The #TROOPERS26 ‘AD & Entra ID Security’ track delivered an incredible experience – much like the entire conference! We were thrilled to host some of the brightest minds in identity research alongside a highly engaged audience who brought valuable insights to the roundtable discussions. While the presentation slides have already been published on the TROOPERS website, several speakers have shared complementary tools, in-depth blog posts, and active social media threads. To make things easy, we’ve compiled a comprehensive list of all these fantastic resources from the track below.
Continue readingEvents
TROOPERS26: Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection
Last week I gave a talk at #TROOPERS26: Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection. I discussed the challenges of incident analysis, such as increasing storage capacities and the lack of integration between tools. I presented a modular framework that integrates established forensic and analysis tools using a decision-tree-based control mechanism. A workflow was designed to control the execution of 14 integrated analysis tools in order to reproduce the manual analysis process usually performed by analysts. Moreover, the framework is capable of identifying whether a system has been compromised and compiles a analyst-oriented report. Together with the audience we took a look at the report in a live demonstration. The evaluation results of the framework were promising as it was able to identify all compromised systems. However, a significant number of false positive classifications were also observed. To improve the framework possible future extensions include functionality such as recovering already deleted files to detect missed Indicators of Compromise. Additionally, our team want to integrate artificial intelligence in the workflow to help in data processing and make more decisions automatically. The slides will be published next week on the conference website. I will add the link in this blog post when they become available. A more detailed description of the content of the talk can be found in the following sections. Looking forward to #TROOPERS27!
Continue readingHeads-up: TROOPERS Roundtable – Supply Chain Security
How to strengthen Supply Chain Security: Practical Exchange and Roadmap
Join an open, practitioner-focused roundtable for direct exchange on supply chain security. This session offers a concise overview of core concepts, e.g. SBOM, CSAF, and VEX and digs into the processes behind them: how to obtain, process and apply information to improve security across the supply chain.
We will examine:
- How SBOM, CSAF and VEX relate and why version-level detail matters.
- The practical value of an SBOM and why it’s increasingly required by law and IT procurement.
- How to create and consume SBOMs?
- Methods to identify dependencies in the context of vulnerabilities.
- Approaches to triage: not all vulnerabilities affect every stakeholder equally.
- Techniques to analyze vulnerabilities and identify affected products and product families.
- Sources of vulnerability information and how to map data unambiguously to products and specific software versions.
- Reporting obligations: where and how to disclose vulnerabilities.
- Tools and automation that help manage information volume and complexity.
- Technical, organizational and personnel challenges to achieving end-to-end supply chain security.
- The role of AI in supply chain security.
- How do we protect ourselves from malicious actors / infected dependencies?
- The Cyber Resilience Act (CRA): implications for companies, products and consumers, the CRA roadmap, and concrete deadlines and actions.
- We will show a live demonstration of the whole process, e.g. covering the consumption of SBOMs, vulnerability identification and assessment, creation of VEX documents.
This roundtable is designed for security practitioners, product owners, compliance officers and decision-makers who want actionable guidance and peer discussion. Expect candid conversation, real-world examples and next steps you can take to strengthen resilience across your supply chains.
Continue readingMCTTP 2025 / Keynote
Three weeks ago, I attended MCTTP 2025 in Munich, organized by Vogel IT and curated by the fine folks Florian Hansemann, Dr. Marc Maisch, and Florian Oelmaier. Awesome event with some very cool talks, and great conversations over dinner and most notably at the Oktoberfest on Saturday (thanks again for that special trip, Flo!). I had the pleasure and honor to give the keynote on the 2nd day. The goal was to make it a bit entertaining and enlightening for the international audience, so I covered some German literature, too ;-). The slides can be found here, and the transcript here. Looking forward to meeting some folks again next year, maybe even at TROOPERS26 😉
Continue reading#TROOPERS25 AD & Entra ID Security Track
The #TROOPERS25 ‘AD & Entra ID Security’ track was a blast – as was the whole conference 😉 – bringing together some of the smartest researchers in the field and a great audience of practitioners willing to share their experiences during the roundtable. The slides of the talks have been released in the interim on the TROOPERS website, but since many speakers published additional blogposts or released tools, we provide a compilation of resources from the track in the following.
