PyCon JP 2024

Your locale preferences have been saved. We like to think that we have excellent support for English in pretalx, but if you encounter issues or errors, please contact us!

Python Powered "Cyber Security" - Tools, Techniques, Exploitation and Automation
2024-09-27 , 4F Track3

In this talk, I'll emphasize Python's pivotal role in addressing cybersecurity challenges, highlighting its versatility and impact. Also, I'll share how I automated Python skills to safeguard the bank corporate site from potential backdoor attacks.

Moreover, I will delve into Python's significance across various cybersecurity domains, including OSINT, Penetration Testing, Vulnerability Assessment, Incident Response, Digital Forensics, SIEM/SOAR, Malware Analysis, Behavioral Analysis, and will showcase a few Python tools and libraries that are handy for conducting these tasks, such as Nmap, SQLmap, Impacket, Scapy, Legion, and essential libraries like Requests, BeautifulSoup4, re, JSON, etc.


Why did you choose this topic?

Because I've been working in Cyber Security for almost a decade now, Python has always been instrumental throughout my journey. Whether it's writing an exploit, utilizing Python automation, or developing Python-based scanners or security-focused web platforms with Django and Flask, Python has consistently supported my endeavors. If you take a look at my GitHub repository, you'll find several Python-based security tools that I've built. (https://github.com/TheNittam)

However, when people hear about PyCon, they often assume it's solely focused on development and Python is all about Development. But in reality, Python has a massive community base in Cyber Security as well. From Pentesting and Incident Response to Digital Forensics and Malware Analysis, Python is ubiquitous. I've chosen this topic to raise awareness that Python's utility in Cyber Security is extensive, longstanding, and continually evolving.

Knowledges and know-how the audience can get from your talk

Below are the takeaways of the Talk.

  1. Understanding Python's pivotal role in addressing cybersecurity challenges.
  2. Recognizing Python's versatility and impact in the field of cybersecurity.
  3. Learning how to automate Python skills can help safeguard from the attacks.
  4. Get to know with python based some awesome Cyber Security Tools/Libraries like Nmap, SQLmap, Impacket, Scapy, Legion, MobSF, Essential libraries like Requests, BeautifulSoup4, re, JSON, etc.
Prior knowledges speakers assume the audience to have

Basic Python and Web Application Workflow Knowledge.

Audience experiment

Intermediate

Language of presentation

English

Language of presentation material

English

Nirmal Dahal, also known as TheNittam or #Nittam. I've been in the cybersecurity industry for a long time and have helped secure over 50+ enterprises against cyber threats. With the goal of securing cyberspace, I co-founded CryptoGen Nepal with other like-minded individuals, which is a Nepal-based cybersecurity firm that has also won the ICT Startup Award. I am the leader of Nepal's largest community of ethical hackers, "Pentester Nepal" and the Nepal Chapter Leader for OWASP (Open Web Application Security Project). We organize cyber security events, raise awareness, share knowledge, and train people about cyber security and potential cyber threats. In April 2021, I was listed on the EC-Council's "Global Ethical Hacking Leaderboard" among the top 10 ethical hackers in the world for the month of April 2021, Quarter 2. Due to my activities and expertise in the cyber security field, I've been featured in magazines and national newspapers. In Quarter 1 of 2017, I was listed as the top 25 hackers on the YESWEHACK platform which is Europe's first BugBounty Platform.