common malware functionalities and the different ways EDRs internally try to detect them.\n\nThe main focus will be on the actual techniques used for avoiding detection and how they can be implemented. We'll cover how different detection scenarios are handled and also some more generic bypasses that still work against advanced EDR systems. We'll also have live demos to show these techniques in action if demo gods allow.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "9NBA3K", "name": "Jaanus K\u00e4\u00e4p", "avatar": "https://pretalx.com/media/avatars/9NBA3K_tABBHFt.webp", "biography": "Jaanus K\u00e4\u00e4p is a seasoned security researcher at Clarified Security, bringing over a decade of expertise in security testing and research. He has uncovered vulnerabilities in a wide range of technologies, including web applications, document parsers, the Windows kernel and drivers, antivirus software, and hypervisors. Jaanus was recognized for his contributions to the field, appearing on the Microsoft Security Response Center's (MSRC) Most Valuable Security Researchers list for five consecutive years.\n\nCurrently, Jaanus is also focused on developing Tuoni, an advanced adversary emulation tool. One of his primary responsibilities is devising methods to circumvent Endpoint Detection and Response (EDR) systems.", "public_name": "Jaanus K\u00e4\u00e4p", "guid": "b07edd5b-d5ee-5c68-852e-16a4d5306fa1", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/9NBA3K/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/T7HQ7Y/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/T7HQ7Y/", "attachments": []}, {"guid": "7b537c37-2ab6-527b-ad25-281044baa7d4", "code": "ZKP7HW", "id": 53364, "logo": null, "date": "2024-09-19T16:00:00+03:00", "start": "16:00", "end": "2024-09-19T17:00:00+03:00", "duration": "01:00", "room": "Workshops", "slug": "bsides-tallinn-2024-53364-web-security-templates-all-the-way-down", "url": "https://pretalx.com/bsides-tallinn-2024/talk/ZKP7HW/", "title": "Web security: templates all the way down", "subtitle": "", "track": "Workshops", "type": "Main track", "language": "en", "abstract": "Estonian web blue team has evolved Locked Shield defence and threat hunting toolkit over past 4 years and a lot of it could - and should - be used also in real life.\n\nWe'll run through the scenario of dockerising whatever webapps, secure configurations, WAF tricks and easy ways to make your logs usable. All templates - sidecar containers, configurations, etc - will be public, docker-savvy participants can follow our scenario on their own computers and the rest gets chance to interact with sample application and navigate through the resulting logs in real time.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "TWAF7C", "name": "Peeter Marvet", "avatar": "https://pretalx.com/media/avatars/TWAF7C_IXtNyIv.webp", "biography": "Peeter wanted to become a scientist when everybody else wanted to be firefighters and policemen. That was at the end of kindergarten. His previous positions were strategy and web development in a digital advertising agency, resident hacker at large web hosting provider and security evangelist in company building e-commerce experiences for major brands.\n\nCurrently intel analyst in C3EE, spending free time sailing and participating in marine SAR - so basically police & firefighting, but also working with people having fancy titles like data scientist.", "public_name": "Peeter Marvet", "guid": "f7b075b5-2a39-538f-aef6-8fc93cb5c746", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/TWAF7C/"}, {"code": "M87HQN", "name": "Johannes Kadak", "avatar": "https://pretalx.com/media/avatars/M87HQN_yVqZHaF.webp", "biography": "Have been taking apart things to see how they work since I was small, and now using those skills for good. Cyber security CTF trainer for the European Cyber Security Challenge Estonian team, cyber governance consultant for enterprise and avid start-upper. Loves cats.", "public_name": "Johannes Kadak", "guid": "8570b27c-6c6e-5d53-b676-3607b3cb7def", "url": "https://pretalx.com/bsides-tallinn-2024/speaker/M87HQN/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2024/talk/ZKP7HW/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2024/talk/ZKP7HW/", "attachments": []}]}}]}}}