Hack.lu 2026

Pauline Bourmeau (Cookie)

Pauline Bourmeau is an independent security researcher specializing in the intersection of artificial intelligence, cognitive psychology, and threat intelligence. She has consulted on multilingual natural language processing, led deep learning and NLP workshops, and created training materials blending STEM with human factors. As founder of DEFCON Paris and contributor to the MISP project, she actively advances collaborative cybersecurity practices.
Previously, Pauline worked as a Threat Intelligence Analyst conducting OSINT, HUMINT, and SOCINT analysis to profile threats and investigate APTs. She holds a Master’s in Criminology with a thesis on cybersecurity intelligence sharing, and a background in sociolinguistics and computer science from Sorbonne and School 42.


Sessions

10-20
10:45
30min
SPOT - Spear-Phishing Overwatching Tool
Mathieu Fourcroy, Pauline Bourmeau (Cookie), William Robinet

Nowadays, the detection of generic mass-scale phishing attacks is quite effective. Techniques that leverage indicators of compromise (IOCs) collection and sharing tools, such as MISP (the Open Source Threat Intelligence Sharing Platform), are well established and give good results in the field. However, detection of targeted attack attempts aka spear-phishing, is much more challenging because the attackers exploit contextual information about the targets they aim for.
By using up-to-date, relevant and precise information about the inner operations of the targeted company, attackers can make their deception far more effective.
SPOT makes use of state-of-the-art natural language processing (NLP) techniques based on machine learning (ML) and large language models (LLMs) in particular to try to detect and prevent spear-phishing attack attempts.

topic: hack.lu
Europe
10-21
10:15
120min
Applied Transformer NLP for Cybersecurity
Pauline Bourmeau (Cookie)

A hands-on two-hour workshop covering applied transformer-based NLP for cybersecurity using the HuggingFace Transformers library. Participants build a complete threat intelligence pipeline from scratch — entity extraction, classification, summarization, and semantic ATT&CK mapping — using only open-source models running locally.

topic: hack.lu
Vianden & Wiltz