BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Ghost Records: Automating Dangling DNS & Subdomain T
 akeover\n   Detection at Enterprise Scale\n   Tags: Cloud Village | Creato
 r Talk/Panel\n   When: Saturday\, Aug 8\, 10:40 - 11:20 PDT\n   Where: LVC
 CW Level 3 W313 (Cloud Village Talks) - [1]Map\n\n   Description:\n\n   Th
 is is not another subdomain takeover 101 talk. It's about what\n   danglin
 g DNS actually looks like at enterprise scale - in large\,\n   multi-accou
 nt AWS environments with sprawling DNS footprints - and the\n   automation
  and hard-won triage lessons the problem demands.\n\n   Let's be honest: ~
 95% of subdomain takeover findings are noise - 3rd-\n   and 4th-level subd
 omains on dead non-prod environments no customer\n   ever visits. They gen
 erate alert fatigue and little else. The other 5%\n   - cookie theft via a
  *.domain.com scope\, OAuth token hijack\, phishing\n   from a legitimate 
 domain carrying a valid TLS cert - are catastrophic.\n   Telling the 5% fr
 om the 95% is the entire game.\n\n   Then there's the bug bounty dynamic. 
 Researchers find these in bulk\n   and report them in bulk. They're frustr
 ated that fixes take weeks\;\n   program owners are frustrated that most r
 eports are low-impact but\n   can't simply be closed. The relationship ero
 des on both sides - a cost\n   nobody puts on a dashboard.\n\n   From what
  We've seen\, the time sinks are predictable: manually\n   triaging hundre
 ds of researcher reports\, chasing low-impact findings\,\n   writing one-o
 ff fix scripts instead of systemic solutions\, and\n   reconstructing reco
 rd ownership after the fact. The structural causes\n   are just as consist
 ent: multi-account sprawl with no central DNS\n   ownership\, rapid dev cy
 cles where IaC teardowns never touch Route53\,\n   and researchers reporti
 ng faster than teams can remediate.\n\n   The core of the talk is architec
 ture: automatically cross-referencing\n   every Route53 A record and CNAME
  against Elastic IPs allocated across\n   all AWS regions\, wired into own
 ership routing and shift-left pipeline\n   hooks. Done right\, this shifts
  detection from reactive to proactive\,\n   can take MTTR from weeks to ho
 urs\, and eliminates entire classes of\n   records at the source.\n\n   We
 'll release Ghost Records\, an open-source tool aimed at the one of\n   th
 e highest impact vector: dangling A records and CNAMEs pointing to\n   rel
 eased or unallocated AWS Elastic IPs. It inventories every EIP\n   across 
 all enabled regions\, cross-references them against Route53\, and\n   flag
 s any DNS record pointing to an IP the account doesn't own.\n   Read-only\
 , multi-account\, parallel scanning\, risk-scored output. Live\n   demo in
 cluded.\n\n   Speakers:Jai Kumar Sharma\,Tom McCarthy\n\n   SpeakerBio:  J
 ai Kumar Sharma\, Principal Offensive Security Engineer\n   at GoDaddy\n\n
    Jai Sharma is a Principal Offensive Security Engineer at GoDaddy\,\n   
 where he leads cloud penetration testing\, red team operations\, AI red\n 
   teaming\, and security research across one of the world's largest\n   do
 main registrars and hosting platforms. A self-taught offensive\n   securit
 y researcher from New Delhi\, India\, he built his career with a\n   hacke
 r's mindset\, breaking code logic\, chasing vulnerabilities\, and\n   prov
 ing real-world business impact from technical exploits. He also\n   leads 
 TTP research\, drives threat emulation efforts\, and works closely\n   wit
 h blue teams to sharpen detection through an adversary-focused\n   lens.\n
 \n   At GoDaddy\, Jai tests the same infrastructure and enterprise\n   env
 ironments that millions of customers rely on. His work spans cloud\n   and
  on-premises penetration testing\, IAM privilege escalation\n   research\,
  and building automated offensive tooling that helps turn\n   point-in-tim
 e assessments into continuous detection. Before GoDaddy\,\n   Jai held off
 ensive security roles at Housing.com\, FIS\, and EY\, giving\n   him first
 hand experience with how security weaknesses and\n   misconfigurations sur
 face across different industries\, architectures\,\n   and maturity levels
 .\n\n   Jai volunteers with the DEF CON community as CTF Ops for the Cloud
 \n   Village and on-site Coordinator for the Bug Bounty Village.\n\n   Spe
 akerBio:  Tom McCarthy\n\n   Tom McCarthy is the Director of Offensive Sec
 urity and Business\n   Information Security Officer at GoDaddy\, where he 
 oversees penetration\n   testing\, red team operations\, and security stra
 tegy across multiple\n   lines of business. With over 15 years in offensiv
 e security —\n   spanning consulting\, penetration testing\, research\, 
 and training —\n   Tom has built multiple penetration testing teams from
  the ground up\n   and led or managed hundreds of penetration tests and re
 d team\n   engagements throughout his career. Tom is a returning DEF CON s
 peaker\,\n   having previously presented research\, tooling\, and training
  at both\n   DEF CON and DerbyCon. He has contributed to open-source offen
 sive\n   security projects including smbexec and Metasploit\, and served a
 s a\n   trainer in hacking and incident response for local\, federal\, and
 \n   military organizations across multiple countries.\n\n   '\n\n   1. #L
 VCCW_Level3_South\n\n\n
DTEND:20260808T182000Z
DTSTART:20260808T174000Z
LOCATION:Cloud Village - LVCCW Level 3 W313 (Cloud Village Talks)
SUMMARY:Ghost Records: Automating Dangling DNS & Subdomain Takeover Detecti
 on at Enterprise Scale
END:VEVENT
END:VCALENDAR
