BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2023//speaker//MMJXP7
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20221017T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20221030T030000
RDATE:20231029T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20230326T030000
RDATE:20240331T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Yeti - old dog\, new tricks - Thomas Chopitea\, Sébastien Larinie
 r
DTSTART;TZID=Europe/Luxembourg:20231017T175500
DTEND;TZID=Europe/Luxembourg:20231017T182500
DTSTAMP:20260816T193024Z
UID:pretalx-hack-lu-2023-JAKAKS@pretalx.com
DESCRIPTION:[Yeti](https://github.com/yeti-platform/yeti) is an opensource
  platform dedicated to the curation and management of operational threat i
 ntelligence\,\ngeared towards incident responders and forensic practitione
 rs. It's written in Python and maintained since ~2017.\n\nIt consists of s
 everal modules:\n\n- a graph database & search engine\n- a threat feed ing
 estion engine\n- a data enrichment module (e.g. sandbox information\, doma
 in resolution\, IOC extraction...)\n- Signature management (YARA\, Sigma\,
  etc.)\n- High-level entity management (Threat actors\, TTPs\, Campaigns) 
 to tie everything together in a neat graph database.\n\nYeti has existed s
 ince 2017\, and is used both in industry and academia\, and has\nrecently 
 been undergoing several big changes\, which we would like to present at\nC
 TI-Summit 2023:
LOCATION:Salle Europe
URL:https://pretalx.com/hack-lu-2023/talk/JAKAKS/
END:VEVENT
BEGIN:VEVENT
SUMMARY:Full Stack Forensics with FOSS - Thomas Chopitea\, Sébastien Lari
 nier
DTSTART;TZID=Europe/Luxembourg:20231019T140000
DTEND;TZID=Europe/Luxembourg:20231019T160000
DTSTAMP:20260816T193024Z
UID:pretalx-hack-lu-2023-7G8EKN@pretalx.com
DESCRIPTION:This workshop will showcase a suite of free and open source to
 ols to leverage\nthreat intelligence in DFIR investigations. Participants 
 will be setting up a\nfull forensics pipeline\, including collection ([GRR
 ](https://github.com/google/grr))\, processing\n([Plaso](https://github.co
 m/log2timeline/plaso)) and analysis ([Timesketch](https://github.com/googl
 e/timesketch/))\, and orchestration\n([dfTimewolf](https://github.com/log2
 timeline/dftimewolf)). In addition to that\, they'll be using [Yeti](https
 ://github.com/yeti-platform/yeti) to augment\ntheir processing and analysi
 s with threat intelligence.\n\nThw workshop will last two hours and is ope
 n for anyone to attend. Experience\ninstalling packages on Linux and using
  the Linux CLI in general is required.\nExperience running and managing Do
 cker containers would be a nice addition.\n\nParticipants will be given an
  initial list of Docker containers to pull and set\nup before the workshop
 \n\n[UPDATE] Here's the list! https://docs.google.com/document/d/1TKqOleH2
 rdtPjybUt3PYybJ7RrH59kqaHnmywJhRPGk/preview\n\n[UPDATE2] Here's the slides
  with the links to everything: https://docs.google.com/presentation/d/1_II
 hazlZF4Nxa_fn4YJ0SieFPJGzP91OwuAO4LIUWOg/edit#slide=id.g24fcb0d3240_0_70
LOCATION:Schengen 1 and 2
URL:https://pretalx.com/hack-lu-2023/talk/7G8EKN/
END:VEVENT
END:VCALENDAR
