Presentations
The 49 talks accepted for SAINTCON 26, grouped by category.
Red-Team
-
Beware the Phone Call (How to Perform Vishing Engagements)
Vishing may not be everyone’s preferred attack vector, but it remains an effective way to achieve impact during a penetration test. This talk focuses on demystifying vishing by breaking down how to prepare, build confidence, and develop realistic pretexts that make calls feel natural rather than forced. We’ll walk through practical preparation techniques that reduce stress and improve consistency, along with strategies for adapting in real time. Through insights from actual penetration tests, we’ll demonstrate how small pieces of intelligence gathered during calls can be leveraged to refine your approach, strengthen your pretext, and increase success over time. Whether you’re new to vishing or looking to improve your approach, this session will provide actionable takeaways to help you elevate your social engineering engagements.
-
Instant API Hacker!
In this rapid-fire, hands-on tactic, you'll go from zero to hacking your first API in 30 minutes! Find and exploit common REST API vulnerabilities in real-time. No prior hacking experience? No problem! APIs are a great first vector to begin your hacking journey. This workshop is designed for beginners who want quick, practical insights—and some fun along the way.
-
Modern Application Pentesting with GitHub Copilot and the Burp Suite MCP Server
Enter the modern day web application penetration testing methodology that leverages Github Co-pilot and burpsuite MCP to not only inspect your code base, but perform AI powered dynamic testing on it as well. We'll be working against a deliberately vulnerable target that audience members can download and follow along as well. You'll leave knowing how to stand up the workflow that could effectively add web app pentesters to your team.
-
MonkeyX - Human driven, AI Compatible Pentest Automation
The offensive security industry is being flooded with AI powered pentesting tools from heavily funded startups and individual researchers building autonomous hacking frameworks. But where does that leave human hackers? This talk explores a different path. Using automation and AI not to replace offensive security professionals, but to amplify them. Attendees will be introduced to MonkeyX, a human driven, AI-compatible framework designed to orchestrate OSINT, attack surface enumeration, and penetration testing activities while maintaining operator control and visibility. MonkeyX enables practitioners to build custom modules, create reusable workflows, integrate the tools and techniques they already rely on, and scale their capabilities through automation. Through real world examples and live demonstrations, this session will show how offensive security teams can leverage automation and AI to achieve greater speed, consistency, and coverage while preserving the creativity, critical thinking, and expertise that make human led security testing effective.
-
Off The (Book)Shelf Hacking: Hackable eReaders
Kindles, Kobos, Boox and BigMes, there's no shortage of eReaders to choose from in 2026, with their paper-like eInk displays designed for one thing: reading books. But underneath that minimalist surface sits a surprisingly hackable IoT device! But when it comes to these devices there are a few quirks, from the locked-down Kindle in need of a jailbreak, to the xteink's open source Crosspoint firmware.
-
ScamOps: Defending Public Trust from Industrialized Cybercrime
Cybercrime is evolving from isolated technical attacks into a scalable business model. Modern criminal groups now operate repeatable “ScamOps” pipelines that combine reconnaissance, social engineering, synthetic personas, deepfake audio and video, credential theft, payment redirection, mule recruitment, crypto movement, and rapid infrastructure replacement. This talk will examine how AI changes the economics of cybercrime by making these operations cheaper, faster, more persuasive, and easier to localize across languages and borders. While AI does not create the criminal ecosystem, it significantly improves the attacker’s ability to scale deception. The session will also explore how criminals hijack trust in digital government, financial services, mobile payments, and smart-nation platforms. Government impersonation scams are especially dangerous because they weaponize the credibility of public institutions, and recent AI-generated video impersonation cases show how synthetic media can turn suspicious messages into convincing multi-channel deception. Attendees will learn: * How cybercrime operations are becoming scalable ScamOps pipelines * Where AI meaningfully improves attacker speed, persuasion, and localization * Why government impersonation and synthetic media create new trust risks * How agencies can modernize incident response for AI-enabled fraud * How intelligence-led disruption, public-private coordination, crypto tracing, and trust-preserving communications can reduce impact
-
Security Testing LLMs (AI)
This session will cover the basics of what LLMs are, how they work, their inherent security weaknesses, how to setup your own LLM Model and how to test a model for resilience against attacks. We will also cover some of the non-technical risks associated with AI and LLMs that we as a society need to find effective ways to address.
