{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.3.0.dev0", "url": "https://pretalx.com"}, "schedule": {"url": "https://pretalx.com/bsidesaugusta-2026/schedule/", "version": "0.6", "base_url": "https://pretalx.com", "conference": {"acronym": "bsidesaugusta-2026", "title": "BSidesAugusta", "start": "2026-10-24", "end": "2026-10-24", "daysCount": 1, "timeslot_duration": "00:05", "time_zone_name": "US/Eastern", "colors": {"primary": "#000000"}, "rooms": [{"name": "Track 1 - Plug N Play", "slug": "5887-track-1-plug-n-play", "guid": "8251ef6c-e2b0-5ef5-bcdb-918faad625c4", "description": "GCC Hull McKnight Building, Plug N Play, enter on 1st or 2nd floor; no overflow", "capacity": 390}, {"name": "Track 2 - Virtual World", "slug": "5888-track-2-virtual-world", "guid": "99ee56cd-3fb6-521b-8fb8-ff4e7b04790c", "description": "GCC Hill McKnight Building, Virtual World, 1st floor; Overflow in Room 2600", "capacity": 152}, {"name": "Track 3 - Room 2400", "slug": "5889-track-3-room-2400", "guid": "db77bdd9-4084-5674-a1aa-50cf3ed14243", "description": "GCC Hull McKnight Building, Room 2400; Overflow in Room 2300", "capacity": 60}, {"name": "Track 4 - Official CTF", "slug": "5890-track-4-official-ctf", "guid": "1d966516-8096-52d3-8fdc-fff5f3535e81", "description": "GCC Hull McKnight Building, Room 2201", "capacity": 40}, {"name": "Track 5 - Workshop", "slug": "5891-track-5-workshop", "guid": "f83d61eb-4aa8-5559-bc81-57aae2866292", "description": "GCC Hull McKnight Building, Room 2301", "capacity": null}], "tracks": [{"name": "Track 1", "slug": "7334-track-1", "color": "#000000"}, {"name": "Track 2", "slug": "7335-track-2", "color": "#000000"}, {"name": "Track 3", "slug": "7336-track-3", "color": "#000000"}, {"name": "Track 4", "slug": "7337-track-4", "color": "#000000"}, {"name": "Alternate", "slug": "7338-alternate", "color": "#000000"}, {"name": "Keynote", "slug": "7339-keynote", "color": "#000000"}, {"name": "Workshop", "slug": "7340-workshop", "color": "#000000"}], "days": [{"index": 1, "date": "2026-10-24", "day_start": "2026-10-24T04:00:00-04:00", "day_end": "2026-10-25T03:59:00-04:00", "rooms": {"Track 1 - Plug N Play": [{"guid": "84170398-dd9e-5d46-816c-2612d9ab437d", "code": "GRFJQM", "id": 103514, "logo": null, "date": "2026-10-24T07:45:00-04:00", "start": "07:45", "end": "2026-10-24T08:30:00-04:00", "duration": "00:45", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-103514-0-doors-open-check-in", "url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "title": "Doors Open / Check-in", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Grab your badge and freebies, then check out the CTF, exhibitors, lock pick village, and raffle table.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "attachments": []}, {"guid": "15f36737-788f-5392-8b94-e17f89c9869f", "code": "AN7JAS", "id": 103513, "logo": null, "date": "2026-10-24T08:30:00-04:00", "start": "08:30", "end": "2026-10-24T09:00:00-04:00", "duration": "00:30", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-103513-4-opening-remarks", "url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "title": "Opening Remarks", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Live in Track 1, Simulcast in Tracks 2-3\nRemarks will be delivered by BSidesAugusta staff and special guests.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "attachments": []}, {"guid": "1192eff2-6a7c-55a2-b6bf-e1503cbbfb22", "code": "S7VVXT", "id": 104233, "logo": null, "date": "2026-10-24T09:00:00-04:00", "start": "09:00", "end": "2026-10-24T10:00:00-04:00", "duration": "01:00", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-104233-4-keynote-tim-kosiba", "url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "title": "Keynote - Tim Kosiba", "subtitle": "", "track": "Keynote", "type": "Talk", "language": "en", "abstract": "*Live in Track 1, Simulcast in all other tracks/rooms*  \n  \nTim Kosiba, Deputy Director of the National Security Agency, will be our keynote speaker!  \n  \n*Live in Track 1, Simulcast in all other tracks/rooms*", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "C8G88E", "name": "Tim Kosiba", "avatar": "https://pretalx.com/media/avatars/avatar_6hFwavm.webp", "biography": "Tim Kosiba serves as the 21st Deputy Director of the National Security Agency. In this capacity, he works with the NSA\u2019s Director and Executive Director to provide leadership in all areas of the enterprise and to represent NSA\u2019s interests both internally and externally.\n \nPrior to his retirement from NSA in 2021, he served as Deputy Commander of NSA/CSS Georgia \u2014 the Agency\u2019s largest Cryptologic Center.\n\nMr. Kosiba\u2019s NSA career spanned a variety of key leadership roles across NSA and USCYBERCOM, including Special U.S. Liaison Officer in Canberra, Australia; Deputy Director of the NSA/CSS Commercial Solutions Center (NCSC); and Chief of Tailored Access Operations (now Computer Network Operations). Mr. Kosiba\u2019s federal service began in 1989 with the Naval Criminal Investigative Service. After several years spent working in the United Kingdom, Mr. Kosiba was recruited by the FBI in 1996, which brought him to the Washington area. Following the events of 9/11, Tim dedicated his digital forensic knowledge to capturing the perpetrators of the attacks, going on to supervise one of the FBI\u2019s largest digital forensics laboratories. He later joined the Joint Functional Component Command for Network Warfare (JFCC-NW) \u2014 the predecessor of USCYBERCOM \u2014 in 2007, where he held the role of Technical Director.\n\nMr. Kosiba returns to NSA after serving as a cybersecurity leader in the private sector for several years. Throughout his career, he has consistently represented USCYBERCOM and NSA at the White House and forged partnerships to advance cybersecurity policy and priorities. He has received several awards from the law enforcement and the intelligence communities and is a recognized technical leader in the cybersecurity field.", "public_name": "Tim Kosiba", "guid": "2d0d3172-2ac8-5b9b-aaaa-035fcbba9be2", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/C8G88E/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "attachments": []}, {"guid": "ac68b209-f8c4-59fb-9435-54832a45e6f6", "code": "8UBAZT", "id": 99782, "logo": null, "date": "2026-10-24T10:00:00-04:00", "start": "10:00", "end": "2026-10-24T11:00:00-04:00", "duration": "01:00", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-99782-finding-evil-fast-windows-memory-triage-with-volatility-3", "url": "https://pretalx.com/bsidesaugusta-2026/talk/8UBAZT/", "title": "Finding Evil Fast: Windows Memory Triage with Volatility 3", "subtitle": "", "track": "Track 1", "type": "Talk", "language": "en", "abstract": "Memory analysis is an essential investigative technique for detecting modern, memory-resident malware. Unfortunately, it is often perceived as a difficult and manual process requiring expert knowledge of operating systems and malware internals. This talk challenges that assumption by presenting five checks that can be automatically performed against Windows memory samples to quickly surface signs of malicious code execution or attacker access. The presented checks answer five critical triage questions: 1) are any processes running with unexpected privileges, 2) are restricted resources being accessed by unexpected processes, 3) are any processes executing code in a suspicious manner, 4) has malware entered the kernel, and 5) does any process or kernel driver match known threat intelligence? All checks will be demonstrated using Volatility 3, the most widely used open source framework for memory analysis. Attendees will leave with a compact workflow that SOC analysts, threat hunters, and incident handlers can use to automatically identify memory-only malware, toolkits, and attacker activity, helping them rapidly prioritize systems during large-scale triage and decide where deeper forensic analysis is warranted.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "LBSXCL", "name": "Andrew Case", "avatar": null, "biography": "Andrew Case is the Director of Research at Volexity and has significant experience in incident response handling, digital forensics, and malware analysis. He has conducted numerous large-scale investigations that span enterprises and industries. Case is a core developer of Volatility, the most widely used open-source memory forensics framework, and a co-author of the highly popular and technical forensics analysis book \u201cThe Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory.\u201d Case has spoken at many industry conferences, including Black Hat, DEF CON, RSA, several BSides events, SecTor, and OMFW.", "public_name": "Andrew Case", "guid": "297c5813-4aa6-51ef-b014-3a5545eb124c", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/LBSXCL/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/8UBAZT/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/8UBAZT/", "attachments": []}, {"guid": "7dc2da8f-615b-5e8f-b4a6-339b3bd9801f", "code": "WJNW7F", "id": 103511, "logo": null, "date": "2026-10-24T11:00:00-04:00", "start": "11:00", "end": "2026-10-24T11:15:00-04:00", "duration": "00:15", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-103511-2-hallway-con", "url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "title": "Hallway Con", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Break", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "attachments": []}, {"guid": "c8d1e148-5d99-5f10-8fac-f8245e792036", "code": "9GMJDP", "id": 103188, "logo": null, "date": "2026-10-24T11:15:00-04:00", "start": "11:15", "end": "2026-10-24T11:45:00-04:00", "duration": "00:30", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-103188-your-ai-agent-takes-orders-from-strangers-prompt-injection-and-the-path-to-governing-agents", "url": "https://pretalx.com/bsidesaugusta-2026/talk/9GMJDP/", "title": "Your AI Agent Takes Orders From Strangers: Prompt Injection and the Path to Governing Agents", "subtitle": "", "track": "Track 1", "type": "Talk", "language": "en", "abstract": "AI agents are showing up in every enterprise. They read email, browse the web, query internal systems, and take actions on their own. Leadership wants them deployed this quarter, and security owns the risk without a playbook. Prompt injection is the top risk on the OWASP Top 10 for LLM Applications, and it is the reason security teams cannot fully trust these agents. An agent cannot tell the difference between data and instructions. A malicious email, web page, or document can give an agent orders, and the agent will follow them using the credentials and permissions of whoever it works for.\n\nWe will walk through how these attacks work in plain English, using real cases: the EchoLeak zero click data exfiltration in Microsoft 365 Copilot and the ForcedLeak attack on Salesforce Agentforce. We will also cover why the common fixes fall short. Better system prompts, output filters, and newer models all help, but none of them stop the attack.\n\nThe second half is about what works. The same controls we already use for people apply to agents: least privilege, separation of duties, egress control, human approval for high risk actions, and audit logs. You will leave with a simple way to explain prompt injection to your CISO, a checklist for reviewing any agent deployment, and first steps for finding and monitoring the agents already running in your environment.\n\nNo AI background needed. If you understand phishing and insider threat, you already understand this talk.