BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Hunting Malicious Office Macros\n   When: Saturday\,
  Aug 13\, 14:15 - 14:45 PDT\n   Where: Virtual - BlueTeam Village - Talks\
 n\n   SpeakerBio:Anton Ovrutsky\n   Anton is a BSides Toronto speaker\, C3
 X volunteer\, and an OSCE\, OSCP\,\n   CISSP\, CSSP certificate holder. An
 ton enjoys the defensive aspects of\n   cybersecurity and loves logs and q
 ueries.\n\n   Description:\n   The talk will cover the following areas:\n\
 n     * Baselining Office macros behaviors\n\n     * Contextualized / Risk
 -based alerting strategies\n\n     * Data sets & Sysmon configurations wil
 l be provided\n\n     * Coverage of new attack vectors such as mark of the
  web bypasses\n       and VSTO files\n\n   When reviewing threat intellige
 nce reports it is common to see\n   malicious Office macros of various typ
 es used as an initial access\n   vector. Recently\, Microsoft announced bi
 g changes to Office behavior\n   in the context of malicious macros. Howev
 er\, organizations still\n   struggle with detecting malicious macros whic
 h is often a prerequisite\n   for implementing any type of hardening chang
 es. The aim of this talk\n   is to address this gap and provide guidance o
 n how to detect malicious\n   macro usage in environments and highlight th
 e necessary steps to\n   ensure systems are properly hardened against this
  threat.\n\n   '\n\n
DTEND:20220813T214500Z
DTSTART:20220813T211500Z
LOCATION:BTV - Virtual - BlueTeam Village - Talks
SUMMARY:Hunting Malicious Office Macros
END:VEVENT
END:VCALENDAR
