BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: redStack: Boot-To-Breach Red Team Platform\n   Tags:
  Red Team Village | Misc\n   When: Friday\, Aug 7\, 16:00 - 17:59 PDT\n   
 Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 -\n   [1
 ]Map\n\n   Description:\n   Prerequisites: complete these before the sessi
 on\, published in advance\n   at https://github.com/BaddKharma/redStack-de
 fcon34 (AWS account\, AWS\n   CLI\, Terraform\, and an OpenVPN client). Se
 tup happens ahead of time so\n   it does not eat into the session.\n\n   A
  two-hour hands-on workshop where attendees stand up a full red team\n   o
 perator stack (https://github.com/BaddKharma/redStack) and run it\n   agai
 nst a live cyber range. Each attendee gets their own instanced\n   range o
 ver an OpenVPN tunnel\, so no public DNS or exposed\n   infrastructure is 
 required. You leave with a working lab to build your\n   own tradecraft an
 d OPSEC on.\n\n   Scope: an intermediate session. It assumes some familiar
 ity with\n   pentest or red team topics\, comfort on a Linux command line\
 , and a\n   working understanding of what a C2 framework does. Deep AWS or
 \n   Terraform experience is not required\, but you must arrive with the\n
    prerequisites completed.\n\n   What you build and run: a full operator 
 stack on AWS from a single\n   Terraform apply. Three C2 frameworks (Mythi
 c\, Sliver\, and Adaptix)\, an\n   Apache redirector that gates traffic on
  a header token and CDN-style\n   URI routing with a decoy page for anythi
 ng that fails\, a Guacamole\n   portal for browser-based access to every h
 ost\, and Kali and Windows\n   operator boxes. You stand each C2 up behind
  the redirector\, then drive\n   a boot-to-breach chain against the live r
 ange to SYSTEM.\n\n   What it is not: an Active Directory exploitation cou
 rse. The initial\n   domain compromise is white-carded\, so attendees star
 t from a provided\n   Administrator hash and spend the time standing up an
 d driving the\n   platform rather than working the AD chain. Web exploitat
 ion\, custom\n   payload development\, and AV or EDR evasion are out of sc
 ope.\n\n   Target: a per-user-instanced Hack Smarter Labs range (a Windows
  Server\n   2022 domain controller) reached over an OpenVPN tunnel\, so no
  two\n   attendees touch the same box. Everything runs in your own throwaw
 ay\n   AWS account and is destroyed at the end. redStack is open source\, 
 so\n   you keep a lab you can redeploy on your own after the workshop.\n\n
    Agenda: 10min Intro and setup check. 30min Deploy the stack from one\n 
   Terraform apply\, narrated live. The tunnel comes up\, and the range\n  
  becomes reachable. 5min Break 30min Stand up the three C2 backends\n   (S
 liver\, Mythic\, Adaptix) behind the redirector\, test a beacon from\n   e
 ach. 5min Break 25min Attack the live range together: Sliver beacon\n   fo
 r initial access\, Mythic and Adaptix staged through it\, SYSTEM on\n   th
 e DC. 10min Q&A and teardown (terraform destroy!)\n\n   Speakers:Michael K
 im\,Michael Ortiz\n\n   SpeakerBio:  Michael Kim\n\n   Michael Kim’s jou
 rney into cybersecurity is a story of resilience\n   and reinvention. Havi
 ng lived in seven countries\, he faced relentless\n   bullying\, racism\, 
 and isolation - challenges that once pushed him to\n   the brink. After pu
 rsuing paths in veterinary medicine\, pharmacy\, law\,\n   and biology\, a
 nd graduating with a zoology degree\, he shifted careers\n   entirely duri
 ng the pandemic\, leaving behind a career as a DJ and\n   music producer t
 o chase a new purpose in cybersecurity. Through\n   persistence and countl
 ess failures\, he rose from a boot camp graduate\n   to a Senior Consultan
 t in Offensive Security at Palo Alto Networks\n   Unit 42\, leading red te
 am operations\, adversary simulations\, and\n   penetration tests for glob
 al clients. His multicultural background and\n   lived experiences shape h
 is unique approach to hacking and\n   problem-solving\, and his story prov
 es that adversity can be\n   transformed into strength - and that anyone\,
  no matter their past\, can\n   build a powerful career in cybersecurity.\
 n\n   SpeakerBio:  Michael Ortiz\n\n   Michael Ortiz is a Red Team Enginee
 r and SME on the U.S. Department of\n   State's Red Cell\, running adversa
 ry emulation across State enterprise\n   and partner networks. His focus s
 pans offensive tradecraft\, evasion\n   engineering against modern EDR's\,
  and the cybersecurity engineering\n   behind durable red team infrastruct
 ure. He's the founder of devZero\n   Security\, an SDVOSB offering offensi
 ve security and security\n   engineering services to federal and commercia
 l clients\, and the\n   developer of redStack\, an open source AWS and Ter
 raform project that\n   stands up a full red team operations stack on dema
 nd. A Marine Corps\n   veteran\, Mike holds OSEP\, OSCP\, CRTO\, and CRTL\
 , among other\n   certifications.\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n\n
 \n
DTEND:20260808T005900Z
DTSTART:20260807T230000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Tac
 tic Table 2
SUMMARY:redStack: Boot-To-Breach Red Team Platform
END:VEVENT
END:VCALENDAR