-
Your Biggest Vulnerability Isn't Yours. Lessons from a Vendor Backdoor in Critical Infrastructure
One click during a routine water-treatment pentest, and we were staring at a live SCADA control panel - pumps spinning, valves indicating, chemical mixing - running on the public internet with no authentication. It relayed any backend command an attacker wanted to send: read alarms, override setpoints, dump the entire configuration including encrypted operator credentials. The vendor's response when this was disclosed? "Just enable authentication." The fix wasn't a fix. Three years later, that same backdoor still ships, still hits hundreds of internet-exposed deployments, and now there's a new development: we re-analyzed the entire codebase in an afternoon and found 41 more vulnerabilities, including five end-to-end attack chains the original engagement never had time to enumerate. One of those chains is reverse-engineering the vendor's "proprietary encryption" - which turns out to be a hardcoded key the same in every shipped binary (!) In this presentation, we’ll show five working attack chains for this (live, running) software package and do an in-depth walkthrough of one, showcasing the exploitation process. By the end, you’ll understand why your security program's biggest exposure isn't the code your team wrote - it's the vendor software running inside your perimeter.
Blue-Team
-
"Hold My Coffee, I’m Building a Security Tool": Security Without Gatekeepers in an AI-First World
Security workflows are shifting from human-centric to AI-centric. Meanwhile, AI coding assistants have democratized software development, transforming domain expertise and creative ideas into powerful solutions without requiring a CS degree, and without consequences if things don’t work out. What happens when these trends collide? Experimentation with AI-enabled security tools and workflows becomes practically mandatory. The risk is minimal; the potential rewards are great. Members of Cisco’s Talos team will share case studies from their research in building AI-driven security workflows. Discover lessons for integrating AI into your operations and learn strategies to guide your customers through their AI transformations.
-
AI is going to kill us all (?)
What are we actually doing when it comes to AI? The security industry has veered so far off of our stated mission and allowed a degree of FUD not seen since the 90s to persist. What are we going to do about it and how can we handle the next evolution of technology? SkyNet is optional (?)
-
Beyond the Honeypot - Interactionless Deception
Most cybersecurity deception strategies rely on the "trap"—waiting for an adversary to touch a honeypot or trigger a canary. But what if the most effective deception is the one the attacker never interacts with? Enter interactionless deception: a strategic shift from detection to deterrence, where the mere presence of deceptive artifacts degrades an attacker's confidence and disrupts their momentum. In this session, we will move beyond the "tripwire" mentality to explore how to turn your environment into a psychological minefield. We will map these techniques against the seven most frequently utilized MITRE ATT&CK TTPs, proposing a model for how psychological friction can degrade adversarial success.
-
Eyes on Everything: Hacking Security Cameras and What It Means for Cybersecurity
In this session, we demonstrate how common physical security systems, including network-connected cameras, can be exploited to gain visibility, bypass controls, and pivot deeper into the enterprise. More importantly, we translate these physical security risks into actionable defenses, showing how organizations can harden camera systems and access controls and leverage them to gather telemetry for your SOC team's defenses.
-
Mapping the SaaS Attack Surface: An Open-Source Identity Graph and Change-Detection Engine
Most companies I've worked with can name maybe half their SaaS apps from memory, and almost none can tell you who holds admin across all of them. Access is scattered across identity providers, groups, roles, and the third-party OAuth apps that quietly hold access, each in its own admin console. Kestrel is an open-source project I'm building that pulls users, groups, roles, permissions, resources, and OAuth grants out of each SaaS app and stitches them into one normalized identity graph, showing who has access to what and how it's all connected. Detections are plain Python policies you can read, test, and version in git, and every finding traces back to the raw data behind it. In this session I'll explain how it's built, demo it against test tenants, show the read-only connector framework for Okta, GitHub, Slack, and Google Workspace, and walk through the architecture tradeoffs (including the parts I got wrong the first time).
