BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//orangecon-2024//talk//ZEXPCK
BEGIN:VTIMEZONE
TZID:Europe/Amsterdam
BEGIN:DAYLIGHT
DTSTART:20230906T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20231029T030000
RDATE:20241027T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20240331T030000
RDATE:20250330T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Protecting organizations against AITM: lessons learned. - Rik van 
 Duijn\, Wesley
DTSTART;TZID=Europe/Amsterdam:20240905T133000
DTEND;TZID=Europe/Amsterdam:20240905T140000
DTSTAMP:20260816T225003Z
UID:pretalx-orangecon-2024-ZEXPCK@pretalx.com
DESCRIPTION:Protecting Hundreds of Organizations Against AiTM: Lessons Lea
 rned" dives into the evolving threat of AiTM) attacks. Our presentation hi
 ghlights the transition from basic phishing tactics to sophisticated metho
 ds that compromise organizational security. The presentation outlines the 
 journey from oldschool phishing attacks\, to phishing framework like UADMI
 N\, and the introduction of tools like Evilginx. And now the SaaS provider
 s allowing anyone to buy access to an AiTM platform.\n\nWe’ve introduced
  a free method of detecting AiTM attacks. Which has allowed us an insight 
 into the scale of AiTM attacks atleast against Microsoft M365 tenants. Thi
 s prompted the development of a fingerprinting tool to gain an insight int
 o the different actors performing these attacks and typical methods they e
 mploy.  \n\nWe give an insight into a popular AiTM SaaS platform and the r
 evenue stream hosting such software creates. The session ends by outlining
  common techniques to prevent these types of attacks. Most organizations u
 se M365 and experience attacks using AITM to bypass MFA. At the same time 
 SaaS providers are building AITM services that allow targeteted attacks al
 lowing for supply chain attacks (AITM targeted against admin sites for: py
 pi\, npmjs and rubygems). At the same time used for very specific scams fo
 r example against booking.com. Attackers use the booking.com hotel login t
 o extract creditcard information for upcomming hotel guests.
LOCATION:Main track
URL:https://pretalx.com/orangecon-2024/talk/ZEXPCK/
END:VEVENT
END:VCALENDAR
