Loading…
Venue: Ballroom clear filter
arrow_back View All Dates
Friday, April 11
 

8:45am ADT

Opening Remarks
Friday April 11, 2025 8:45am - 9:00am ADT
Friday April 11, 2025 8:45am - 9:00am ADT
Ballroom

9:15am ADT

Cracking the Vault: Defending Against Modern Active Directory Exploits
Friday April 11, 2025 9:15am - 10:00am ADT
Active Directory (AD) is a cornerstone of enterprise IT environments, providing critical services such as authentication, authorization, and identity management. However, its pervasive use also makes it a prime target for cyber attackers. This paper explores the evolving landscape of Active Directory cyber attacks, focusing on the methods and techniques used by threat actors to compromise AD environments. We will analyze case studies of recent high-profile breaches, highlighting the common vulnerabilities exploited and the tactics employed to escalate privileges, maintain persistence, and exfiltrate sensitive data. The discussion will include an examination of the tools and strategies used in these attacks, such as pass-the-hash, golden and silve ticket, kerberosting, DCSync, Golden SAML and Azure AD Token Theft attacks. We will also cover the latest defensive measures and best practices for securing Active Directory and Azure Active Director, including monitoring, detection, and incident response strategies. The aim is to provide IT professionals and cybersecurity practitioners with actionable insights to fortify their AD environments against sophisticated threats and ensure the integrity and security of their networks.



Speakers
avatar for Peter Morin

Peter Morin

Director, OT Cybersecurity Consulting, PricewaterhouseCoopers LLP.
Peter Morin is a Senior Consultant specializing in OT/IoT cybersecurity, bringing over 25 years of industry experience to the table. With a robust background information technology and cybersecurity, Peter has become a trusted advisor to organizations navigating the complex and rapidly... Read More →
Friday April 11, 2025 9:15am - 10:00am ADT
Ballroom

11:00am ADT

Crypto currency and investigations
Friday April 11, 2025 11:00am - 11:45am ADT
A brief overview of crypto currency and investigations into offences involving crypto currency.
Speakers
KJ

Karren Jensen

Cybercrime Investigator, Royal Canadian Mounted Police
Police officer since 2004. Digital Forensic examiner with 8 years experience, recognized as an expert in digital forensics in Provincial Court and Court of Queen's Bench. Cybercrime investigator since June 2023.
Friday April 11, 2025 11:00am - 11:45am ADT
Ballroom

11:45am ADT

Buffet Lunch Service & Sponsor Prize Draws
Friday April 11, 2025 11:45am - 1:00pm ADT
Friday April 11, 2025 11:45am - 1:00pm ADT
Ballroom

1:00pm ADT

Gen AI in SecOps: Hype vs Concrete, Practical Use Cases
Friday April 11, 2025 1:00pm - 1:45pm ADT
There is a lot of hype around LLMs and Generative AI in cybersecurity - enough to make one roll their eyes into the back of their head. However, there are also a lot of organizations that are getting real value. In this talk, we will unpack some of the hype - and share real world use cases you can deploy NOW, showing how generative AI is being used today in security operations centers to take an existing process that is bottlenecked by humans, and supercharge it, using AI and automation to do what humans used to have to do - using both open-source as well as commercial tools.
Speakers
avatar for Jason Keirstead

Jason Keirstead

VP Security Strategy, Simbian
Jason Keirstead is VP of Security Strategy at Simbian, where he is working to leverage generative AI to revolutionize cybersecurity. He has over 21 years experience in the industry, and is a subject-matter expert in topics such as threat intelligence, collective defense, SIEM, SOAR... Read More →
Friday April 11, 2025 1:00pm - 1:45pm ADT
Ballroom

2:00pm ADT

Persōna Theory: Infiltration & Deception of Emerging Threat Groups
Friday April 11, 2025 2:00pm - 2:45pm ADT
Our personas are fabrications and constructions of our inner self that we project outwards.  We do this through various means and influences such as race, gender, sex, ability, age, culture, religion, norms,  class, and status. For the “real world” aka “irl” we do all this by expression in our clothing, makeup, hairstyling, our hobbies, our network of friends, colleagues, and acquaintances. We leverage all of these facets and we create masks, personas, that we think will best interact with the world around us. The same concepts apply when creating personas for infiltrating online communities. 

Online communities are built on trust, reputation, and currency which can take various forms such as data, crypto, intel and notoriety. This talk is an exploration of techniques; linguistics, OPSEC, OSINT, and SOCENG. Tactical operations and concepts like hours of online operation, timezone shifting, and using low ranking accounts as canon fodder for probing, and psychological models used in the infiltration of emerging threat actor groups.
Speakers
avatar for Tammy Harper

Tammy Harper

Senior Threat Intelligence Researcher, Flare
Tammy is a Senior Threat Intelligence Researcher and Certified Dark Web Investigator at Flare. She brings a unique approach to studying cybercrime, utilizing linguistic practices such as frequency and stylometric analyses, along with transliteration, to uncover patterns and behaviors... Read More →
Friday April 11, 2025 2:00pm - 2:45pm ADT
Ballroom

3:00pm ADT

Closing Keynote - Inside the Mind of a Social Engineer: Real Attacks, Hard Truths, and What They Mean for Your Organization
Friday April 11, 2025 3:00pm - 4:00pm ADT
Social engineering isn’t just about tricking people—it’s about understanding how humans think, behave, and make decisions in the moment. As a professional social engineer, Snow has spent her career breaking into buildings, bypassing security measures, and convincing people into handing over sensitive information. Sometimes, she succeeds. Other times, she gets caught. Either way, every engagement can reveal critical security gaps that organizations overlook.

In this keynote, Snow will take you inside the mind of a social engineer, sharing real-world stories, the tactics that work (and why), and the moments where organizations fought back effectively. We’ll also examine a hard truth: traditional security awareness training is failing us. But this isn’t just about her stories - it’s about your security. Throughout the talk, Snow will leave you with critical questions to take back to your organization.




Speakers
avatar for Stephanie Carruthers

Stephanie Carruthers

Global Lead of Cyber Range and Cyber Crisis Management, X-Force, IBM
Stephanie "Snow" Carruthers holds a dual role at IBM X-Force as Chief People Hacker and Global Head of Cyber Range. An expert in social engineering, Snow has earned the distinction of winning three unique black badges for excelling in Social Engineering and Physical Security competitions... Read More →
Friday April 11, 2025 3:00pm - 4:00pm ADT
Ballroom

4:00pm ADT

Closing Remarks & Passport Grand Prize Draws
Friday April 11, 2025 4:00pm - 5:00pm ADT
Friday April 11, 2025 4:00pm - 5:00pm ADT
Ballroom
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -