BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: From Disk Image to ATT&CK in One Binary — a Refere
 nce\n   Architecture for Modern Incident Response (in Rust)\n   Tags: LOON
 G Community | Creator Talk/Panel\n   When: Friday\, Aug 7\, 12:00 - 12:59 
 PDT\n   Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - [1]Map\n\n   
 Description:\n\n   A Reference Architecture for Modern Incident Response (
 in Rust)\n\n   Incident response still runs on a toolbox: a dozen single-p
 urpose\n   parsers\, a pile of CSVs\, a timeline stitched together by hand
 \, and a\n   senior analyst's memory holding it all together. Every engage
 ment\n   re-solves the same plumbing. Every new artifact means a new scrip
 t.\n   And the hard-won expertise — how to read a prefetch run-count\, h
 ow\n   to resolve a ControlSet in an offline hive\, which event IDs actual
 ly\n   matter — lives in people\, not in code you can run twice.\n\n   T
 his talk argues for a different shape: incident response as a\n   framewor
 k\, not a toolbox — and backs the argument with a working\n   reference 
 implementation\, Issen\, an open-source DFIR engine written in\n   Rust. Y
 ou point Issen at evidence — an E01/EWF/VMDK or raw disk\n   image\, a m
 emory dump — and it returns a single normalized timeline\n   and an ATT&
 CK-mapped report. One static binary. No Python runtime\, no\n   agent\, no
  cloud. It runs the same on an examiner's laptop\, in CI\, or\n   inside a
  sealed evidence enclave.\n\n   Under the hood\, Issen is deliberately thi
 n. The real work lives in a\n   fleet of standalone\, single-responsibilit
 y forensic libraries — each\n   a deep expert in one artifact family (NT
 FS and the change journal\,\n   registry hives\, prefetch\, SRUM\, browser
  history\, EVTX\, SQLite\, Windows\n   and Linux memory) — that know not
 hing about each other. Issen is the\n   orchestration and correlation laye
 r that wires them into one story and\n   speaks one normalized vocabulary 
 of findings ("consistent with\," never\n   a verdict)\, each tagged to MIT
 RE ATT&CK. We'll walk the layered model\n   that makes this composition wo
 rk — container → filesystem / memory\n   / log → parser → orchestr
 ation — and why every parser is\n   medium-agnostic by design.\n\n   The
  most useful — and least glamorous — lesson is the one the talk\n   is
  really about: capability is cheap to build and expensive to wire.\n   Dem
 onstrated live against the public "Stolen Szechuan Sauce" case\,\n   we'll
  show artifacts that were completely correct in isolation yet\n   invisibl
 e end-to-end\, because a decoder existed but nothing called it\,\n   or a 
 file was extracted but never classified\, or a real-world quirk\n   (offli
 ne hives have no CurrentControlSet\; large registry values are\n   split i
 nto "big data" segments) quietly returned nothing. We'll trace\n   each fr
 om "zero results" to ground truth.\n\n   Engineering substance throughout:
  panic-free\, forbid(unsafe) parsers\n   that treat every input as hostile
 \; correctness validated against\n   independent external oracles (not jus
 t the authors' own fixtures)\; and\n   a clean separation between observed
  fact\, forensic inference\, and the\n   conclusions that belong to a huma
 n\, not a tool.\n\n   You'll leave with: a concrete\, composable architect
 ure for an IR\n   pipeline you can adopt or fork\; a working open-source r
 eference to\n   start from today\; a repeatable method for finding "dark" 
 capability in\n   your own tooling\; and a sober view of what to automate\
 , what to keep\n   human\, and how to phrase findings so they survive scru
 tiny.\n\n   SpeakerBio:  HUI Kwun Tai\, Albert (4n6h4x0r)\, DC852\n\n   Al
 bert Hui (@4n6h4x0r) is a digital forensics and incident response\n   prac
 titioner and the founder of Security Ronin. He builds open-source\n   fore
 nsic tooling — including Issen\, a Rust DFIR engine\, and a family\n   o
 f panic-free libraries spanning disk\, memory\, registry\, and\n   applica
 tion artifacts — and works hands-on as an examiner and expert\n   witnes
 s testifying before courts of law\, where findings have to\n   survive cro
 ss-examination\, not just look good on a slide. He's drawn\n   to tooling 
 an analyst can actually run twice: reproducible\, offline\,\n   and honest
  about the line between observed fact and inference. In a\n   past life he
  was an IBM Global Security Architect and a Deloitte Risk\n   Advisory Dir
 ector — which goes some way to explaining his propensity\n   for horizon
 tal thinking.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T195900Z
DTSTART:20260807T190000Z
LOCATION:Misc - LVCCW Level 1 Hall 3 1100 (Creator Stage 7)
SUMMARY:From Disk Image to ATT&CK in One Binary — a Reference Architectur
 e for Modern Incident Response (in Rust)
END:VEVENT
END:VCALENDAR
