BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Burning Redirectors Before Blue Team Does\n   Tags: 
 Red Team Village | Misc\n   When: Friday\, Aug 7\, 12:00 - 13:59 PDT\n   W
 here: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 -\n   [1]
 Map\n\n   Description:\n\n   Red team operators rely on redirectors to pro
 xy C2 callbacks\, but\n   monitoring those redirectors for blue team detec
 tion is typically\n   handled by either manual log review or deploying a f
 ull SIEM pipeline.\n   Neither scales well during active assessments. Nigh
 tWatcher is a\n   traffic monitoring agent that analyzes redirector access
  logs through\n   detection rules and a reasoning engine that identifies a
 ttack phase\n   progression (reconnaissance through takedown) rather than 
 issuing\n   disconnected alerts. NightRouter is a decision routing agent t
 hat\n   receives NightWatcher's assessments\, recommends a redirector acti
 on\n   (drain\, reduce weight\, quarantine)\, and presents it to the opera
 tor\n   via Slack interactive messages for approval or rejection.\n\n   In
  this tactic\, attendees will deploy NightWatcher/NightRouter\n   locally\
 , simulate blue team traffic patterns against redirectors\,\n   observe th
 e attack phase reasoning and escalation detection\, and\n   execute redire
 ctor actions through the Slack human-in-the-loop\n   approval flow. The st
 ack runs in mock mode with no external\n   infrastructure dependencies req
 uired.\n\n   Speakers:Mohamed AbuMuslim\,Saad Nasir\n\n   SpeakerBio:  Moh
 amed AbuMuslim\n\n   I am a security researcher and offensive security eng
 ineer\n   specializing in red teaming\, penetration testing\, adversarial 
 AI\, and\n   product security engineering.\n\n   My work focuses on identi
 fying exploitable weaknesses across modern\n   attack surfaces\, including
  web applications\, APIs\, cloud platforms\,\n   enterprise infrastructure
 \, Active Directory\, and LLM-enabled systems.\n   I combine offensive ope
 rations\, applied research\, and security\n   engineering to solve complex
  security problems\, validate security\n   posture\, and improve how organ
 izations build and assess secure\n   products.\n\n   Over the years\, I ha
 ve led and contributed to offensive security\n   capability building in co
 mplex environments\, including helping\n   establish Microsoft Egypt & Mid
 dle East’s first offensive security\n   team and previously helping buil
 d PwC’s offensive security\n   capability in Egypt\, and served as Manag
 er and Practice Lead at EY\n   leading offensive security engagements. My 
 experience spans startups\,\n   mid-sized organizations\, and multinationa
 l enterprises.\n\n   I regularly speak at conferences including Black Hat\
 , DEF CON\, BSides\,\n   and OWASP Cairo on topics such as AI red teaming\
 , cloud attack\n   simulation\, supply-chain risk\, log manipulation\, and
  practical\n   offensive tradecraft. I also design and deliver hands-on tr
 aining\,\n   contribute to security education\, and support community init
 iatives\n   through AI Village\, BSides Albuquerque\, OWASP Cairo\, and Cy
 berDose.\n\n   SpeakerBio:  Saad Nasir\n\n   Saad Nasir is a cybersecurity
  leader specializing in red teaming\,\n   penetration testing\, and applic
 ation security. He currently leads Red\n   Team and Application Security i
 nitiatives\, overseeing offensive\n   security operations\, adversary simu
 lation\, and security assessments\n   across enterprise environments.\n\n 
   With more than 10 years of cybersecurity experience\, Saad has led\n   o
 ffensive security engagements spanning web applications\, cloud\n   platfo
 rms\, internal networks\, and Active Directory environments. He is\n   the
  founder and organizer of Security BSides Albuquerque\, helping grow\n   o
 ne of New Mexico's largest community-driven cybersecurity\n   conferences.
 \n\n   Saad is pursuing a PhD in National Security and holds a Master's\n 
   degree in Cybersecurity\, along with multiple industry certifications\,\
 n   including OSCP and CISM. He is passionate about sharing practical\n   
 skills\, helping defenders understand the mindset of attackers\, and\n   a
 dvancing the cybersecurity community through mentoring\, conference\n   sp
 eaking\, and hands-on training.\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20260807T205900Z
DTSTART:20260807T190000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Tac
 tic Table 1
SUMMARY:Burning Redirectors Before Blue Team Does
END:VEVENT
END:VCALENDAR
