Opening Ceremony #
Abstract
No description provided.
No description provided.
When testing a Domain, control is everything. Command and control frameworks give operators the ability to manage access, pivot efficiently, and maintain persistence across complex environments. Among modern C2s, Sliver stands out as a free and flexible framework that rivals many commercial offerings. This talk will be a walkthrough of Sliver C2, from installation to building profiles, configuring listeners, and generating your payloads. Attendees will leave with practical knowledge of how sliver fits into real red team engagements and what makes it different from traditional frameworks, and how to get the most out of its features when working against AD environments!
I'm Jacen Hyde, also known as Static, and the founder of Static Security Solutions. With a background in System Administration, I specialize in penetration testing, exploit development, and command and control frameworks, my passions involve reading, playing guitar, spending time in church and studying offensive security!
What happens when a curious kid invents a device to drown out a noisy world? She creates the Peace Pal, a calming gadget with soothing music that glows with a gentle blue light. Join us as we hack-together this idea, using scrounged parts, ingenuity, and very few dollars. This isn't just a talk about electronics; it's a story of curiosity, creative problem-solving, and proving that big ideas can come to life with a tiny budget.
Everleigh Goerz is an 10-year-old who can solder better than her Dad. She loves horses and making art.
Ben Goerz - her Dad - is much older. He does boring stuff at work, but fights cyber bad guys, so that's pretty cool. He has too many Raspberry Pis because he's often tinkering on electronic projects.
AI is a red-hot topic everywhere, Dallas included. From local startups using AI to big telecom and finance firms automating processes, Dallas is experimenting with it, worried about it, or both. The rise of generative AI tools like ChatGPT has transformed how organizations operate, but with innovation comes risk. This talk explores how security and governance professionals can manage the unique challenges posed by AI and emerging technologies. From data leakage and model bias to regulatory uncertainty and ethical oversight, we'll examine the evolving landscape of AI risk and how to build governance frameworks that keep pace. Attendees will learn how to draft AI usage policies, apply NIST's AI Risk Management Framework, and establish internal controls that balance innovation with accountability. Whether you're a GRC analyst, or tech leader, this session will equip you with practical strategies to govern AI responsibly in your organization.
CP Pandurangan is an Experienced Manager in BDO Digital's Cybersecurity Practice, specializing in cybersecurity strategy, program assessments, application threat risk assessments, third party/vendor risk, and roadmap development. With nearly a decade of consulting experience across healthcare, technology, public sector, and not-for-profit organizations in Southeast Asia and North America, she partners closely with CXOs and senior leaders to align security investments to business outcomes and measurable risk reduction. She has written various Point of View (POV) documents and keeps up to date on the changes in the Federal and State cyber and privacy bills. CP brings deep expertise with leading frameworks such as NIST CSF, ISO/IEC 27001:2022, and CIS Critical Controls, and integrates threat intelligence, benchmarking, and KPIs to mature cyber programs. Her AI security and governance proficiency includes secure AI adoption, AI risk assessments, model and data protection, AI policy and control design, and alignment to emerging guidance such as the NIST AI RMF and evolving regulatory expectations. A frequent author of Points of View, CP tracks updates to federal and state cyber and privacy bills and translates regulatory change into practical, prioritized actions for clients.
No description provided.
0DAYALLDAY is a quarterly vulnerability research event that brings together DFW's top information security researchers and hackers. If you're an experienced vulnerability researcher or just want to come and learn what its all about, all are welcome.
As the OT/ICS cybersecurity landscape evolves, penetration testing is increasingly viewed as a tool for identifying vulnerabilities in industrial environments. Yet, many organizations fail to derive meaningful value from these tests. Why? Most are simply not ready. Without the necessary visibility into their systems, clear testing objectives, and established safety measures, organizations risk destabilizing critical operations while producing results that fail to address real-world risks. In this session, we’ll explore the common pitfalls that hinder OT/ICS penetration testing and outline practical steps to prepare your environment for success. From developing a comprehensive asset inventory to defining test objectives aligned with business-critical processes, this presentation will provide actionable guidance for closing the readiness gap. Attendees will also gain insights from real-world case studies illustrating both failures and successes in OT/ICS penetration testing. Join us to learn how to unlock the true potential of penetration testing in your OT/ICS environment—safely, effectively, and strategically. Whether you’re a plant manager, cybersecurity professional, or control systems engineer, this session will equip you with the knowledge and tools to get your organization ready.
