BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Analyzing PIPEDREAM: Challenges in testing an ICS at
 tack\n   toolkit.\n   When: Saturday\, Aug 13\, 12:30 - 13:15 PDT\n   Wher
 e: Caesars Forum - Alliance 301-309\, 321 (Track 4) - [1]Map\n\n   Speaker
 Bio:Jimmy Wylie \, Principal Malware Analyst II \, Dragos\, Inc.\n   Jimmy
  Wylie is a Principal Malware Analyst at Dragos\, Inc. who spends\n   his 
 days (and nights) searching for and analyzing threats to critical\n   infr
 astructure. He was the lead analyst on PIPEDREAM\, the first ICS\n   attac
 k "utility belt"\, TRISIS\, the first malware to target a safety\n   instr
 umented system\, and analysis of historical artifacts of the\n   CRASHOVER
 RIDE attack\, the first attack featuring malware specifically\n   tailored
  to disrupt breakers and switchgear in an electric\n   transmission substa
 tion.\n\n   Jimmy has worked for various DoD contractors\, leveraging a va
 riety of\n   skills against national level adversaries\, including network
  analysis\,\n   dead disk and memory forensics\, and software development 
 for detection\n   and analysis of malware. After leaving the DoD contracti
 ng world\, he\n   joined Focal Point Academy\, where he developed and taug
 ht malware\n   analysis courses to civilian and military professionals acr
 oss the\n   country. In his off-time\, Jimmy enjoys learning about operati
 ng\n   systems internals\, playing pool\, cheap beer\, and good whiskey.\n
 \n   Twitter: [2]@mayahustle\n\n   Description:\n   Identified early in 20
 22\, PIPEDREAM is the seventh-known ICS-specific\n   malware and the fifth
  malware specifically developed to disrupt\n   industrial processes. PIPED
 REAM demonstrates significant adversary\n   research and development focus
 ed on the disruption\, degradation\, and\n   potentially\, the destruction
  of industrial environments and physical\n   processes. PIPEDREAM can impa
 ct a wide variety of PLCs including Omron\n   and Schneider Electric contr
 ollers. PIPEDREAM can also execute attacks\n   that take advantage of ubiq
 uitous industrial protocols\, including\n   CODESYS\, Modbus\, FINS\, and 
 OPC-UA.\n\n   This presentation will summarize the malware\, and detail th
 e\n   difficulties encountered during the reverse engineering and analysis
 \n   of the malware to include acquiring equipment and setting up our lab.
 \n   This talk will also release the latest results from Drago's lab\n   i
 ncluding an assessment of the breadth of impact of PIPEDREAM's\n   CODESYS
  modules on equipment beyond Schneider Electric's PLCs\, testing\n   Omron
  servo manipulation\, as well as OPC-UA server manipulation. While\n   a b
 ackground in ICS is helpful to understand this talk\, it is not\n   requir
 ed. The audience will learn about what challenges they can\n   expect to e
 ncounter when testing ICS malware and how to overcome them.\n\n   '\n\n   
 1. https://defcon.outel.org/consolidated_page.html#CaesarsAllianceBR\n   2
 . https://twitter.com/mayahustle\n\n\n
DTEND:20220813T201500Z
DTSTART:20220813T193000Z
LOCATION:DC - Caesars Forum - Alliance 301-309\, 321 (Track 4)
SUMMARY:Analyzing PIPEDREAM: Challenges in testing an ICS attack toolkit.
END:VEVENT
END:VCALENDAR