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "JKUWEN", "name": "Steven Jung", "avatar": null, "biography": "Steven Jung is Co-Founder and CEO of CodeIntegrity, an agent security company. He works with enterprise security teams putting AI agents into production, with hands on experience in prompt injection exploits, agent takeover techniques, and the controls that stop them: least privilege, egress control, and audit logging. He spends most of his time watching AI agents get tricked into doing things nobody authorized, and teaching teams how to stop it.", "public_name": "Steven Jung", "guid": "c542d875-9023-5fd3-a3a5-ac286d1f7c5c", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/JKUWEN/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/9GMJDP/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/9GMJDP/", "attachments": []}, {"guid": "a9f4afea-4087-5842-9b5b-eaa0bbd8d259", "code": "XFZ98W", "id": 103512, "logo": null, "date": "2026-10-24T11:45:00-04:00", "start": "11:45", "end": "2026-10-24T12:45:00-04:00", "duration": "01:00", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-103512-0-lunch", "url": "https://pretalx.com/bsidesaugusta-2026/talk/XFZ98W/", "title": "Lunch", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Enjoy lunch provided by Chick-fil-A!  A vegetarian option will also be available. \nLunch is served in the lobby of the Shaffer MacCartney Building.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/XFZ98W/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/XFZ98W/", "attachments": []}, {"guid": "8af5a9e4-408e-59ea-92dd-82274f3afbfc", "code": "PPNTCE", "id": 102939, "logo": null, "date": "2026-10-24T12:45:00-04:00", "start": "12:45", "end": "2026-10-24T13:45:00-04:00", "duration": "01:00", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-102939-hands-eyes-memory-a-live-progressive-demo-from-stateless-chatbot-to-fully-agentic-ai", "url": "https://pretalx.com/bsidesaugusta-2026/talk/PPNTCE/", "title": "Hands, Eyes & Memory: - A Live Progressive Demo From Stateless Chatbot to Fully Agentic AI", "subtitle": "", "track": "Track 1", "type": "Talk", "language": "en", "abstract": "Join us for an exciting, code-first exploration where we transform a humble chat completion script into a sophisticated, fully agentic AI system, all through a series of live, iterative Python demonstrations.\nWe'll kick off with a memory-less agent that does well with single questions but stumbles on conversational follow-ups. Watch as we add persistent message history, enabling coherent multi-turn dialogues. Next, we'll hit the wall of context limits when tackling file operations and large data, revealing why raw tool access isn't enough.\nThrough hands-on additions of tool-calling capabilities, we'll differentiate between built-in tools and configurable MCP services. Our agent will gain \"hands\" to act on the world, \"eyes\" to inspect complex data structures (databases, logs, packets, registries), and advanced memory architectures to manage its cognitive load.\nCulminating in a blueprint for agentic memory management, including adaptive system prompts, modular skill loading, planning modes, and compressible context, we'll demonstrate how these elements combine to create truly autonomous, efficient AI agents.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "MPC8ZX", "name": "Mark Baggett", "avatar": null, "biography": "Mark Baggett is a SANS Faculty Fellow, cybersecurity leader, and author of SEC573: AI-Powered Security Automation and SEC673: Advanced Information Security Automation with Python. As CTO of the SANS Internet Storm Center and a former Technical Advisor to the U.S. Department of Defense, he brings more than three decades of hands-on experience in threat detection, incident response, penetration testing, and defensive automation.\n\nMark specializes in helping security professionals turn Python, AI, and automation into practical tools that strengthen real-world defense. The 15th person worldwide to earn the GIAC Security Expert (GSE) certification, he is also an accomplished open-source developer, educator, and community leader. Known for making complex technical topics approachable, Mark equips defenders of every coding level to build capabilities they can use immediately.", "public_name": "Mark Baggett", "guid": "641fe711-aebc-59e5-86a4-c5950e51a531", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/MPC8ZX/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/PPNTCE/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/PPNTCE/", "attachments": []}, {"guid": "f4f5c241-a4a7-58d6-98e4-f00dee486cfd", "code": "WR7LGP", "id": 101519, "logo": null, "date": "2026-10-24T13:45:00-04:00", "start": "13:45", "end": "2026-10-24T14:45:00-04:00", "duration": "01:00", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-101519-dealing-with-shadows", "url": "https://pretalx.com/bsidesaugusta-2026/talk/WR7LGP/", "title": "Dealing with Shadows", "subtitle": "", "track": "Track 1", "type": "Talk", "language": "en", "abstract": "Ransomware negotiations are rarely just about money. They are high-pressure engagements shaped by psychology, leverage, timing, and uncertainty, all while organizations are still assessing the scope of compromise.\n\nThis talk offers a practitioner\u2019s perspective on negotiating with threat actors during live extortion events. Drawing on real-world cases, it examines how threat actors communicate, what their behavior signals, and how disciplined negotiation strategy can influence outcomes beyond the final payment amount. Attendees will learn how pacing, message control, and delay are used to buy time, reduce risk, and preserve decision-making authority under crisis conditions.\n\nThe session also addresses common misconceptions about ransom negotiations, frequent mistakes that increase cost and exposure, and how negotiation fits into a broader incident response strategy that balances technical, legal, financial, and human factors. This presentation is about what works, and what doesn\u2019t. What you should do, and maybe more importantly, what you should never do.", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "TZWWAX", "name": "Matt Barnett", "avatar": null, "biography": "Matt Barnett is a cybersecurity executive and incident response leader who has worked on high-stakes ransomware incidents affecting organizations across multiple industries. He is frequently seen on NBC as a go to resource in Philadelphia for cyber events. As a founder of SEVN-X, he specializes in adversary-focused security, digital forensics, and incident response, including direct involvement in ransomware negotiations where business risk, legal exposure, and operational survival intersect. Matt brings a rare perspective from the front lines\u2014combining technical depth, real-world negotiation experience, and an understanding of how threat actors think, operate, and exploit pressure. His talks focus on what actually happens during ransomware events, what organizations get wrong, and how negotiation decisions shape outcomes long after the ransom note appears.", "public_name": "Matt Barnett", "guid": "344d2e36-9b11-557b-ba33-498b5b0ac5bd", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/TZWWAX/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/WR7LGP/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/WR7LGP/", "attachments": []}, {"guid": "2285c76e-c7c6-5a8e-8bb4-c81bad8addc6", "code": "WJNW7F", "id": 103511, "logo": null, "date": "2026-10-24T14:45:00-04:00", "start": "14:45", "end": "2026-10-24T15:00:00-04:00", "duration": "00:15", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-103511-3-hallway-con", "url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "title": "Hallway Con", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Break", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "attachments": []}, {"guid": "4a9a6563-5c3d-564a-a580-2761699e7e27", "code": "LXEFNA", "id": 101564, "logo": null, "date": "2026-10-24T15:00:00-04:00", "start": "15:00", "end": "2026-10-24T16:00:00-04:00", "duration": "01:00", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-101564-so-crates-security-onion-containerized-rapid-analysis-of-threats-evil-and-sus", "url": "https://pretalx.com/bsidesaugusta-2026/talk/LXEFNA/", "title": "SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!", "subtitle": "", "track": "Track 1", "type": "Talk", "language": "en", "abstract": "SO-CRATES is a new free and open source project for analyzing pcap files, log files, and binary files. Designed from first principles, it's a single container image that is simple yet tremendously powerful. In this talk, we'll discuss the reasons for building a new tool, how it compares to the full Security Onion platform, and then see how you can view network alerts, file alerts, and log alerts. We'll then dive deeper into browsing network metadata (DNS, HTTP, TLS, flows), extracting ASCII transcripts, viewing per-packet hexdumps, and carving individual streams.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "9TCR9P", "name": "Doug Burks", "avatar": "https://pretalx.com/media/avatars/YSSREN_8IZBUxN.webp", "biography": "Doug Burks started Security Onion in 2008 to provide a comprehensive platform to help folks peel back the layers of their enterprise and make their adversaries cry. Today, Security Onion has over 2,500,000 downloads and is being used by organizations around the world for threat hunting, enterprise security monitoring, and log management. In 2014, Doug started Security Onion Solutions LLC to help those organizations by providing training, professional services, and hardware appliances. Doug is a CEO, public speaker, teacher, former president of the Greater Augusta ISSA, and co-founder of BSides Augusta, but what he really likes the most is catching bad guys.", "public_name": "Doug Burks", "guid": "37dd0115-a37a-500d-981a-6a414c5d47fd", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/9TCR9P/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/LXEFNA/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/LXEFNA/", "attachments": []}, {"guid": "9a0cb5a3-d4a5-553a-a9a4-44d5f533a3b0", "code": "J9TMXD", "id": 98768, "logo": null, "date": "2026-10-24T16:00:00-04:00", "start": "16:00", "end": "2026-10-24T17:00:00-04:00", "duration": "01:00", "room": "Track 1 - Plug N Play", "slug": "bsidesaugusta-2026-98768-hold-my-coffee-i-m-building-a-security-tool-security-without-gatekeepers-in-an-ai-first-world", "url": "https://pretalx.com/bsidesaugusta-2026/talk/J9TMXD/", "title": "Hold My Coffee, I\u2019m Building a Security Tool\": Security Without Gatekeepers in an AI-First World", "subtitle": "", "track": "Track 1", "type": "Talk", "language": "en", "abstract": "Security workflows are shifting from human-centric to AI-centric. Meanwhile, AI coding assistants have democratized software development, transforming domain expertise and creative ideas into powerful solutions without requiring a CS degree, and without consequences if things don\u2019t work out. \nWhat happens when these trends collide? \n\nExperimentation with AI-enabled security tools and workflows becomes practically mandatory. The risk is minimal; the potential rewards are great. \n\nMembers of Cisco\u2019s Talos team will share case studies from their research in building AI-driven security workflows. Discover frameworks for integrating AI into your operations and learn strategies to guide your customers through their AI transformations.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "YSYSJR", "name": "David J. Bianco", "avatar": null, "biography": "David is a Principal Cybersecurity Research Engineer with Cisco Talos, where he studies practical and effective uses of AI for defensive security operations. He is also a SANS Certified Instructor, where he teaches network forensics. David has nearly 30 years of experience in the information security field, primarily in incident detection and response, threat hunting, and Cyber Threat Intelligence (CTI).  