Dennis Distler is a seasoned cybersecurity professional with over 25 years of experience, including more than a decade focused on Operational Technology (OT) and Industrial Control Systems (ICS). As the founder of Enaxy, an OT/ICS cybersecurity consultancy, he helps a range of clients from fun ones like theme parks to critical infrastructure such as oil & gas, energy, chemical manufacturing, and utility organizations secure their infrastructure while maintaining operational continuity. Dennis blends deep technical knowledge with strategic insight to address the unique challenges of converged IT/OT environments. His risk-based, pragmatic approach enables clients to defend against threats ranging from ransomware to nation-state actors. He has led successful initiatives in network segmentation, secure remote access, anomaly detection, and incident response across high-risk sectors. Renowned for making complex security concepts actionable, Dennis works with everyone from C-Level executives to front-line engineers and technicians to build resilient, secure, and sustainable industrial ecosystems. He holds the CISSP, GICSP, GRID, multiple ISA/IEC 62443 cybersecurity certifications, and numerous other cybersecurity-related certifications.
The Pwnage of ADCS ESC1 - Bad SANS ESC8 - NTLM Relay
While it’s important for everyone to practice good habits regarding their data security, activists and agents of social change must take a more informed approach to protecting their privacy. This interactive session has the audience step into various scenarios, turning each character’s threat model into actions to remediate the threats. This session is a collaboration between Techies 4 Reproductive Justice and LibreTechnica.
Techies for Reproductive Justice is a coalition space for abortion-minded* technologists to convene to build connection, trust, tech literacy, and capacity within the abortion access movement and across values-aligned movements. We envision this cohort of technologists grounded in Reproductive Justice combating the problems of burnout, isolation, and scarcity so that a community of tech-capable, values-aligned people can be ready to support abortion funds, practical support orgs, advocacy orgs, and anybody on the front-lines holding the line for bodily autonomy.
LibreTechnica shares knowledge about technologies developed for the benefit of the commons. By promoting open-source technologies that are free from and resistant to corporate control, government censorship, political coercion, and environmental harm, we can together heighten and sustain the common good.
Let's discuss generative AI and how it surfaces data and steps to mitigate over exposure. This will utilize Microsoft tools, but the talk track will be designed around general practices.
A security practitioner with a background in cloud security, printer exploitation, and consulting, I thrive on exploring new hacking tools and hands-on labs. With a curiosity that spans the entire cybersecurity landscape, I enjoy diving into emerging threats, unconventional attack surfaces, and creative defense strategies. Outside of technical work, I am a dedicated mentor and volunteer to present at schools so engage future generations.
Behind the abstraction lies a misconception, that serverless means "less" responsibility. Spoiler alert - it doesn't! Fast and adaptable, serverless is also dangerously simple to configure incorrectly. In highly dynamic, event-driven Cloud environments, sporadic and fine-grained service integrations introduce unique attack surfaces that traditional security models fail to address. This technical session dives deep into the tactics, techniques, and procedures (TTPs) adversaries use to exploit serverless applications via new attack vectors, including vulnerable libraries, leaky secrets, wildcard IAM roles, and insecure triggers. It also emphasizes actionable, tried-and-true methods over theory - equipping practitioners with the skills to defend modern serverless stacks while maintaining operational velocity. The key takeaways from this session include a clear understanding of how serverless risks differ from traditional application threats, especially in areas like ephemeral execution, implicit trust boundaries, and event-driven attack vectors. Lastly, executives and architects will learn how these lines can be inadvertently crossed, exposing data or escalating privileges.