-
Overfed and Undernourished: The Modern SOC's Decision Crisis
We've spent twenty years building security programs designed to answer one question: "What happened?" The result is an industry drowning in telemetry, dashboards, alerts, threat intelligence, attack paths, and now AI-generated recommendations. We've never had more information, yet many security teams still struggle to prioritize risk, make decisions, and respond effectively when it matters most. Maybe the problem isn't visibility. Maybe we've confused collecting information with understanding it. In this session, we'll challenge the conventional wisdom that more data leads to better security and explore how modern SOCs have become overfed on information but undernourished on context, ownership, and decision-making. Through real-world examples and a new way of thinking about security operations, attendees will learn why the future belongs to organizations that can answer a different question: not "What happened?" but "What should we do next?" This isn't a talk about more tools, more AI, or more visibility. It's a talk about better decisions and why they may be the most overlooked security control in your organization.
-
Scaling Threat Detection with AI using Detection-as-Code
Threat detection from research to implementation has been historically manual and slow. For blue teams operating across sprawling tech stack environments, this can creates a scalability challenge. Meanwhile, threat actors using AI tools have only lowered the barrier to weaponization and exploitation as they accelerate the pace of their attacks. This session explores how AI coding agents, layered on top of a Detection-as-Code foundation, can dramatically compress the path from detection hypothesis to production from weeks to hours and deliver solid detection content at a much faster speed. We will highlight the integration points where AI agents reliably pay off, including drafting boilerplate detection logic, applying style guides, performing bulk edits across hundreds of rules behind human review, and more. We’ll also share the areas where these agents fall short, teaching us where the human must stay in the loop. Attendees will leave with a practical, phased implementation model they can apply directly to scale detection engineering in their own environments.
-
Securing the AI You Put in Command of Your Business (25 Min)
Building HAL Without Killing the Crew. "I'm sorry, Dave. I'm afraid I can't do that." HAL 9000 was an autonomous AI with full control and no human able to stop him, and that's close to the AI businesses are now wiring into their operations. We've crossed from AI that answers to AI that acts: agents that hold the keys, send the email, and move the money on their own. It's one of the juiciest attack surfaces in your environment today, and most teams running it have never threat-modeled it. In this fast briefing we trace how a single poisoned document hijacks an agent, then rebuild it so it can't be, and you'll leave able to spot a HAL and build one that won't kill the crew.
-
So You Want to Build Malicious Infrastructure: A Field Guide to Adversary TTPs
Building malicious infrastructure is harder than it looks. Adversaries run into the same architectural decisions any engineer does, including where to host, how to register domains without leaving a trail, what tools to use, how to route traffic, and how to keep systems online when they are being actively disrupted. This talk walks through those decisions using real examples from APT groups, ransomware affiliates, phishing kit operators, and large scale fraud networks. At each step, the same choices that make infrastructure work also make it discoverable. We look at how consistent patterns reveal careful actors, what renting a phishing kit does to operational security, and how defenders can follow breadcrumbs from a single domain back to a larger identity.
-
Stop Chasing Ghosts: Building an Intel-Driven Vulnerability Management Program
Every Blue Team knows the pain of a Friday afternoon fire drill triggered by a theoretical CVSS 9.8 vulnerability that ultimately has no path to exploitation in their environment. While standard calculator-based triage provides a necessary industry baseline, it creates a massive "context gap," trapping security teams in reactive cycles and burning political capital on patches for flaws that lack an actual threat landing zone. To break this cycle of alert fatigue, this session unveils a practical blueprint for Intel-Driven Vulnerability Management. We will explore how to fuse external threat intelligence, like live exploit tracking and dark web chatter, with internal enterprise telemetry from your EDR, SIEM, and asset baselines. By correlating these previously siloed data streams, defenders can instantly distinguish between widespread theoretical noise and targeted, imminent threats. Attendees will walk away with an actionable framework to bypass generic scoring models like SSVC and EPSS entirely, enabling their organizations to abandon exhausting, one-size-fits-all mandates in favor of Precision Remediation that prioritizes surgical fixes based on actual exploitability.
