BSidesAugusta

BSidesAugusta

Andrew Case

Andrew Case is the Director of Research at Volexity and has significant experience in incident response handling, digital forensics, and malware analysis. He has conducted numerous large-scale investigations that span enterprises and industries. Case is a core developer of Volatility, the most widely used open-source memory forensics framework, and a co-author of the highly popular and technical forensics analysis book “The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory.” Case has spoken at many industry conferences, including Black Hat, DEF CON, RSA, several BSides events, SecTor, and OMFW.

  • Finding Evil Fast: Windows Memory Triage with Volatility 3
Andrew Gomez

Andrew Gomez is a seasoned Cybersecurity professional with over 9 years of experience in penetration testing, red team engagements, and threat hunting. As a former Captain in the U.S. Army Cyber branch, he specialized in adversary detection and simulation. Currently, Andrew leads offensive security teams as Adversary Simulations Consultant at SpecterOps. Andrew holds a bachelor's degree in Computer Science from the University of North Georgia, a master's degree in Cybersecurity from Georgia Tech, and maintains several industry certifications from Offensive Security, ZeroPoint Security, SANS, and ISC2.

  • Weaponizing Chromium for Offensive Operations
Andrew Stein

With 14 years experience in cybersecurity and computer network operations, I bring a mission driven approach to the advancement of cybersecurity priorities. Fueled by a strong drive for personal development and intellectual growth, I continually seek opportunities that push boundaries and expand my capabilities. My career has been enriched by working alongside high-performing teams on impactful, technically demanding projects across diverse domains.

My experience in cybersecurity includes penetration testing, red team engagements, and developing advanced tools across diverse domains, ranging from military and healthcare, to research and communications. I’ve worked on a broad array of platforms, including enterprise networks, embedded systems, industrial control systems, and defense technologies. These varied efforts have demanded a dynamic mix of skills; from low-level analysis and software development to strategic policy design and clear, executive level communication

  • The Box Is a Lie: Open-World Environments Without Real Machines
Caviness

D. Caviness is a cybersecurity educator, mentor, and workforce pipeline builder based in Augusta, Georgia, where she teaches within the Cyber Academy of Excellence. She specializes in preparing high school students for real-world cybersecurity careers through industry-aligned instruction, hands-on labs, and certification pathways such as CompTIA Security+.
With experience coaching CyberPatriot and CTF teams as well as guiding students toward internships, scholarships, and early career opportunities, Caviness brings a unique perspective at the intersection of education and industry. Her work focuses on bridging the gap between classroom learning and operational readiness helping students develop not only technical knowledge, but also the problem-solving, communication, and critical thinking skills required in modern security operations centers (SOCs).
Caviness is particularly passionate about expanding access to cybersecurity education, supporting diverse learners, and redefining what “entry-level talent” looks like in today’s workforce. Through her programs, she has helped students build professional portfolios, earn certifications, and take their first steps into the cybersecurity field.
She brings to the stage a practical, inside view of the emerging talent pipeline—offering insights that help organizations better identify, develop, and integrate the next generation of cybersecurity professionals

  • Why Your Future SOC Analyst Is Still in High School: Fixing the Cyber Talent Pipeline
david a girivn

Husband, Father, Hacker, BJJ nerd, Surfer. I have been an offensive security engineer, architect and leader at companies like 1Password, Red Canary, Bit Discovery, Sumo Logic and founder of Assury.

  • Pocketful of Control Planes: Attack Chains Against Agentic AI (and How to Kill Them)
David Branscome

David is a Global Partner Solutions Architect for Security, Compliance and Identity at Microsoft. In this role, David is responsible for training and supporting Microsoft partners on the latest security compliance and identity solutions, including Microsoft 365, Azure and Windows.
David has been with Microsoft for 16+ years in a variety of roles, from Microsoft Consulting Services to Premier Field Engineer and most recently in the partner support organization.
David is a certification junkie and holds numerous security certifications, including CISSP, GCWN, GCED, GCDA, GMOB, GCIH, GISP, GSEC, GSOC, GCFA, GDAT, GCPN, GCFR, GCTD, GRTP and CISSP.

