<?xml version='1.0' encoding='utf-8' ?>
<iCalendar xmlns:pentabarf='http://pentabarf.org' xmlns:xCal='urn:ietf:params:xml:ns:xcal'>
    <vcalendar>
        <version>2.0</version>
        <prodid>-//Pentabarf//Schedule//EN</prodid>
        <x-wr-caldesc></x-wr-caldesc>
        <x-wr-calname></x-wr-calname>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>H9HAEZ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-H9HAEZ</pentabarf:event-slug>
            <pentabarf:title>Sbud: infovis in infosec</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T110000</dtstart>
            <dtend>20231016T113000</dtend>
            <duration>003000</duration>
            <summary>Sbud: infovis in infosec</summary>
            <description>Have you ever taken the screenshot of a hex viewer or a text editor, then you wanted to add annotations, highlights, descriptions?
Ever tried to update someone else&apos;s visualisation?

Sbud is a set of visualisation renderers driven by text.
Offline, no framework, no dependency. Themes and fonts are supported. MIT licence.
Save as SVG, PDF, PNG... Text is kept, still selectable, still updatable.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/H9HAEZ/</url>
            <location>Salle Europe</location>
            
            <attendee>Ange Albertini</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>XZPCVE@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-XZPCVE</pentabarf:event-slug>
            <pentabarf:title>Detecting VPNs/proxies by analyzing their attack patterns over time</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T113000</dtstart>
            <dtend>20231016T115000</dtend>
            <duration>002000</duration>
            <summary>Detecting VPNs/proxies by analyzing their attack patterns over time</summary>
            <description>Crowdsec is an open source intrusion detection system which uses a crowdsourcing approach to collect threat intelligence from the community and to return a distilled version of the resulting data as an ip blocklist that is relevant and up to date to the community. 
Recently, we have started improving our threat intelligence by enriching it with various additional information on malicious ips. One of these projects involved setting up a machine learning system that detects whether a given attacker is using an anonymization service such as a proxy or a vpn. In this talk we show:
* How we define attack patterns for each ip
* How we monitor the evolution of attack patterns over time and how we can use this to detect anonymization.  

We also present other findings that we discovered on the way and hope that our results could help threat researchers even if they don&apos;t have access to data as exhaustive as the crowdsec CTI.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/XZPCVE/</url>
            <location>Salle Europe</location>
            
            <attendee>Emanuel Seemann</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>PUXBQ8@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-PUXBQ8</pentabarf:event-slug>
            <pentabarf:title>SBOMs: are they a threat or a menace?</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T115000</dtstart>
            <dtend>20231016T122000</dtend>
            <duration>003000</duration>
            <summary>SBOMs: are they a threat or a menace?</summary>
            <description>SBOMs are discussed everywhere. What are they? How do you create one (using open source tools of course)? What do you do with one if you have it? How to break through the hype and ensure that they contain useful data? How can you use these for red team and blue team ops support? 

I am a co-founder of SPDX, an active contributor to CycloneDX and the creator of Package URL (PURL) which is a standard to identify packages in these SBOMS as well VEX (Vulnerability Exploitability Exchange) specs such as CSAF and OpenVex. PURL are also used by many SCA tools and vulnerability databases as the key id to search for package vulnerabilities.

I am unwillingly part of the hype around SBOM, yet I am also uniquely positioned to deliver a constructive critique and help you cut through this hype so you get the essential inside information to decide what to do with SBOMs (or do nothing!)</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/PUXBQ8/</url>
            <location>Salle Europe</location>
            
            <attendee>Philippe Ombredanne</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>RMTECU@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-RMTECU</pentabarf:event-slug>
            <pentabarf:title>Token Smart Contract Analyzer</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T140000</dtstart>
            <dtend>20231016T140500</dtend>
            <duration>000500</duration>
            <summary>Token Smart Contract Analyzer</summary>
            <description>Hi!
We have received your proposal &quot;Token Smart Contract Analyzer&quot; to hack.lu. We will notify you once we have had time to consider all proposals, but until then you can see and edit your proposal at https://pretalx.com/hack-lu-2023/me/submissions/NN9AHG/.
Please do not hesitate to contact us if you have any questions!
The hack.lu organisers
________________________________________
Full proposal content:
Proposal title: Token Smart Contract Analyzer
Abstract: A Tool to Detect Fraudulent Token Contracts on Ethereum Blockchain
Description: Smart contracts have demonstrated new ways to manage and trade digital assets, conduct financial transactions, and transform business processes. Several concepts have emerged to enable investors to own or trade digital assets. Trading platforms relying entirely on decentralized, known as decentralized exchanges, allow unrestricted financial transactions to exchange digital assets. Beyond the opportunities offered, using the decentralized environment remains complex to understand by most of its users, consequently giving adversaries opportunities to benefit from investors based on scamming schemes. The cryptocurrency market is damaged by malicious actors that aim to drain investor funds via scamming token smart contracts. This research paper initially highlights related problems with fraudulent token contracts. Further, it proposes a solution for identifying several fraudulent schemas in the crypto ecosystem via a dynamic algorithmic solution supported by the SC Analyzer tool based on real-time data.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/RMTECU/</url>
            <location>Salle Europe</location>
            
            <attendee>TGrandjean</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7WUYKM@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-7WUYKM</pentabarf:event-slug>
            <pentabarf:title>Cloaking malicious web content delivery</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T140500</dtstart>
            <dtend>20231016T141000</dtend>
            <duration>000500</duration>
            <summary>Cloaking malicious web content delivery</summary>
            <description>Very short introduction into browser fingerprinting, cloaking and CTI related to it.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/7WUYKM/</url>
            <location>Salle Europe</location>
            
            <attendee>Jeroen Pinoy</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MNCC3H@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MNCC3H</pentabarf:event-slug>
            <pentabarf:title>The composition analysis of binary Java, ELF, Go, and JavaScript apps</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T141000</dtstart>
            <dtend>20231016T141500</dtend>
            <duration>000500</duration>
            <summary>The composition analysis of binary Java, ELF, Go, and JavaScript apps</summary>
            <description>I routinely analyze large app and system binaries to find out what they are made of and if they contain unknown software or vulnerable code.

I will highlight some useful FOSS tools such Lief, BANG, ScanCode.io, Elf inspector tools to support this short talk.

Join me to discover how you can determine what software goes into a binary to get back to its corresponding source (in a white box context).</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/MNCC3H/</url>
            <location>Salle Europe</location>
            
            <attendee>Philippe Ombredanne</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>XREWCZ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-XREWCZ</pentabarf:event-slug>
            <pentabarf:title>Case Management</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T141500</dtstart>
            <dtend>20231016T142000</dtend>
            <duration>000500</duration>
            <summary>Case Management</summary>
            <description>A flexible case management that can be used for forensic, threat intel... Work with different organization, follow tasks of your team, make report...</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/XREWCZ/</url>
            <location>Salle Europe</location>
            
            <attendee>Cruciani David</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JBPW3R@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JBPW3R</pentabarf:event-slug>
            <pentabarf:title>GeoOpen and mmdb-server: A Comprehensive Open Source Solution for IP Address Geolocation</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T142000</dtstart>
            <dtend>20231016T142500</dtend>
            <duration>000500</duration>
            <summary>GeoOpen and mmdb-server: A Comprehensive Open Source Solution for IP Address Geolocation</summary>
            <description>https://hdoc.csirt-tooling.org/OgdCNqHYQpukzRKN0T2hmg?both</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/JBPW3R/</url>
            <location>Salle Europe</location>
            
            <attendee>Alexandre Dulaunoy</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>YL9AAY@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-YL9AAY</pentabarf:event-slug>
            <pentabarf:title>CTI is dead, long live CTI!</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T143000</dtstart>
            <dtend>20231016T150000</dtend>
            <duration>003000</duration>
            <summary>CTI is dead, long live CTI!</summary>
            <description>The Cyber Threat Intelligence (CTI) remains a bit of a buzzword. What a CTI team does, for who it does it and how, are still covered in mystery or a maintained artistic blur.

Often CTI is regarded as retrieving threat reports, digesting them or researching a malware or infrastructure to make a report. Other teams then retrieve, digest, extract IOCs and or TTPs and then implement mitigations or write another internal presentation. While this may help protect from certain attacks, many reports do not directly concern our constituencies. And more to the point, the reports may not be timely when an incident is being handled by a CSIRT.

A complementary approach, could be to identify, collect and analyze the data that we already &quot;have&quot; but sometimes tend to forget. We will present a more constituency centric approach and some of the challenges we face as an MSSP. 

By combining these complementary approaches, an outward looking and inward knowing, we could revive CTI in a more long term, less buzzword way, and more importantly better protect our constituency.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/YL9AAY/</url>
            <location>Salle Europe</location>
            
            <attendee>David</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>WVZVZH@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-WVZVZH</pentabarf:event-slug>
            <pentabarf:title>FOSStering an ISAC: Enabling a Community with Open-Source Tools</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T150000</dtstart>
            <dtend>20231016T153000</dtend>
            <duration>003000</duration>
            <summary>FOSStering an ISAC: Enabling a Community with Open-Source Tools</summary>
            <description>&#8226; Brief overview of MISP architecture
&#8226; RH-ISAC custom taxonomy
    o Categorizing intelligence:
        &#9642; Source where intelligence was shared
        &#9642; Sector of member who shared intelligence
        &#9642; Threat type (e.g., ATO, info stealer, credential harvester, etc.)
&#8226; RH-ISAC custom galaxy 
    o Threat actor profiles/clusters
        &#9642; Prioritizing threat actors
        &#9642; Data sources
        &#9642; Custom cluster elements
&#8226; Intel Sharing and Normalization
    o mail2misp
    o Sharing templates
    o MISP objects
    o PDF/video documentation resources
&#8226; Enriching and vetting attributes
    o Automating enrichment with PyOTI
    o Enrichment services
    o Enrichment tags
    o Vetted attributes &#8220;feed&#8221;
&#8226; Intel Interoperability
    o RH-ISAC developed integrations
    o Existing 3rd party integrations
    o MISP Sync
&#8226; What&#8217;s next!</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/WVZVZH/</url>
            <location>Salle Europe</location>
            
            <attendee>JJ Josing</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MGMYZA@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MGMYZA</pentabarf:event-slug>
            <pentabarf:title>Kunai: your new Threat Hunting tool for Linux</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T153000</dtstart>
            <dtend>20231016T160000</dtend>
            <duration>003000</duration>
            <summary>Kunai: your new Threat Hunting tool for Linux</summary>
            <description>This presentation aims to introduce the community to Kunai, a new Threat Hunting tool designed specifically for Linux Systems.

I&apos;ll start by discussing the project&apos;s origin and my motivations for initiating it, followed by an exploration of the tool&apos;s inner workings and implementation details. This section will conclude with an overview of the challenges encountered during the tool&apos;s development.

Next, I will highlight its key features, emphasizing how it differs from existing tools. The latter part of this section will explore practical Threat Hunting scenarios that can be realized with the tool.

In conclusion, I will summarize the key takeaways from this tool and share our future plans for its development.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/MGMYZA/</url>
            <location>Salle Europe</location>
            
            <attendee>Quentin JEROME</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>L7UC9M@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-L7UC9M</pentabarf:event-slug>
            <pentabarf:title>Why does the CTI industry struggle with communicating uncertainties?</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T160000</dtstart>
            <dtend>20231016T162000</dtend>
            <duration>002000</duration>
            <summary>Why does the CTI industry struggle with communicating uncertainties?</summary>
            <description>This talk will present a comparative study of how security vendors utilize Words of Estimative Probability (WEP) and confidence levels, which are tools used in intelligence analysis to convey uncertainties. It aims to shed light on the varying approaches used in the industry.

While the talk will not exhaustively explain why some vendors struggle in this area at an industry level, it will emphasize that working with uncertainties and effectively communicating them can also be challenging for individual analysts. 

WEP and confidence levels might appear difficult to grasp. To bridge this gap, the talk will translate these abstract concepts into language that resonates with the technical audience. It will provide practical guidelines for utilizing WEP and offer specific steps to differentiate terms such as &quot;likely&quot; and &quot;highly likely.&quot; Additionally, the presentation will explore various approaches to communicating uncertainties, highlighting their respective advantages and disadvantages for different types of threat report consumers.

