BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Qemuno – An uninvited guest\n   When: Sunday\, Aug
  14\, 12:30 - 12:59 PDT\n   Where: Flamingo - Sunset-Scenic Ballroom (Adve
 rsary Village) - [1]Map\n\n   SpeakerBio:Oleg Lerner\n   Oleg leads Sygnia
 ’s Adversarial Research team\, which is focused on\n   offensive and def
 ensive research for Sygnia’s Adversarial Tactics\n   department. Oleg is
  a cyber security expert with more than 9 years of\n   offensive and defen
 sive cyber security experience in research and\n   development\, as well a
 s red/purple team engagements and product\n   assessments. Oleg has a deep
  technical background that spans offensive\n   engineering projects and to
 ols development to security research and\n   analysis. Before joining Sygn
 ia\, Oleg served in an IDF technological\n   unit\, and later worked as a 
 security researcher at CyberArk\,\n   researching domain network protocols
  and a variety of security\n   solutions. At Sygnia\, Oleg leads research 
 and innovation of offensive\n   tools and infrastructure\, for red-team ac
 tivities. His experience\n   enables him to bring a unique perspective to 
 security engagements and\n   network operations\, and challenge operationa
 l assets from a unique\n   perspective.\n   Twitter: [2]@oleglerner\n\n   
 Description:\n   Evolving endpoint protection controls\, including hardeni
 ng and\n   security software with enhanced detection capabilities and grea
 ter\n   visibility coverage\, have been pushing red team and purple team\n
    operational complexity to a higher level. Malicious actors and\n   secu
 rity professionals alike are increasingly focusing on leveraging\n   virtu
 alization technologies to overcome prevention and detection\n   mechanisms
 . Although utilizing virtualization as an attack platform\n   assists in e
 vading most security controls by “default”\, creating\n   and using a 
 virtualization platform in a client environment poses its\n   own challeng
 es. We embraced the trend and created our own virtualized\n   offensive op
 erations suite \, which can be utilized to execute any\n   offensive tool\
 , starting from network reconnaissance to privilege\n   escalation\, avoid
 ing the cat and mouse game of crafting custom\n   payloads and tools to ev
 ade the latest endpoint security stack\n   detection mechanisms. The offen
 sive operations suite utilizes a QEMU\n   open-source emulator as the virt
 ualization software\, coupled with a\n   lean Linux distribution\, docker 
 containerization platform\, and a\n   custom GUI web interface based on a 
 Flask micro-framework. The suite\n   leverages docker technology to create
  modularity\, in order to maximize\n   functionality and avoid issues like
  software and OS dependencies\,\n   while keeping the build lean for ease 
 of deployment in offensive\n   security engagements. In this talk\, we wil
 l present the architecture\n   and capabilities of the Qemuno offensive op
 erations suite\, present\n   several real use cases where we leveraged Qem
 uno\, and demo how it can\n   be leveraged in a highly-hardened environmen
 t.\n   '\n\n   1. https://defcon.outel.org/consolidated_page.html#Flamingo
 ThirdFloor\n   2. https://twitter.com/oleglerner\n\n\n
DTEND:20220814T195900Z
DTSTART:20220814T193000Z
LOCATION:AVV - Flamingo - Sunset-Scenic Ballroom (Adversary Village)
SUMMARY:Qemuno – An uninvited guest
END:VEVENT
END:VCALENDAR
