BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Protect/hunt/respond with Fleet and osquery\n   When
 : Thursday\, Aug 11\, 09:00 - 12:59 PDT\n   Where: Harrah's - Goldfield + 
 Tonopah (Workshops) - [1]Map\n   Speakers:Guillaume Ross\,Kathy Satterlee\
 n\n   SpeakerBio:Guillaume Ross \, Head of Security\n   Guillaume started 
 hacking away in the early 90s. Whereby hacking\, we\n   mean "understandin
 g how pkzip works so he could fit this game on his\n   ridiculous HDD". He
  then went on to work in IT\, focusing on large\n   scale endpoint deploym
 ents for a few years. He then became a security\n   consultant\, working w
 ith all types of different organizations\, doing\n   endpoint security\, m
 obile security\, and cloud security until he\n   started leading security 
 in startups. Guillaume is currently the Head\n   of Security at Fleet Devi
 ce Management\, the company behind the open\n   source project Fleet. Guil
 laume dislikes doing meaningless "best\n   practices" work that has no pra
 ctical value and enjoys leveraging\n   great open source software availabl
 e to all of us to improve security.\n\n   Guillaume has spoken and given w
 orkshops at various conferences like\n   BSidesLV\, BsidesSF\, DEF CON\, R
 SAC\, Thotcon and Northsec on many\n   topics\, including mobile security\
 , endpoint security\, logging and\n   monitoring.\n\n\n   SpeakerBio:Kathy
  Satterlee \, Developer Advocate\n   Kathy is a Developer Advocate at Flee
 t Device Management. She\n   generally has a pretty good idea of how Fleet
  and osquery work\n   together and what people are doing with them. She al
 so usually knows\n   who to reach out to when she doesn’t have a clue.\n
 \n   Description:\n   In this workshop\, we will learn how to use Fleet an
 d osquery to ensure\n   systems are protected\, detect suspicious activity
 \, hunt for attackers\,\n   and respond to incidents. First\, we'll see ho
 w to deploy Fleet to\n   manage osquery agents. Then\, we will use shared 
 Fleet instances to\n   track the security posture of systems\, inventory v
 ulnerable\n   applications\, and perform threat hunting. These Fleet insta
 nces will\n   be connected to a shared Slack workspace\, where we will gen
 erate\n   custom alerts to ensure insecure systems can be dealt with. Thes
 e\n   shared Fleet instances will output data to centralized logging\n   (
 Graylog)\, which we will use to create dashboards as well as alerting\n   
 for suspicious activity. At the end of this workshop\, you'll know how\n  
  to use Fleet and osquery to ensure your workstations and servers are\n   
 secure\, to quickly find vulnerable systems as well as discover\n   attack
 ers performing techniques such as establishing persistence and\n   privile
 ge escalation.\n\n   Materials\n         A laptop with internet access\, a
  web browser\, virtualization app\n         such as VirtualBox or VMware\,
  and Docker (on main OS or in a\n         VM). We recommend bringing at le
 ast one or two VMs (Mac\, Windows\n         or Linux) ready to use as osqu
 ery clients.\n\n   Prereq\n         Basic understanding of operating syste
 ms and networking. No\n         knowledge of Fleet or osquery itself is ne
 eded.\n\n   '\n\n   1. https://defcon.outel.org/consolidated_page.html#Har
 rahs\n\n\n
DTEND:20220811T195900Z
DTSTART:20220811T160000Z
LOCATION:WS - Harrah's - Goldfield + Tonopah (Workshops)
SUMMARY:Protect/hunt/respond with Fleet and osquery
END:VEVENT
END:VCALENDAR