Some logical approaches that effectively combine WEP and confidence levels may be complex for untrained readers to comprehend. However, alternative methods that deviate from standard intelligence analysis tradecraft could be viable in certain cases. Regardless of the chosen approach, transparency and consistency are essential considerations for any CTI team, including security vendors.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/L7UC9M/</url>
            <location>Salle Europe</location>
            
            <attendee>Ondra Rojcik</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>YV8H3B@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-YV8H3B</pentabarf:event-slug>
            <pentabarf:title>Ensuring IoC quality at CERT-FR</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T163000</dtstart>
            <dtend>20231016T170000</dtend>
            <duration>003000</duration>
            <summary>Ensuring IoC quality at CERT-FR</summary>
            <description>Thanks to its central position in the French cybersecurity ecosystem, CERT-FR has access to a lot of information and thus, a lot of IoCs. For internal usage and further sharing, these IoCs must reach a certain level of quality and remain usable over time. In order to manage this, CERT-FR provides its analysts with a library and a set of Python scripts. Analysts have to use these scripts in order to push data into the production MISP instance.   

The tools are based on an internal library, itself based on pymisp.  It provides a set of functions, superseding pymisp&#8217;s ones, to create, update and delete attributes and tags in MISP. It does so both to apply more verification in order to guarantee their quality and to ensure that the input of the different types of IoCs will be consistent over time. This consistency is also essential for further automated exploitation by other internal tools. Thus, the scripts used by the analysts ensure that the data in IoC is normalized, following CERT-FR standards and that the tools consuming it will have access to the necessary data. It also ensures that the IoC lifecycle is correctly followed limiting analyst errors.  

The presentation will first cover what we call a quality IoC at CERT-FR. Then we will detail the normalization we apply to the data and the rules that need to be applied on IoCs before they can be pushed into MISP and why we need to apply these rules.   

Finally the internal library will be presented, to show some of the provided functions. Analysts can rely on these functions in their own tools or they can use the set of tools provided with the library to push their IoC into MISP. This set of tools will be also presented, in order to show how the normalization and rules are applied at CERT-FR. We will also give a brief feedback on how we want to improve the tools, following (constructive) criticism we have from analysts and other works we are currently carrying out regarding normalization and storing of technical IoCs.  

In a nutshell, this presentation will provide a feedback on the challenges encountered by CERT-FR on its IoCs usage and the solutions developed to keep the base as clean as possible over time.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/YV8H3B/</url>
            <location>Salle Europe</location>
            
            <attendee>Barrault Victor</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>KTDHFU@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-KTDHFU</pentabarf:event-slug>
            <pentabarf:title>MISP updates</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T170000</dtstart>
            <dtend>20231016T173000</dtend>
            <duration>003000</duration>
            <summary>MISP updates</summary>
            <description>Another year has passed since the last CTI Summit, with MISP having gone through a long list of changes and extensions - this talk aims to summarise what has happened since October 2022 as well as giving a glimpse into what the core team has in store for the community in the near future.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/KTDHFU/</url>
            <location>Salle Europe</location>
            
            <attendee>Andras Iklody</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>RGZCBL@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-RGZCBL</pentabarf:event-slug>
            <pentabarf:title>Malware AV evasion tricks. Cryptography in malware</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231016T173000</dtstart>
            <dtend>20231016T175000</dtend>
            <duration>002000</duration>
            <summary>Malware AV evasion tricks. Cryptography in malware</summary>
            <description>Practical implementation and simulation of APT attack with using non popular cryptography algorithms. Using Hemming and
Reed-Solomon codes to check integrity of the payload and C2 connections</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/RGZCBL/</url>
            <location>Salle Europe</location>
            
            <attendee>cocomelonc</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>CHCVTP@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-CHCVTP</pentabarf:event-slug>
            <pentabarf:title>Cratos - Use your bloody indicators</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T090000</dtstart>
            <dtend>20231017T092500</dtend>
            <duration>002500</duration>
            <summary>Cratos - Use your bloody indicators</summary>
            <description>In this talk we will walk through some use cases and releasing and open-source project Cratos an FastAPI application that allows integrating your MISP data into your security infrastructure, minimizing the risk of leaking your contextual data while still automating the tasks, and also allowing to cache data.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/CHCVTP/</url>
            <location>Salle Europe</location>
            
            <attendee>Dennis Rand</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDEXYV@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDEXYV</pentabarf:event-slug>
            <pentabarf:title>IPFS Unveiled: Exploring Data Collection, Analysis, and Security</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T093000</dtstart>
            <dtend>20231017T100000</dtend>
            <duration>003000</duration>
            <summary>IPFS Unveiled: Exploring Data Collection, Analysis, and Security</summary>
            <description>Join us for an in-depth exploration of IPFS, where we&apos;ll uncover its inner workings and dive into exclusive data collection and analysis techniques specific to this decentralized network. We&apos;ll also take a quick tour of IPFS&apos;s wide range of applications, including both everyday uses and those that may involve questionable or risky activities, giving you a comprehensive understanding of its capabilities.
In addition, we will try to help you fortify your organization against any potential misuse or harm facilitated through IPFS. We will provide practical tips and tricks during our talk, empowering you to strengthen your security measures.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDEXYV/</url>
            <location>Salle Europe</location>
            
            <attendee>Patrick Ventuzelo</attendee>
            
            <attendee>Tanguy Laucournet</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>QWNF3T@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-QWNF3T</pentabarf:event-slug>
            <pentabarf:title>He is everywhere: A tale of Lazarus and his family</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T101500</dtstart>
            <dtend>20231017T104500</dtend>
            <duration>003000</duration>
            <summary>He is everywhere: A tale of Lazarus and his family</summary>
            <description>Discuss the threat groups behind North Korea and summarize their relationships, which cluster as Lazarus, Kimsuky, ScarCruft, BlueNoroff, Andariel, and Konni. We&apos;ll also look at the incidents they&apos;ve been responsible for since 2009 and identify their favorite Techniques.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/QWNF3T/</url>
            <location>Salle Europe</location>
            
            <attendee>JeongGak Lyu, @lazarusholic</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>8R8JUA@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-8R8JUA</pentabarf:event-slug>
            <pentabarf:title>Cerebrate - learning to run</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T104500</dtstart>
            <dtend>20231017T110000</dtend>
            <duration>001500</duration>
            <summary>Cerebrate - learning to run</summary>
            <description>Having undertaken a journey of transformation and becoming operational in most aspects it was originally intended, this talk aims to walk participants through the changes as well as giving some insights into how Cerebrate is changing how we manage our communities.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/8R8JUA/</url>
            <location>Salle Europe</location>
            
            <attendee>Andras Iklody</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>SMDFBC@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-SMDFBC</pentabarf:event-slug>
            <pentabarf:title>Digital Tug of War: Unraveling the Cyber Battle Between Ukraine and Russia</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T110000</dtstart>
            <dtend>20231017T113000</dtend>
            <duration>003000</duration>
            <summary>Digital Tug of War: Unraveling the Cyber Battle Between Ukraine and Russia</summary>
            <description>Embark on a fascinating journey to uncover the multifaceted narrative of the protracted conflict between Ukraine and Russia that has captivated the world for over a year. This presentation aims to provide a comprehensive summary of the significant events, key moments and complex dynamics that have shaped this ongoing geopolitical saga.

Amidst this turbulent backdrop, the realm of cyber threat intelligence has become a critical battleground, adding an unprecedented layer of complexity to an already volatile situation. We will delve into the myriad challenges that have emerged in the context of cyber threat intelligence and explore how they have shaped the course of the conflict and influenced the dynamics of global security.

One of the main objectives of our discussion will be the intrinsic value and indispensability of threat intelligence in current conflict scenarios. Threat Intelligence serves as a beacon of foresight, equipping organizations and nations with the knowledge and tools necessary to proactively defend against cyber threats. By analyzing evolving tactics, techniques, and procedures used by adversaries, threat intelligence enables the identification of potential vulnerabilities, allowing stakeholders to strengthen their defenses and increase overall resilience.

In addition, we will explore the complex interplay between threat intelligence and critical organizational processes. Detection engineering, the art of developing robust systems and mechanisms to identify and neutralize cyber threats, increasingly relies on timely and accurate threat intelligence. The synergy between detection engineering and threat intelligence supports the creation of sophisticated and proactive defense strategies that provide a more secure digital environment for organizations of all sizes.

Validation, another key aspect in cyber threat intelligence, is becoming increasingly important in the context of the Ukraine-Russia conflict. Validating the authenticity and reliability of threat data is essential to distinguish real threats from false alarms. By implementing robust verification procedures, organizations can distinguish between genuine cyber threats and misleading or deceptive information, thereby optimizing resource allocation and response efforts.

Finally, our presentation will underscore the importance of organizational resilience in the face of persistent cyber threats. Threat intelligence acts as a critical foundation upon which resilience strategies are built. By leveraging threat intelligence, organizations can develop comprehensive response plans, identify potential attack vectors, and implement proactive measures to mitigate risks and minimize the impact of cyber incidents.

Join us as we embark on this thought-provoking exploration of the Ukraine-Russia conflict, where the convergence of geopolitical tensions and cyber threat intelligence makes for a compelling narrative. Prepare to gain invaluable insights into the complex interplay between these domains and emerge equipped with a deeper understanding of the evolving landscape of contemporary warfare.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/SMDFBC/</url>
            <location>Salle Europe</location>
            
            <attendee>Ondrej Nekovar</attendee>
            
            <attendee>Jan</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UXXCXQ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UXXCXQ</pentabarf:event-slug>
            <pentabarf:title>How to operationalize CTI - A real world example</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T113000</dtstart>
            <dtend>20231017T120000</dtend>
            <duration>003000</duration>
            <summary>How to operationalize CTI - A real world example</summary>
            <description>While the journey is still ongoing, we want to highlight what worked so far and what not so much. 
From building and maintaining collections to the daily business of a CTI analyst of providing relevant information to our stakeholders without becoming a news clipping service.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UXXCXQ/</url>
            <location>Salle Europe</location>
            
            <attendee>Melanie Niethammer</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>KML7KQ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-KML7KQ</pentabarf:event-slug>
            <pentabarf:title>Liberate the CSAM hashsets!</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T133000</dtstart>
            <dtend>20231017T133500</dtend>
            <duration>000500</duration>
            <summary>Liberate the CSAM hashsets!</summary>
            <description>Where are the CSAM hashsets?</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/KML7KQ/</url>
            <location>Salle Europe</location>
            
            <attendee>Andras Iklody</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MESUKB@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MESUKB</pentabarf:event-slug>
            <pentabarf:title>Cobalt Striked?</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T133500</dtstart>
            <dtend>20231017T134000</dtend>
            <duration>000500</duration>
            <summary>Cobalt Striked?</summary>
            <description>I ll detail the timeline of this event, what is and is not in the leak, and what message the leaker left to us, analysts.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/MESUKB/</url>
            <location>Salle Europe</location>
            
            <attendee>Vincent Hinderer</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NGU8KF@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-NGU8KF</pentabarf:event-slug>
            <pentabarf:title>Are Leaked Credentials Dumps Used by Attackers?</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T134000</dtstart>
            <dtend>20231017T134500</dtend>
            <duration>000500</duration>
            <summary>Are Leaked Credentials Dumps Used by Attackers?</summary>
            <description>I searched for some old credentials with my domain &#171;&#160;root shell.be&#160;&#187; and checked if they were used in brute-force attacks&#8230;.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/NGU8KF/</url>
            <location>Salle Europe</location>
            
            <attendee>Xavier Mertens</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MNNLZP@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MNNLZP</pentabarf:event-slug>
            <pentabarf:title>Lessons learned from sharing intel about potential fraud / compromise</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T134500</dtstart>
            <dtend>20231017T135000</dtend>
            <duration>000500</duration>
            <summary>Lessons learned from sharing intel about potential fraud / compromise</summary>
            <description>Some lessons learned and anecdotes from spending several years sharing threat intelligence related to potential fraud / compromise.