  • They Didn’t Build It, They Didn’t Pay for It, But They’re Running It Right Now - In YOUR Environment
David J. Bianco

David is a Principal Cybersecurity Research Engineer with Cisco Talos, where he studies practical and effective uses of AI for defensive security operations. He is also a SANS Certified Instructor, where he teaches network forensics. David has nearly 30 years of experience in the information security field, primarily in incident detection and response, threat hunting, and Cyber Threat Intelligence (CTI). He is the creator of the Pyramid of Pain and lead author of the PEAK threat hunting framework. Really, he just wants to make security better for everyone. You can follow David on Bluesky as @DavidJBianco.bsky.social or on Mastodon as @DavidJBianco@infosec.exchange.

  • Hold My Coffee, I’m Building a Security Tool": Security Without Gatekeepers in an AI-First World
Doug Burks

Doug Burks started Security Onion in 2008 to provide a comprehensive platform to help folks peel back the layers of their enterprise and make their adversaries cry. Today, Security Onion has over 2,500,000 downloads and is being used by organizations around the world for threat hunting, enterprise security monitoring, and log management. In 2014, Doug started Security Onion Solutions LLC to help those organizations by providing training, professional services, and hardware appliances. Doug is a CEO, public speaker, teacher, former president of the Greater Augusta ISSA, and co-founder of BSides Augusta, but what he really likes the most is catching bad guys.

  • SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!
Eric Logan

Eric M. Logan brings over 26 years of dedicated experience in IT and cybersecurity across K-12 and higher education environments. Currently serving as Director of Information & Network Security for DeKalb County School District, Eric leads the district's cybersecurity transformation, having built their first dedicated security team and launched innovative programs like Cyber Champions, which empowers students to become peer leaders in digital safety.

His career spans prestigious institutions including Georgia Tech Research Institute, where he served as Cybersecurity Operations Manager and later as Governance, Risk & Compliance Manager, and Emory University, where he provided technical expertise to researchers and managed campus-wide technology systems. Eric's unique perspective combines hands-on technical expertise with strategic leadership and a genuine passion for education.

Based in Thomaston, Georgia, Eric is deeply involved in professional organizations including ISSA, ISACA, and FBI InfraGard, and believes in building bridges between technical expertise and practical application in educational settings.

  • The Sector Everyone Ignores: Why K-12 Is Critical Infrastructure and What We Can Learn From It
George Sandford

George Sandford (he/him) is a punk, a security professional, and the founder of Ok2Ask4Help — an org built on the radical idea that asking for help is a good thing, actually. With 25+ years in the field and a lifetime of lessons from the pit, George speaks on community, career navigation in infosec, and why the hardest problems in security are always about the humans.

  • More Human Than Human: Why the Skills AI Can't Replicate Are the Ones We Stopped Teaching
Jared Hrabak

Jared Hrabak is a cybersecurity engineer and U.S. Army Reserve officer with over 16 years of service, including time on a Cyber Protection Team and participation in Cyber Officer selection boards. By day, he works in cybersecurity consulting, but his real interest is understanding how systems work and fail.

Jared’s background spans DoD contracting, large-scale security operations supporting financial environments, and hands-on offensive security training. He holds multiple certifications including CISSP, GPEN, GWAPT, and GCIH.

He is a recipient of the DoD Vulnerability Disclosure Program (VDP) Researcher of the Month and Researcher of the Year awards. His work focuses on identifying real-world access control failures through curiosity-driven analysis rather than full-time bug hunting.

  • HOW I HACKED THE DOD (by accident) AND SAVED THEM BILLIONS
JD Delgado
  • Know Thy Extensions: Governing the Browser Attack Surface in the Enterprise
Mackenize Morris

Mackenize Morris is a Principal Industrial Consultant at the industrial cybersecurity company Dragos, Inc. where he assists the professional services teams in conducting network and vulnerability assessments.

Prior to joining Dragos, Mackenize worked as a process controls engineer and system architect for a DOE contractor. In addition to his responsibilities he became the system administrator of the DCS system until fully switching over to an ICS cybersecurity position within the DOE complex.

Mackenize received his B.S. in Chemical Engineering and MBA from the University of South Carolina and his Masters in Information Security Engineering from the SANS Technology Institute. He currently holds the following certifications: GCPM, GCIP, GSEC, GDSA, GREM, GCCC, GRID, GCIA, GISCP, GPEN, GMON, GCIH, GWAPT and CISSP.

Mackenize lives in Aiken, South Carolina down the street from his brother’s horse farm where he keeps his horse, Riley. Besides riding horses, Mackenize fences as part of the Augusta Fencers Club and teaches at the University of South Carolina - Aiken where he is a fan of the esports teams.