He is the creator of the Pyramid of Pain and lead author of the PEAK threat hunting framework. Really, he just wants to make security better for everyone. You can follow David on Bluesky  as @DavidJBianco.bsky.social or on Mastodon as @DavidJBianco@infosec.exchange.", "public_name": "David J. Bianco", "guid": "56ffa78c-d6d1-567d-8cf0-9c15ecf811cb", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/YSYSJR/"}, {"code": "NCCDMS", "name": "Tamara Chacon", "avatar": "https://pretalx.com/media/avatars/8ULVVF_ZQCW4xd.webp", "biography": "Tamara is a Senior Security Strategist with Cisco Talos. Where she focuses on preaching security fundamentals, good cyber hygiene and the team's research. She holds a degree in Criminal Justice and Anthropology from the University of Northern Colorado and a Cybersecurity Career Studies Cert. With a passion for bridging human behavior and digital defense, she brings a unique perspective to the cybersecurity world. She is a founding member of the Splunk SURGe Team.", "public_name": "Tamara Chacon", "guid": "cbd735f9-b281-5289-b1cb-188ada14e7a7", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/NCCDMS/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/J9TMXD/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/J9TMXD/", "attachments": []}], "Track 2 - Virtual World": [{"guid": "615409ac-2417-56e1-883b-7a237811ba51", "code": "GRFJQM", "id": 103514, "logo": null, "date": "2026-10-24T07:45:00-04:00", "start": "07:45", "end": "2026-10-24T08:30:00-04:00", "duration": "00:45", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-103514-3-doors-open-check-in", "url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "title": "Doors Open / Check-in", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Grab your badge and freebies, then check out the CTF, exhibitors, lock pick village, and raffle table.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "attachments": []}, {"guid": "b873e173-61c2-5c8a-9054-f1dbccdc6b1d", "code": "AN7JAS", "id": 103513, "logo": null, "date": "2026-10-24T08:30:00-04:00", "start": "08:30", "end": "2026-10-24T09:00:00-04:00", "duration": "00:30", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-103513-0-opening-remarks", "url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "title": "Opening Remarks", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Live in Track 1, Simulcast in Tracks 2-3\nRemarks will be delivered by BSidesAugusta staff and special guests.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "attachments": []}, {"guid": "7bee0a6b-654a-5ed0-9221-a0bf13331f2a", "code": "S7VVXT", "id": 104233, "logo": null, "date": "2026-10-24T09:00:00-04:00", "start": "09:00", "end": "2026-10-24T10:00:00-04:00", "duration": "01:00", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-104233-0-keynote-tim-kosiba", "url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "title": "Keynote - Tim Kosiba", "subtitle": "", "track": "Keynote", "type": "Talk", "language": "en", "abstract": "*Live in Track 1, Simulcast in all other tracks/rooms*  \n  \nTim Kosiba, Deputy Director of the National Security Agency, will be our keynote speaker!  \n  \n*Live in Track 1, Simulcast in all other tracks/rooms*", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "C8G88E", "name": "Tim Kosiba", "avatar": "https://pretalx.com/media/avatars/avatar_6hFwavm.webp", "biography": "Tim Kosiba serves as the 21st Deputy Director of the National Security Agency. In this capacity, he works with the NSA\u2019s Director and Executive Director to provide leadership in all areas of the enterprise and to represent NSA\u2019s interests both internally and externally.\n \nPrior to his retirement from NSA in 2021, he served as Deputy Commander of NSA/CSS Georgia \u2014 the Agency\u2019s largest Cryptologic Center.\n\nMr. Kosiba\u2019s NSA career spanned a variety of key leadership roles across NSA and USCYBERCOM, including Special U.S. Liaison Officer in Canberra, Australia; Deputy Director of the NSA/CSS Commercial Solutions Center (NCSC); and Chief of Tailored Access Operations (now Computer Network Operations). Mr. Kosiba\u2019s federal service began in 1989 with the Naval Criminal Investigative Service. After several years spent working in the United Kingdom, Mr. Kosiba was recruited by the FBI in 1996, which brought him to the Washington area. Following the events of 9/11, Tim dedicated his digital forensic knowledge to capturing the perpetrators of the attacks, going on to supervise one of the FBI\u2019s largest digital forensics laboratories. He later joined the Joint Functional Component Command for Network Warfare (JFCC-NW) \u2014 the predecessor of USCYBERCOM \u2014 in 2007, where he held the role of Technical Director.\n\nMr. Kosiba returns to NSA after serving as a cybersecurity leader in the private sector for several years. Throughout his career, he has consistently represented USCYBERCOM and NSA at the White House and forged partnerships to advance cybersecurity policy and priorities. He has received several awards from the law enforcement and the intelligence communities and is a recognized technical leader in the cybersecurity field.", "public_name": "Tim Kosiba", "guid": "2d0d3172-2ac8-5b9b-aaaa-035fcbba9be2", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/C8G88E/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "attachments": []}, {"guid": "70c0be0f-0cc9-5f09-9c9b-d480cf4fd160", "code": "FM8ESG", "id": 102530, "logo": null, "date": "2026-10-24T10:00:00-04:00", "start": "10:00", "end": "2026-10-24T11:00:00-04:00", "duration": "01:00", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-102530-ai-pocalypse", "url": "https://pretalx.com/bsidesaugusta-2026/talk/FM8ESG/", "title": "Ai-pocalypse", "subtitle": "", "track": "Track 2", "type": "Talk", "language": "en", "abstract": "Ai has taken over all of the defense discussion in the last couple of years.  Will it help?  Will it result in all of our jobs going away?  If so how?  In this talk we'll cut through all the hyperbole and focus on the data.  What can AI do and no do and what does that mean for us as cyber-defenders?  The future is incredibly interesting.  We are on the cusp of a new era of cyber-defense and it's up to you to seize it.  This talk is about how to do exactly that.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "BKJVJE", "name": "Tim Crothers", "avatar": null, "biography": "Tim Crothers serves as a board advisor to Acalvio and several other startups, and is hard at work on his next book. Prior roles include SVP, Global Cyber Defense for United Health Group, a Fortune 4 company, and CSO for Mandiant, where he defended both Mandiant and Google Cloud against some of the world's most sophisticated adversaries. With over 40 years in the technology sector and a security focus since 1994, Tim has broad expertise with a particular passion for cyber threat intelligence, reverse engineering, incident response, and breach investigation. In addition to his leadership and technical accomplishments, Tim is a prolific author and dynamic speaker. Tim has authored 17 books and presents frequently at some of the world's largest cybersecurity conferences. Above all, Tim is dedicated to finding and developing talent, driven by his belief that each of us has a responsibility to leave the world a little better than we found it.", "public_name": "Tim Crothers", "guid": "4bce3b3e-da8a-56f7-9101-9b35a89bf43f", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/BKJVJE/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/FM8ESG/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/FM8ESG/", "attachments": []}, {"guid": "e7b7fd42-5afa-5fce-b23a-de7d0a9c570d", "code": "WJNW7F", "id": 103511, "logo": null, "date": "2026-10-24T11:00:00-04:00", "start": "11:00", "end": "2026-10-24T11:15:00-04:00", "duration": "00:15", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-103511-1-hallway-con", "url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "title": "Hallway Con", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Break", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "attachments": []}, {"guid": "bb5e9605-3b8a-5e43-b1c7-fa5bc03dd825", "code": "7KNFZ3", "id": 99300, "logo": null, "date": "2026-10-24T11:15:00-04:00", "start": "11:15", "end": "2026-10-24T11:45:00-04:00", "duration": "00:30", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-99300-evolutions-in-critical-infrastructure-attacks", "url": "https://pretalx.com/bsidesaugusta-2026/talk/7KNFZ3/", "title": "Evolutions in Critical Infrastructure Attacks", "subtitle": "", "track": "Track 2", "type": "Talk", "language": "en", "abstract": "Attacks against critical infrastructure organizations have increased from 2025 to 2026 including definitive proof of AI-enabled attacks. Claude and other tools are being leveraged for low sophisticated threat actors to speed up their payload development timeline. Mixed with the rise of hacktivist organizations there is a pervasive theme among these incidents. \"This attack could have been prevented by basic security controls and defensible architecture\".", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "LSBK98", "name": "Mackenize Morris", "avatar": "https://pretalx.com/media/avatars/EKESJN_YFXf78Z.webp", "biography": "Mackenize Morris is a Principal Industrial Consultant at the industrial cybersecurity company Dragos, Inc. where he assists the professional services teams in conducting network and vulnerability assessments.\n\nPrior to joining Dragos, Mackenize worked as a process controls engineer and system architect for a DOE contractor. In addition to his responsibilities he became the system administrator of the DCS system until fully switching over to an ICS cybersecurity position within the DOE complex. \n\nMackenize received his B.S. in Chemical Engineering and MBA from the University of South Carolina and his Masters in Information Security Engineering from the SANS Technology Institute. He currently holds the following certifications: GCPM, GCIP, GSEC, GDSA, GREM, GCCC, GRID, GCIA, GISCP, GPEN, GMON, GCIH, GWAPT and CISSP. \n\nMackenize lives in Aiken, South Carolina down the street from his brother\u2019s horse farm where he keeps his horse, Riley. Besides riding horses, Mackenize fences as part of the Augusta Fencers Club and teaches at the University of South Carolina - Aiken where he is a fan of the esports teams. \n\nMackenize\u2019s name is pronounced like Mackenzie; the IZE spelling was a result of a spelling error on his birth certificate.", "public_name": "Mackenize Morris", "guid": "7bfa19ef-e457-5064-ab37-fb5248a8fc67", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/LSBK98/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/7KNFZ3/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/7KNFZ3/", "attachments": []}, {"guid": "a6d0711b-5507-5d13-b5d6-0d1897faa27c", "code": "XFZ98W", "id": 103512, "logo": null, "date": "2026-10-24T11:45:00-04:00", "start": "11:45", "end": "2026-10-24T12:45:00-04:00", "duration": "01:00", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-103512-1-lunch", "url": "https://pretalx.com/bsidesaugusta-2026/talk/XFZ98W/", "title": "Lunch", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Enjoy lunch provided by Chick-fil-A!  A vegetarian option will also be available. \nLunch is served in the lobby of the Shaffer MacCartney Building.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/XFZ98W/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/XFZ98W/", "attachments": []}, {"guid": "30ce33ea-1cec-51d4-a76b-c0584cf71686", "code": "H9VJTM", "id": 99489, "logo": null, "date": "2026-10-24T12:45:00-04:00", "start": "12:45", "end": "2026-10-24T13:45:00-04:00", "duration": "01:00", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-99489-machine-learning-for-hunting-malware", "url": "https://pretalx.com/bsidesaugusta-2026/talk/H9VJTM/", "title": "Machine Learning for Hunting Malware", "subtitle": "", "track": "Track 2", "type": "Talk", "language": "en", "abstract": "After 9 years of hunting for malware, the ScumBots project has found and successfully analyzed over 23,000 malware binaries. It has also found over 10,000 binaries that it couldn\u2019t recognize or analyze.  