Based on experiences with both &apos;real&apos; and &apos;simulated&apos; scenarios.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/MNNLZP/</url>
            <location>Salle Europe</location>
            
            <attendee>Jeroen Pinoy</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>9X7V8Y@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-9X7V8Y</pentabarf:event-slug>
            <pentabarf:title>Sigma Project News</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T135000</dtstart>
            <dtend>20231017T135500</dtend>
            <duration>000500</duration>
            <summary>Sigma Project News</summary>
            <description>Sigma got recently some updates:

* the new [SigmaHQ website](https://sigmahq.io).
* Sigma blog
* Rule packages
* Query post-processing
* ...

This talk gives a short overview about these news.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/9X7V8Y/</url>
            <location>Salle Europe</location>
            
            <attendee>Thomas Patzke</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>AHNLUP@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-AHNLUP</pentabarf:event-slug>
            <pentabarf:title>Do we consider this as a risks already</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T135500</dtstart>
            <dtend>20231017T140000</dtend>
            <duration>000500</duration>
            <summary>Do we consider this as a risks already</summary>
            <description>What else people should consider in the threat models</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/AHNLUP/</url>
            <location>Salle Europe</location>
            
            <attendee>Vladimir Kropotov</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>LHDBVE@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-LHDBVE</pentabarf:event-slug>
            <pentabarf:title>JTAN - data sharing network</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T140000</dtstart>
            <dtend>20231017T143000</dtend>
            <duration>003000</duration>
            <summary>JTAN - data sharing network</summary>
            <description>Details TBC.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/LHDBVE/</url>
            <location>Salle Europe</location>
            
            <attendee>Alexandre Dulaunoy</attendee>
            
            <attendee>Pawe&#322; Pawli&#324;ski</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NMLPHG@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-NMLPHG</pentabarf:event-slug>
            <pentabarf:title>Turbocharging IOC validation: Become a more efficient CTI analyst</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T143000</dtstart>
            <dtend>20231017T150000</dtend>
            <duration>003000</duration>
            <summary>Turbocharging IOC validation: Become a more efficient CTI analyst</summary>
            <description>The session is based on real-world experience and will cover:
- Intro to Low-Regret Model. 
- Scenarios which will take you down a rabbit hole and how to avoid them
- When you, as a CTI analyst, should stop enriching an IOC
- How to conduct IOC associations and linkage 
- A live demonstration of a highly efficient and automated method to gain optimal results 
and improve the IOC validation process using Low-Regret Model.

The session will also provide participants with valuable sources to aid them in effectively 
validating IOCs in their role as a CTI analyst.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/NMLPHG/</url>
            <location>Salle Europe</location>
            
            <attendee>Arwa Alomari</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GVL7FM@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GVL7FM</pentabarf:event-slug>
            <pentabarf:title>Modern IOCs matching with Suricata</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T150000</dtstart>
            <dtend>20231017T153000</dtend>
            <duration>003000</duration>
            <summary>Modern IOCs matching with Suricata</summary>
            <description>Suricata is an high performance open source IDS and NSM engine that exist since 2009. The IDS function has evolved over the years and ,among other features, the dataset one has been developed to be able to match on a list of elements.

We will present how the feature is designed and how it is really convenient to do matching of IOCs on the live network traffic as well as building network wide patient zero database for metadata. We will also cover how the NSM produced data can be used to do matching on past traffic when new IOCs are added.

And finally we will present IOCMite an open source tool linking MISP and Suricata in both direction using the dynamic nature of dataset.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/GVL7FM/</url>
            <location>Salle Europe</location>
            
            <attendee>Eric Leblond</attendee>
            
            <attendee>Peter Manev</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>HNAUGB@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-HNAUGB</pentabarf:event-slug>
            <pentabarf:title>PXF-X - A modular python framework to hunt, extract and enrich Post-Exploitation Framework artifacts</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T153000</dtstart>
            <dtend>20231017T160000</dtend>
            <duration>003000</duration>
            <summary>PXF-X - A modular python framework to hunt, extract and enrich Post-Exploitation Framework artifacts</summary>
            <description>PXF-X should fully automate all the required analysis steps. In essence, this means: 1) artifacts are hunted with VirusTotal Livehunting YARA rules, 2) the samples are then obtained and analyzed in several ways, 3) the extracted information is then enriched by different intelligence sources and reconnaissance methods.
PXF-X is designed in a modular way. The intention is that various modules can be integrated sucessively. Currently three different Frameworks are supported: Meterpreter, Cobalt Strike and Brute Ratel C4. A bunch of others are in the makings.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/HNAUGB/</url>
            <location>Salle Europe</location>
            
            <attendee>Joel Doenne</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>WVFPNK@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-WVFPNK</pentabarf:event-slug>
            <pentabarf:title>Pyrrha: navigate easily into your system binaries</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T161500</dtstart>
            <dtend>20231017T164500</dtend>
            <duration>003000</duration>
            <summary>Pyrrha: navigate easily into your system binaries</summary>
            <description>Pyrrha is an extension of Sourcetrail [1] an open-source code source explorer (for c/cpp, Python, and Java). This extension uses LIEF [2] to analyze imports and exports of each library and binary of the firmware and create links between them. The result is exported as a sourcetrail database. Thanks to Sourcetrail UI, the user will be able to navigate and search in the resulting firmware mapping.

Pyrrha has been open-sourced and is available on GitHub: https://github.com/quarkslab/pyrrha

[1] https://github.com/CoatiSoftware/Sourcetrail
[2] https://lief-project.github.io/</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/WVFPNK/</url>
            <location>Salle Europe</location>
            
            <attendee>Elo&#239;se Brocas</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>P8KXTK@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-P8KXTK</pentabarf:event-slug>
            <pentabarf:title>Threat actors &amp; surveillance companies targeting telecom operators</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T164500</dtstart>
            <dtend>20231017T171500</dtend>
            <duration>003000</duration>
            <summary>Threat actors &amp; surveillance companies targeting telecom operators</summary>
            <description>Telecom operators are at the heart of our societies, and all the citizens have a mobile phone today, which makes the operators an ideal target. This presentation will get more in depth into specific threat actors which are supporting the work of global surveillance companies and attacking all operators around the world. We will go over the investigations we have conducted on attacks targeting the operators of many countries across the globe and the impact for the populations and national security of these countries.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/P8KXTK/</url>
            <location>Salle Europe</location>
            
            <attendee>Alexandre de Oliveira</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>XHLVWG@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-XHLVWG</pentabarf:event-slug>
            <pentabarf:title>How Crowdsec is building a collaborative, trustable, and crowdsourced CTI to change the cybersecurity landscape</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T171500</dtstart>
            <dtend>20231017T173500</dtend>
            <duration>002000</duration>
            <summary>How Crowdsec is building a collaborative, trustable, and crowdsourced CTI to change the cybersecurity landscape</summary>
            <description>Over the past years CTI has evolved from a simple blocklist to a more end-to-end approach.
Learn about the crowdsourced approach to achieving this CTI thanks to using an open-source security engine that detects &amp; blocks more than 150 behaviors across a network of 60k nodes spread all over the globe, ensuring that the CTI system is continually updated with the latest information &amp; can respond quickly to new threats. You will also get insights on the data that builds this next-generation CTI &amp; see examples of DDOS events, CVEs blocked, &amp; a description of malicious actors reported on the Internet. 
To conclude you will get insights of machine learning applications to classify IP addresses based on their behavior.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/XHLVWG/</url>
            <location>Salle Europe</location>
            
            <attendee>Matthieu Mazzolini</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>99YBB9@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-99YBB9</pentabarf:event-slug>
            <pentabarf:title>MISP42: connecting CTI and SOC teams</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T173500</dtstart>
            <dtend>20231017T175500</dtend>
            <duration>002000</duration>
            <summary>MISP42: connecting CTI and SOC teams</summary>
            <description>The presentation will present the challenges CTI and SOC team may have in using in an actionable way IOCs on the monitoring and detection platforms to introduce why MISP42 was developed for Splunk (it was the main platform of the SOC at the time).

Then the 2 main use cases will be detailed with practical examples
- use MISP IOC into Splunk for hunting, retrosearch, threat activity or detection enrichment.
- use findings/matches on Splunk to create new events or increment sightings factors
and finally illustrate the swiss-knife concept of MISP42 (one command designed to be a wrapper of MISP REST API)</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/99YBB9/</url>
            <location>Salle Europe</location>
            
            <attendee>Remi Seguy</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JAKAKS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JAKAKS</pentabarf:event-slug>
            <pentabarf:title>Yeti - old dog, new tricks</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T175500</dtstart>
            <dtend>20231017T182500</dtend>
            <duration>003000</duration>
            <summary>Yeti - old dog, new tricks</summary>
            <description>We are going to tell the story of Yeti, why it was created, where it&apos;s now, and about all the friends we made along the way.

Besides the new DFIR twist we want to give Yeti, we&apos;ll highlight some of the major changes in the codebase:
  - Total revamp of the Web UI using VueJS.
  - Backend migration to ArangoDB (graph database)
  - Code health: Python typing, e2e tests, making development faster and more
    reliable, and making community contributions much easier.
  - Production and development Docker images
  - Integration with third-party OSS tools such as Timesketch and Turbinia.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/JAKAKS/</url>
            <location>Salle Europe</location>
            
            <attendee>Thomas Chopitea</attendee>
            
            <attendee>S&#233;bastien Larinier</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UCRUZT@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UCRUZT</pentabarf:event-slug>
            <pentabarf:title>Managing spam, phishing and other boring tasks with your users and constituents</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T140000</dtstart>
            <dtend>20231017T160000</dtend>
            <duration>020000</duration>
            <summary>Managing spam, phishing and other boring tasks with your users and constituents</summary>
            <description>Please make sure before attending this workshop that you can install python 3 software on your device, and your device should preferably be running Ubuntu 22.04 or more recent. As the workshop is relatively short and depending on how many people will attend, we may not have time to do a lot of sysadmin work during the workshop.

The tools we will use are the following:

* Lookyloo (to analyze URLs)
* Pandora (to analyze files)
* Lacus (optionally, to capture the URLs when you have a lot of them)
* An URL monitoring interface (to compare a specific URL over time)
* Phishtank Lookup (to check if a URL is known or not)

We will also see how to integrate Lookyloo and Pandora to handle the cases where the URL points to a file, and where the file is a web document, or it contains URLs.

Integration with 3rd party services:

* MISP (to share the indicators)
* Ticketing system (to manage interactions with other entities, typically take down requests)
* Validate if URL is known with VirusTotal, PhishtankLookup, URLScan, URLHaus
* Validate if a file is known with Virustotal, ManwareBazaar, HybridAnalysis, MwDB, JoeSandbox
* Add contextual information with SaneJS, uWhoisd, Hashlookup</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UCRUZT/</url>
            <location>Schengen 1 and 2</location>
            
            <attendee>Rapha&#235;l Vinot</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7KYDJW@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-7KYDJW</pentabarf:event-slug>
            <pentabarf:title>Cryptocurrency &amp; Web3 OSINT Workshop</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T163000</dtstart>
            <dtend>20231017T183000</dtend>
            <duration>020000</duration>
            <summary>Cryptocurrency &amp; Web3 OSINT Workshop</summary>
            <description>This workshop offers a practical understanding of Blockchain, Smart Contracts, DApps, and NFTs. Participants will learn the basics of Web3 OSINT, including extracting and analyzing on-chain and off-chain data. The workshop also provides a guide to important websites and tools, with a focus on the process of linking and verifying information. It&apos;s an opportunity to enhance your skills within the realm of cryptocurrency and Web3.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/7KYDJW/</url>
            <location>Schengen 1 and 2</location>
            
            <attendee>Patrick Ventuzelo</attendee>
            
            <attendee>Tanguy Laucournet</attendee>
            
            <attendee>Mohammed Benhelli</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T103000</dtstart>
            <dtend>20231017T120000</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T140000</dtstart>
            <dtend>20231017T153000</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T163000</dtstart>
            <dtend>20231017T180000</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UUS37B@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UUS37B</pentabarf:event-slug>
            <pentabarf:title>Three Ways to Reverse-Engineering Cryptographic Functions</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T090000</dtstart>
            <dtend>20231017T120000</dtend>
            <duration>030000</duration>
            <summary>Three Ways to Reverse-Engineering Cryptographic Functions</summary>
            <description>Outline:

  0. Environment: We have an encryption tool, some libraries an already encrypted, secret file.

  1. Black box: Just by using the encryption tool, what can we infer about the used primitives, keys, IVs etc.? Misusing the issues and stream cipher properties, we can even get parts of the keystream and start decrypting content.
  
