BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Ghost in the Water: Simulating a Nation-State PLC Sa
 botage\n   Campaign\n   Tags: Red Team Village | Misc\n   When: Sunday\, A
 ug 9\, 14:00 - 14:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team Vil
 lage) Tactic Table 4 -\n   [1]Map\n\n   Description:\n\n   Critical infras
 tructure protocols designed in the late 70s were never\n   built to handle
  a modern adversary. In this hands-on Tactic\, we move\n   beyond theoreti
 cal slides to execute a high-fidelity\,\n   nation-state-style operation a
 gainst a municipal water treatment\n   facility. Using a portable Software
 -in-the-Loop (SiL) environment\,\n   participants will experience the raw 
 tradecraft of industrial sabotage\n   without the need for a six-figure ha
 rdware rack.\n\n   This session focuses on "Living-off-the-Ladder" (LotL)â
 €”the art of\n   using legitimate industrial function codes to perform una
 uthorized\n   actions. You will not be dropping malware\; you will be\n   
 programmatically manipulating the physics of the plant using the same\n   
 TTPs seen in recent geopolitical conflicts.\n\n   The Mission (30â€“60 Min
 ute Sprint):\n\n   Industrial Interrogation: Use unauthenticated DNP3 and 
 S7comm\n   discovery to fingerprint PLCs and map the process logicâ€”captu
 ring\n   vendor data and firmware versions silently.\n\n   The Memory Heis
 t: Execute a "Credential Harvest" (T0861) by\n   programmatically reading 
 PLC holding registers to recover plaintext\n   maintenance keys.\n\n   Coo
 rdinated Sabotage: Trigger a "Slow-and-Low" chemical setpoint\n   override
  (Modbus FC16) across multiple facilities simultaneously\,\n   observing r
 eal-time physical feedback from the simulated plant\n   sensors. â€˘ Phase
  1: Automated multi-protocol fingerprinting and\n   asset discovery. â€˘ P
 hase 2: Executing a "Memory Heist" to extract\n   plaintext maintenance cr
 edentials directly from PLC registers. â€˘\n   Phase 3: A coordinated "Slo
 w-and-Low" chemical setpoint override\,\n   providing real-time visual fee
 dback of the physical process failure.\n\n   Attendee Takeaway: Participan
 ts will build the muscle memory required\n   to navigate OT environments a
 nd will leave with a deployable\,\n   containerized SiL framework to conti
 nue their own ICS research and\n   detection validation at home. Attendees
  will leave with a deployable\n   SiL framework and the "Living-off-the-La
 dder" playbook to continue\n   their own ICS research without the need for
  expensive hardware.\n\n   Speakers:Blessen Thomas\,Javier HernĂˇndez\,Woj
 ciech Poparda\n\n   SpeakerBio:  Blessen Thomas\n\n   Blessen Thomas is an
  Independent Security Researcher.He has more than\n   13+ years of experie
 nce in Red Teaming\, Appsec (Web\, Thick\, API &\n   Mobile Apps)\, Smart 
 Watch Wearable Application Penetration Testing\,\n   Mobile Penetration Te
 st (iOS\,Android\,Windows platform)\, IoT\,OT\n   \,mainframes\,SAP\,SWIFT
 \,RPA\,Cloud\,ATM\,KIOSK\,Vulnerability Assessment and\n   Network Penetra
 tion Test\,Physical Covert Entry\,Wireless\n   assessments\,Telecom(2G\,3G
 \,USSD) etc. for several enterprise companies\n   and financial institutio
 ns all across the globe. He is a B.Tech in\n   Information Technology from
  Anna University and holds industry\n   certifications such as SANS GPEN\,
 CRTO\,OPST\,CREST CRT(PEN)\,CREST\n   CPSA\,OSCP\,CRTP\,OSWP\,C)PTE\,CEH\,
 CHFI. He has been listed and\n   acknowledged in various â€śHALL OF FAMESâ
 €ť for various companies such\n   as Oracle\,Sony\, Kayako\, Appcelerator\
 , Hotgloo\, Meldium\, Splunk and\n   many more for responsible disclosure.