So I did what any sane person would do, I trained a machine learning model to try and analyze the 10,000 unknown files. I\u2019ll explain why I did it, how I did it, and what I learned along the way.  I\u2019ll also give you the tools to do this for yourself, and also give you the model files trained from ScumBots corpus of known malware.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "BFPPBY", "name": "Paul Melson", "avatar": null, "biography": "Paul Melson has been working in computer security since 2001, and has spent the majority of the last two decades to detecting and disrupting cybercriminals.  He works on the Cybersecurity team at Capital One and is also the author and operator of the ScumBots project.", "public_name": "Paul Melson", "guid": "6c0ef77f-a4f2-5bd9-89bd-5642c33dafed", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/BFPPBY/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/H9VJTM/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/H9VJTM/", "attachments": []}, {"guid": "991278ee-9090-53f6-8b63-8ab8248db1cc", "code": "VDVJXC", "id": 103248, "logo": "https://pretalx.com/media/bsidesaugusta-2026/submissions/VDVJXC/image_W8tLu9q.webp", "date": "2026-10-24T13:45:00-04:00", "start": "13:45", "end": "2026-10-24T14:15:00-04:00", "duration": "00:30", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-103248-what-s-an-agentic-ctf-playing-mind-games-with-an-agent", "url": "https://pretalx.com/bsidesaugusta-2026/talk/VDVJXC/", "title": "What\u2019s an agentic CtF? Playing mind games with an agent", "subtitle": "", "track": "Track 2", "type": "Talk", "language": "en", "abstract": "A real world Capture the Flag exercise that was designed for a human adversary. A new edition involving a red teaming AI agent. The agent is given a prompt representing the mission statement: to capture a set of 5 flags within a 30 minute time window. The defender\u2019s goal? Impacting the agent and attempting to deny the agent from completing the CtF challenge. \n\nThis session is a dive into agentic attacks, why the dynamic reasoning and concurrency aspects of agentic attacks matter more than the machine-speed of execution, and the defender\u2019s journey in designing countermeasures. The talk distills the essence of a range of CtF exercises performed with a team of agents and the learnings from the defender\u2019s perspective.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "AR3ANW", "name": "Suril Desai", "avatar": "https://pretalx.com/media/avatars/WZTHLZ_WKx8T9W.webp", "biography": "Suril is VP Engineering and Security SME at Acalvio Technologies. Suril has deep domain expertise in cybersecurity and Computer Science. Suril has spoken at numerous security conferences and believes in sharing his knowledge and learning from the interactions.", "public_name": "Suril Desai", "guid": "bedb20e5-bed9-5e4d-8645-c354fa5f7558", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/AR3ANW/"}, {"code": "7GKW77", "name": "Scott Hawk", "avatar": null, "biography": null, "public_name": "Scott Hawk", "guid": "16ea8f61-a9fa-5b0b-a071-f7dafdb64093", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/7GKW77/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/VDVJXC/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/VDVJXC/", "attachments": []}, {"guid": "f53ca4a6-31a6-5029-87cb-c665acc4ea83", "code": "XLXEKY", "id": 100854, "logo": null, "date": "2026-10-24T14:15:00-04:00", "start": "14:15", "end": "2026-10-24T14:45:00-04:00", "duration": "00:30", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-100854-the-sector-everyone-ignores-why-k-12-is-critical-infrastructure-and-what-we-can-learn-from-it", "url": "https://pretalx.com/bsidesaugusta-2026/talk/XLXEKY/", "title": "The Sector Everyone Ignores: Why K-12 Is Critical Infrastructure and What We Can Learn From It", "subtitle": "", "track": "Track 2", "type": "Talk", "language": "en", "abstract": "Strip away the crayon drawings and here is what K-12 in the U.S. is: an enterprise network serving tens of millions of users, holding Social Security numbers, medical records, disability status, and behavioral data on children, staffed by people whose primary job is not security, under near-constant attack. One breach in 2024 exposed the records of 60 million students and 10 million teachers in a single hit. The sector gets compromised at a rate most industries would declare a national emergency. Nobody is talking about it.\n\nThis talk draws on the experience of defending a large urban district serving over 92,000 students, 14,000 staff, and 138 schools. It makes the case that K-12 is not a niche problem. It is the most honest stress test available for defending a high-value, data-rich environment with enterprise-scale exposure and a fraction of enterprise-level resources. The threat patterns, governance failures, defender strategies, and hard lessons from K-12 translate directly to any organization doing more with less.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "9EYUTH", "name": "Eric Logan", "avatar": "https://pretalx.com/media/avatars/Q8PXSF_JZQkbPN.webp", "biography": "Eric M. Logan brings over 26 years of dedicated experience in IT and cybersecurity across K-12 and higher education environments. Currently serving as Director of Information & Network Security for DeKalb County School District, Eric leads the district's cybersecurity transformation, having built their first dedicated security team and launched innovative programs like Cyber Champions, which empowers students to become peer leaders in digital safety.\n\nHis career spans prestigious institutions including Georgia Tech Research Institute, where he served as Cybersecurity Operations Manager and later as Governance, Risk & Compliance Manager, and Emory University, where he provided technical expertise to researchers and managed campus-wide technology systems. Eric's unique perspective combines hands-on technical expertise with strategic leadership and a genuine passion for education.\n\nBased in Thomaston, Georgia, Eric is deeply involved in professional organizations including ISSA, ISACA, and FBI InfraGard, and believes in building bridges between technical expertise and practical application in educational settings.", "public_name": "Eric Logan", "guid": "93610223-920a-543b-b68b-380100d29555", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/9EYUTH/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/XLXEKY/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/XLXEKY/", "attachments": []}, {"guid": "20dd1090-e32e-5bff-b21d-59d7bd098565", "code": "WJNW7F", "id": 103511, "logo": null, "date": "2026-10-24T14:45:00-04:00", "start": "14:45", "end": "2026-10-24T15:00:00-04:00", "duration": "00:15", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-103511-4-hallway-con", "url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "title": "Hallway Con", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Break", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "attachments": []}, {"guid": "a8c45a62-4e27-5389-a893-7478fb349da0", "code": "BWS3JJ", "id": 99117, "logo": null, "date": "2026-10-24T15:00:00-04:00", "start": "15:00", "end": "2026-10-24T16:00:00-04:00", "duration": "01:00", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-99117-they-didn-t-build-it-they-didn-t-pay-for-it-but-they-re-running-it-right-now-in-your-environment", "url": "https://pretalx.com/bsidesaugusta-2026/talk/BWS3JJ/", "title": "They Didn\u2019t Build It, They Didn\u2019t Pay for It, But They\u2019re Running It Right Now - In YOUR Environment", "subtitle": "", "track": "Track 2", "type": "Talk", "language": "en", "abstract": "You deployed an AI service, followed the docs, and even remembered to rotate your passwords (well - mostly). But somewhere on the internet, a criminal syndicate is using your Azure API key to generate content you\u2019d rather not explain to HR - and they\u2019re billing it to you. This session walks through the Storm-2139 takedown - a real Microsoft Digital Crimes Unit operation spanning four countries, a federal lawsuit, and criminals who responded by harassing Microsoft\u2019s lawyers online (yes, really). We\u2019ll cover how AI APIs became the hottest new attack surface, and what you can actually do about it before the bill arrives.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "GAJW8Z", "name": "David Branscome", "avatar": "https://pretalx.com/media/avatars/9AMXEQ_F6JSqMC.webp", "biography": "David is a Global Partner Solutions Architect for Security, Compliance and Identity at Microsoft.  In this role, David is responsible for training and supporting Microsoft partners on the latest security compliance and identity solutions, including Microsoft 365, Azure and Windows.\nDavid has been with Microsoft for 16+ years in a variety of roles, from Microsoft Consulting Services to Premier Field Engineer and most recently in the partner support organization.\nDavid is a certification junkie and holds numerous security certifications, including CISSP, GCWN, GCED, GCDA, GMOB, GCIH, GISP, GSEC, GSOC, GCFA, GDAT, GCPN, GCFR, GCTD, GRTP and CISSP.", "public_name": "David Branscome", "guid": "4c875755-71ae-5807-bdfb-8f3773edf170", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/GAJW8Z/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/BWS3JJ/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/BWS3JJ/", "attachments": []}, {"guid": "774d27f0-7289-53e8-af7b-a23eba22f055", "code": "ZFLNGK", "id": 103233, "logo": null, "date": "2026-10-24T16:00:00-04:00", "start": "16:00", "end": "2026-10-24T17:00:00-04:00", "duration": "01:00", "room": "Track 2 - Virtual World", "slug": "bsidesaugusta-2026-103233-how-i-hacked-the-dod-by-accident-and-saved-them-billions", "url": "https://pretalx.com/bsidesaugusta-2026/talk/ZFLNGK/", "title": "HOW I HACKED THE DOD (by accident) AND SAVED THEM BILLIONS", "subtitle": "", "track": "Track 2", "type": "Talk", "language": "en", "abstract": "While reviewing my own promotion records in a Department of Defense web application, I noticed sensitive identifiers being passed in backend requests. Acting as a fully authenticated but non-privileged user, this curiosity revealed a widespread access control failure within an internal personnel system.\nThis talk examines how common vulnerabilities\u2014such as indirect object reference flaws and over-trusted authenticated users\u2014can expose massive amounts of Personally Identifiable Information without exploits, malware, or elevated access. Limited, ethical testing demonstrated access paths to sensitive records across multiple DoD populations. All findings were responsibly disclosed through official vulnerability channels.\nRather than focusing on specific technologies, the presentation highlights repeatable failure patterns in internal applications, why \u201ctrusted user\u201d assumptions break down, and how curiosity-driven analysis uncovers issues that compliance testing often misses. Attendees will leave with a stronger mindset for evaluating internal systems, improving defensive testing programs, and understanding why internal vulnerability discovery is critical to modern security.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "XL7RVX", "name": "Jared Hrabak", "avatar": "https://pretalx.com/media/avatars/RS9KTK_xquSlHq.webp", "biography": "Jared Hrabak is a cybersecurity engineer and U.S. Army Reserve officer with over 16 years of service, including time on a Cyber Protection Team and participation in Cyber Officer selection boards. By day, he works in cybersecurity consulting, but his real interest is understanding how systems work and fail.\n\nJared\u2019s background spans DoD contracting, large-scale security operations supporting financial environments, and hands-on offensive security training. He holds multiple certifications including CISSP, GPEN, GWAPT, and GCIH.