  2. Dynamic analysis with Frida: By hooking the right OLE functions, we understand what library calls are used and what the obfuscated static passphrase is, that the application uses.
  
  3. Static analysis with Ghidra: To confirm our assumptions about the primitives and to understand the key derivation, we dive into the libraries with Ghidra, detect indicators for common crypto and reconstruct what they do.
  
  4. In the end, we can implement a version of the cryptographic function including the key derivation in python, and reverse it to decrypt the secret file.


Target audience: People interested in reverse engineering with some prior understanding but no required experience in the field. Some programming experience assumed (C++ or similar for understanding objects in ghidra, python for the script at the end, JavaScript for Frida).


Software requirements: Windows (VM) with admin rights, python, Frida and Ghidra installed
 -- or --
VirtualBox and about 50 GB of free space to use a provided VM</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UUS37B/</url>
            <location>Hollenfels</location>
            
            <attendee>Finn Steglich</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GAKCQP@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GAKCQP</pentabarf:event-slug>
            <pentabarf:title>Customize Your Own Command &amp; Control: Design and Code Your Own Implant in a Real Infrastructure</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T140000</dtstart>
            <dtend>20231017T180000</dtend>
            <duration>040000</duration>
            <summary>Customize Your Own Command &amp; Control: Design and Code Your Own Implant in a Real Infrastructure</summary>
            <description>Command &amp; Control is a cornerstone of any attacker&apos;s infrastructure, whether they are affiliated with state actors (APTs), cybercriminals, or legitimate Red Team operators.

&quot;Customize Your Own C&amp;C&quot; is a 4-hour workshop designed for those interested in quickly diving into the world of Command &amp; Control design and architecture, and learning how to develop their own implant using a well-known open-source framework.

In this bring-your-own-laptop workshop, participants will have the opportunity to learn about the architecture and design of a well-known open-source framework as an example. They will also receive a comprehensive, hands-on introduction to designing a simple custom implant. This will involve working with two already prepared virtual machines and culminating in the creation of their own integrated x64 implant (utilizing a C++/Python wrapper)</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/GAKCQP/</url>
            <location>Hollenfels</location>
            
            <attendee>Guillaume Prigent</attendee>
            
            <attendee>Adrien Barchapt-Perrot</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>XTDTNH@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-XTDTNH</pentabarf:event-slug>
            <pentabarf:title>An Introduction to ARM64 Assembly and Shellcode</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T140000</dtstart>
            <dtend>20231017T160000</dtend>
            <duration>020000</duration>
            <summary>An Introduction to ARM64 Assembly and Shellcode</summary>
            <description>AN INTRODUCTION TO ARM64 ASSEMBLY AND SHELLCODE

WORKSHOP AGENDA
- An introduction to ARM64 architecture and assembly
- Working with an emulated ARM64 instance
- Fundamental differences between ARM32 and ARM64 assembly
- The 64-bit process memory layout and addressing
- The ARM64 debugging environment
- Exploring memory corruption bugs on ARM64
- Practical ARM64 shellcode

To participate interactively in this hands-on workshop, please bring with you:
- A Linux/macOS system with Docker installed and running

To make the most out of the workshop, it would be awesome if you have:
- Familiarity with Intel x86 or ARM32 Assembly Language
- Basic experience with disassembly and reverse engineering
- A working knowledge of GDB
- The ability to write simple Python scripts</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/XTDTNH/</url>
            <location>Vianden&amp;Wiltz</location>
            
            <attendee>Saumil Shah</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GL99GV@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GL99GV</pentabarf:event-slug>
            <pentabarf:title>Using systematic code reuse analysis to create robust YARA rules</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231017T163000</dtstart>
            <dtend>20231017T183000</dtend>
            <duration>020000</duration>
            <summary>Using systematic code reuse analysis to create robust YARA rules</summary>
            <description>**Required prior knowledge**

This workshop is tailored to cybersecurity practitioners that either actively create
malware detection and identification rules with YARA or intend to start doing so.
Participants must be familiar with:

- Basic understanding of YARA rules
- Basic knowledge of static binary analysis with disassemblers
- Basic knowledge of the x86/x64 instruction set

**Required system setup**
- Recommended OS: Ubuntu
- CPU Arch: Intel 32/64-bit (ARM not supported)
- Minimum of 8GB RAM, 16GB recommended
- Minimum of 100GB free disk space, 150GB recommended

**Background**

YARA is a commonly used tool to detect and identify malware. There are roughly two
types of YARA rules used on binary files: 1) based on metadata and strings and 2)
based on code / instruction sequences.
There are benefits by basing YARA rules on code. Since code reuse is frequent
amongst binaries of a malware family, it offers plenty of options to base a YARA rule
on. If the chosen code is stable across multiple variants of a malware, then it can
result in very robust rules.
This approach comes with certain challenges. A key aspect is being able to find
stable / heavily reused code amongst many binaries of a malware family. Unless some sort of automation is at play, this quickly becomes difficult and time-
consuming. Once suitable reused code is identified, it needs to be turned into a YARA rule, so that it works even when compiler differences, optimizations or instruction set changes are involved.
Addressing these challenges and adding some automation along the way, enables
the creation of robust YARA rules with less manual effort.

**Workshop content**

The goal of this workshop is to create robust YARA rules for a handful of malware
families based on automatically identifying shared code between many binaries of a
family.

The approach includes the following parts:

- Study a set of good and bad examples of existing YARA rules to provide
some background.
- Pre-process a set of malware binaries, as well as goodware binaries to make
their code searchable on the granularity of a function.
- We automatically identify which functions are reused frequently for a malware
family.
- We need to exclude functions that are part of compilers, libraries or other
malware families to avoid creating false positives.
- From the set of reused functions, we will extract instruction sequences to
create YARA rules with.
- We will vet our new rules against the corpus of binaries to check for false
positives and adjust the rule creation accordingly.

We will look at the following real-world challenges:

- All binaries share library code from the compiler or 3rd party libraries. This
code is not useful for malware identification and will need to be filtered out
during the process.
- How to reliably generate a YARA rule from a set of instruction sequences.
- We need to make choices on how many and which instructions of a function
and how many functions in total we want to consider building a Yara rule. A
good balance has to be found.
- The quality of the function similarity algorithm is crucial in finding the right
matches. Especially since compiler versions, compiler optimization flags and
instruction set differences have to be considered.
- The quality of the disassembler in detecting functions and their content
strongly influences the quality of results.

During the workshop, we will be exclusively using open source tools and a set of
publicly available binaries in unpacked form.

The takeaways for the participants of this workshop are:

- Understanding the differences between good and bad YARA rules, be it
based on code or based on strings/metadata.
- Understanding the code reuse approach to YARA rules writing, with its
benefits and challenges.
- Understanding of the tooling required to identify code reuse over many
binaries.
- Understanding how to apply this process to real-world malware.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/GL99GV/</url>
            <location>Vianden&amp;Wiltz</location>
            
            <attendee>Jonas Wagner</attendee>
            
            <attendee>Carlos Rubio Ricote</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>TEUHBF@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-TEUHBF</pentabarf:event-slug>
            <pentabarf:title>How Digital Technologies are Redefining Warfare and Why It Matters</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T090000</dtstart>
            <dtend>20231018T093000</dtend>
            <duration>003000</duration>
            <summary>How Digital Technologies are Redefining Warfare and Why It Matters</summary>
            <description>Cyber capabilities have been used for military purposes for more than two decades. But the digital operational area of States is no longer limited to cyber operations. In line with the global trend toward digitalization of our societies, armed forces around the world are developing innovative strategies to exploit the digital sphere in more complex ways than ever before. As a result of these developments, the line between civilians and combatants as well as between civilian objects and military targets, is in danger of becoming blurred. In particular, it is now easier than ever to involve civilians in military cyber operations and to harm them using these means. And the more the military is relying on cables, satellites or clouds that are originally designed for civilian use, the more likely it becomes that this infrastructure will be exposed to harm during armed conflicts, with significant adverse consequences on civilians.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/TEUHBF/</url>
            <location>Salle Europe</location>
            
            <attendee>Mauro Vignati</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>ZBRV3J@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-ZBRV3J</pentabarf:event-slug>
            <pentabarf:title>Ongoing EvilEye Campaigns Targeting CCP Adversaries</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T093000</dtstart>
            <dtend>20231018T100000</dtend>
            <duration>003000</duration>
            <summary>Ongoing EvilEye Campaigns Targeting CCP Adversaries</summary>
            <description>Everything is in the abstract.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/ZBRV3J/</url>
            <location>Salle Europe</location>
            
            <attendee>Rascagneres Paul</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JXGQJJ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JXGQJJ</pentabarf:event-slug>
            <pentabarf:title>Defeating VPN Always-On</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T100000</dtstart>
            <dtend>20231018T103000</dtend>
            <duration>003000</duration>
            <summary>Defeating VPN Always-On</summary>
            <description>This talk is more than just the outcome of my technical research against one particular network security feature. It is an attempt to fully embrace the hacker spirit through the revolt against Control, the unreasonable time trying to understand the technological subtleties and finally the sharing of beautifully simple techniques to break free.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/JXGQJJ/</url>
            <location>Salle Europe</location>
            
            <attendee>Maxime Clementz</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JTAB9A@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JTAB9A</pentabarf:event-slug>
            <pentabarf:title>The Renaissance of Cyber Physical Offensive Capabilities</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T103000</dtstart>
            <dtend>20231018T110000</dtend>
            <duration>003000</duration>
            <summary>The Renaissance of Cyber Physical Offensive Capabilities</summary>
            <description>For the last ten years we have seen a fast evolving operational technology (OT) security community learning about cyber physical attacks and how to defend against them. However, since the beginning of the conflict in Ukraine, we have seen a twist in the OT threat landscape. A renaissance or breakthrough period of innovation is making threats to cyber physical systems more streamlined and common than ever before.

During the conflict, we have observed the intensification of threat activity coming from different fronts, including criminals, hacktivists, and nation-states. Such activity has resulted in a quick turnaround in the development of malware and capabilities to target OT systems. In this talk, I will provide an overview of the evolution of OT threats focusing primarily on new capabilities we have observed since the eve of Ukraine&#8217;s invasion. 

Among other things, I will discuss recent leaked documents hinting on Russia&#8217;s development of OT cyber capabilities, and the recent disclosure of highly specialized malware including INDUSTROYER2, INCONTROLLER, and most recently COSMICENERGY. Using our findings, I will also discuss the implications for defenders in the light of this new era of discovery of cyber physical offensive capabilities.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/JTAB9A/</url>
            <location>Salle Europe</location>
            
            <attendee>Daniel Kapellmann Zafra</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>QYPDSN@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-QYPDSN</pentabarf:event-slug>
            <pentabarf:title>Introduction to cyberwarfare: theory and practice</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T110000</dtstart>
            <dtend>20231018T114500</dtend>
            <duration>004500</duration>
            <summary>Introduction to cyberwarfare: theory and practice</summary>
            <description>This talk presents a strict analysis of technology, policy, international law, and cyberwarfare, focusing on the realities of armed conflict in cyberspace. Ukraine and other events in Central Eastern Europe will provide food for thoughts and a case study. The main premise is grounded in sound analysis of rules, strategies, and the mechanics of conflicts. 

Some relevant points to consider follow. What&#8217;s the relevance to the armed conflict areas? What&#8217;s the relevance to the countries non-neutral in a conflict? Should companies prepare in any way, and if so, how? Are there particular risk to IT companies, IT administrators, developers, software engineers, security engineers?