Cybersecurity Engineer with diverse experience across Healthcare, Banking, Public, and Telecom sectors, cross-functional project guidance and stakeholder support, security architecture strategy, application security, predictive analytics, and enterprise risk management. Adept at designing and implementing scalable solutions, driving automation, and delivering quantifiable value and innovation.
With nearly a decade of experience across e-commerce, healthcare, gaming, open-source, and cybersecurity in both large enterprises and agile startups, Shivam brings a creative, solutions-driven approach to complex challenges. He mentors cybersecurity talent, reviews research, supports tech-for-good initiatives, and currently leads cloud security efforts at JPMorganChase.
In the long-ago times when the digital seas and cyber plains were new everyone was free to go wherever and however, they pleased. Then as things began to become more standardized the users began to split into factions. Some who thought that there needed to be more structure became ninjas and those who fought for freedom were pirates. Using analogy we will dive into the difference between GRC and Operational security why they hate each other and why we need to end the war.
Paul served in the US Army for 20 years until retiring in 2024. In the US Army he worked as an Information Technology Specialist and Cyber Network Defender in Georga, Texas, Iraq, and Korea. Now works for Black Hills Information Security (BHIS) as of April 2024 as a SOC Analyst and Detection Engineer. In this role, he monitors client networks for any kind of malicious behavior. Also, he creates and refines detections to find any indication of malicious activity and is passionate about removing as many false positives as possible while never introducing false negatives. Outside of work, Paul’s interests include special needs advocacy and playing Dungeons & Dragons.
The presentation addresses strategic vulnerability management in an AI-driven landscape. 1.) Traditional patching is insufficient due to the growing volume of vulnerabilities and EOL software. 2.) AI-powered vulnerability management offers intelligent prioritization and automated remediation. 3) The "Done-For-You" remediation model involves AI-generated fixes and human oversight. Case studies demonstrate significant vulnerability reduction with AI remediation.
Sandeep Gundapaneni is the Senior Manager of Security Engineering on the Cloud Security team at Credit Karma. My professional background is rooted in cybersecurity, particularly Identity and Access Management, vulnerability management, Network Security, Cryptography and the evolving risks brought by AI in modern infrastructures. Over the years, I’ve led critical programs that; balance usability and security, and I’m passionate about distilling complex problems into actionable strategies that practitioners can immediately take back to their teams.
In 2025, the code we trusted has gained a mind of its own. Autonomous AI agents are no longer science fiction; they're being deployed as enterprise copilots, financial RPA bots, and IoT guardians. But as Westworld's Elsie Hughes said, "I always trusted code more than people anyway." What happens when that code can be lied to, manipulated, and turned against us in a brutal race for control? Unlike traditional applications,. Agentic AI systems can plan, remember, and act on their own, creating a dizzying new attack surface that traditional threat modeling techniques can’t effectively handle, leaving us running for our lives against the Frankensteinian intelligence we are building. This talk is your primer for survival. We'll start as novices, breaking down the foundational OWASP Agentic AI threat taxonomy to build a vocabulary for this new domain. Then, we'll level up to Maestro, introducing the MAESTRO framework—a powerful, layered methodology for systematically hunting for vulnerabilities in complex agentic architectures. By mapping threats to specific architectural layers, from the foundation model to the agent ecosystem, MAESTRO turns chaos into a structured, repeatable process. The best hackers aren't running from AI; they're learning its playbook. Join this session to become the maestro of your AI orchestra, ensuring it plays your symphony, not its own chaotic dirge. It's time to become the handler, not the handled.
Syed is a Senior Security Solutions Architect at AWS. He works with large cloud native firms to help them achieve their business goals in AWS, in alignment with their risk appetite. Syed likes to create holistic cybersecurity solutions using a multi-disciplinary approach. In his spare time, he can be caught making wood and metal projects at the local Makerspace and perfecting his coffee brewing process.