\n\nHe is a recipient of the DoD Vulnerability Disclosure Program (VDP) Researcher of the Month and Researcher of the Year awards. His work focuses on identifying real-world access control failures through curiosity-driven analysis rather than full-time bug hunting.", "public_name": "Jared Hrabak", "guid": "f9d49b92-c20f-5109-a528-72aeb6709277", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/XL7RVX/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/ZFLNGK/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/ZFLNGK/", "attachments": []}], "Track 3 - Room 2400": [{"guid": "885033b6-0596-513a-b8ec-0ba0d76980db", "code": "GRFJQM", "id": 103514, "logo": null, "date": "2026-10-24T07:45:00-04:00", "start": "07:45", "end": "2026-10-24T08:30:00-04:00", "duration": "00:45", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-103514-4-doors-open-check-in", "url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "title": "Doors Open / Check-in", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Grab your badge and freebies, then check out the CTF, exhibitors, lock pick village, and raffle table.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "attachments": []}, {"guid": "463c4f33-23fd-58e0-8dc9-a3a6d6faf122", "code": "AN7JAS", "id": 103513, "logo": null, "date": "2026-10-24T08:30:00-04:00", "start": "08:30", "end": "2026-10-24T09:00:00-04:00", "duration": "00:30", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-103513-2-opening-remarks", "url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "title": "Opening Remarks", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Live in Track 1, Simulcast in Tracks 2-3\nRemarks will be delivered by BSidesAugusta staff and special guests.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "attachments": []}, {"guid": "d2163235-fd89-510e-b59a-796d7cb30edd", "code": "S7VVXT", "id": 104233, "logo": null, "date": "2026-10-24T09:00:00-04:00", "start": "09:00", "end": "2026-10-24T10:00:00-04:00", "duration": "01:00", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-104233-3-keynote-tim-kosiba", "url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "title": "Keynote - Tim Kosiba", "subtitle": "", "track": "Keynote", "type": "Talk", "language": "en", "abstract": "*Live in Track 1, Simulcast in all other tracks/rooms*  \n  \nTim Kosiba, Deputy Director of the National Security Agency, will be our keynote speaker!  \n  \n*Live in Track 1, Simulcast in all other tracks/rooms*", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "C8G88E", "name": "Tim Kosiba", "avatar": "https://pretalx.com/media/avatars/avatar_6hFwavm.webp", "biography": "Tim Kosiba serves as the 21st Deputy Director of the National Security Agency. In this capacity, he works with the NSA\u2019s Director and Executive Director to provide leadership in all areas of the enterprise and to represent NSA\u2019s interests both internally and externally.\n \nPrior to his retirement from NSA in 2021, he served as Deputy Commander of NSA/CSS Georgia \u2014 the Agency\u2019s largest Cryptologic Center.\n\nMr. Kosiba\u2019s NSA career spanned a variety of key leadership roles across NSA and USCYBERCOM, including Special U.S. Liaison Officer in Canberra, Australia; Deputy Director of the NSA/CSS Commercial Solutions Center (NCSC); and Chief of Tailored Access Operations (now Computer Network Operations). Mr. Kosiba\u2019s federal service began in 1989 with the Naval Criminal Investigative Service. After several years spent working in the United Kingdom, Mr. Kosiba was recruited by the FBI in 1996, which brought him to the Washington area. Following the events of 9/11, Tim dedicated his digital forensic knowledge to capturing the perpetrators of the attacks, going on to supervise one of the FBI\u2019s largest digital forensics laboratories. He later joined the Joint Functional Component Command for Network Warfare (JFCC-NW) \u2014 the predecessor of USCYBERCOM \u2014 in 2007, where he held the role of Technical Director.\n\nMr. Kosiba returns to NSA after serving as a cybersecurity leader in the private sector for several years. Throughout his career, he has consistently represented USCYBERCOM and NSA at the White House and forged partnerships to advance cybersecurity policy and priorities. He has received several awards from the law enforcement and the intelligence communities and is a recognized technical leader in the cybersecurity field.", "public_name": "Tim Kosiba", "guid": "2d0d3172-2ac8-5b9b-aaaa-035fcbba9be2", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/C8G88E/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "attachments": []}, {"guid": "44dcb735-fcc5-5734-8cdd-09dfc89befac", "code": "QWR7E7", "id": 98673, "logo": null, "date": "2026-10-24T10:00:00-04:00", "start": "10:00", "end": "2026-10-24T11:00:00-04:00", "duration": "01:00", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-98673-weaponizing-chromium-for-offensive-operations", "url": "https://pretalx.com/bsidesaugusta-2026/talk/QWR7E7/", "title": "Weaponizing Chromium for Offensive Operations", "subtitle": "", "track": "Track 3", "type": "Talk", "language": "en", "abstract": "Chromium is no longer just a place to steal cookies from. It is a place for persistence and post exploitation for adversaries.\n\nThis talk starts with remotely enabling Chrome DevTools Protocol (CDP) inside a live Chrome or Edge process as a post-exploitation primitive. Once CDP is exposed, the browser\u2019s own debugging interface becomes an operator console: enumerate or open new tabs, capture screenshots of active browser sessions, steal browser cookies, inspect a user's history, enumerate and load extensions, proxy authenticated requests, and interact with web apps from the user\u2019s trusted browser context all in a hidden context from the user. Instead of fighting protections like device-bound session cookies, we will highlight how we can operate through the browser they are bound to.\n\nThen we take the idea further: from browser control to browser persistence. We\u2019ll examine how operators can abuse Chromium\u2019s extension ecosystem, Native Messaging hosts, and Isolated Web Apps can be chained into a Mythic C2 agent for persistence. Along the way, we\u2019ll cover how extension allowlist policies can be bypassed when trust is anchored to extension IDs. \n\nThis talk will also enable defenders by illuminating what artifacts are left behind when operators abuse chromium browsers for post-exploitation primitives.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "ZETYXC", "name": "Andrew Gomez", "avatar": "https://pretalx.com/media/avatars/Z8FFMT_ktoupL4.webp", "biography": "Andrew Gomez is a seasoned Cybersecurity professional with over 9 years of experience in penetration testing, red team engagements, and threat hunting. As a former Captain in the U.S. Army Cyber branch, he specialized in adversary detection and simulation. Currently, Andrew leads offensive security teams as Adversary Simulations Consultant at SpecterOps. Andrew holds a bachelor's degree in Computer Science from the University of North Georgia, a master's degree in Cybersecurity from Georgia Tech, and maintains several industry certifications from Offensive Security, ZeroPoint Security, SANS, and ISC2.", "public_name": "Andrew Gomez", "guid": "62500742-a290-5430-847e-cd4a2fc3ff52", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/ZETYXC/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/QWR7E7/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/QWR7E7/", "attachments": []}, {"guid": "36c4dcb0-4705-5b34-958a-5124ff0a499d", "code": "WJNW7F", "id": 103511, "logo": null, "date": "2026-10-24T11:00:00-04:00", "start": "11:00", "end": "2026-10-24T11:15:00-04:00", "duration": "00:15", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-103511-0-hallway-con", "url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "title": "Hallway Con", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Break", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "attachments": []}, {"guid": "85e459a7-5c17-5a3e-8e7f-0b96f3f985bf", "code": "S8WBFH", "id": 98870, "logo": null, "date": "2026-10-24T11:15:00-04:00", "start": "11:15", "end": "2026-10-24T11:45:00-04:00", "duration": "00:30", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-98870-why-your-future-soc-analyst-is-still-in-high-school-fixing-the-cyber-talent-pipeline", "url": "https://pretalx.com/bsidesaugusta-2026/talk/S8WBFH/", "title": "Why Your Future SOC Analyst Is Still in High School: Fixing the Cyber Talent Pipeline", "subtitle": "", "track": "Track 3", "type": "Talk", "language": "en", "abstract": "Despite years of discussion around the cybersecurity talent shortage, organizations continue to struggle to fill entry level roles. Job postings demand experience that \u201centry level\u201d candidates cannot realistically have, while capable, motivated learners are overlooked. The result isn\u2019t just a pipeline problem it\u2019s a misalignment between how talent is developed and how it is evaluated.\nFrom the perspective of a high school cybersecurity educator actively preparing students for certifications, competitions, and early career pathways, this talk offers a grounded look at what the next generation of analysts actually brings to the table and where the gaps truly exist. These students are not starting from zero; many already possess foundational technical skills, hands-on lab experience, and a strong security mindset. However, they often lack exposure to professional workflows, communication expectations, and real-world operational context.\nThis session will break down the disconnect between classroom preparation and industry expectations, highlighting common misconceptions about entry-level talent. Attendees will gain insight into what emerging candidates can already do, what they still need to learn, and why traditional hiring filters may be excluding high-potential individuals.\nMost importantly, this talk provides actionable strategies for bridging the gap redefining entry level expectations, designing meaningful early career opportunities, and engaging with talent earlier in the pipeline. Whether you are a hiring manager, team lead, or practitioner involved in mentoring, you will leave with practical ways to better identify, develop, and integrate the next generation of cybersecurity professionals.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "R8VHLH", "name": "Caviness", "avatar": null, "biography": "D. Caviness is a cybersecurity educator, mentor, and workforce pipeline builder based in Augusta, Georgia, where she teaches within the Cyber Academy of Excellence. She specializes in preparing high school students for real-world cybersecurity careers through industry-aligned instruction, hands-on labs, and certification pathways such as CompTIA Security+.\nWith experience coaching CyberPatriot and CTF teams as well as guiding students toward internships, scholarships, and early career opportunities, Caviness brings a unique perspective at the intersection of education and industry. Her work focuses on bridging the gap between classroom learning and operational readiness helping students develop not only technical knowledge, but also the problem-solving, communication, and critical thinking skills required in modern security operations centers (SOCs).\nCaviness is particularly passionate about expanding access to cybersecurity education, supporting diverse learners, and redefining what \u201centry-level talent\u201d looks like in today\u2019s workforce. Through her programs, she has helped students build professional portfolios, earn certifications, and take their first steps into the cybersecurity field.