Mackenize’s name is pronounced like Mackenzie; the IZE spelling was a result of a spelling error on his birth certificate.

  • Evolutions in Critical Infrastructure Attacks
Mark Baggett

Mark Baggett is a SANS Faculty Fellow, cybersecurity leader, and author of SEC573: AI-Powered Security Automation and SEC673: Advanced Information Security Automation with Python. As CTO of the SANS Internet Storm Center and a former Technical Advisor to the U.S. Department of Defense, he brings more than three decades of hands-on experience in threat detection, incident response, penetration testing, and defensive automation.

Mark specializes in helping security professionals turn Python, AI, and automation into practical tools that strengthen real-world defense. The 15th person worldwide to earn the GIAC Security Expert (GSE) certification, he is also an accomplished open-source developer, educator, and community leader. Known for making complex technical topics approachable, Mark equips defenders of every coding level to build capabilities they can use immediately.

  • Hands, Eyes & Memory: - A Live Progressive Demo From Stateless Chatbot to Fully Agentic AI
Matt Barnett

Matt Barnett is a cybersecurity executive and incident response leader who has worked on high-stakes ransomware incidents affecting organizations across multiple industries. He is frequently seen on NBC as a go to resource in Philadelphia for cyber events. As a founder of SEVN-X, he specializes in adversary-focused security, digital forensics, and incident response, including direct involvement in ransomware negotiations where business risk, legal exposure, and operational survival intersect. Matt brings a rare perspective from the front lines—combining technical depth, real-world negotiation experience, and an understanding of how threat actors think, operate, and exploit pressure. His talks focus on what actually happens during ransomware events, what organizations get wrong, and how negotiation decisions shape outcomes long after the ransom note appears.

  • Dealing with Shadows
Moazzam Khan

Moazzam Khan is a security professional at Cisco, where he has spent the past four years working on XDR detections and improving frameworks that enhance detection efficacy. Previously, he worked at IBM across IPS/IDS, SIEM, and threat intelligence, gaining broad experience in core security technologies.He holds both a master’s degree and a doctorate in electrical and computer engineering from the Georgia Institute of Technology. Outside of work, Moazzam enjoys competing in Atlanta tennis league

  • Attacks and Defenses for Multi-Agent AI Systems
Paul Melson

Paul Melson has been working in computer security since 2001, and has spent the majority of the last two decades to detecting and disrupting cybercriminals. He works on the Cybersecurity team at Capital One and is also the author and operator of the ScumBots project.

  • Machine Learning for Hunting Malware
Robert McCurdy

Robert is an Offensive Security Specialist and Penetration Testing Lead with 20+ years of experience identifying, exploiting, and remediating vulnerabilities across complex enterprise environments. He is an expert in simulating real-world attack scenarios to strengthen organizational security posture.

  • Demystifying Android Assessment: Rapid Portable Lab Setup and RealTime App Inspection with JAMBOREE
Scott Hawk
  • What’s an agentic CtF? Playing mind games with an agent
Steven Jung

Steven Jung is Co-Founder and CEO of CodeIntegrity, an agent security company. He works with enterprise security teams putting AI agents into production, with hands on experience in prompt injection exploits, agent takeover techniques, and the controls that stop them: least privilege, egress control, and audit logging. He spends most of his time watching AI agents get tricked into doing things nobody authorized, and teaching teams how to stop it.

  • Your AI Agent Takes Orders From Strangers: Prompt Injection and the Path to Governing Agents
Suril Desai

Suril is VP Engineering and Security SME at Acalvio Technologies. Suril has deep domain expertise in cybersecurity and Computer Science. Suril has spoken at numerous security conferences and believes in sharing his knowledge and learning from the interactions.

  • What’s an agentic CtF? Playing mind games with an agent
Tamara Chacon

Tamara is a Senior Security Strategist with Cisco Talos. Where she focuses on preaching security fundamentals, good cyber hygiene and the team's research. She holds a degree in Criminal Justice and Anthropology from the University of Northern Colorado and a Cybersecurity Career Studies Cert. With a passion for bridging human behavior and digital defense, she brings a unique perspective to the cybersecurity world. She is a founding member of the Splunk SURGe Team.

