Loading…
Type: Track 1 clear filter
arrow_back View All Dates
Friday, April 11
 

9:15am ADT

Cracking the Vault: Defending Against Modern Active Directory Exploits
Friday April 11, 2025 9:15am - 10:00am ADT
Active Directory (AD) is a cornerstone of enterprise IT environments, providing critical services such as authentication, authorization, and identity management. However, its pervasive use also makes it a prime target for cyber attackers. This paper explores the evolving landscape of Active Directory cyber attacks, focusing on the methods and techniques used by threat actors to compromise AD environments. We will analyze case studies of recent high-profile breaches, highlighting the common vulnerabilities exploited and the tactics employed to escalate privileges, maintain persistence, and exfiltrate sensitive data. The discussion will include an examination of the tools and strategies used in these attacks, such as pass-the-hash, golden and silve ticket, kerberosting, DCSync, Golden SAML and Azure AD Token Theft attacks. We will also cover the latest defensive measures and best practices for securing Active Directory and Azure Active Director, including monitoring, detection, and incident response strategies. The aim is to provide IT professionals and cybersecurity practitioners with actionable insights to fortify their AD environments against sophisticated threats and ensure the integrity and security of their networks.



Speakers
avatar for Peter Morin

Peter Morin

Director, OT Cybersecurity Consulting, PricewaterhouseCoopers LLP.
Peter Morin is a Senior Consultant specializing in OT/IoT cybersecurity, bringing over 25 years of industry experience to the table. With a robust background information technology and cybersecurity, Peter has become a trusted advisor to organizations navigating the complex and rapidly... Read More →
Friday April 11, 2025 9:15am - 10:00am ADT
Ballroom

11:00am ADT

Crypto currency and investigations
Friday April 11, 2025 11:00am - 11:45am ADT
A brief overview of crypto currency and investigations into offences involving crypto currency.
Speakers
KJ

Karren Jensen

Cybercrime Investigator, Royal Canadian Mounted Police
Police officer since 2004. Digital Forensic examiner with 8 years experience, recognized as an expert in digital forensics in Provincial Court and Court of Queen's Bench. Cybercrime investigator since June 2023.
Friday April 11, 2025 11:00am - 11:45am ADT
Ballroom

1:00pm ADT

Gen AI in SecOps: Hype vs Concrete, Practical Use Cases
Friday April 11, 2025 1:00pm - 1:45pm ADT
There is a lot of hype around LLMs and Generative AI in cybersecurity - enough to make one roll their eyes into the back of their head. However, there are also a lot of organizations that are getting real value. In this talk, we will unpack some of the hype - and share real world use cases you can deploy NOW, showing how generative AI is being used today in security operations centers to take an existing process that is bottlenecked by humans, and supercharge it, using AI and automation to do what humans used to have to do - using both open-source as well as commercial tools.
Speakers
avatar for Jason Keirstead

Jason Keirstead

VP Security Strategy, Simbian
Jason Keirstead is VP of Security Strategy at Simbian, where he is working to leverage generative AI to revolutionize cybersecurity. He has over 21 years experience in the industry, and is a subject-matter expert in topics such as threat intelligence, collective defense, SIEM, SOAR... Read More →
Friday April 11, 2025 1:00pm - 1:45pm ADT
Ballroom

2:00pm ADT

Persōna Theory: Infiltration & Deception of Emerging Threat Groups
Friday April 11, 2025 2:00pm - 2:45pm ADT
Our personas are fabrications and constructions of our inner self that we project outwards.  We do this through various means and influences such as race, gender, sex, ability, age, culture, religion, norms,  class, and status. For the “real world” aka “irl” we do all this by expression in our clothing, makeup, hairstyling, our hobbies, our network of friends, colleagues, and acquaintances. We leverage all of these facets and we create masks, personas, that we think will best interact with the world around us. The same concepts apply when creating personas for infiltrating online communities. 

Online communities are built on trust, reputation, and currency which can take various forms such as data, crypto, intel and notoriety. This talk is an exploration of techniques; linguistics, OPSEC, OSINT, and SOCENG. Tactical operations and concepts like hours of online operation, timezone shifting, and using low ranking accounts as canon fodder for probing, and psychological models used in the infiltration of emerging threat actor groups.
Speakers
avatar for Tammy Harper

Tammy Harper

Senior Threat Intelligence Researcher, Flare
Tammy is a Senior Threat Intelligence Researcher and Certified Dark Web Investigator at Flare. She brings a unique approach to studying cybercrime, utilizing linguistic practices such as frequency and stylometric analyses, along with transliteration, to uncover patterns and behaviors... Read More →
Friday April 11, 2025 2:00pm - 2:45pm ADT
Ballroom
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -