BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Saf
 e-Read and\n   Quick Triage in an Ephemeral MicroVM\n   Tags: DEF CON Demo
  Labs | Intermediate | Defense/Blue Team | Malware |\n   Purple Team | Sec
 Ops | Threat Intel/Hunting | DEF CON Demo Labs\n   When: Saturday\, Aug 8\
 , 14:00 - 14:45 PDT\n   Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6
 ) - [1]Map\n\n   Description:\n\n   When TSA scans your luggage\, they see
  what's inside without opening\n   the bag. MailX-Ray brings that pattern 
 to email triage.\n\n   Phishing reports hit analysts as small crises: open
  carefully\, don't\n   trigger anything\, extract IOCs\, hand off to detec
 tion. Tooling lives\n   at two extremes: cloud sandboxes that ship custome
 r data offsite\, or\n   lightweight CLIs that run malicious parsers direct
 ly on the analyst's\n   host. Neither produces a portable safe artifact\, 
 on-prem and\n   hardware-isolated\, in roughly 30 seconds.\n\n   MailX-Ray
  does. Every email is processed inside an ephemeral\n   hardware-virtualiz
 ed microVM with no network device. Network egress is\n   prevented by desi
 gn. Output includes a single-file portable HTML\n   safe-read report\, str
 uctured JSON with 45+ offline signal categories\,\n   and optional STIX an
 d MISP exports for SOC integration. Original\n   attachment binaries are n
 ever re-distributed.\n\n   It's not a malware sandbox. No decompilation\, 
 no execution\, no\n   verdicts. It's a non-invasive structural scan: the f
 irst 30 seconds of\n   email triage\, with zero network egress\, on the an
 alyst's own laptop.\n\n   Demo Labs attendees will see the live pipeline a
 cross real phishing\n   scenarios\, including encrypted nested archives. O
 pen source on the day\n   of the talk.\n\n   SpeakerBio:  Uğur "uJohn" Ca
 n ATASOY\n\n   Uğur Can Atasoy is a Senior Security Engineer at Udemy\, w
 orking\n   primarily on blue and purple team operations.\n\n   A believer 
 in hybrid approaches that combine technical fieldwork with\n   academic ri
 gor\, he has spent the past decade across higher education\,\n   media\, d
 efense\, and automotive sectors in roles spanning security\n   architect\,
  specialist\, trainer\, and consultant. His work spans both\n   offense an
 d defense — from security operations\, threat hunting\,\n   intrusion de
 tection\, purple teaming\, and adversary simulation to\n   penetration tes
 ting and secure architecture. He has served as a Senior\n   Content Engine
 er at TryHackMe and as an Information Security Architect\n   at Mercedes-B
 enz. He has delivered security training for NATO\n   personnel\, law enfor
 cement investigators\, and military leadership\,\n   spoken at DeepSec (Vi
 enna)\, holds CCSP\, GCIA\, OSCP\, and OSWP\, and\n   served as an ISC2 SM
 E for exam and training item development. He has\n   been recognized by Or
 acle and IBM for responsible disclosure.\n\n   MailX-Ray is his answer to 
 a recurring annoyance: every tool in the\n   email triage stack is either 
 a cloud SaaS that ships customer data\n   offsite\, a heavyweight VM-based
  sandbox that takes minutes per sample\,\n   or an unprotected CLI that ru
 ns malicious parser input directly on the\n   analyst's host. It produces 
 a safe artifact analysts can read and\n   forward.\n\n   Links:\n       Gi
 tHub - [2]https://github.com/ugurcanatasoy/MailX-Ray\n   '\n\n   1. #LVCCW
 _Level1_Hall3\n   2. https://github.com/ugurcanatasoy/MailX-Ray\n\n\n
DTEND:20260808T214500Z
DTSTART:20260808T210000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)
SUMMARY:MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quic
 k Triage in an Ephemeral MicroVM
END:VEVENT
END:VCALENDAR
