BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Your OpSec Is Showing\n   Tags: Recon Village | Crea
 tor Talk/Panel\n   When: Saturday\, Aug 8\, 13:30 - 13:59 PDT\n   Where: L
 VCCW Level 1 Hall 3 801 (Creator Stage 2) - [1]Map\n\n   Description:\n   
 Most threat intelligence focuses on what attackers have already done:\n   
 payloads\, malware families\, and post-compromise behavior. But\n   advers
 aries are far more fluid at the payload layer than they are at\n   the inf
 rastructure layer. Domains rotate\, IPs churn\, and malware gets\n   recom
 piled but infrastructure leaves patterns.\n\n   This article explores how 
 to track threat actors through their\n   infrastructure by leveraging fing
 erprinting techniques that expose\n   those patterns at scale.\n\n   We’
 ll walk through practical methods including JARM for active TLS\n   stack 
 fingerprinting\, JA3/JA4 for identifying consistent communication\n   beha
 viors\, SSH host key correlation for infrastructure pivoting\, and\n   Mur
 murHash for clustering phishing kits and web panels through shared\n   ass
 ets. Individually\, these signals are useful. Combined\, they allow\n   de
 fenders to map infrastructure clusters tied to a single actor or\n   campa
 ign—even when traditional indicators change.\n\n   The focus is not on a
 ttribution for its own sake\, but on building a\n   repeatable approach to
  discovering “sister infrastructure” and\n   identifying campaigns ear
 lier in their lifecycle. By shifting\n   attention away from payloads and 
 toward the systems attackers stand up\n   to operate\, defenders can detec
 t patterns before deployment and reduce\n   time to awareness.\n\n   Attac
 kers rely on reuse of configurations\, tooling\, and\n   infrastructure. T
 hat reuse creates fingerprints. And those\n   fingerprints are often more 
 durable than the indicators most teams\n   prioritize.\n\n   If you want t
 o track threat actors effectively\, stop chasing malware.\n\n   Track the 
 infrastructure they can’t help but reuse.\n\n   SpeakerBio:  Fae Blu3Bir
 d" Carlisle\n\n   Fae Carlisle (Blu3Bird) is a threat intelligence and DFI
 R practitioner\n   working at the intersection of intelligence\, detection
 \, and threat\n   hunting. She is an active member of hackers.town hacking
  community.\n   Her work focuses on operationalizing intelligence\, buildi
 ng systems\n   and workflows that turn fragmented signals into actionable 
 insights\n   for real-world defense. She has experience developing intelli
 gence\n   pipelines and supporting detection efforts in production environ
 ments\,\n   with a focus on bridging the gap between analysis and response
 .\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T205900Z
DTSTART:20260808T203000Z
LOCATION:Recon Village - LVCCW Level 1 Hall 3 801 (Creator Stage 2)
SUMMARY:Your OpSec Is Showing
END:VEVENT
END:VCALENDAR