-
The End of Human-Scale AppSec
**The End of Human-Scale AppSec: Governing an Agentic Workforce** For decades, application security programs have been built around a simple assumption: humans are the primary producers of software. We train developers, review pull requests, conduct threat modeling exercises, and build controls around human decision-making. That assumption is rapidly breaking down. AI coding assistants are evolving into autonomous agents capable of designing, writing, testing, reviewing, and deploying software. As organizations adopt these systems to increase velocity and remain competitive, AppSec teams face a fundamental challenge: how do you govern an engineering workforce that is increasingly non-human? In this session, Ken Johnson, CTO of DryRun Security, explores the implications of agentic software development for application security. We'll examine which security practices are likely to survive, which must fundamentally change, and where traditional approaches may become bottlenecks rather than safeguards. We'll discuss the ramifications for threat modeling, code review, security testing, change management, accountability, and governance as software production scales beyond human capacity. Most importantly, we'll explore how security teams can adapt. Attendees will leave with a framework for evaluating emerging AI-driven development practices, understanding the risks and opportunities of agentic systems, and preparing their organizations for a future where software is increasingly created, reviewed, and maintained by AI agents operating at machine speed.
-
This Little Brite of Mine: Mobile Forensics for Fun and (Sometimes) Profit
Think mobile forensics tools are out of reach? Think again! This talk shows you how to source older Cellebrite UFED Touch hardware and how to get real-world, professional-grade tools without the enterprise price tag. We'll cover: 📱 Why older mobile forensics hardware still packs a punch 🔍 Where to find to find affordable Cellebrite UFED Touch units and what to look out for 😇 A real-life example of forensics being used for good 🎥 Live demo of mobile data extraction in action ⚖️ Legal and ethical considerations for mobile forensics Perfect for aspiring DFIR analysts, private investigators, security researchers, and anyone curious about mobile device forensics without the six-figure budget!
-
Uncharted Territory: AI Now and in the Future
This industry has been relatively the same for the past 15 years with no substantial breakthroughs or innovation. Well established, polished, and always striving to implement layers of defense. With AI, it feels like a whole new industry - something is vastly different and the future looks uncharted. That can seem scary for some, but exciting for others. Let’s dive into what’s changing, how we can change with this, and what we can do right now. This will be a technical talk. I’ll be diving into some of the ways I do development, ensure good code quality, and develop at scale more than I ever had before. I’ll also cover open weight vs frontier models, fine tuning, building models, and the 8xh200’s infrastructure we built and what we use them for in innovating every day.
-
Your malware infection is just three RMMs in a trenchcoat
For the better part of the past 20 years, malspam has served the purpose of delivering malware to unsuspecting email recipients. But over the past 18 months, a dramatic change has been taking place: Commercial remote monitoring and management tools (RMMs) have supplanted purpose-built malware as the initial-access deliverable of choice for many threat actors. There are a number of reasons why this is the case, and in this presentation, attendees will be able to see how vibe-coded slop spam and RMMs are becoming the norm for both untargeted attacks and targeted attacks against specific individuals and organizations, with one RMM sometimes delivering multiple other RMMs as payloads as part of complex attack chains, intent to provide as many backdoors as possible.
-
Zero to Hero: How to Build and Mature Your Threat Hunting Program
An effective threat hunting program catches attackers that have slipped past your organization’s preventative and detective controls. In this workshop, participants will learn how to scale their own threat hunting and threat intelligence capabilities. Led by an analyst who built their organization’s threat hunting program, this discussion will teach foundational principles of threat hunting, how to perform both indicator-based and hypothesis-based hunts, how to mature a threat hunting posture with threat intelligence, and which principles of threat hunting matter most to leadership. Designed for attendees both with threat hunting experience and for those with no experience, this workshop serves as a valuable resource for anyone seeking to start or mature their threat hunting program.
Fundamentals
-
Applying Zero-Trust to a Satellite Command and Control System
Learn how a satellite ground system is organized and the unique engineering challenges in applying zero-trust techniques to an operational technology (OT) system in space. This presentation will show how to analyze a system for zero-trust needs, some of the difficulties in implementing zero trust in OT systems, and lessons learned that can apply to any type of system.
