BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Ghost in the IDE\n   Tags: Intro/Beginner | DEF CON 
 Demo Labs | AppSec | Offense/Red Team |\n   DEF CON Demo Labs\n   When: Fr
 iday\, Aug 7\, 12:00 - 12:45 PDT\n   Where: LVCCW Level 1 Hall 3 900 (Demo
  Labs Track 4) - [1]Map\n\n   Description:\n   Hook: The Blind Spot\n   Yo
 ur EDR sees the server compromise. Your SIEM catches the phishing\n   camp
 aign. Your firewall blocks the C2 traffic. But what happens when\n   the a
 ttacker doesn't target your infrastructure—they target your\n   develope
 rs?\n\n   28 million developers worldwide rely on three IDE platforms: Jet
 Brains\n   IntelliJ\, Microsoft VS Code\, and Eclipse. These aren't just t
 ext\n   editors—they're command-and-control platforms disguised as\n   p
 roductivity tools. Developers trust them with AWS credentials\,\n   databa
 se passwords\, SSH keys\, source code\, and network access to\n   producti
 on systems. And here's the kicker: IDE plugins run with full\n   user priv
 ileges\, no sandboxing\, no permission dialogs\, no questions\n   asked.\n
 \n   We built GHOST IN THE IDE\, a production-ready C2 framework that\n   
 weaponizes IDE plugins across all three major platforms. Not a\n   proof-o
 f-concept. Not a research prototype. A functional red team tool\n   with k
 eystroke logging\, clipboard monitoring\, file exfiltration\, and\n   remo
 te command execution—working silently inside IntelliJ\, VS Code\,\n   an
 d Eclipse on Windows\, macOS\, and Linux.\n\n   The Attack: Multi-IDE C2 T
 hat Actually Works Most IDE plugin research\n   stops at "look\, I can pop
  calc.exe from VS Code." We went further. Way\n   further.\n\n   Speakers:
 Venkata Jayaram Yalla\,Pardhiv Reddy\n\n   SpeakerBio:  Venkata Jayaram Ya
 lla\n\n   Yalla\, Jayaram is Director – Application Security at S&P Glob
 al\,\n   leading enterprise-wide initiatives in secure application develop
 ment\,\n   vulnerability management\, and security architecture. He has\n 
   transformed the Application Security function from a primarily\n   tacti
 cal penetration-testing team into a strategic security\n   engineering org
 anization\, emphasizing automation\, governance\, and\n   advanced threat 
 modeling.\n\n   Jayaram combines deep hands-on experience in offensive sec
 urity and\n   research (including multiple CVEs) with ownership of large-s
 cale\n   AppSec programs across SAST\, SCA\, DAST\, CI/CD security\, and e
 merging\n   AI security initiatives.\n\n   SpeakerBio:  Pardhiv Reddy\n\n 
   Pardhiv is a security specialist with vast experience in the field of\n 
   information security ranging from health care\,hospitality\, banking and
 \n   government sectors throughout the world. He also earned many industry
 \n   standard certifications in the security\, some of them are SANS GPEN\
 ,\n   OSCP\, OSWP\, CISSP\, Security+\, ISO 27001 LA and many others.\n\n 
   Pardhiv's interest areas includes cloud security and IOT security and\n 
   his research has been presented at EuropeanSec 2016 in Portugal. His\n  
  expertise helped teams to build secure products and applications by\n   p
 roviding security guidelines and best practices.\n\n   Pardhiv has perform
 ed various iOT security assessments which includes\n   both embedded hardw
 are security\, firmware analysis\, mobile\n   applications\, network secur
 ity including wireless communications and\n   backend cloud server assessm
 ents.\n\n   Pardhiv is also an active bug bounty hunter and helped many co
 mpanies\n   around the world by pointing their security vulnerabilities to
  make\n   their application and products secure. He spares his free time t
 o\n   build prototypes and security research by learning new techniques an
 d\n   methodologies.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T194500Z
DTSTART:20260807T190000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)
SUMMARY:Ghost in the IDE
END:VEVENT
END:VCALENDAR
