{"id":437,"date":"2025-10-03T10:03:40","date_gmt":"2025-10-03T14:03:40","guid":{"rendered":"https:\/\/bsidesmtl.ca\/?page_id=437"},"modified":"2025-10-03T10:45:20","modified_gmt":"2025-10-03T14:45:20","slug":"programme-2024-fr","status":"publish","type":"page","link":"https:\/\/bsidesmtl.ca\/fr\/bsides-montreal-fr\/programme-2024-fr\/","title":{"rendered":"Programme 2024 | FR"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"437\" class=\"elementor elementor-437\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-42b8c48 e-flex e-con-boxed e-con e-parent\" data-id=\"42b8c48\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9ba12c1 elementor-widget elementor-widget-heading\" data-id=\"9ba12c1\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">2024 Horaire| 14 Septembre | Biblioth\u00e8que et Archives nationales du Qu\u00e9bec<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-927c490 elementor-widget elementor-widget-text-editor\" data-id=\"927c490\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\">8:30AM | Ouverture des portes et caf\u00e9<br \/><\/span><\/span><\/span><\/strong><\/p><p><strong><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\">\u00a0<\/span><\/span><\/span><\/strong><\/p><p><strong><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\">9:00AM \u2013 9:05AM | Mot d&rsquo;ouverture<br \/><\/span><\/span><\/span><\/strong><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>\u00a0<\/b><\/span><\/span><\/span><\/p><p><strong><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\">9:05AM \u2013 11:00AM |\u00a0<\/span><\/span><\/span><\/strong><strong style=\"color: var( --e-global-color-text );\"><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><a href=\"https:\/\/bsidesmtl.ca\/workshop-github\/\"><u>Workshop \u00ab\u00a0Intro to Windows Forensics for Insider Threat\u00a0\u00bb<\/u><\/a><\/span><\/span><\/span><\/strong><\/p><div>\u00a0<\/div><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>9:05AM \u2013 9:30AM | Reconsidering Cybercriminal Expertise Through Their Behavior With Command-Line Interface vs Graphical User Interface<br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Andr\u00e9anne Bergeron<\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/span><\/p><p><strong><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\">9:30AM &#8211; 9:55AM | Beyond Interactions: Hacking Chatbots Like A Pro<br \/><\/span><\/span><\/span><\/strong><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Naveen Konrajankuppam Mahavishnu &amp; Mohankumar Vengatachalam<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>9:55AM \u2013 10:20AM | Deciphering Threat Modeling: Balancing Tools and Manual Approaches For Effective Security<\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Niharika Gehani<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>10:20AM \u2013 10:45AM | Dump Me If You Can &#8211; Hardware Hacking<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b><br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Adrien Lasalle<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>10:45AM \u2013 11:00AM | PAUSE CAF\u00c9<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b><br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>\u00a0<\/b><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>11:00AM \u2013 11:25AM | Persona Theory: Infiltration &amp; Deception of Emerging Threat Groups<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b><br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Tammy Harper<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>11:25AM \u2013 11:50AM | Hide And Seek: Chasing Cybercriminals Around The World<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b><br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Constance Prevot<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>11:50AM \u2013 12:15PM | MacOS Red Team On Corporate Scenarios<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b><br \/><\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">L0gan<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>12:15PM \u2013 1:15PM | DINER FOURNI SUR PLACE<\/b><\/span><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b><br \/><\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><span style=\"font-weight: bold;\">1:15PM \u2013 4:15PM | <\/span><\/span><\/span><\/span><\/span><u><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span style=\"font-weight: bold;\"><a href=\"https:\/\/bsidesmtl.ca\/workshop-github\/\">Workshop \u00ab\u00a0<\/a><\/span><\/span><\/span><\/span><span style=\"color: #244084; font-family: Montserrat, serif; font-size: small;\"><span style=\"font-weight: bold;\"><a href=\"https:\/\/bsidesmtl.ca\/workshop-github\/\">Recon Like an Adversary: Uncovering Modern Techniques in Attack Surface Management\u00a0\u00bb<\/a><\/span><\/span><\/u><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>1:15PM \u2013 1:40PM | La roue des changements de comportement en cybers\u00e9curit\u00e9<\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">M\u00e9lina