\nShe brings to the stage a practical, inside view of the emerging talent pipeline\u2014offering insights that help organizations better identify, develop, and integrate the next generation of cybersecurity professionals", "public_name": "Caviness", "guid": "cbec1910-cea7-5443-aa49-ed6744150863", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/R8VHLH/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/S8WBFH/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/S8WBFH/", "attachments": []}, {"guid": "03935b61-75f8-557c-a562-cc5ada45b8ae", "code": "XFZ98W", "id": 103512, "logo": null, "date": "2026-10-24T11:45:00-04:00", "start": "11:45", "end": "2026-10-24T12:45:00-04:00", "duration": "01:00", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-103512-2-lunch", "url": "https://pretalx.com/bsidesaugusta-2026/talk/XFZ98W/", "title": "Lunch", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Enjoy lunch provided by Chick-fil-A!  A vegetarian option will also be available. \nLunch is served in the lobby of the Shaffer MacCartney Building.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/XFZ98W/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/XFZ98W/", "attachments": []}, {"guid": "f0e291b4-b7e3-5a5e-8ef1-d2dc5740cebc", "code": "NSWTHN", "id": 103251, "logo": null, "date": "2026-10-24T12:45:00-04:00", "start": "12:45", "end": "2026-10-24T13:15:00-04:00", "duration": "00:30", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-103251-know-thy-extensions-governing-the-browser-attack-surface-in-the-enterprise", "url": "https://pretalx.com/bsidesaugusta-2026/talk/NSWTHN/", "title": "Know Thy Extensions: Governing the Browser Attack Surface in the Enterprise", "subtitle": "", "track": "Track 3", "type": "Talk", "language": "en", "abstract": "A typical enterprise has hundreds to thousands of Chrome extensions running against its most sensitive systems, and little visibility into what those add-ons can actually do. An extension a single employee installs to \"make Gmail nicer\" may quietly hold permission to read cookies on every site the user visits. And \"every site\" includes your SSO, your secrets manager, your source control, your CRM.\n\nWe flipped the default: an allow-list posture where new extensions must be requested, and an evaluation engine that decides each request, acts on the decision, and explains it in plain English to the person who asked. This talk walks through how we built it and what we learned.\n\nEvaluating a request means asking two different questions. The first is universal: a dangerous capability is dangerous no matter who installs it, and the engine checks for that like any scanner would. The second is the one a generic score structurally can't see \u2014 the environment the extension is running in. An extension that reads cookies across every site it can reach is a recognizable pattern anywhere. What an off-the-shelf tool can't do is resolve that \"every site\" against the specific hosts where a given org's SSO, secrets manager, and source control actually live, or know that the org's policy rules out a whole class of tool that's perfectly normal elsewhere. We'll dig into how the engine layers that context on top of the general evaluation, weighing capabilities in combination rather than in isolation and measuring access against an explicitly modeled set of the resources an org actually cares about, to land on an allow, block, or escalate-to-human decision.\n\nThe system spans both sides: the analysis that produces a verdict and the action taken on it. A user asks for an extension through the Chrome Web Store's own request flow; the request is enriched, evaluated, and acted on automatically \u2014 Chrome policy applied, a review ticket opened for the hard cases, the right people notified. The same model of the environment that produces the verdict also shapes the guardrail: rather than a coarse approve-or-block, Chrome's policy schema lets an extension be allowed but fenced off from the specific hosts that environment flagged as sensitive, and the engine drives that control straight from the verdict.\n\nAutomated security decisions tend to fail as black boxes: users route around controls they don't understand, and reviewers don't trust verdicts whose reasoning they can't see. So we treated the explanation as part of the control, not a log line. Alongside the decision, the engine assembles a plain-English justification from the facts that drove it, collapsing overlapping reasons into something that reads the way a human reviewer would write it. That justification surfaces in the portal: the interface where employees see what's approved, blocked, or under review, where a blocked extension becomes a self-service path to request a review rather than a dead-end, and where admins make and record the manual-review calls. The portal is where the whole system stops being a policy engine and becomes something people will actually use instead of work around.\n\nWe run all of this in production today on static analysis: we reason about what an extension declares it can do, not what it does when it runs. We'll talk honestly about where that line holds, and where we're taking it next \u2014 dynamic analysis of runtime behavior.\n\nAttendees should leave able to reason about browser-extension risk in the context of their own environment, not a generic score built for someone else's.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "XHYG7W", "name": "Zach Schrag", "avatar": null, "biography": "Zach is a Software Engineer at Roblox and a recent college graduate. The work behind this talk, governing which browser extensions employees can run against sensitive internal systems, was their first project on the team. This is their first time speaking at a conference, and they're looking forward to sharing what they built with the BSides community.", "public_name": "Zach Schrag", "guid": "e3b6ec71-4dbd-553e-ba56-e61a2a6994c3", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/XHYG7W/"}, {"code": "X87YSZ", "name": "JD Delgado", "avatar": null, "biography": null, "public_name": "JD Delgado", "guid": "a7048007-7846-579a-bc85-dcbfdd544bbb", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/X87YSZ/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/NSWTHN/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/NSWTHN/", "attachments": []}, {"guid": "507eb5e5-3b70-55af-9220-1c72d877ae67", "code": "CFZ9JC", "id": 103137, "logo": null, "date": "2026-10-24T13:15:00-04:00", "start": "13:15", "end": "2026-10-24T13:45:00-04:00", "duration": "00:30", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-103137-attacks-and-defenses-for-multi-agent-ai-systems", "url": "https://pretalx.com/bsidesaugusta-2026/talk/CFZ9JC/", "title": "Attacks and Defenses for Multi-Agent AI Systems", "subtitle": "", "track": "Track 3", "type": "Talk", "language": "en", "abstract": "This talk provides an attacker focused look at how adversaries can exploit these environments through techniques such as prompt injection, RAG poisoning, tool abuse, privilege escalation, and data exfiltration. Using real world attack scenarios, we will explore how individual weaknesses can combine into larger compromise paths that are difficult to detect with traditional security approaches.\nThe session will also discuss practical defensive strategies, including secure agent architecture, permission modeling, monitoring, and risk mitigation techniques. Attendees will gain a clearer understanding of how attackers approach multi-agent AI systems and how organizations can build more resilient AI deployments.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "VVQLQ3", "name": "Moazzam Khan", "avatar": "https://pretalx.com/media/avatars/CU7DDR_tmic8at.webp", "biography": "Moazzam Khan is a security professional at Cisco, where he has spent the past four years working on XDR detections and improving frameworks that enhance detection efficacy. Previously, he worked at IBM across IPS/IDS, SIEM, and threat intelligence, gaining broad experience in core security technologies.He holds both a master\u2019s degree and a doctorate in electrical and computer engineering from the Georgia Institute of Technology. Outside of work, Moazzam enjoys competing in Atlanta tennis league", "public_name": "Moazzam Khan", "guid": "284c72ac-bf7c-5265-bf4d-add68d9bd2e4", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/VVQLQ3/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/CFZ9JC/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/CFZ9JC/", "attachments": []}, {"guid": "e184f449-c5eb-5184-acf5-c77baafc77d2", "code": "LCGH38", "id": 102408, "logo": null, "date": "2026-10-24T13:45:00-04:00", "start": "13:45", "end": "2026-10-24T14:15:00-04:00", "duration": "00:30", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-102408-the-intelligence-driven-advantage-a-practical-guide-to-building-cti-into-your-security-program", "url": "https://pretalx.com/bsidesaugusta-2026/talk/LCGH38/", "title": "The Intelligence-Driven Advantage: A Practical Guide to Building CTI Into Your Security Program", "subtitle": "", "track": "Track 3", "type": "Talk", "language": "en", "abstract": "In many organizations, Cyber Threat Intelligence (CTI) is viewed as a high-cost luxury reserved for mature SOCs. However, when implemented strategically, CTI is one of the most cost-effective force multipliers available to a security leader. By moving beyond simple \"indicator feeds\" and focusing on actionable context, organizations can simultaneously sharpen their technical response and revolutionize their security awareness culture.\n\nThis session explores a pragmatic, low-cost approach to building a CTI-driven security program. We will demonstrate how real-world threat data can be used to enrich the knowledge of security analysts, moving them from reactive alert-clearing to proactive threat hunting. Furthermore, we will show how to transform \"boring\" security awareness training into a dynamic, intelligence-led engagement program that uses current, industry-specific threats to educate employees.\n\nAttendees will learn how to:\n\n- Leverage Low-Cost Intelligence: Utilize OSINT, ISACs, and community sharing to build a high-value program on a budget.\n- Enrich Technical Teams: Use adversary TTPs to prioritize patching, tune detection logic, and build analyst critical thinking skills.\n- Modernize Awareness: Replace generic training templates with real-world intelligence that resonates with employees and turns them into active \"human sensors.\"\n- Speak to the Board: Translate technical threat data into the language of business risk and ROI to gain executive buy-in.\n\nWhether you are a solo practitioner or leading a growing team, this talk provides a blueprint for using intelligence to build a more informed, resilient, and executive-aligned security organization.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "TCDCKS", "name": "Timothy De Block", "avatar": "https://pretalx.com/media/avatars/UAJZCM_XbdgPRN.webp", "biography": "In the vast, uncharted expanse of the digital frontier, I proudly hold the title of Head of Security Exploration at Exploring Information Security\u2014think of me as the cybersecurity equivalent of an intergalactic explorer, but with fewer spaceships and more firewalls. My mission? To boldly go where no security program has gone before, mapping the hidden threats and uncovering innovative solutions to keep the cyberverse safe.\n\nEach day is a new expedition into the unknown, navigating the treacherous waters of ransomware reefs, evading the phishing pirates, and scaling the towering zero-day vulnerabilities. With my trusty toolkit of cutting-edge strategies, creative problem-solving, and an unyielding curiosity, I chart paths through the chaos, transforming the complex into the comprehensible and the chaotic into the secure.\n\nI\u2019m also something of a digital cartographer, translating the vast, enigmatic world of cybersecurity into stories and insights that anyone can understand\u2014because what\u2019s an exploration without sharing tales of the journey? These narratives don\u2019t just demystify cybersecurity; they inspire others to become explorers themselves, fostering a culture of curiosity and vigilance across the organization.