BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Building Adversary Chains Like an Operator\n   When:
  Friday\, Aug 12\, 15:00 - 16:59 PDT\n   Where: Flamingo - Sunset-Scenic B
 allroom (Adversary Village) - [1]Map\n   Speakers:David Hunt\,Stephan Wamp
 ouille\n\n   SpeakerBio:David Hunt\n   Daniel Feichter has his original ba
 ckground in industrial engineering\,\n   he started 3.5 years ago more or 
 less as an offensive security rookie\n   in an employed relationship. For 
 different reasons he decided to start\n   his own company in 2022 (Infosec
  Tirol)\, with which he focuses even\n   more on offensive security like A
 PT testing\, adversary simulation and\n   red teaming. Daniel invests a lo
 t of his time in learning and\n   researching in the area of endpoint secu
 rity. Based on the Windows\n   Internals he tries day by day to better und
 erstand AV/EPP/EDR products\n   on Windows and is always looking for new w
 ays to bypass and evade\n   them.\n   Twitter: [2]@privateducky\n\n   Spea
 kerBio:Stephan Wampouille \, Software Engineer\n   Stephan is a software e
 ngineer at Prelude Research\, where he works on\n   cutting-edge offensive
  security tools and tradecraft. He originally\n   worked on the Operator C
 2 platform before moving on to build the\n   library of TTPs hosted on cha
 ins.prelude.org. Stephan is a veteran\n   Defcon speaker\, previously givi
 ng a talk on autonomous lateral\n   movement\, as applied to Linux servers
 \, at Defcon 29.\n\n   Description:\n   Every week\, the Prelude security 
 team builds attack chains that\n   emulate the most notorious threat actor
 s online. The attacks are\n   released in an event called “TTP Tuesday
  and each chain can be\n   browsed on chains.prelude.org. For those with 
 an Operator license\, the\n   chains pop into the command-and-control (C2)
  application\n   automatically. For the first time\, the author of Operato
 r - along with\n   Prelude security engineers - will walk you through thei
 r process of\n   building and releasing these chains. In this workshop\, y
 ou will learn\n   how to:\n\n     * Evaluate open-source threat intelligen
 ce and output it as an\n       attack plan.\n\n     * Convert your plan in
 to an actionable set of TTPs called a\n       “chain”.\n\n     * Selec
 t hosts around your network to test your plan.\n\n     * Deploy agents on 
 your selected hosts and execute your chain\n       against them.\n\n     *
  Put your chains on repeat so they’re constantly at work in your\n      
  environment.\n\n     * Package your results into a report that can measur
 e your success.\n\n   You should expect to be hands-on\, with a laptop run
 ning Operator.\n   Expect to walk away from this workshop with both knowle
 dge of how to\n   build attack chains and a brand new\, unreleased chain t
 hat will go out\n   in a future TTP Tuesday event. Attackers use advanced 
 tactics to\n   infiltrate your network and run undetected. Learn how to em
 ulate them\n   so you can get ahead of their game. Proactive adversary emu
 lation\n   leads to better detection\, which leads to faster response and 
 a more\n   robust grasp of your current risk profile.\n\n   '\n\n   1. htt
 ps://defcon.outel.org/consolidated_page.html#FlamingoThirdFloor\n   2. htt
 ps://twitter.com/privateducky\n\n\n
DTEND:20220812T235900Z
DTSTART:20220812T220000Z
LOCATION:AVV - Flamingo - Sunset-Scenic Ballroom (Adversary Village)
SUMMARY:Building Adversary Chains Like an Operator
END:VEVENT
END:VCALENDAR