Girard<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>1:40PM \u2013 2:05PM | Maslow&rsquo;s Pyramid To Craft An Efficient Cybersecurity Spending Strategy<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b><br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Anne-Marie Faber &amp; Julien Turcot<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>2:05PM \u2013 2:30PM | Applying Edward Tufte&rsquo;s Design Principles in Cybersecurity and OSINT Reporting<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b><br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Zuzanna Chociej<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>2:30PM \u2013 2:55PM | Experience Report: Running A Cybersecurity Camp For 13-15-year-olds In Maine<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b><br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Gary Cantrell, Scott Valcourt &amp; Lindsay Jamieson<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>2:55PM \u2013 3:10PM | PAUSE CAF\u00c9<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b><br \/><\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>3:10PM \u2013 3:35PM | Panorama des menaces num\u00e9riques li\u00e9es \u00e0 la Chine<\/b><\/span><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b><br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Mathieu Tartare &amp; Matthieu Faou<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>3:35PM \u2013 4:00PM | Versus Killnet<br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\"><span lang=\"fr-CA\">Alex Holden<\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/p><p><span lang=\"fr-CA\"><b style=\"color: #244084; font-family: Montserrat, serif; font-size: small;\">4:00PM \u2013 4:25PM | <\/b><span style=\"color: #244084; font-family: Montserrat, serif; font-size: small;\"><b>Cybers\u00e9curit\u00e9 et triche dans les jeux vid\u00e9o : un danger insoup\u00e7onn\u00e9<\/b><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\"><span lang=\"fr-CA\">Jonathan Nomed<\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/p><p><span lang=\"fr-CA\"><b style=\"color: #244084; font-family: Montserrat, serif; font-size: small;\">4:25PM \u2013 4:50PM | <\/b><span style=\"color: #244084; font-family: Montserrat, serif; font-size: small;\"><b>Prot\u00e9gez vos pipelines CI\/CD dans Github Actions avec Bullfrog<\/b><\/span><br \/><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Fran\u00e7ois Allard &amp; Mathieu Larose<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>4:50PM \u2013 4:55PM | Mots de fermeture<\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>4:55PM \u2013 8:00PM | Cocktail<\/b><\/span><\/span><\/span><\/span><b><\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-17c1a56 e-flex e-con-boxed e-con e-parent\" data-id=\"17c1a56\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-62dfb26 elementor-widget elementor-widget-heading\" data-id=\"62dfb26\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">2024 Horaire \u2015 Programme d\u00e9taill\u00e9<\/h2>\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-3a13158 e-con-full e-flex e-con e-child\" data-id=\"3a13158\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ab31c1e elementor-widget elementor-widget-image\" data-id=\"ab31c1e\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/Melina-rcnum9ldhsrbylzqqo84m2zxl5waa3josewofo0qx0.jpg\" title=\"Melina.jpg\" alt=\"Melina.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1055ff0 elementor-widget elementor-widget-heading\" data-id=\"1055ff0\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">M\u00e9lina Girard<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2b2dc32 elementor-widget elementor-widget-heading\" data-id=\"2b2dc32\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">La roue des changements de comportement en cybers\u00e9curit\u00e9<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-874c3f7 elementor-widget elementor-widget-text-editor\" data-id=\"874c3f7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Le facteur humain est souvent identifi\u00e9 comme l\u2019un des maillons les plus vuln\u00e9rables en mati\u00e8re de cybers\u00e9curit\u00e9. Les recherches sur l\u2019efficacit\u00e9 \u00e0 long terme de la formation en cybers\u00e9curit\u00e9 chez les utilisateurs donnent des r\u00e9sultats mitig\u00e9s. Certaines \u00e9tudes indiquent que les programmes d&rsquo;\u00e9ducation, de formation et de sensibilisation \u00e0 la s\u00e9curit\u00e9 (SETA) peuvent, dans un premier temps, r\u00e9duire la susceptibilit\u00e9 au phishing et diminuer les taux de clics. Cependant, l\u2019impact de ces programmes diminue souvent au bout d&rsquo;un mois, soulevant des questions sur leur efficacit\u00e9 \u00e0 long terme et sur la n\u00e9cessit\u00e9 de m\u00e9thodes alternatives pour induire des comportements s\u00e9curitaires durables chez les utilisateurs. Une approche innovante pour comprendre et influencer ces comportements en cybers\u00e9curit\u00e9 est l&rsquo;application de la roue des changements de comportement (Behavior Change Wheel, BCW). Cette