Ukraine war highlights the importance of cyberware. Yet, the reality may appear different from prior conceptions or expectations.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/QYPDSN/</url>
            <location>Salle Europe</location>
            
            <attendee>Lukasz Olejnik</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GRKRS9@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GRKRS9</pentabarf:event-slug>
            <pentabarf:title>You can learn anything.</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T133000</dtstart>
            <dtend>20231018T133500</dtend>
            <duration>000500</duration>
            <summary>You can learn anything.</summary>
            <description>Lightening</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/GRKRS9/</url>
            <location>Salle Europe</location>
            
            <attendee>Pauline Bourmeau (Cookie)</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>DZKRNU@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-DZKRNU</pentabarf:event-slug>
            <pentabarf:title>Velocity Raptor: Accelerating Velociraptor Hunting with Tenzir Pipelines</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T133500</dtstart>
            <dtend>20231018T134000</dtend>
            <duration>000500</duration>
            <summary>Velocity Raptor: Accelerating Velociraptor Hunting with Tenzir Pipelines</summary>
            <description>In this talk we showcase how to interact with a Velociraptor server from Tenzir pipelines, speeding up DFIR work by flexibly processing the output of hunts</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/DZKRNU/</url>
            <location>Salle Europe</location>
            
            <attendee>Matthias Vallentin</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>XNQD37@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-XNQD37</pentabarf:event-slug>
            <pentabarf:title>TIDeMEC : A Detection Engineering platform homegrown at the European Commission</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T134000</dtstart>
            <dtend>20231018T134500</dtend>
            <duration>000500</duration>
            <summary>TIDeMEC : A Detection Engineering platform homegrown at the European Commission</summary>
            <description>TIDeMEC is a platform that has been built for the better part of the past 2 years at the EC, and builds on top of years of astute observations of what goes **wrong** in the detection engineering field. It is an opinionated end-to-end platform, data model, framework and solution built on top of DevOps and as-code principles, with an emphasis on traceability, consistency, safety and automation. The data model of TIDeMEC scales from the input of a threat intelligence signal to the deployment of a detection rule whilst maintaining programmatic relations between actors, threat, detection objectives, and rules. We will also lay the plans for TIDeX , a potential exchange built on top of the TIDeMEC data objects with the vision to connect SOCs with precise and actionable knowledge objects.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/XNQD37/</url>
            <location>Salle Europe</location>
            
            <attendee>Amine Besson</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>39NCZQ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-39NCZQ</pentabarf:event-slug>
            <pentabarf:title>Deming - ISMS Open Source</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T134500</dtstart>
            <dtend>20231018T135000</dtend>
            <duration>000500</duration>
            <summary>Deming - ISMS Open Source</summary>
            <description>Deming is an Open Source tool designed to help CISOs set up and maintain their information security management system. Using this application, CISOs can easily plan and track the implementation of security controls and the continuous improvement cycle required by ISO 27001. The application is designed to be easy to use and customize, with a intuitive user interface.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/39NCZQ/</url>
            <location>Salle Europe</location>
            
            <attendee>Didier Barzin</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>BNJJVZ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-BNJJVZ</pentabarf:event-slug>
            <pentabarf:title>Belgian Cyber Reserve Forces</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T135000</dtstart>
            <dtend>20231018T135500</dtend>
            <duration>000500</duration>
            <summary>Belgian Cyber Reserve Forces</summary>
            <description>A quick intro of the Belgian Military Cyber Reserve.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/BNJJVZ/</url>
            <location>Salle Europe</location>
            
            <attendee>Christophe Vandeplas</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>Z7UP7B@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-Z7UP7B</pentabarf:event-slug>
            <pentabarf:title>Non vulnerable package dependency resolution</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T135500</dtstart>
            <dtend>20231018T140000</dtend>
            <duration>000500</duration>
            <summary>Non vulnerable package dependency resolution</summary>
            <description>Software package ecosystems such as Maven, npm and PyPI as well as Linux distros define rich conventions to document package metadata and dependency relationships and constraints.

Vulnerability databases define which range of a package versions are subject to a known vulnerability.

Until now, these contexts have been considered separately. 
- package management tools resolve the version expression of the dependent package of a package to resolved versions in order to install the selected versions. 
- security tools check if resolved package versions are affected by known vulnerabilities (even when integrated in a package management tool)

This leads to duplicated efforts and either to the resolution of a vulnerable dependency graph; or vulnerability remediation that ignore functional constraints and may demand significant code refactoring.

We propose a new approach to resolve software package vulnerable version ranges and dependency version constraints together.

The obvious benefit is that you get both at once: non-vulnerable code and up-to-date code, and this is something that is not currently done by software package managers nor by security check tools. 

This is made possible because of a universal syntax to identify packages called Package URL, a universal notation for version ranges that support equally the functional constraints and the vulnerable ranges, and an on-demand dependency resolver that can use these as inputs. And also a vulnerability database that is keyed by Package URLs.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/Z7UP7B/</url>
            <location>Salle Europe</location>
            
            <attendee>Philippe Ombredanne</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JGQCU3@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JGQCU3</pentabarf:event-slug>
            <pentabarf:title>Embedded Threats: A Deep Dive into the eSIM World</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T140000</dtstart>
            <dtend>20231018T143000</dtend>
            <duration>003000</duration>
            <summary>Embedded Threats: A Deep Dive into the eSIM World</summary>
            <description>This talk is posed to be the 2023 continuation of a talk called &quot;Mobile Authentication Subspace Travel&quot;[^1] given in 2015 at different security conferences. The main point of this talk was to implement what is nowadays
called an eSIM by patching the baseband of popular MediaTek phones and to explore the relation of mobile
network security, SIM card modules, and the baseband attack surface they pose.
Fast-foward to 2023, eSIMs are now a featured standard by the GSMA and present in all modern devices.
On top of this, they are now present on Desktop systems such as Microsoft Windows as well. 

The talk will highlight the security aspects of eSIMs by covering the following topics:

1. Overview of the eSIM attack surface in desktop systems and a comparison with mobile operating systems:

We will begin the talk with a comprehensive overview of the attack surface of eSIM technology in desktop systems, addressing the differences and similarities with mobile operating systems. This analysis will address the unique challenges and vulnerabilities that arise from the rather complex architecture and implementation of eSIMs on desktop and mobile platforms, and highlight the need for a comprehensive understanding of the potential risks in both environments. Especially the risks in a multi-user Enterprise environment will be covered.

2. Secure deployment of eSIM profiles (from SM-DP+ to hardware eSIM):

Secure deployment of eSIM profiles is a critical component of maintaining the overall security of the mobile networks, but also of the actual hardware devices as well as operating systmes. We will discuss the process from the Subscription Manager - Data Preparation Plus (SM-DP+) server and how the profiles are dployed to the hardware eSIM. By examining key security measures and best practices to ensure the confidentiality, integrity, and availability of eSIM profiles throughout the deployment lifecycle, we will show potential risks arising from profiles originally intended for debugging purposes only and also test if the security mitigations intended by the GSMA to keep control over the eSIM ecosystem are actually effective..

3. Attack surface on Windows and the Local Profile Assistant (LPA) service in the light of privilege escalation attacks:

To investigate security implicatoins on Windows Desktop systems, we will examine the local attack surface,  focusing on the Local Profile Assistant (LPA) service and its potential role in privilege escalation attacks both in an organization and on the local system. We will outline the potential vulnerabilities and attack vectors that can be exploited by attackers to gain unauthorized access and elevated privileges within the system, emphasizing the importance of securing the LPA service and its associated components.

4. Use of eSIMs in offensive red-teaming operations:

Finally, we will explore the innovative ways in which eSIM technology can be used in offensive red-teaming operations to simulate sophisticated cyber threats and assess an organization&apos;s overall security posture. This section will present real-world examples and scenarios that demonstrate how eSIMs can be used to circumvent traditional security measures, exfiltrate sensitive data, and compromise network infrastructures.


In summary, the rapid adoption of eSIM technology offers a host of new opportunities and conveniences, but also introduces a number of potential vulnerabilities and security issues. By comprehensively examining the attack surface associated with eSIMs and discussing secure deployment practices, local attack vectors, and red-teaming applications, this presentation aims to inspire a proactive approach to securing eSIM technology. It is critical that the cybersecurity community come together and develop robust strategies to mitigate risks and ensure the continued security and reliability of this breakthrough innovation to ultimately promote a more secure and connected world.

[1] https://conference.hitb.org/hitbsecconf2015ams/materials/D1T1%20-%20Markus%20Vervier%20-%20Mobile%20Authentication%</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/JGQCU3/</url>
            <location>Salle Europe</location>
            
            <attendee>Markus Vervier</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>CUKBTG@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-CUKBTG</pentabarf:event-slug>
            <pentabarf:title>Building an evil phone charging station.</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T143000</dtstart>
            <dtend>20231018T150000</dtend>
            <duration>003000</duration>
            <summary>Building an evil phone charging station.</summary>
            <description>In April 2023, multiple news articles got published stating, quote, &quot;the FBI warns consumers not to use public phone charging stations&quot;. This lead to quite some interesting discussion online. With experts divided on the risks involved.

We will briefly go over older attacks (HID devices, usb-ethernet dongles) and how feasable these are, however the main focus of this presentation is investigating the risks of HDMI (and displayport) mirroring, and building a POC to automatically extract data from the video output.

We will also release the code for this research project, we hope you can build on top of it!</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/CUKBTG/</url>
            <location>Salle Europe</location>
            
            <attendee>Stef van Dop</attendee>
            
            <attendee>Tom&#225;s Philippart</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>SVEQQ3@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-SVEQQ3</pentabarf:event-slug>
            <pentabarf:title>Do&apos;s and don&apos;ts in file formats</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T150000</dtstart>
            <dtend>20231018T153000</dtend>
            <duration>003000</duration>
            <summary>Do&apos;s and don&apos;ts in file formats</summary>
            <description>Having dissected [hundreds](https://github.com/corkami/pics/blob/master/binary/README.md) of file formats and come up with many different kinds of abuses, whether they are design-based (polyglots, hash collision...) or parser-based (insert your typical fuzzing crash here), the author is familiar with looking at the typical mistakes when exploring specifications, designing a format, or assessing the security of a parser.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/SVEQQ3/</url>
            <location>Salle Europe</location>
            
            <attendee>Ange Albertini</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>Q9JHXM@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-Q9JHXM</pentabarf:event-slug>
            <pentabarf:title>ACME: benefits of deploying an Internet Security protocol inside your corporate network</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T153000</dtstart>
            <dtend>20231018T160000</dtend>
            <duration>003000</duration>
            <summary>ACME: benefits of deploying an Internet Security protocol inside your corporate network</summary>
            <description>This talk will give a  feedback on the deployment of an ACME proxy in front of a private Certificate Authority (CA) in a corporate network. 

I will expose:
- our analysis of the shortcomings of our current CA setup (slowness, heaviness, not so robust security controls),
- our search to improve our architecture,
- why we look at the Internet CA landscape,
- why we choose ACME.

I will then detailed to the audience:
- the expected benefits of having an ACME service inside your corporate ecosystem like robustness or automation opportunities 
- but also the unexpected ones like non anticipated uses cases provided directly by our IT users or massive ACME appropriation by a wide variety of IT professionals in the company that were not regular users of our original CA setup.
 
And, finally, I will end speaking about new ACME use cases in private networks provided by the IT security industry like the new ACME challenge, device-attest-01, proposed by Google [1] and used by Apple in its Managed Device Attestation [2] solution used to enrolled new corporate private iOS/MacOS/iPadOS devices.

[1] https://www.ietf.org/id/draft-acme-device-attest-01.html
[2] https://support.apple.com/guide/deployment/managed-device-attestation-dep28afbde6a/web</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/Q9JHXM/</url>
            <location>Salle Europe</location>
            
            <attendee>Christophe Brocas</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>VKSLBY@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-VKSLBY</pentabarf:event-slug>
            <pentabarf:title>Your unknown Twins: Identity in the era of Deepfakes, AI and mass Biometrics exposure</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T161500</dtstart>
            <dtend>20231018T164500</dtend>
            <duration>003000</duration>
            <summary>Your unknown Twins: Identity in the era of Deepfakes, AI and mass Biometrics exposure</summary>
            <description>This presentation includes use cases of face, fingerprint and retina biometric exposure, including recordings of live experiments. Finally, we demonstrate how emerging AI technologies can drastically accelerate the ability for criminal users to build a complete identity theft enterprise - where robust digital twins of everyone unfortunate enough to have leaked details are available for all to buy.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/VKSLBY/</url>
            <location>Salle Europe</location>
            
            <attendee>Vladimir Kropotov</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>PL3P7Y@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-PL3P7Y</pentabarf:event-slug>
            <pentabarf:title>PHP filter chains: How to use it</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T164500</dtstart>
            <dtend>20231018T171500</dtend>
            <duration>003000</duration>
            <summary>PHP filter chains: How to use it</summary>
            <description>This technical talk aims to introduce local file inclusion vulnerabilities on PHP applications. To show why PHP filters chain exploitation can be useful to know during an audit.