\n\nJoin me as I continue the adventure, delving deeper into the labyrinth of cybersecurity. Together, we\u2019ll uncover new ways to make the digital world safer, smarter, and maybe even a little more fun. Grab your compass (or your keyboard)\u2014and let\u2019s go exploring!", "public_name": "Timothy De Block", "guid": "d125c917-bbbf-55ea-be17-3c476bd34673", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/TCDCKS/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/LCGH38/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/LCGH38/", "attachments": []}, {"guid": "59fc6125-c4e1-511c-b728-4c3df787c160", "code": "DE8WC7", "id": 103223, "logo": null, "date": "2026-10-24T14:15:00-04:00", "start": "14:15", "end": "2026-10-24T14:45:00-04:00", "duration": "00:30", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-103223-more-human-than-human-why-the-skills-ai-can-t-replicate-are-the-ones-we-stopped-teaching", "url": "https://pretalx.com/bsidesaugusta-2026/talk/DE8WC7/", "title": "More Human Than Human: Why the Skills AI Can't Replicate Are the Ones We Stopped Teaching", "subtitle": "", "track": "Track 3", "type": "Talk", "language": "en", "abstract": "Who's running your team right now \u2014 you, or the tools you built to help you? Your AI doesn't panic at 2 am. It doesn't burn out, check out, or fail to have the hard conversation. But it also can't lead. And right now, neither can a lot of the humans beside it.\n\nLook around your team. Understaffed. Overextended. Burning through people faster than you can replace them. New talent who've never had a real mentor, never learned to lead under pressure, never had the kind of hard conversation that actually builds judgment \u2014 because nobody had the time or the skills to teach them. This isn't bad luck. It's the accumulated damage of a pandemic that vaporized two years of in-person mentorship, followed by an AI wave that automated enough of the technical work that we convinced ourselves the human layer underneath didn't need investment anymore. We were wrong.\n\nThe data is unambiguous: two-thirds of organizations report critical skills gaps, cybersecurity job satisfaction has dropped 8 points in two years, and hiring managers are now ranking curiosity and problem-solving above technical certifications. The skills disappearing fastest aren't on any exam \u2014 they're judgment under pressure, leading through ambiguity, holding a team together when the playbook runs out. We didn't just lose those skills. We stopped teaching them. In some cases, we selected against them.\n\nThis session is part diagnosis, part field manual for practitioners operating in the real landscape \u2014 not the conference brochure version of it. We'll cover exactly what broke, why it's worse in security than most fields, and how to use AI \u2014 the very thing accelerating the atrophy \u2014 to rebuild the human skills no algorithm can replace. Because at 2 am during a crisis, when the alerts won't stop, and someone in the room is about to break \u2014 something in that room has to be human enough to hold it together. That part doesn't get automated. It gets developed. Or it gets lost.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "UXEBGN", "name": "George Sandford", "avatar": "https://pretalx.com/media/avatars/AR9Z8Y_NJ8ndMZ.webp", "biography": "George Sandford (he/him) is a punk, a security professional, and the founder of Ok2Ask4Help \u2014 an org built on the radical idea that asking for help is a good thing, actually. With 25+ years in the field and a lifetime of lessons from the pit, George speaks on community, career navigation in infosec, and why the hardest problems in security are always about the humans.", "public_name": "George Sandford", "guid": "0c99c221-99d3-5996-adaa-69406425bc77", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/UXEBGN/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/DE8WC7/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/DE8WC7/", "attachments": []}, {"guid": "23fdff87-842f-5c68-ac96-b10956aeb97c", "code": "WJNW7F", "id": 103511, "logo": null, "date": "2026-10-24T14:45:00-04:00", "start": "14:45", "end": "2026-10-24T15:00:00-04:00", "duration": "00:15", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-103511-5-hallway-con", "url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "title": "Hallway Con", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Break", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/WJNW7F/", "attachments": []}, {"guid": "a9749d14-019f-5056-9204-e340c4ae459f", "code": "9WDZH9", "id": 103226, "logo": "https://pretalx.com/media/bsidesaugusta-2026/submissions/9WDZH9/image_dbz1MtS.webp", "date": "2026-10-24T15:00:00-04:00", "start": "15:00", "end": "2026-10-24T16:00:00-04:00", "duration": "01:00", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-103226-pocketful-of-control-planes-attack-chains-against-agentic-ai-and-how-to-kill-them", "url": "https://pretalx.com/bsidesaugusta-2026/talk/9WDZH9/", "title": "Pocketful of Control Planes: Attack Chains Against Agentic AI (and How to Kill Them)", "subtitle": "", "track": "Track 3", "type": "Talk", "language": "en", "abstract": "AI agents don't attack like software, and they don't fail like humans. After years spent breaking traditional systems and now agentic ones I've watched the industry try to bolt old defenses onto a fundamentally new attack surface. It doesn't work, and the attack chains prove it.\nThis talk walks through the attacks actually hitting production AI agents today: privilege escalation through tool chaining, cross-session credential bleed, autonomy drift, and the ways a single compromised agent can pivot faster and further than any human attacker. We'll show why these don't map onto existing frameworks and why treating an agent like a user, or like an API, gets you owned either way.\nFrom there we build the AI Agent Kill Chain: a practical model for where these attacks can actually be interrupted, and what stops them for real architecture, not policy documents. You'll leave with a holistic strategy you can apply Monday morning, not another slide of best practices.\nAlong the way, we'll call out what the AI security market is currently selling versus what it's actually stopping  because right now most of it is marketing wrapped around old tooling, and that gap is exactly where the breaches are happening.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "EWMXKC", "name": "david a girivn", "avatar": null, "biography": "Husband, Father, Hacker, BJJ nerd, Surfer. I have been an offensive security engineer, architect and leader at companies like 1Password, Red Canary, Bit Discovery, Sumo Logic and founder of Assury.", "public_name": "david a girivn", "guid": "51d44dd0-3f34-57ff-ba82-1e7bc0050484", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/EWMXKC/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/9WDZH9/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/9WDZH9/", "attachments": []}, {"guid": "c51d1674-0c15-52db-bc28-5e6f6008c3b7", "code": "EDQGDM", "id": 101997, "logo": "https://pretalx.com/media/bsidesaugusta-2026/submissions/EDQGDM/image_WmGfnvH.webp", "date": "2026-10-24T16:00:00-04:00", "start": "16:00", "end": "2026-10-24T17:00:00-04:00", "duration": "01:00", "room": "Track 3 - Room 2400", "slug": "bsidesaugusta-2026-101997-the-box-is-a-lie-open-world-environments-without-real-machines", "url": "https://pretalx.com/bsidesaugusta-2026/talk/EDQGDM/", "title": "The Box Is a Lie: Open-World Environments Without Real Machines", "subtitle": "", "track": "Track 3", "type": "Talk", "language": "en", "abstract": "The expected path is where a simulated environment feels most convincing. The real test begins when someone treats it like an open world, wanders off the route, and pushes toward what should be the edge. This talk asks whether the illusion can hold when the machine being explored does not actually exist: no provisioned system, no command execution, just believable responses produced in real time. For deception, training, and security research, that kind of sustained exploration is valuable, but traditional labs make it expensive because every believable layer has to be built and maintained, especially for legacy hosts, industrial systems, carrier-grade equipment, or exotic architectures. This talk explores a just-in-time approach that uses guided language models to render the world around the user instead of building it in advance. Through real examples and a demo of the working implementation, I will share design choices, failure modes, and lessons from a system that must generate, remember, and react in real time. The result is a different way to think about simulated environments: not building every possible branch in advance, but creating believable depth at the moment exploration demands it.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "ZYRZSE", "name": "Andrew Stein", "avatar": "https://pretalx.com/media/avatars/PH7DJA_YmoVTHP.webp", "biography": "With 14 years experience in cybersecurity and computer network operations, I bring a mission driven approach to the advancement of cybersecurity priorities. Fueled by a strong drive for personal development and intellectual growth, I continually seek opportunities that push boundaries and expand my capabilities. My career has been enriched by working alongside high-performing teams on impactful, technically demanding projects across diverse domains.\n\nMy experience in cybersecurity includes penetration testing, red team engagements, and developing advanced tools across diverse domains, ranging from military and healthcare, to research and communications. I\u2019ve worked on a broad array of platforms, including enterprise networks, embedded systems, industrial control systems, and defense technologies. These varied efforts have demanded a dynamic mix of skills; from low-level analysis and software development to strategic policy design and clear, executive level communication", "public_name": "Andrew Stein", "guid": "a62c0dac-c6fd-5615-bab2-d21bce4f1ef2", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/ZYRZSE/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/EDQGDM/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/EDQGDM/", "attachments": []}], "Track 4 - Official CTF": [{"guid": "800c4882-1a61-5005-a211-90d6af61e862", "code": "GRFJQM", "id": 103514, "logo": null, "date": "2026-10-24T07:45:00-04:00", "start": "07:45", "end": "2026-10-24T08:30:00-04:00", "duration": "00:45", "room": "Track 4 - Official CTF", "slug": "bsidesaugusta-2026-103514-1-doors-open-check-in", "url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "title": "Doors Open / Check-in", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Grab your badge and freebies, then check out the CTF, exhibitors, lock pick village, and raffle table.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "attachments": []}, {"guid": "21e948c7-659a-5d2c-82f7-9e24c55dbde0", "code": "AN7JAS", "id": 103513, "logo": null, "date": "2026-10-24T08:30:00-04:00", "start": "08:30", "end": "2026-10-24T09:00:00-04:00", "duration": "00:30", "room": "Track 4 - Official CTF", "slug": "bsidesaugusta-2026-103513-1-opening-remarks", "url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "title": "Opening Remarks", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Live in Track 1, Simulcast in Tracks 2-3\nRemarks will be delivered by BSidesAugusta staff and special guests.