-
Are You Smarter than a 5th Grader? Security Edition
You don't always need a complex, million-dollar attack strategy to compromise an organization—sometimes a default password or unpatched vulnerability is all it takes. Yet in today's digital world, we assume that every organization implements the core principles of basic cybersecurity. The reality? Most organizations fail to do so, leaving critical vulnerabilities out in the open. In this game-show style session, we'll tackle seven questions about cybersecurity fundamentals and explore how to bridge the gap between knowing the rules and effectively applying them.
-
Autonomous Adversaries: Agentic AI as Attacker, Agentic AI as Defender
AI has collapsed the time from vulnerability to exploit from years to hours. This session shows how autonomous agents discover and weaponize flaws at machine speed, and how defenders can use the same capability to get ahead.
-
Badge Talk
Electronic conference badges look simple when they are sitting on a table. Getting from “wouldn’t it be cool if…” to a pile of working badges is a different story. This talk takes a behind-the-scenes look at the design and development of the SAINTCON electronic badge, including the hardware, firmware, docking stations, and games that turned a conference badge into an interactive experience. Along the way, we’ll look at some of the design challenges, unexpected problems, and questionable decisions that come with building something at this scale.
-
Come for these hands and you'll get them: How to jailbrake the iPolish e-ink press-ons
Smart e-ink press-on nails are tiny displays glued to your fingers, controlled through an app, wand, and cloud backend. This talk uses them as a weird IoT case study in DRM, e-waste, BLE security, and app-dependent hardware. We’ll cover how APK reverse engineering revealed the protocol before the hardware arrived, what security boundaries were missing, and how independent Android, ESP32, and Flipper clients can keep the nails working after the official ecosystem would have ended their support
-
Cyber Thursday: Security Playground Live
SAINTCON 2026 CFP Abstract Cyber Thursday: Security Playground Live The last Thursday of each month, engineers, architects, defenders, customers, and curious technologists gather in our office for a simple reason: to learn by doing. Cyber Thursday is not a webinar. It is not a sales presentation. It is not a slide deck disguised as marketing. It is a recurring community event where participants get hands-on with real security technologies through guided labs, capture-the-flag exercises, live demonstrations, collaborative research, architecture reviews, and open discussion. Topics change monthly based on industry trends, emerging threats, and whatever happens to capture the attention of a room full of security professionals. For SAINTCON, we are bringing Cyber Thursday to the main stage. Rather than presenting a single technology or product, this session will showcase the format, energy, successes, failures, and lessons learned from building a hands-on security community series. Attendees will experience a live version of the activities that have become staples of our monthly events, including technology challenges, problem-solving exercises, interactive demonstrations, and audience participation. Past Cyber Thursday sessions have included: Endpoint Detection and Response (EDR) capture-the-flag challenges Zero Trust and SASE platform exercises Network Detection and Response (NDR) investigations SSL certificate automation workshops Cloud-Native Application Protection Platform (CNAPP) hands-on labs Threat hunting and security operations demonstrations Industry roundtable discussions and architecture reviews The goal is not to teach attendees how to click through a product interface, sit through a vendor talk and get another hat, or wonder when lunch is going to be served. The goal is to demonstrate how meaningful learning happens when experienced practitioners are given a problem to solve, the tools to explore, and the freedom to experiment. Whether you're building security training for your organization, looking for new ways to engage engineers, or simply interested in how a community-driven security program operates, this session offers a practical look at turning security education into an experience people actually want to attend. Join us as we transform a SAINTCON presentation slot into a live Cyber Thursday event and show why hands-on learning continues to outperform passive instruction in today's security landscape.
-
Hackers Challenge shakedown
Stumped on a challenge? Want to vent about how long it took you notice that one detail? Come to the Hacker's Challenge shakedown and ask questions and provide therapy to the other contestants.