To illustrate it, we will show vulnerable code samples and ways to patch them.

Two tools were developed to exploit it and will also be presented :
 - https://github.com/synacktiv/php_filter_chain_generator
 - https://github.com/synacktiv/php_filter_chains_oracle_exploit</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/PL3P7Y/</url>
            <location>Salle Europe</location>
            
            <attendee>R&#233;mi Matasse</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UCRUZT@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UCRUZT</pentabarf:event-slug>
            <pentabarf:title>Managing spam, phishing and other boring tasks with your users and constituents</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T100000</dtstart>
            <dtend>20231018T120000</dtend>
            <duration>020000</duration>
            <summary>Managing spam, phishing and other boring tasks with your users and constituents</summary>
            <description>Please make sure before attending this workshop that you can install python 3 software on your device, and your device should preferably be running Ubuntu 22.04 or more recent. As the workshop is relatively short and depending on how many people will attend, we may not have time to do a lot of sysadmin work during the workshop.

The tools we will use are the following:

* Lookyloo (to analyze URLs)
* Pandora (to analyze files)
* Lacus (optionally, to capture the URLs when you have a lot of them)
* An URL monitoring interface (to compare a specific URL over time)
* Phishtank Lookup (to check if a URL is known or not)

We will also see how to integrate Lookyloo and Pandora to handle the cases where the URL points to a file, and where the file is a web document, or it contains URLs.

Integration with 3rd party services:

* MISP (to share the indicators)
* Ticketing system (to manage interactions with other entities, typically take down requests)
* Validate if URL is known with VirusTotal, PhishtankLookup, URLScan, URLHaus
* Validate if a file is known with Virustotal, ManwareBazaar, HybridAnalysis, MwDB, JoeSandbox
* Add contextual information with SaneJS, uWhoisd, Hashlookup</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UCRUZT/</url>
            <location>Schengen 1 and 2</location>
            
            <attendee>Rapha&#235;l Vinot</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GHS8XH@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GHS8XH</pentabarf:event-slug>
            <pentabarf:title>Non-state actors&#8217; cyber activity in Armed Conflict: impact, implications and remediation</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T140000</dtstart>
            <dtend>20231018T153000</dtend>
            <duration>013000</duration>
            <summary>Non-state actors&#8217; cyber activity in Armed Conflict: impact, implications and remediation</summary>
            <description>This session will aim to:
- Raise awareness and build knowledge in the community about the potential unwanted consequences of non-state cyber activities and the underlying legal context;
- Discuss together with the participants the observed specific TTPs typically used by non-state actors engaged in the cyber dimension of a conflict and the evolving underlying strategies;
- Potential mitigation and (self-)restraint measures to avoid civilian targets, unnecessary injury or suffering. E.g. See 8 suggested rules for &quot;civilian hackers&quot; proposed by https://blogs.icrc.org/law-and-policy/2023/10/04/8-rules-civilian-hackers-war-4-obligations-states-restrain-them/
- Long-term effects of the non-state actor engagement &#8216;banalisation&#8217; - i.e. potential post-conflict consequences of a laissez-faire attitude to the increasingly militarised broader cyber community</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/GHS8XH/</url>
            <location>Schengen 1 and 2</location>
            
            <attendee>Deleted User</attendee>
            
            <attendee>Mauro Vignati</attendee>
            
            <attendee>Elena R&#252;ckheim</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T090000</dtstart>
            <dtend>20231018T103000</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T103000</dtstart>
            <dtend>20231018T120000</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T140000</dtstart>
            <dtend>20231018T153000</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T161500</dtstart>
            <dtend>20231018T174500</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>KRG3WK@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-KRG3WK</pentabarf:event-slug>
            <pentabarf:title>Analyzing Cobalt Strike Beacons, Servers and Traffic</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T100000</dtstart>
            <dtend>20231018T120000</dtend>
            <duration>020000</duration>
            <summary>Analyzing Cobalt Strike Beacons, Servers and Traffic</summary>
            <description>Didier has developed tools to extract the configuration of Cobalt Strike beacons, to detect Cobalt Strike beacons and to analyze/decrypt Cobalt Strike network traffic.

These tools allow you to deal with Cobalt Strike beacons, without having to reverse engineer malicious code.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/KRG3WK/</url>
            <location>Hollenfels</location>
            
            <attendee>Didier Stevens</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>M9CWW9@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-M9CWW9</pentabarf:event-slug>
            <pentabarf:title>The new Sigma Toolchain</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T140000</dtstart>
            <dtend>20231018T160000</dtend>
            <duration>020000</duration>
            <summary>The new Sigma Toolchain</summary>
            <description>This workshop aims to give an introduction to the new Sigma Python toolchain, *pySigma* (the library) and *Sigma CLI* (converter, rule checker, ATT&amp;CK heatmap generator, ...). I will give a brief introduction to some important concepts like plugins, backends and processing pipelines and continue with hands-on exercises:

* Discover and install backends and pipelines required for conversion.
* Basic conversion of queries.
* Building own processing pipelines (e.g. field name mappings).
* Rule checking
* Creating a MITRE&#8482;&#65039;ATT&amp;CK heatmap from a rule set.
* Creating backends with the cookiecutter template.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/M9CWW9/</url>
            <location>Hollenfels</location>
            
            <attendee>Thomas Patzke</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GUNJJH@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GUNJJH</pentabarf:event-slug>
            <pentabarf:title>Kunai workshop: your new Threat Hunting tool for Linux</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T161500</dtstart>
            <dtend>20231018T174500</dtend>
            <duration>013000</duration>
            <summary>Kunai workshop: your new Threat Hunting tool for Linux</summary>
            <description>This workshop aims to introduce the community to Kunai, a new Threat Hunting tool designed specifically for Linux Systems, in addition to the hack.lu talk by the same name</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/GUNJJH/</url>
            <location>Hollenfels</location>
            
            <attendee>Quentin JEROME</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>3RBM3A@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-3RBM3A</pentabarf:event-slug>
            <pentabarf:title>Build your own malware analysis pipeline using open source tools</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231018T090000</dtstart>
            <dtend>20231018T120000</dtend>
            <duration>030000</duration>
            <summary>Build your own malware analysis pipeline using open source tools</summary>
            <description>Hands-on workshop showcasing MWDB, mwdblib, Karton and malduck.

IMPORTANT: please remember to take your laptop with you. You will need to have a working Linux environment, with a docker-compose and Python installed.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/3RBM3A/</url>
            <location>Vianden&amp;Wiltz</location>
            
            <attendee>Micha&#322; Praszmo</attendee>
            
            <attendee>psrok1</attendee>
            
            <attendee>Jaros&#322;aw Jedynak</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>WKYGQN@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-WKYGQN</pentabarf:event-slug>
            <pentabarf:title>Internet exposure of satellite modems, and their vulnerabilities</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T090000</dtstart>
            <dtend>20231019T093000</dtend>
            <duration>003000</duration>
            <summary>Internet exposure of satellite modems, and their vulnerabilities</summary>
            <description>ONYPHE &amp; ESIEA partnered to create an assessment about satellite modems and their current state of vulnerabilities. We will speak about different brands, give some pictures about how many of them are exposed on the Internet, and give some numbers on their vulnerabilities.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/WKYGQN/</url>
            <location>Salle Europe</location>
            
            <attendee>Patrice Auffret</attendee>
            
            <attendee>Arnaud Girault</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>USNSEZ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-USNSEZ</pentabarf:event-slug>
            <pentabarf:title>Almost 2 years after log4j .. if your PSIRT has survived, Are the Lessons learned or not learned  on security incident &amp; vulnerability management ?</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T093000</dtstart>
            <dtend>20231019T095500</dtend>
            <duration>002500</duration>
            <summary>Almost 2 years after log4j .. if your PSIRT has survived, Are the Lessons learned or not learned  on security incident &amp; vulnerability management ?</summary>
            <description>In this talk we will try to:
 
** Review the theory and framework for security operation (detect/respond/recover &amp; lessons learned) in real case scenario log4j

** Highlight that in security incident management : 

- PSIRT (when it exists) is not a magic team or heroes

- Full recovery takes time  

** Admit that there are no other choices than
 
- Shift Left (SSDLC)
- Involve the management and accountable players  (CMDB, SBOM, BCP)
- Collectively align our incident response and vulnerability management approaches and forces</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/USNSEZ/</url>
            <location>Salle Europe</location>
            
            <attendee>FrederiqueD, Thales</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>J3GJY9@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-J3GJY9</pentabarf:event-slug>
            <pentabarf:title>Avoiding the basilisk&apos;s fangs: State-of-the-art in AI LLM detection</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T100000</dtstart>
            <dtend>20231019T104000</dtend>
            <duration>004000</duration>
            <summary>Avoiding the basilisk&apos;s fangs: State-of-the-art in AI LLM detection</summary>
            <description>Are LLMs going to upend, or just end the world? Will malevolent AIs spread disinformation and FUD to enslave humanity in a world of fear? Will Roko&apos;s Basilisk come to pass? In order to help stay these dramatic end-times, LLM detectors are here! We can build safe, AI-free zones to limit the digital &quot;noise&quot; that these models can blast out at scale, if only we can reliably detect and classify a content&apos;s origin.
This talk does a deep dive into the leading LLM text detectors, both open-source and commercial, and compares them against a number of different datasets. Next, we throw into the mix ZipPy, a novel open-source detector based on code written in the mid-1980s that outperforms the state-of-the-art in a number of dimensions. ZipPy is simple (less than 200 lines of Python), and it codifies the intuition about a core difference between LLMs and humans that no additional amount of data or training cores can overcome--being unique! Using ZipPy we can walk through the features used to differentiate a text&apos;s origins and how with a simple, embedded detector we can build a human-centric world where LLMs are used only to help us rather than subvert us.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/J3GJY9/</url>
            <location>Salle Europe</location>
            
            <attendee>Jacob Torrey</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>Q89X9U@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-Q89X9U</pentabarf:event-slug>
            <pentabarf:title>Permissionless Universal Overlays</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T104000</dtstart>
            <dtend>20231019T112000</dtend>
            <duration>004000</duration>
            <summary>Permissionless Universal Overlays</summary>
            <description>Brief Outline: 
- The Android User Interface  
- GUI Confusion Attacks: The story so far 
- A behavior so far unnoticed 
- Attacking System Dialogs 
- Attacking 3rd party applications 
- Defense and Takeaways 

Detailed Outline: 
- The presentation starts with an overview of the Android User Interface, focusing on the components that are relative to the attack that I am going to describe.  
- Then I am going to present a brief overview of the GUI Confusion techniques so far, and their mass scale usage as an attack vector from many modern malware campaigns. The objective is to give context to the audience about these attacks as well as to underline their impact and why they should not be underestimated. 
- The next (main) section describes the Android&apos;s back stack and focuses on the following behavior: 
 -- When a new activity is pushed on the top of the stack, the overlapped one maintains its graphical state as well as the ability to receive touches from the user. The same behavior applies to system dialogues and system menus that are used to enable or disable special permissions.  
 -- When a transparent activity is pushed on the top of the stack it literally integrates the GUI of the one that was pushed lower. This creates the illusion that the overlapped activity is the one in the foreground. 

- An Android application can create a transparent activity and apply to its window one or a combination of many flags that are defined in the android.view.WindowManager.LayoutParams class.  
- These flags can be used to define how a view reacts to user taps and choose to consume or dispatch them to an underlying view.  
- In the next section I am going to describe my GUI confusion technique which leverages the behavior described in the previous section.  
I first classify my targets as &quot;Single-Step&quot; (SS) and &quot;Multi-Step&quot; (MS) decision makers, where in the first class belong the dialogs where a single tap suffices to determine a critical permission approval. For the second class the user must be guided to a particular component of a particular screen to approve or decline a special permission (e.g., draw on top of other apps).  

