BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Saf
 e-Read and\n   Quick Triage in an Ephemeral MicroVM\n   Tags: DEF CON Demo
  Labs | Intermediate | Defense/Blue Team | Malware |\n   Purple Team | Sec
 Ops | Threat Intel/Hunting | DEF CON Demo Labs\n   When: Friday\, Aug 7\, 
 16:00 - 16:45 PDT\n   Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) 
 - [1]Map\n\n   Description:\n\n   When TSA scans your luggage\, they see w
 hat's inside without opening\n   the bag. MailX-Ray brings that pattern to
  email triage.\n\n   Phishing reports hit analysts as small crises: open c
 arefully\, don't\n   trigger anything\, extract IOCs\, hand off to detecti
 on. Tooling lives\n   at two extremes: cloud sandboxes that ship customer 
 data offsite\, or\n   lightweight CLIs that run malicious parsers directly
  on the analyst's\n   host. Neither produces a portable safe artifact\, on
 -prem and\n   hardware-isolated\, in roughly 30 seconds.\n\n   MailX-Ray d
 oes. Every email is processed inside an ephemeral\n   hardware-virtualized
  microVM with no network device. Network egress is\n   prevented by design
 . Output includes a single-file portable HTML\n   safe-read report\, struc
 tured JSON with 45+ offline signal categories\,\n   and optional STIX and 
 MISP exports for SOC integration. Original\n   attachment binaries are nev
 er re-distributed.\n\n   It's not a malware sandbox. No decompilation\, no
  execution\, no\n   verdicts. It's a non-invasive structural scan: the fir
 st 30 seconds of\n   email triage\, with zero network egress\, on the anal
 yst's own laptop.\n\n   Demo Labs attendees will see the live pipeline acr
 oss real phishing\n   scenarios\, including encrypted nested archives. Ope
 n source on the day\n   of the talk.\n\n   SpeakerBio:  Uğur "uJohn" Can 
 ATASOY\n\n   Uğur Can Atasoy is a Senior Security Engineer at Udemy\, wor
 king\n   primarily on blue and purple team operations.\n\n   A believer in
  hybrid approaches that combine technical fieldwork with\n   academic rigo
 r\, he has spent the past decade across higher education\,\n   media\, def
 ense\, and automotive sectors in roles spanning security\n   architect\, s
 pecialist\, trainer\, and consultant. His work spans both\n   offense and 
 defense — from security operations\, threat hunting\,\n   intrusion dete
 ction\, purple teaming\, and adversary simulation to\n   penetration testi
 ng and secure architecture. He has served as a Senior\n   Content Engineer
  at TryHackMe and as an Information Security Architect\n   at Mercedes-Ben
 z. He has delivered security training for NATO\n   personnel\, law enforce
 ment investigators\, and military leadership\,\n   spoken at DeepSec (Vien
 na)\, holds CCSP\, GCIA\, OSCP\, and OSWP\, and\n   served as an ISC2 SME 
 for exam and training item development. He has\n   been recognized by Orac
 le and IBM for responsible disclosure.\n\n   MailX-Ray is his answer to a 
 recurring annoyance: every tool in the\n   email triage stack is either a 
 cloud SaaS that ships customer data\n   offsite\, a heavyweight VM-based s
 andbox that takes minutes per sample\,\n   or an unprotected CLI that runs
  malicious parser input directly on the\n   analyst's host. It produces a 
 safe artifact analysts can read and\n   forward.\n\n   Links:\n       GitH
 ub - [2]https://github.com/ugurcanatasoy/MailX-Ray\n   '\n\n   1. #LVCCW_L
 evel1_Hall3\n   2. https://github.com/ugurcanatasoy/MailX-Ray\n\n\n
DTEND:20260807T234500Z
DTSTART:20260807T230000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)
SUMMARY:MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quic
 k Triage in an Ephemeral MicroVM
END:VEVENT
END:VCALENDAR