-
Hacking the Wasteland: Cybersecurity Lessons from the Fallout Franchise
What if the post-apocalyptic wasteland could teach you real cybersecurity skills? This talk draws parallels between the iconic Fallout video game franchise and core infosec concepts — from zero-day vulnerabilities and authentication controls to social engineering, governance failures, and the dangers of technical shortcuts. Whether you’ve logged 200 hours in the wasteland or never picked up a controller, you’ll walk away with practical security takeaways wrapped in a story you won’t forget.
-
Modern Digital Forensics and Criminal Investigations
Digital forensics has transformed as comprehensively as technology has evolved. The rising quantity of data, advancements in security, and ever expanding integration of technology into absolutely everything has put a spotlight of importance on digital forensics in criminal investigations. This presentation dives into how digital forensics enhances criminal investigations in the modern day, providing an overview of what digital evidence looks like now and how it fits into the law enforcement space. Discussion of digital forensics tools and workflows will be covered. It will also explore some of the interesting challenges and changes that forensic analysts and examiners must face.
-
Protecting the Elderly
At Arctic Wolf we have put together a program to present security best practices to senior citizens. We found so much success with this that we adapted a presentation for high school students. I have loved this program and want to share how we developed this program to encourage others to do the same, spreading it's influence further than possible with a single company initiative.
-
Rebuilding the Ship at Sea: What AI Actually Changes in Security
This session examines how AI fits into the changes that information security has undergone through the lens of the Greco-Roman philosopher Plutarch’s Ship of Theseus paradox. In the past 15 years, we have seen the success of ransomware, a move to the cloud, implementation of zero-trust, remote work through COVID, and now AI. Just like the Ship of Theseus during its mythic journey, many of the planks on which we’ve stood and so many of the oars we pull have been replaced. But it’s important to keep sight of how security fundamentals remain the same as we navigate the changing waters of artificial intelligence with its radical promise and unprecedented risk.
-
So I Married a Security Director: How to work with your SREs (without having to marry them first)
As an Opera Singer and music professor who became a Security Compliance Officer, ended up a Site Reliability Engineer and married to a Security Director, I've had an interesting perspective on teams, work, and their interactions. The goal of this presentation is to help security professionals interact and communicate more successfully with their SREs. WARNING: This talk may present, and challenge some professional stereotypes.
-
Surviving the ThunderDome: Strategies for the Post Glasswing-Mythos World
The rules of the arena just changed. Anthropic's Project Glasswing quietly handed frontier AI — Claude Mythos Preview — to a small circle of trusted organizations for cybersecurity use. The implications cut both ways. Defenders who understand what Mythos-tier AI makes possible gain an asymmetric advantage. Those who don't are already behind. This session rips back the curtain on what Glasswing actually is, why Mythos was kept out of public hands, and what it means that adversaries are racing toward the same capabilities. We'll move fast through the new threat landscape — AI-accelerated phishing, autonomous vulnerability chaining, adaptive malware, and identity impersonation at machine scale — and spend the bulk of our time where it matters most: survival strategies that actually work. Fighting AI with AI. Hardening identity before it becomes the breach. Shrinking blast radius because assume-breach isn't a philosophy anymore, it's a schedule. You'll leave with a concrete, Monday-morning playbook — not a vendor pitch, not a framework slide. Just the moves that keep defenders standing when the ThunderDome gets loud. Two people enter. Let's make sure you're the one who walks out.
-
TOTP is not enough anymore
TOTP is dead, and most defenders don't know it yet. I'll hijack a fully MFA-protected account live on stage using the same session-stealing phishing kits that attackers use today — then talk about techniques to protect accounts.
-
Understanding the Quantum Threat: Computing, Networking, and Cryptography Fundamentals
Quantum computing is moving from theory toward engineering reality, and it carries direct consequences for the cryptography that secures today's networks. This introductory session brings security practitioners up to speed on two connected topics: how quantum computers work and why they're fast for certain problems, and how quantum networking distributes entanglement to enable capabilities like quantum key distribution. We'll ground every concept in security relevance — including why RSA, Diffie-Hellman, and ECC are genuinely threatened by Shor's algorithm while properly-keyed AES-256 remains quantum-resistant against Grover's, and what "Harvest Now, Decrypt Later" means for data you transmit today. You'll leave with a clear, accurate mental model of how quantum computing threatens current public-key cryptography, why the timeline ("Years to Quantum") remains uncertain, and how quantum key distribution uses the laws of physics to detect eavesdropping.