  • Hold My Coffee, I’m Building a Security Tool": Security Without Gatekeepers in an AI-First World
Tim Crothers

Tim Crothers serves as a board advisor to Acalvio and several other startups, and is hard at work on his next book. Prior roles include SVP, Global Cyber Defense for United Health Group, a Fortune 4 company, and CSO for Mandiant, where he defended both Mandiant and Google Cloud against some of the world's most sophisticated adversaries. With over 40 years in the technology sector and a security focus since 1994, Tim has broad expertise with a particular passion for cyber threat intelligence, reverse engineering, incident response, and breach investigation. In addition to his leadership and technical accomplishments, Tim is a prolific author and dynamic speaker. Tim has authored 17 books and presents frequently at some of the world's largest cybersecurity conferences. Above all, Tim is dedicated to finding and developing talent, driven by his belief that each of us has a responsibility to leave the world a little better than we found it.

  • Ai-pocalypse
Tim Kosiba

Tim Kosiba serves as the 21st Deputy Director of the National Security Agency. In this capacity, he works with the NSA’s Director and Executive Director to provide leadership in all areas of the enterprise and to represent NSA’s interests both internally and externally.

Prior to his retirement from NSA in 2021, he served as Deputy Commander of NSA/CSS Georgia — the Agency’s largest Cryptologic Center.

Mr. Kosiba’s NSA career spanned a variety of key leadership roles across NSA and USCYBERCOM, including Special U.S. Liaison Officer in Canberra, Australia; Deputy Director of the NSA/CSS Commercial Solutions Center (NCSC); and Chief of Tailored Access Operations (now Computer Network Operations). Mr. Kosiba’s federal service began in 1989 with the Naval Criminal Investigative Service. After several years spent working in the United Kingdom, Mr. Kosiba was recruited by the FBI in 1996, which brought him to the Washington area. Following the events of 9/11, Tim dedicated his digital forensic knowledge to capturing the perpetrators of the attacks, going on to supervise one of the FBI’s largest digital forensics laboratories. He later joined the Joint Functional Component Command for Network Warfare (JFCC-NW) — the predecessor of USCYBERCOM — in 2007, where he held the role of Technical Director.

Mr. Kosiba returns to NSA after serving as a cybersecurity leader in the private sector for several years. Throughout his career, he has consistently represented USCYBERCOM and NSA at the White House and forged partnerships to advance cybersecurity policy and priorities. He has received several awards from the law enforcement and the intelligence communities and is a recognized technical leader in the cybersecurity field.

  • Keynote - Tim Kosiba
  • Keynote - Tim Kosiba
  • Keynote - Tim Kosiba
  • Keynote - Tim Kosiba
  • Keynote - Tim Kosiba
Timothy De Block

In the vast, uncharted expanse of the digital frontier, I proudly hold the title of Head of Security Exploration at Exploring Information Security—think of me as the cybersecurity equivalent of an intergalactic explorer, but with fewer spaceships and more firewalls. My mission? To boldly go where no security program has gone before, mapping the hidden threats and uncovering innovative solutions to keep the cyberverse safe.

Each day is a new expedition into the unknown, navigating the treacherous waters of ransomware reefs, evading the phishing pirates, and scaling the towering zero-day vulnerabilities. With my trusty toolkit of cutting-edge strategies, creative problem-solving, and an unyielding curiosity, I chart paths through the chaos, transforming the complex into the comprehensible and the chaotic into the secure.

I’m also something of a digital cartographer, translating the vast, enigmatic world of cybersecurity into stories and insights that anyone can understand—because what’s an exploration without sharing tales of the journey? These narratives don’t just demystify cybersecurity; they inspire others to become explorers themselves, fostering a culture of curiosity and vigilance across the organization.

Join me as I continue the adventure, delving deeper into the labyrinth of cybersecurity. Together, we’ll uncover new ways to make the digital world safer, smarter, and maybe even a little more fun. Grab your compass (or your keyboard)—and let’s go exploring!

  • The Intelligence-Driven Advantage: A Practical Guide to Building CTI Into Your Security Program
Zach Schrag

Zach is a Software Engineer at Roblox and a recent college graduate. The work behind this talk, governing which browser extensions employees can run against sensitive internal systems, was their first project on the team. This is their first time speaking at a conference, and they're looking forward to sharing what they built with the BSides community.

  • Know Thy Extensions: Governing the Browser Attack Surface in the Enterprise