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "attachments": []}, {"guid": "666b70aa-07e9-5219-8e76-f4c0828f34ed", "code": "S7VVXT", "id": 104233, "logo": null, "date": "2026-10-24T09:00:00-04:00", "start": "09:00", "end": "2026-10-24T10:00:00-04:00", "duration": "01:00", "room": "Track 4 - Official CTF", "slug": "bsidesaugusta-2026-104233-2-keynote-tim-kosiba", "url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "title": "Keynote - Tim Kosiba", "subtitle": "", "track": "Keynote", "type": "Talk", "language": "en", "abstract": "*Live in Track 1, Simulcast in all other tracks/rooms*  \n  \nTim Kosiba, Deputy Director of the National Security Agency, will be our keynote speaker!  \n  \n*Live in Track 1, Simulcast in all other tracks/rooms*", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "C8G88E", "name": "Tim Kosiba", "avatar": "https://pretalx.com/media/avatars/avatar_6hFwavm.webp", "biography": "Tim Kosiba serves as the 21st Deputy Director of the National Security Agency. In this capacity, he works with the NSA\u2019s Director and Executive Director to provide leadership in all areas of the enterprise and to represent NSA\u2019s interests both internally and externally.\n \nPrior to his retirement from NSA in 2021, he served as Deputy Commander of NSA/CSS Georgia \u2014 the Agency\u2019s largest Cryptologic Center.\n\nMr. Kosiba\u2019s NSA career spanned a variety of key leadership roles across NSA and USCYBERCOM, including Special U.S. Liaison Officer in Canberra, Australia; Deputy Director of the NSA/CSS Commercial Solutions Center (NCSC); and Chief of Tailored Access Operations (now Computer Network Operations). Mr. Kosiba\u2019s federal service began in 1989 with the Naval Criminal Investigative Service. After several years spent working in the United Kingdom, Mr. Kosiba was recruited by the FBI in 1996, which brought him to the Washington area. Following the events of 9/11, Tim dedicated his digital forensic knowledge to capturing the perpetrators of the attacks, going on to supervise one of the FBI\u2019s largest digital forensics laboratories. He later joined the Joint Functional Component Command for Network Warfare (JFCC-NW) \u2014 the predecessor of USCYBERCOM \u2014 in 2007, where he held the role of Technical Director.\n\nMr. Kosiba returns to NSA after serving as a cybersecurity leader in the private sector for several years. Throughout his career, he has consistently represented USCYBERCOM and NSA at the White House and forged partnerships to advance cybersecurity policy and priorities. He has received several awards from the law enforcement and the intelligence communities and is a recognized technical leader in the cybersecurity field.", "public_name": "Tim Kosiba", "guid": "2d0d3172-2ac8-5b9b-aaaa-035fcbba9be2", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/C8G88E/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "attachments": []}, {"guid": "a972da86-e8ef-5c02-ba95-76759906ae5d", "code": "ZVZCKB", "id": 104234, "logo": null, "date": "2026-10-24T10:00:00-04:00", "start": "10:00", "end": "2026-10-24T17:00:00-04:00", "duration": "07:00", "room": "Track 4 - Official CTF", "slug": "bsidesaugusta-2026-104234-0-bsidesaugusta-2026-ctf-hosted-by-steelgate", "url": "https://pretalx.com/bsidesaugusta-2026/talk/ZVZCKB/", "title": "BSidesAugusta 2026 CTF hosted by SteelGate", "subtitle": "", "track": "Workshop", "type": "Workshop", "language": "en", "abstract": "This isn't your standard point-and-click exercise. The team at SteelGate LLC have been working overtime to spin up a custom playground of hackable web apps, pwnable services, and brain melting cryptography just waiting to be cracked wide open.  \n\nWe are dropping you and your team into a Jeopardy style gauntlet. Whether you're a seasoned operator hunting for zero-days or just looking to pop your first shell, this environment is designed to test your limits and hopefully learn something new!  \n\nNo advance registration is required. Just show up with your team(or just yourself), pick a handle, and get to hacking. **A Wi-Fi enabled laptop loaded with your hacking suite is required to participate.** We will have a few loaner laptops pre-loaded with Kali Linux for those that need one, available on a first come first served basis.  \n\nCheck out https://sgctf.lol/ for updates.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/ZVZCKB/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/ZVZCKB/", "attachments": []}], "Track 5 - Workshop": [{"guid": "04d17119-5fa5-5ccb-b817-270813c0ce94", "code": "GRFJQM", "id": 103514, "logo": null, "date": "2026-10-24T07:45:00-04:00", "start": "07:45", "end": "2026-10-24T08:30:00-04:00", "duration": "00:45", "room": "Track 5 - Workshop", "slug": "bsidesaugusta-2026-103514-2-doors-open-check-in", "url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "title": "Doors Open / Check-in", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Grab your badge and freebies, then check out the CTF, exhibitors, lock pick village, and raffle table.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/GRFJQM/", "attachments": []}, {"guid": "e5c962ba-2cb0-5081-a3a2-c27898f3c93f", "code": "AN7JAS", "id": 103513, "logo": null, "date": "2026-10-24T08:30:00-04:00", "start": "08:30", "end": "2026-10-24T09:00:00-04:00", "duration": "00:30", "room": "Track 5 - Workshop", "slug": "bsidesaugusta-2026-103513-3-opening-remarks", "url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "title": "Opening Remarks", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Live in Track 1, Simulcast in Tracks 2-3\nRemarks will be delivered by BSidesAugusta staff and special guests.", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/AN7JAS/", "attachments": []}, {"guid": "fb152704-a2cd-52ac-8ebd-e533cf5996b1", "code": "S7VVXT", "id": 104233, "logo": null, "date": "2026-10-24T09:00:00-04:00", "start": "09:00", "end": "2026-10-24T10:00:00-04:00", "duration": "01:00", "room": "Track 5 - Workshop", "slug": "bsidesaugusta-2026-104233-1-keynote-tim-kosiba", "url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "title": "Keynote - Tim Kosiba", "subtitle": "", "track": "Keynote", "type": "Talk", "language": "en", "abstract": "*Live in Track 1, Simulcast in all other tracks/rooms*  \n  \nTim Kosiba, Deputy Director of the National Security Agency, will be our keynote speaker!  \n  \n*Live in Track 1, Simulcast in all other tracks/rooms*", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "C8G88E", "name": "Tim Kosiba", "avatar": "https://pretalx.com/media/avatars/avatar_6hFwavm.webp", "biography": "Tim Kosiba serves as the 21st Deputy Director of the National Security Agency. In this capacity, he works with the NSA\u2019s Director and Executive Director to provide leadership in all areas of the enterprise and to represent NSA\u2019s interests both internally and externally.\n \nPrior to his retirement from NSA in 2021, he served as Deputy Commander of NSA/CSS Georgia \u2014 the Agency\u2019s largest Cryptologic Center.\n\nMr. Kosiba\u2019s NSA career spanned a variety of key leadership roles across NSA and USCYBERCOM, including Special U.S. Liaison Officer in Canberra, Australia; Deputy Director of the NSA/CSS Commercial Solutions Center (NCSC); and Chief of Tailored Access Operations (now Computer Network Operations). Mr. Kosiba\u2019s federal service began in 1989 with the Naval Criminal Investigative Service. After several years spent working in the United Kingdom, Mr. Kosiba was recruited by the FBI in 1996, which brought him to the Washington area. Following the events of 9/11, Tim dedicated his digital forensic knowledge to capturing the perpetrators of the attacks, going on to supervise one of the FBI\u2019s largest digital forensics laboratories. He later joined the Joint Functional Component Command for Network Warfare (JFCC-NW) \u2014 the predecessor of USCYBERCOM \u2014 in 2007, where he held the role of Technical Director.\n\nMr. Kosiba returns to NSA after serving as a cybersecurity leader in the private sector for several years. Throughout his career, he has consistently represented USCYBERCOM and NSA at the White House and forged partnerships to advance cybersecurity policy and priorities. He has received several awards from the law enforcement and the intelligence communities and is a recognized technical leader in the cybersecurity field.", "public_name": "Tim Kosiba", "guid": "2d0d3172-2ac8-5b9b-aaaa-035fcbba9be2", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/C8G88E/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/S7VVXT/", "attachments": []}, {"guid": "8f7ef795-0080-5f1d-8906-b121b2ac4d35", "code": "HTPKD7", "id": 104403, "logo": null, "date": "2026-10-24T10:00:00-04:00", "start": "10:00", "end": "2026-10-24T15:00:00-04:00", "duration": "05:00", "room": "Track 5 - Workshop", "slug": "bsidesaugusta-2026-104403-demystifying-android-assessment-rapid-portable-lab-setup-and-realtime-app-inspection-with-jamboree", "url": "https://pretalx.com/bsidesaugusta-2026/talk/HTPKD7/", "title": "Demystifying Android Assessment: Rapid Portable Lab Setup and RealTime App Inspection with JAMBOREE", "subtitle": "", "track": "Workshop", "type": "Workshop", "language": "en", "abstract": "## Abstract\n\nConfiguring an Android penetration testing environment historically meant wrestling with broken `$PATH` variables, driver conflicts, complex SDK installations, root bypass workarounds, and strict administrative machine policies[cite: 1]. **JAMBOREE** changes all of that[cite: 1]. Designed to make mobile application security accessible to everyone, JAMBOREE is a portable, no-admin installer that provisions a fully functional Android security testing stack in seconds[cite: 1].\n\nIn this 4-hour hands-on workshop, intermediate security professionals will break down the myth that mobile testing requires hours of tedious setup and maintenance[cite: 1]. The first half of the session guides attendees through initializing a portable lab environment\u2014spinning up a rooted Android Virtual Device (AVD) complete with Magisk, Burp Suite interception configurations, Java/Python runtime dependencies, and Objection\u2014all without requiring administrative privileges on their Windows host machines[cite: 1].\n\nIn the second half, participants put the stack to work in real-time[cite: 1]. Attendees will intercept live HTTP/HTTPS traffic, dynamically inspect application runtimes, and analyze off-the-shelf, real-world Android applications[cite: 1]. If time permits, attendees will have the freedom to unpack and inspect target apps of their own choosing under guided supervision[cite: 1].\n\n---\n\n## Prerequisites\n\n* **Knowledge:** Basic understanding of Android architecture and core operating concepts[cite: 1]. Prior experience with device rooting, custom ROMs, or mobile modding is strongly recommended[cite: 1].\n* **Hardware:** A Windows laptop with internet access (no local admin rights required\u2014only WSL or \"virtual machine platform\" enabled on the laptop)[cite: 1].\n\n---\n\n## Key Takeaways\n\n* Spin up a complete, zero-admin Android security testing environment on Windows using JAMBOREE[cite: 1].\n* Configure and operate a rooted Android emulator integrated with Burp Suite and Objection[cite: 1].\n* Master dynamic analysis techniques for real-world Android applications in real-time[cite: 1].\n\n## NOTES: Attendance in this session will limited. First come, first served. We will break for lunch at regular lunch time.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "97C7VS", "name": "Robert McCurdy", "avatar": null, "biography": "Robert is an Offensive Security Specialist and Penetration Testing Lead with 20+ years of experience identifying, exploiting, and remediating vulnerabilities across complex enterprise environments. He is an expert in simulating real-world attack scenarios to strengthen organizational security posture.", "public_name": "Robert McCurdy", "guid": "c05f26f8-698f-5b47-b5ea-a5d6999b0b97", "url": "https://pretalx.com/bsidesaugusta-2026/speaker/97C7VS/"}], "links": [], "feedback_url": "https://pretalx.com/bsidesaugusta-2026/talk/HTPKD7/feedback/", "origin_url": "https://pretalx.com/bsidesaugusta-2026/talk/HTPKD7/", "attachments": []}]}}]}}}