-
Your Scanner Is Lying to You: Building LLM-Assisted Vulnerability Triage
SAST and SCA tools find real vulnerabilities. They also generate enough noise that engineers learn to ignore the queue — false positive rates of 50–80% in production codebases are common, and the ticket backlog becomes a liability in itself. The hardest problem isn't detection. It's triage. This talk is a practitioner retrospective on building AVM, an LLM-assisted triage engine that sits between your scanner and your ticket queue. Feed it SARIF output from any scanner; get back structured findings with confidence levels, exploit path narratives, and recommended actions — before a human reviewer ever touches the queue. I'll walk through what worked (LLMs are genuinely good at common vulnerability patterns), where it struggled (confident false negatives are a real failure mode, and prompt injection via SARIF is weirder than it sounds), and what I'd design differently. Along the way: the threat model for putting an LLM inside your security pipeline, why "inconclusive" is sometimes the most honest answer a machine can give, and what the experience taught me about trusting automated triage. Working code, real screenshots, and honest lessons from building something that touches your most sensitive findings.
Policy/Procedures
-
Doing GRC Without Being a Jerk
If you liked the 2023 Saintcon hit "Making Security Happen Without Being A Jerk", good news - we're back with more! GRC is having its moment by finally moving past spreadsheet dependence and realizing there's two letters before the C, but there's a lot of work to show that the G and R really matter. Whether you're new to the GRC realm, a recovering compliance specialist, a technical security purist, or an optimistic builder, let's talk about how we're moving past compliance theater and providing structure for better operations.
-
Guardrails for Ghosts: Managing Risk in Agentic AI Systems
AI Agents are here, and security experts need to strategically balance the risk of agentic AI systems against an innovation-hungry market with an exceptionally high risk-appetite. This presentation will serve as the starting point for engineers, architects, and managers to explore the risks of agentic AI and the associated risk mitigation strategies available to ensure that security teams embrace the changing technology landscape without jeopardizing the security of their current and future systems.
-
Utah's State-Endorsed Digital Identity (SEDI): Regaining Privacy in a Surveillance World
Utah has recently passed new legislation requiring the creation of a new cryptographic identity based on strong cryptography, decentralized identity standards, individual control, and a mandate for strong security and privacy features. This presentation will describe how and why our identity privacy is under continual attack, illustrate recent attack impacts, and why a new type of digital identity is required. Utah's new State-Endorsed Digital Identity (SEDI) identity credential will be presented along with an overview of the underlying architectural technologies. The expertise of session attendees will be solicited and enable participants to participate in creating, analyzing, and performing penetration testing on SEDI technologies.
-
What Social Engineers Know About You That Your Security Team Doesn't
The social engineer studied your users more carefully than your security team did — and most awareness training is designed to prove that point. Security training uses urgency, authority, and fear to compel behavior change; malicious social engineering uses the same three mechanisms for the exact opposite purpose, because they were engineered to bypass skepticism, not activate it. After 16 years on the attacker's side — red team work, phishing simulations, social engineering assessments — I've found that the most important thing that experience revealed isn't how to attack people, it's how not to train them. This briefing covers the psychological mechanics social engineers depend on: why urgency bypasses skepticism, how authority disarms critical thinking, why helpfulness is exploitable, and what actually interrupts these patterns — making the case that curiosity, not compliance, is the behavior worth training.
-
Zero-Trust Zero-Network-Latency Authorization
Cadbury Eggs keep getting smaller, your level of trust in your system should too. Zero-trust models for microservices is now considered best practice. Come learn how to use OPA, Rego, and JWTs to implement zero-trust security for your microservices.
Product/Service Promotion
-
The True Cost of Building at Machine Speed
AI is changing how software is built. Engineering teams are shipping 10 to 50 times more code, moving faster than any security team can review, and pulling from open source registries that attackers are actively targeting. The productivity gains are real. So is the security risk that comes with it.
