Attention: You are using an outdated browser, device or you do not have the latest version of JavaScript downloaded and so this website may not work as expected. Please download the latest software or switch device to avoid further issues.
Join us and earn xx CPEs!
This is a community event specifically for people who work in or around security operations, or who are interested in switching to this field or expanding their knowledge. The content is primarily technically oriented.
CEOs, founders, co-founders, vendors, and all salespeople are not permitted to attend this event.
(We're still working on this agenda)
|
1:30 pm |
Registration
|
|
2:00 pm |
Welcome & short introduction from Mark Beerends, SIGS Contributor & Cyber Strategy Partner at Prusec GmbH
|
|
2:00 pm |
Patrick Lodder, Global Head of Threat Intelligence Services at NVISO Security VSHELL - Tracking a State actor used Modern Post-Exploitation Framework in the Wild This presentation provides a short overview of how VShell works and why it is attractive for adversaries. We will then focus on what happened after disclosure: how VShell infrastructure can still be fingerprinted today, how tracking methods have evolved, and what we have observed in the wild over the past year. Using practical examples from real world tracking, we demonstrate how network fingerprints, infrastructure patterns, and traffic analysis still allow defenders and investigators to monitor VShell deployments and identify potential victims. The session will also reflect on the broader question of whether public threat research actually changes attacker behaviour, or whether many detection and tracking opportunities remain effective long after publication.
|
|
2:30 pm |
Nicolas Heiniger, Senior Red Team Operator at Swiss Re Choose your own Adventure - Red Team Edition
|
|
3:15 pm |
Nils Maeckelberghe, Co-Founder & Managing Director of Crimson7 Always Under Attack: Continuous (AI) Purple Teaming Attendees leave with a repeatable model for behavior-level detection validation, a live look at how detections regress between tests and how to catch it the week it happens, and a closed attack-to-defense loop that turns every missed technique into a rule the blue team keeps. KEY TAKEAWAYS
|
| 3:25 pm |
Short presentation from a sponsor
|
|
3:35 pm |
Break
|
|
4:15 pm |
4 different Breakout Sessions to join - you can choose/attend two of them |
|
|
|
|
|
Breakout Session 1: Andra-Irina Vasile, Senior Business Information Security Officer at SIX Group & Founder at Netiquetteers From Tool to Teammate: Making AI a Strategic Partner in Cybersecurity KEY POINTS
|
|
|
|
|
|
Breakout Session 2: Markus Riegler, Senior Executive - Cyber Threat Intelligence at IKARUS Security Software GmbH From Report to Detection: Using LLMs to Transform Cyber Threat Intelligence into Actionable Detection Rules |
|
|
|
|
|
Breakout Session 3: Nils Maeckelberghe, Co-Founder & Managing Director of Crimson7 A journey which will allow you to detect and remediate the most sophisticated attacks What if defenders operated in the same way? In this talk, we explore how institutions can combine Cyber Threat Intelligence (CTI), Continuous Purple Teaming, Detection & Response-as-code (DRaC), and Threat Hunting to build a continuously validated detection capability; one that turns shared intelligence into tested controls and measurable defensive coverage, allowing you to move at the Speed of Threat. |
|
|
|
|
|
Breakout Session 4: (details will follow) |
|
|
|
|
5:20 pm |
Short break and change the room to the next Breakout Session of your choice
|
|
5:30 pm |
Start of the second Breakout Session round
|
|
6:30 pm |
Dinner & Networking till open end |
Event Moderator
Mark Beerends
SIGS Contributor & Cyber
Strategy Partner at Prusec GmbH
Event Speakers and Roundtable Moderator
|
Nicolas Heiniger |
|
Patrick Lodder Global Head of Threat Intelligence Services at NVISO |
| Markus Riegler Senior Executive - Cyber Threat Intelligence at IKARUS Security Software GmbH |
Andra-Irina Vasile |
|
|
|