BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//talk//NZBYRK
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251020T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Turning the Tables: Command & no Control - Ben
DTSTART;TZID=Europe/Luxembourg:20261020T154500
DTEND;TZID=Europe/Luxembourg:20261020T161500
DTSTAMP:20261009T050416Z
UID:pretalx-hack-lu-2026-NZBYRK@pretalx.com
DESCRIPTION:Command & Control\, or C2\, is used at some point in all intru
 sions in order for the threat actor to communicate with victim hosts and c
 ontrol them. \n\nThis talk explores how defenders can turn adversary C2 im
 plementations against them by finding mistakes in cryptography\, protocol 
 design\, infrastructure hygiene\, and operational security. Through real-w
 orld case studies\, we will walk through malware that used blockchain-base
 d C2 with weak encryption\, allowing historic commands to be recovered fro
 m public on-chain data\, and a separate campaign where expired attacker in
 frastructure enabled sinkholing\, victim telemetry collection\, and safe r
 eimplementation of server-side C2 behavior for analysis.\n\nRather than tr
 eating C2 as a black box\, this talk shows how reverse engineering\, infra
 structure hunting\, emulation\, and creative defensive thinking can provid
 e intelligence collection opportunities.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/NZBYRK/
END:VEVENT
END:VCALENDAR