SS dialogs (like the ones that belong to Contacts/Camera/Call-Logs etc. permission controllers) can be overlapped using a single specially crafted activity.  
For MS dialogs I use a trampoline Activity which reforms itself according to a step indexing. 
In both cases a tap is dispatched to the underlying view as long as the overlapping window carries the FLAG_NOT_TOUCH_MODAL flag. The taps can be tracked without implementing any special technique, since a single tap moves the activity to the PAUSE state. This event can&apos;t be interpreted as a signal to: 
-- End the activity for SS dialogs  
-- Respawn a reformed activity for MS dialogs 
-- Hijack the user interaction for 3rd party applications 

- Finally, I demonstrate how from zero permissions my application gets dangerous and/or special permissions approved.   
- In the next section I demonstrate how to attack 3rd party Applications using only the PACKAGE_USAGE_STATS permission in order to track the activity that is currently in the foreground. The difference with similar &quot;App Switch&quot; attacks is that the overlay integrates the GUI of the victim app regardless of the activity that is currently active. As a show case I demonstrate an approval to a fraudulent bank transaction which without my attack would be rejected by the user.     
- In the last core section, I describe how to defend Android applications from this attack since, even though Google provided a fix for system dialogs, 3rd party applications are still vulnerable.  
- Wrapping up and key takeaways.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/Q89X9U/</url>
            <location>Salle Europe</location>
            
            <attendee>Dimitrios Valsamaras</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>EMHDSZ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-EMHDSZ</pentabarf:event-slug>
            <pentabarf:title>Raiders of the Lost Arts</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T112000</dtstart>
            <dtend>20231019T115000</dtend>
            <duration>003000</duration>
            <summary>Raiders of the Lost Arts</summary>
            <description>Vintage clothing, computers from the 80s, vinyl and retro-games are all the rage: everything that was once old and outdated is making a comeback. Surely we infosec folk are unaffected by such trends. Aren&apos;t we at the bleeding edge of the future, protecting our assets with expensive vendors solution that declare their effectiveness with proper buzzwords; Real-Time, Cloud Based and Always On? 

Unfortunately, this does not seem to be the case. Sure, some modern problems have been addressed, but old and sometimes even ancient attacks persist. Some of them don&apos;t show up in your logs, and some are difficult to defend against, assuming you are even looking for them. 

Can you DDoS a company by sending letters? How much revenue will you lose if the neighboring building receives an unexpected package? Who really gets into trouble when you drop a few USB sticks in the parking lot? 

Lean back and enjoy an overview of the dangers of unencrypted, unauthenticated protocols, exploitation of human expectations, sabotage and how to spot if someone on the inside is trying to ruin your day without even touching their computer.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/EMHDSZ/</url>
            <location>Salle Europe</location>
            
            <attendee>Stefan Hager</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NN9AHG@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-NN9AHG</pentabarf:event-slug>
            <pentabarf:title>Token Smart Contract Analyzer</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T133000</dtstart>
            <dtend>20231019T133500</dtend>
            <duration>000500</duration>
            <summary>Token Smart Contract Analyzer</summary>
            <description>Smart contracts have demonstrated new ways to manage and trade digital assets, conduct financial transactions, and transform business processes. Several concepts have emerged to enable investors to own or trade digital assets. Trading platforms relying entirely on decentralized, known as decentralized exchanges, allow unrestricted financial transactions to exchange digital assets. Beyond the opportunities offered, using the decentralized environment remains complex to understand by most of its users, consequently giving adversaries opportunities to benefit from investors based on scamming schemes. The cryptocurrency market is damaged by malicious actors that aim to drain investor funds via scamming token smart contracts. This research paper initially highlights related problems with fraudulent token contracts. Further, it proposes a solution for identifying several fraudulent schemas in the crypto ecosystem via a dynamic algorithmic solution supported by the SC Analyzer tool based on real-time data.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/NN9AHG/</url>
            <location>Salle Europe</location>
            
            <attendee>TGrandjean</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>VXJJP7@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-VXJJP7</pentabarf:event-slug>
            <pentabarf:title>Suricata Language Server</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T133500</dtstart>
            <dtend>20231019T134000</dtend>
            <duration>000500</duration>
            <summary>Suricata Language Server</summary>
            <description>Suricata Language Server (SLS) is released under the GPLv3 license and is known to work on most editors including vim, neovim, emacs, kate and Visual code.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/VXJJP7/</url>
            <location>Salle Europe</location>
            
            <attendee>Eric Leblond</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7UTMU8@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-7UTMU8</pentabarf:event-slug>
            <pentabarf:title>Wintermute: an LLM pen-testing buddy</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T134000</dtstart>
            <dtend>20231019T134500</dtend>
            <duration>000500</duration>
            <summary>Wintermute: an LLM pen-testing buddy</summary>
            <description>We analyze the impact of different prompt designs, benefits
of in-context learning, and the advantages of offering highlevel guidance to LLMs. We discuss challenging areas for
LLMs, including maintaining focus during testing, coping
with errors, and finally compare them with both stochastic
parrots as well as with human hackers.

The research will be published on arxiv.org the week of hack.lu.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/7UTMU8/</url>
            <location>Salle Europe</location>
            
            <attendee>Aaron Kaplan</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>YGXGV7@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-YGXGV7</pentabarf:event-slug>
            <pentabarf:title>SLP DoS Amplification - someone is having fun</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T134500</dtstart>
            <dtend>20231019T135000</dtend>
            <duration>000500</duration>
            <summary>SLP DoS Amplification - someone is having fun</summary>
            <description>CVE-2023-29552 is a recent high profile vulnerability that allows for one of the most powerful and still working denial of service reflective amplification attack. 
Someone has been having fun and we can see it. 
In five minutes, will explain what this type of attack is and in particular CVE-2023-29552, who is affected and one of the several creative uses that allows us to see what is going on at the moment.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/YGXGV7/</url>
            <location>Salle Europe</location>
            
            <attendee>Pedro Umbelino</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>9KSPFC@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-9KSPFC</pentabarf:event-slug>
            <pentabarf:title>DER Editing, Easy-Peasy with asn1template</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T135000</dtstart>
            <dtend>20231019T135500</dtend>
            <duration>000500</duration>
            <summary>DER Editing, Easy-Peasy with asn1template</summary>
            <description>https://github.com/wllm-rbnt/asn1template/blob/main/README.md</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/9KSPFC/</url>
            <location>Salle Europe</location>
            
            <attendee>William Robinet</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MFUYZL@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MFUYZL</pentabarf:event-slug>
            <pentabarf:title>Supply chain resilience: challenges &amp; solutions</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T135500</dtstart>
            <dtend>20231019T140000</dtend>
            <duration>000500</duration>
            <summary>Supply chain resilience: challenges &amp; solutions</summary>
            <description>In today&#8217;s interconnected world, organisations rely on a complex network of suppliers, providers, and contractors to deliver software, hardware, and services. However, this very interconnectedness poses a significant cybersecurity risk &#8211; supply chain attacks. In this lightning talk, we will share some insights &amp; thoughts on managing and securing an organisation&#8217;s supply chain.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/MFUYZL/</url>
            <location>Salle Europe</location>
            
            <attendee>Sa&#226;d Kadhi</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>M8VTSS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-M8VTSS</pentabarf:event-slug>
            <pentabarf:title>Open Wounds: The last 5 years have left Bluetooth to bleed</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T140000</dtstart>
            <dtend>20231019T143000</dtend>
            <duration>003000</duration>
            <summary>Open Wounds: The last 5 years have left Bluetooth to bleed</summary>
            <description>.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/M8VTSS/</url>
            <location>Salle Europe</location>
            
            <attendee>Xeno Kovah</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>WULFLD@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-WULFLD</pentabarf:event-slug>
            <pentabarf:title>The rise of malicious MSIX file</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T143000</dtstart>
            <dtend>20231019T150000</dtend>
            <duration>003000</duration>
            <summary>The rise of malicious MSIX file</summary>
            <description># Basics of MSIX file
First, we will present a basics of MSIX file, including how it was devised, what features it provides, and its file format and the behavior. We will also cover how to create MSIX files and its third-party builders. In addition, this chapter will provide what the Package Support Framework is and how it can be exploited by threat actors.

# Attack Cases
In this chapter, we will detail specific attack cases of MSIX file abuse. In particular, we will share attack cases by an attack group we call SteelClover. SteelClover, also known as DEV-0569 or Water Minyades, is a financially motivated threat group that has been active since around 2019. This attack group delivers malware through Exploit Kit or fake software distribution starting with a malvertising. We have confirmed that they began abusing MSIX files in March 2023. This chapter will briefly offer basic information on SteelClover and victimology, and then share specific attack flows. Additionally, we will show a detailed process tree and our analysis result of how a malicious MSIX file is delivered to a potential victim user, and how it causes a compromise when executed. This gives the audience an in-depth understanding of actual attack cases that exploit MSIX files.

# Defense
This chapter will focus on defenses against attacks that exploit MSIX files. For example, it will provide interesting characteristics of file creation, process creation, and other behaviors, along with specific detection logic to detect these behaviors. MSIX files have many characteristic behaviors, and without knowing them, it is extremely difficult to understand the nature of the breach. This chapter will enable the audience to know how to protect your own organization against MSIX file abuses and to take concrete actions.

# Wrap-Up
Finally, we will wrap up our presentation. Based on specific attack cases of compromise using MSIX files, we will consider defensive measures to protect one&apos;s own organization from such threats. This session will help the audience gain a basic overview of an MSIX file and a deeper understanding of attack cases that exploit MSIX files, and to take concrete countermeasures.

# Appendix: IoCs
We will list the IoCs of the malicious MSIX files presented in this session.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/WULFLD/</url>
            <location>Salle Europe</location>
            
            <attendee>Shogo Hayashi</attendee>
            
            <attendee>Rintaro Koike</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>YAQLW9@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-YAQLW9</pentabarf:event-slug>
            <pentabarf:title>Reviving our oldest Tool - Using Bayesian inference to detect cyber attacks</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T150000</dtstart>
            <dtend>20231019T152000</dtend>
            <duration>002000</duration>
            <summary>Reviving our oldest Tool - Using Bayesian inference to detect cyber attacks</summary>
            <description>Crowdsec is an open source IPS/IDS that is built on the leaky bucket algorithm. This algorithm can detect a lot of common cyber attack patterns such as bruteforce attacks or exploits with known payload delivery vectors such as log4shell. However it is suboptimal at detecting attacks at the application level. To amend this we created the Bayesian bucket, which uses Bayesian inference internally to determine whether a given user is behaving in fraudulent ways. Bayesian inference has long been used to fight email spam and we show that it is quite adept at fighting other cybercrime. 
In particular we present:
* How we implemented the Bayesian bucket
* How you can train it using our open source toolkit
* A demo on real world data</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/YAQLW9/</url>
            <location>Salle Europe</location>
            
            <attendee>Emanuel Seemann</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>YXMSQV@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-YXMSQV</pentabarf:event-slug>
            <pentabarf:title>Using Apple Sysdiagnose for mobile forensics and integrity checks</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T153000</dtstart>
            <dtend>20231019T160000</dtend>
            <duration>003000</duration>
            <summary>Using Apple Sysdiagnose for mobile forensics and integrity checks</summary>
            <description>Intended audience: Incident handlers and forensic investigators.

Introduction:
---------------
For a long time, the incident response analysis of iOS devices has been&#8230; essentially challenging.

While the analyst is usually interested in understanding what the system was doing (system logs), typical acquisition tools only focus on collecting users&#8217; data. Thus they often do not provide what the incident responder was looking for. Furthermore, the usual way to get access to the full device is by jailbreaking the device or using specialised (expensive) tools reserved for law enforcement. Jailbreaking has the downside of breaking the chain of custody and therefore the trust in the final state of the device as well as the immutability of the analysis is put into question.

Enter Sysdiagnose&#8230;
-----------------------

This talk will focus on repurposing an Apple feature which was originally intended for diagnostic and debugging purposed for developers as well as for repair shops.
The Sysdiagnose process on Apple devices collects data on how the system behaves and is typically what an analyst wants to look at.

Collecting Sysdiagnose artefacts
-----------------------------------
Sysdiagnose is triggered by a user action and creates archives containing system information in various formats, such as:
- plist configuration files
- logs and output of commands
- sqlite databases with application histories etc.

The result can be extended by pushing extra profiles to the device that turn on extra debugging and enhance the content of the archive.

Collecting Sysdiagnose archives on IOS
-------------------------------------------
While the process is well described on Apple&#8217;s website, we will quickly show how to start the acquisition process on an iPhone and how to retrieve the data via a few different techniques ranging from AirDrop to typical forensic tools.