How-To Demonstration
-
Deleted But Not Gone
You care about your privacy, so you think you've deleted all traces of your activity after using a non-personal device. You deleted the cookies off the browser, cleared the recycle bin, and you restarted the device, but did you know that's not enough to protect your privacy? Come join us to learn what Windows truly remembers and some steps you can take to protect your privacy.
-
Every Day Carry Part Deux : Electric Boogaloo
Last year we witnesses BP (Hot Standby) decimate the competition with his EDC kit. This year, we’re kicking it up a notch. We’re gonna have to see evidence of it working. New challenges, a new wig, hopefully a less hot tablecloth suit.
-
Jup1t3r Unplugged...
Description update coming soon
-
My SIEM is Not My Castle; Knights, Farmers and a Little AI
Many security teams erroneously treat their SIEM platforms as their castle as they scout for threats from the towers. I will discuss with real examples how we can turn SIEM platforms into an abundant food source for the entire business. With a medieval perspective, I’ll share ways to enable developers to write better code, SRE’s to resolve outages more effectively, leaders to lead from data, HR to hire more effective talent, and finance to gain new perspectives, as security teams feed, and protect, them all.
-
Tag, You’re It: Physical Tracking Tech, Defense, and How to DIY Your Own
We live in an era where our location data is constantly harvested, but what happens when the tracking becomes physical? From the clandestine beacons of the Cold War to the consumer-grade AirTags tucked into backpacks today, physical tracking technology has become incredibly cheap, accessible, and pervasive. In this talk, we will trace the evolution of physical tracking tech, analyze how modern implementations exploit wireless protocols like BLE, cellular, and GPS, and discuss practical defense strategies to detect and neutralize unwanted eyes. Finally, we will demystify the threat by turning the tables: demonstrating how to build and deploy a fully functional, budget-friendly tracking beacon using off-the-shelf DIY hardware. Attendees will leave with a deep understanding of the tracking landscape and the knowledge required to both defend against and build these systems.
-
The Browser's Blind Spot: How to Analyze Chrome Extensions for Hidden Risk
Chrome extensions are installed by millions of users, including enterprise employees, yet they can be one of the least-scrutinized attack surfaces in modern security programs. They operate inside the browser after authentication, bypassing client-side controls, like EDR, entirely. We'll walk through the full technical picture: how extensions are packaged and distributed as CRX files, what the manifest reveals, how to extract and analyze JavaScript for permission abuse and data exfiltration patterns (including the fetch() loophole that MV3 doesn't close), how to detect obfuscated code and suspicious binary asset abuse, and how LLM-based analysis pipelines can evaluate these signals at scale. The Chrome Web Store explicitly prohibits obfuscation and base64-encoded payloads, yet both appear regularly in extensions that made it through review. And when malicious extensions are discovered, the store's enforcement is often not immediate; extensions have remained available for days after being flagged.
-
When AI Reverse Engineer Time Travels
Reverse engineering is a core part of malware analysis and vulnerability research, where analysts must understand opaque, often obfuscated binaries without access to source code. Frontier models are beginning to transform this workflow by helping triage decompiler output, drive analysis tools, and accelerate investigations, but static analysis alone can still lead models down convincing yet incorrect paths. This talk explores how integrating Codex with Time Travel Debugging traces through TTDObjectsPy helps ground analysis in real execution history, reducing false confidence and enabling more reliable, evidence-driven reverse engineering.
-
You Only Need Two Skills: A Simpler Way to Build Task-Specific Agents
What if your next task-specific agent started with two skills and a few plain-text files? Orchflows builds on Claude Code and Codex using two primitives: /orch-work and /orch-review. We’ll compose those primitives into reusable workflows, put domain expertise in modular guidance, and build feedback loops that improve both the results and the process that produces them. Starting with everyday automation, we’ll work toward a bigger question: how could the same approach help robots acquire new behaviors? A simulated drone game introduces Nervelet’s connection to a changing environment and Jev’s fast decision-making. Together, they point toward systems that can react quickly while improving what they know how to do.