Continue readingTROOPERS24 Agenda Preview: Active Directory & Entra ID Security Track
Hi,
are you curious about the agenda of the Active Directory- & Entra ID security track at TROOPERS24? Here’s a sneak peak of the already published tracks:
Wednesday, 2024-06-26:
- A Decade of Active Directory Attacks: What We’ve Learned & What’s Next – Sean Metcalf
- ADillesHeel: Making the Impossible Possible in AD Attack Path Analysis – SHANG-DE JIANG
- So You Performed A Forest Recovery. How Do You Reconnect Your AD Again With Azure AD? – Jorge de Almeida Pinto
- Decrypting the Directory: A Journey into a static analysis of the Active Directory NTDS to identify misconfigurations and vulnerabilities – Bastien Cacace (XMCO company)
- Say Hello to your new cache flow! – Geoffrey Bertoli, Rémi Jullian
- Analyzing and Executing ADCS Attack Paths with BloodHound – by Andy Robbins, Jonas Bülow Knudsen
Thursday, 2024-06-27:
- The (almost) complete LDAP guide – Sapir Federovsky
- Exploiting Token-Based Authentication: Attacking and Defending Identities in the 2020s – Dr Nestori Syynimaa
- Attacking Primary Refresh Tokens using their MacOS implementation – Olaf Hartong, Dirk-jan Mollema
- Misconfiguration Manager: Overlooked and Overprivileged – Duane Michael, Chris Thompson
- The Registry Rundown – Cedric Van Bockhaven, Max Grim
The full conference agenda including timeslots will be published soon at TROOPERS24. The trainings are already sold out, but a handful of tickets is currently left. Stay tuned & make the world a safer place!
Continue readingSummary of 'Software-Defined Radio applied to security assessments' at Troopers21
The training Software-Defined Radio applied to security assessments was held by Sébastien Dudek at Troopers21 and was remotely organized – like most other events – due to Covid-19. Once we were all caffeinated, we had an exciting journey through basically all things radio.
We started with the technical and physical basics in radio technology, such as various sorts of antennas, analog to digital coding (and backward), encoding schemes, and general risks and possible vulnerabilities of using radio devices. Commonly found vulnerabilities include the following:
Continue readingACM WiSec 2020
Last week I attended ACM WiSec. Of course, only virtually. The first virtual conference I attended. Coincidentally, it was also the first conference I presented at. While the experience was quite different from a “real” conference, the organizers did a great job to make the experience as good as possible with, for example, a mattermost instance to interact with other conference participants.
In the following, I will list a few talks and papers that I either found very interesting or that generally stood out to me:
Continue readingTROOPERS20 Training Teaser: Attack And Defence In AWS: Chaining Vulnerabilities To Go Beyond The OWASP Top 10
Attackers are everywhere. They are now on the cloud too! Attacking the most popular cloud provider – AWS, requires the knowledge of how different services are setup, what defences do we need to bypass, what service attributes can be abused, where can information be leaked, how do I escalate privileges, what about monitoring solutions that may be present in the environment and so on! We try to answer these questions in our intense, hands-on scenario driven training on attacking and subsequently defending against the attacks on AWS.
Continue readingTROOPERS20 Training Teaser: Hacking Node.js & Electron apps, shells, injections and fun!
Did you know that in the ever evolving field of Web and Desktop apps, it turns out these can all now be powered with JavaScript? You read that right: JavaScript is now used to power both web apps (Node.js) as well as Desktop apps (Electron). What could possibly go wrong?
So, the burning question is: how does this affect Web and Desktop app security? If you want to find out, come to our training and you will experience this in a 100% hands-on fashion! 🙂
Continue reading