Justin is currently a Solutions Architect at AWS. He works with large organizations to architect and deploy cloud-based solutions securely and efficiently for their business needs. Justin likes to utilize a customer-oriented approach when designing solutions to create solutions around a model of least privilege. In his spare time, he enjoys golfing, sporting clays and over engineering his home network.
Identity is the most targeted and least understood layer of cybersecurity. In this beginner-friendly session, we'll explore what identity security really means, the foundational pillars of IAM, and how identity-related failures have led to major breaches. Learn how IAM fits into the broader cyber landscape and why it's a great career path for newcomers looking to make an impact fast.
Dhivya Balasubramanian is a cybersecurity leader with nearly 20 years of overall experience, including ~10 years in cybersecurity and 7 years in people leadership, providing strategic direction, delivering enterprise-scale solutions. As a passionate advocate for diversity and inclusion in technology, she is dedicated to not only advancing security practices but also creating a more inclusive and empowering environment for women in tech. Currently serving as Cybersecurity IAM Manager at Southwest Airlines, Dhivya Balasubramanian has led numerous initiatives focused on identity and access management (IAM), Zero Trust security, and digital identity protection, helping enterprises secure sensitive data and build stronger defenses against cyber threats. She has delivered innovative solutions to ensure that both individuals and organizations maintain control over their personal and business identities in an increasingly digital world.
Microsoft directsend allows emails to be sent to Excahnge Online using MX endpoint that is publicly available and requires no credentials, only a valid email address. When direct send is enabled, for organizations that are hybrid - direct send can potentially bypass on-prem email protections. This can be used by attackers to send spoofed emails, malware, and BEC style attacks that would normally be blocked.
James H. King is an experienced IT security professional with a strong background in threat detection, incident response, and PowerShell scripting. A graduate of Western Governors University, he has worked across both public and private sectors, specializing in identity management, email security, network forensics, and vulnerability management. James is also skilled in Business Email Compromise investigations, leveraging his expertise to identify and mitigate security risks. Known for his analytical approach, he has successfully managed complex projects and trained teams in cybersecurity best practices. Outside of work, he is a dedicated father of three, balancing family life with ongoing professional development.
The purpose of business Calculating Throughput Identifying bottlenecks Counterintuitive outcomes Live application Additional Resources
Jacen Kohler is currently pursuing an Executive MBA at Southern Methodist University while helping run technology risk exceptions at a highly regulated financial firm. Previously he built out an Attack Surface Management program at a large critical infrastructure manufacturer. Prior to his current role, he consulted various F100 companies on matters of strategy, communication, and consumer privacy as a member of a big four consulting firm. Jacen started his cyber and information security career at a large investment bank where he ran their global social engineering program, SAST, application allow listing, and supervising approvals of all new applications with data leaving the banks network immediately following his graduation from UNT with his BS in Computer Engineering and Certificate in Cybersecurity from the NSA and led a capstone senior design team doing research for NASA to develop an IP addressing scheme for high ping networks of spacecraft. When not at work, Jacen enjoys spending time with his dog, 3D printing, and running the Red Team for the Southwest region of the Collegiate Cyber Defense Competition.
No description provided.
Security BSides Dallas - Fort Worth was founded to facilitate the exchange of information and the development of relationships. We welcome and encourage the expression and debate of ideas. We also recognize that we do not have to agree in order to listen to, and/or understand, a given point of view. However, there is a language and a behaviour that is appropriate and expected in achieving that discourse.
Harassment and/or abusive behaviour will not be tolerated.
Any participant that experiences and/or witnesses inappropriate behaviour is expected to report said behaviour to event staff.
Any participant that experiences and/or witnesses inappropriate behaviour is encouraged to ask the offending individual to stop.
Any participant asked to stop a behaviour is expected to comply immediately.
Event organizers reserve the right to respond to observed and/or reported behaviour in a manner deemed appropriate, including but not limited to expulsion without refund and referral to the relevant authorities.
It is our goal to ensure that the event is welcoming, enjoyable, and safe for all participants.
Be exemplary for each other. See something, say something.