  He has been a bug bounty hunter\n   and contributor for the OWASP Mobile 
 Testing Guide Project(MSTG)\,Tamer\n   OS\, Seclists\, OWASP top 10 API\, 
 OSSTMM\, Awesome Mainframe\n   Hacking\,RvR\,WAVSEP Benchmark sectool proj
 ects. His research\n   training/talks has been accepted into various secur
 ity conferences\n   like Hack in the Box-Dubai\,Hacktivity -Hungary\, CanS
 ecWest\n   -Canada\,OWASP Appsec EU- London -UK\,OWASP Appsec Europe-Italy
 \,\n   RootCon-Philippines \,OWASP PH\,OWASP New Zealand Day\, Infosec\n  
  SouthWest\,Austin\,Texas\, FSec-Croatia\, Hackbeach\, Hackfest\,\n   Shak
 acon\,ITWeb-South Africa\, Jordan Cyber Security Summit\,\n   HITCON-Taiwa
 n\, OWASP AppSec-Bucharest\, OWASP Appsec\n   Africa-Morocco\,CircleCityCo
 n\,OWASP\n   Botswana\,CactusCon\,Bsides-London\,Prishtina\,Aarhus\,Vilniu
 s\,Elbsides\,Kristiansand\,Athens\n   and many more. He has been invited a
 s Speaker for Radio Talk Shows for\n   All India Radio. He spends his leis
 ure time playing drumkit and\n   percussion.\n\n   SpeakerBio:  Javier Her
 nĂˇndez\n\n   Javier is a Red Team Operator and Malware Developer speciali
 zing in\n   offensive engineering\, adversary emulation\, and custom tooli
 ng\n   development. Holding certifications such as OSEP and CRTO\, he has\
 n   delivered highâ€‘impact security engagements across both consulting\n 
   environments and inâ€‘house security teams. His work focuses on\n   craf
 ting stealthy implants\, evasion techniques\, and\n   automationâ€‘driven 
 offensive capabilities. Passionate about applied\n   research\, he explore
 s the intersection of malware development and\n   AIâ€‘augmented offensive
  security to help organizations strengthen\n   their resilience against mo
 dern threats\n\n   SpeakerBio:  Wojciech Poparda\n\n   Wojciech Poparda is
  a cybersecurity consultant. He helps organizations\n   proactively defend
  their digital infrastructure by thinking like an\n   adversary. Leveragin
 g a deep foundation in Offensive Security\, he\n   specializes in designin
 g resilient Security Architectures that bridge\n   the gap between complex
  attack vectors and enterprise defense\, with a\n   sharp focus on Cloud S
 ecurity and Identity & Access Management (IAM).\n\n   His approach is back
 ed by rigorous technical validation\, holding\n   industry-leading certifi
 cations including OSCP\, CRTE\, CRTP\, CRTO\,\n   CPTS\, CWES\, AWS Certif
 ied Solutions Architect - Associate and AWS\n   Certified Security - Speci
 alty. He is also an Associate of ISC2\,\n   having successfully passed the
  CISSP exam.\n\n   Beyond the terminal\, he channels the discipline\, focu
 s\, and resilience\n   required for cybersecurity into his life as a triat
 hlete. As an\n   IRONMAN European and World Championships finisher\, he br
 ings the same\n   endurance and dedication to solving complex security cha
 llenges as he\n   does to the race course.\n\n   '\n\n   1. #LVCCW_Level1_
 Hall1\n\n\n
DTEND:20260809T215900Z
DTSTART:20260809T210000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Tac
 tic Table 4
SUMMARY:Ghost in the Water: Simulating a Nation-State PLC Sabotage Campaign
END:VEVENT
END:VCALENDAR