Collecting Sysdiagnose archives on other Apple devices
------------------------------------------------------------
While the research motivating this talk is coming from the need to analyse iOS devices, in practice the features which we are looking at will be available throughout all of Apple OSes:
- Mac OS (MacBook Air, MacBook Pro, Mac Pro, iMac&#8230;)
- Watch OS (Apple Watch)
- iPad OS (for tablets)
-TV OS (Apple TV)
- &#8230;

Extracting information from Sysdiagnose archives and building a timeline
------------------------------------------------------------------------------
In this part we will present some Python scripts to extract all timestamped information from the Sysdiagnose archive in order to build a timeline in your favorite timeline analysis tool

Splunk &amp; Timesketch
In order to perform investigations on the gathered data, an easy solution is to import it into a dedicated SIEM. In this part, we will present how we standardise the outputs from our scripts to easily import them into tools like Splunk for further forensics analysis. We also developed a re-usable TimeSketch module to import the generated timeline in TimeSketch.

Challenges
--------------------
Sysdiagnose is calling different tools and commands to generate its output. Unfortunately, all those tools have their own output format, especially regarding timestamps. We will present some specificities of Sysdiagnose&#8217;s output and how we handled them.

Identifying IOS system tampering using Sysdiagnose artefacts
-------------------------------------------------------------------
In this section we show practically how an iOS device can be analysed by using the Sysdiagnose artefacts and their value: applicate update history, running processes, memory mapping&#8230;

Examples of investigation
----------------------------
In this section we shows practical examples of analysis with Sysdiagnose. We did a few Sysdiagnose acquisitions on test devices to simulate scenarii and prove the effectivness of this analysis technique.

Issues and limits of Sysdiagnose
-----------------------------------
The Sysdiagnose process raises a few issues and concerns:

The data is collected by a process which runs on the investigated device. The output can only be trusted as long as it runs normally. Rootkits and binaries alteration could affect the results and lead to wrong conclusions.

The format of the files included into the archive depends on the version of iOS and running applications. The SQLite DB schema, for instance, can radically change with an application update. Keeping a working toolset therefore requires continuous research, testing and validation.

The Sysdiagnose output is mostly undocumented. Every single file needs to be manually analysed and understood to correctly interpret the results and avoid wrong conclusions.

Alternative ways to check integrity
--------------------------------------
In this last section we will discuss how integrity can be checked by using more intrusives methods that could be combined with a jailbreak. While those techniques give a full access, they will also question the value of the results from a forensic perspective due to their intrusiveness.

References
------------
https://www.jessesquires.com/blog/how-to-sysdiagnose-ios/
https://www.manpagez.com/man/1/sysdiagnose/
https://github.com/cheeky4n6monkey/iOS_sysdiagnose_forensic_scripts
https://www.apple.com/business/docs/site/iOS_Security_Guide.pdf
https://developer.apple.com/bug-reporting/profiles-and-logs/
https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/YXMSQV/</url>
            <location>Salle Europe</location>
            
            <attendee>David Durvaux</attendee>
            
            <attendee>Aaron Kaplan</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>FXZEVC@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-FXZEVC</pentabarf:event-slug>
            <pentabarf:title>A deep dive into Maritime Cybersecurity.</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T161500</dtstart>
            <dtend>20231019T164500</dtend>
            <duration>003000</duration>
            <summary>A deep dive into Maritime Cybersecurity.</summary>
            <description>Although it is still too little known, the maritime and port sector is essential to our modern economies. Ships and ports should now be seen as complex information systems. 
This increased digitalisation brings with it new risks that must be taken into account by international organisations, administrations, public and private operators, shipowners and shipbuilders.
What are the vulnerabilities? Which incidents happened over the last years?
After a description of the sector for the non-mariners, we will take a deep dive into the maritime systems, and detail the unique incident statistics we compile at the Maritime Computer Emergency Response Team.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/FXZEVC/</url>
            <location>Salle Europe</location>
            
            <attendee>JACQ</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>DCQYBF@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-DCQYBF</pentabarf:event-slug>
            <pentabarf:title>Operation Duck Hunt - A peak behind the curtain of DuckTail</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T164500</dtstart>
            <dtend>20231019T171500</dtend>
            <duration>003000</duration>
            <summary>Operation Duck Hunt - A peak behind the curtain of DuckTail</summary>
            <description>Through an extensive investigation into DuckTail&apos;s infrastructure, a critical vulnerability in their exfiltration methodology was uncovered. The exploitation of this flaw resulted in the acquisition of numerous screenshots extracted from the personal machines of the threat actors, exposing glaring deficiencies in operational security (OPSEC) practices.

These screenshots provide a revealing glimpse into various aspects of DuckTail&apos;s operations. Notably, they divulge fragments of the infostealer&apos;s source code, reveal the techniques employed by the threat actors to disseminate the malware, and unveil confidential dialogues exchanged among the perpetrators, ultimately leading to their identification.

This talk will delve into the intricacies of DuckTail&apos;s exfiltration infrastructure and its inherent weakness. I will demonstrate the threat actors&apos; methods of infection and delivery. Furthermore, attendees will gain invaluable insights into the clandestine activities that unfolded behind the scenes, providing a comprehensive understanding of the broader context.

It will shed light on the concealed elements of DuckTail&apos;s operations, offering a unique opportunity to deepen your knowledge of the evolving cyber threat landscape, highlighting how modern criminal enterprises operate and infect their targets.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/DCQYBF/</url>
            <location>Salle Europe</location>
            
            <attendee>Pol Thill</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MGMYZA@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MGMYZA</pentabarf:event-slug>
            <pentabarf:title>Kunai: your new Threat Hunting tool for Linux</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T171500</dtstart>
            <dtend>20231019T174500</dtend>
            <duration>003000</duration>
            <summary>Kunai: your new Threat Hunting tool for Linux</summary>
            <description>This presentation aims to introduce the community to Kunai, a new Threat Hunting tool designed specifically for Linux Systems.

I&apos;ll start by discussing the project&apos;s origin and my motivations for initiating it, followed by an exploration of the tool&apos;s inner workings and implementation details. This section will conclude with an overview of the challenges encountered during the tool&apos;s development.

Next, I will highlight its key features, emphasizing how it differs from existing tools. The latter part of this section will explore practical Threat Hunting scenarios that can be realized with the tool.

In conclusion, I will summarize the key takeaways from this tool and share our future plans for its development.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/hack-lu-2023/talk/MGMYZA/</url>
            <location>Salle Europe</location>
            
            <attendee>Quentin JEROME</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7G8EKN@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-7G8EKN</pentabarf:event-slug>
            <pentabarf:title>Full Stack Forensics with FOSS</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T140000</dtstart>
            <dtend>20231019T160000</dtend>
            <duration>020000</duration>
            <summary>Full Stack Forensics with FOSS</summary>
            <description>- Introduction
  - What to expect of the workshop
- Quick tour / install / configuration
  - Timesketch
  - Yeti
- Adding some forensics intelligence to Yeti
- Your first forensic analysis with Timesketch!
- Adding threat intelligence to the mix

Optional (if time permits)
  - dfTimewolf
  - Configuring all these tools to work together, triggering a first analysis
    using dfTimewolf.
  - Tweaking Timesketch analyzers</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/7G8EKN/</url>
            <location>Schengen 1 and 2</location>
            
            <attendee>Thomas Chopitea</attendee>
            
            <attendee>S&#233;bastien Larinier</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>TLTFKF@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-TLTFKF</pentabarf:event-slug>
            <pentabarf:title>Building Your Own Workflows in MISP: Tutorial and Hands-on</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T161500</dtstart>
            <dtend>20231019T174500</dtend>
            <duration>013000</duration>
            <summary>Building Your Own Workflows in MISP: Tutorial and Hands-on</summary>
            <description>MISP has been a widely used open source CTI platform for the past decade, with a long list of tools that allow users to customise the data models and contextualisation of the platform, yet true customisation of the actual workflows and processes had to be done externally using custom scripts.
With the introduction of MISP workflows, this has changed and the workshop aims to walk the audience through some of the potential ideas of how one could adapt the tool to their own CSIRT&#8217;s or SOC&#8217;s workflows by using some hands-on examples during the session.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/TLTFKF/</url>
            <location>Schengen 1 and 2</location>
            
            <attendee>Sami Mokaddem</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T090000</dtstart>
            <dtend>20231019T103000</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T103000</dtstart>
            <dtend>20231019T120000</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UDFFNS@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UDFFNS</pentabarf:event-slug>
            <pentabarf:title>Dismantle the bomb</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T140000</dtstart>
            <dtend>20231019T153000</dtend>
            <duration>013000</duration>
            <summary>Dismantle the bomb</summary>
            <description>In a 90 minute workshop a team of max. 5 persons can enter the room. During the first 15 minutes they will receive a briefing on the mission. The countdown timers starts the mission (75 minutes)
Goal is to stop the countdown timer connected to a bomb fixed on a 10l white paint bucket</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://pretalx.com/hack-lu-2023/talk/UDFFNS/</url>
            <location>Echternach&amp;Diekirch</location>
            
            <attendee>Stijn Tomme</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>PFNABT@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-PFNABT</pentabarf:event-slug>
            <pentabarf:title>CyberChef: Enhancing Existing Operations and Adding New Operations</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T140000</dtstart>
            <dtend>20231019T160000</dtend>
            <duration>020000</duration>
            <summary>CyberChef: Enhancing Existing Operations and Adding New Operations</summary>
            <description>Like usual with workshops from Didier Stevens, this will be very hands-on with many exercises.
This workshop requires a Linux laptop or a Windows/Linux/Mac laptop with a Linux virtual machine.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/PFNABT/</url>
            <location>Hollenfels</location>
            
            <attendee>Didier Stevens</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MSZDZD@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MSZDZD</pentabarf:event-slug>
            <pentabarf:title>DFIRTrack - The Incident Response Tracking Application</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T100000</dtstart>
            <dtend>20231019T120000</dtend>
            <duration>020000</duration>
            <summary>DFIRTrack - The Incident Response Tracking Application</summary>
            <description>Are you an Incident Responder working on large (customer) security incidents? Are you tired of maintaining huge spreadsheets (aka _Spreadsheet of DOOM_)? Do you have to manually create customer system or artifact reports? Then DFIRTrack may be just what you are looking for...

In this workshop we will show you how to install, configure and use DFIRTrack. We will cover the following features in detail:
- Installation ( manually and using docker or ansible)
- Configuration and customization
- Overview of the main entities (systems, artifacts, tasks, ...)
- Import, export and manipulation capabilities
- Automation through scheduled tasks and workflows
- Roadmap, feedback and feature discussion

Most things will be done through hands-on examples. A notebook is required, ideally with a working Docker setup.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/MSZDZD/</url>
            <location>Vianden&amp;Wiltz</location>
            
            <attendee>Mathias Stuhlmacher</attendee>
            
            <attendee>Lionne Stangier</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>9ZY9VJ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-9ZY9VJ</pentabarf:event-slug>
            <pentabarf:title>As We Are Many</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20231019T140000</dtstart>
            <dtend>20231019T170000</dtend>
            <duration>030000</duration>
            <summary>As We Are Many</summary>
            <description>On a Linux system we will prepare an USB stick with 3 little test files like &apos;test1.txt&apos;, &apos;test2.txt&apos; and &apos;test3.txt&apos; with some little test content inside. If connecting the spooky USB stick to a Windows based PC (VM guest) the USB stick is mounted and we see three &apos;.txt&apos; files. But the content is different and doesn&apos;t match the content we created on the Linux PC.

Analyzing the stick with different tools leads to confusing results. It does not help to understand what is going wrong here. The idea of this workshop is to provide the students with the knowledge to build their own *spooky* USB stick.

Students should bring a Linux alike workstation and an empty USB stick, to build their own *spooky* USB stick.. A VM with a Windows OS guest system would help to test the results.

Attendees should be familiar with the command line interface.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Training</category>
            <url>https://pretalx.com/hack-lu-2023/talk/9ZY9VJ/</url>
            <location>Vianden&amp;Wiltz</location>
            
            <attendee>Michael Hamm</attendee>
            
        </vevent>
        
    </vcalendar>
</iCalendar>