pr\u00e9sentation explore comment cet outil conceptuel, couramment utilis\u00e9 dans les domaines de la sant\u00e9 publique et des sciences comportementales, pourrait \u00eatre utilis\u00e9 pour am\u00e9liorer la s\u00e9curit\u00e9 num\u00e9rique. La BCW se compose de trois couches principales, offrant une approche holistique et structur\u00e9e pour changer un comportement : la source du comportement, les interventions et les politiques. En analysant la source du comportement (COM-B), nous comprenons les capacit\u00e9s, les opportunit\u00e9s et les motivations n\u00e9cessaires au changement. Les interventions sont ensuite con\u00e7ues sp\u00e9cifiquement pour cibler ces d\u00e9terminants, et des politiques appropri\u00e9es sont mises en place pour soutenir et maintenir les changements de comportement. Cette approche int\u00e9gr\u00e9e garantit que les interventions sont non seulement bien cibl\u00e9es mais aussi soutenues par des structures et des politiques solides. En appliquant la BCW \u00e0 la cybers\u00e9curit\u00e9, nous pouvons maximiser les chances de succ\u00e8s des changements de comportement, renfor\u00e7ant ainsi la r\u00e9silience des organisations face aux menaces num\u00e9riques et favorisant une culture de s\u00e9curit\u00e9 proactive.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2a2f8cc elementor-widget elementor-widget-heading\" data-id=\"2a2f8cc\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-286d3bc elementor-widget elementor-widget-text-editor\" data-id=\"286d3bc\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>M\u00e9lina Girard<\/strong> est une \u00e9tudiante au doctorat en criminologie \u00e0 l\u2019Universit\u00e9 de Montr\u00e9al. Elle est r\u00e9cipiendaire de la prestigieuse bourse du Fonds de recherche du Qu\u00e9bec \u2013 Soci\u00e9t\u00e9 et culture (FRQSC) et a remport\u00e9 le Troph\u00e9e Cyber-Talent 2023 dans la cat\u00e9gorie acad\u00e9mique. Elle s\u2019int\u00e9resse particuli\u00e8rement aux recherches en sources ouvertes ainsi qu&rsquo;aux aspects sociaux de la cybers\u00e9curit\u00e9, observant les facteurs individuels et de groupe qui peuvent influencer ou expliquer certains comportements. M\u00e9lina suit \u00e9galement des cours de pentesting durant son temps libre afin de renforcer ses comp\u00e9tences techniques dans le domaine de la cybers\u00e9curit\u00e9. Le contenu de cette pr\u00e9sentation est inspir\u00e9 de la note de synth\u00e8se que M\u00e9lina a r\u00e9alis\u00e9e pour la Chaire de recherche en pr\u00e9vention de la cybercriminalit\u00e9 (CRPC), et qui sera publi\u00e9e prochainement sur leur site web.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6962e73 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"6962e73\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f054066 e-con-full e-flex e-con e-child\" data-id=\"f054066\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b756ef5 elementor-widget elementor-widget-image\" data-id=\"b756ef5\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/Ahold-rcnum9ldhsrbylzqqo84m2zxl5waa3josewofo0qx0.jpg\" title=\"Ahold.jpg\" alt=\"Ahold.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e14e0b4 elementor-widget elementor-widget-heading\" data-id=\"e14e0b4\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Alex Holden<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-35d0bac elementor-widget elementor-widget-heading\" data-id=\"35d0bac\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Versus Killnet<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a6308ae elementor-widget elementor-widget-text-editor\" data-id=\"a6308ae\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The infamous Russian hacktivist group, Killnet, operated as a clandestine cyber army, orchestrated by a select few to create chaos and inflict harm. Despite its notoriety, investigating the true operators behind Killnet proved to be a significant challenge, given its checkered history and inconsistent behavior. However, through an in-depth investigation and direct confrontation with the gang, we shed the veil of secrecy shrouding the group and will share a compelling personal account detailing how we disrupted Killnet, plunging it into a death spiral. Our strategy to dismantle this cyber army hinded on identifying a critical vulnerability \u2013 its connection to the Russian illegal drug marketplace &#8211; Solaris. By exposing this nefarious link and diverting proceeds from the Russian drug operation to support a Ukrainian charity, we triggered widespread questioning of Killnet&rsquo;s leadership and actions. This created an instability and within the group and beyond, ultimately leading to loss of support of the Russian government and breaking of financial ties. Delving deeper, we will explore the true identity of Killnet&rsquo;s leader, KillMilk, and explore his dark and criminal past. This will allow you to see some of the Killnet\u2019s actions in a different light and interpret the public events and actions associated with Killnet. Our successful efforts to undermine Killnet&rsquo;s leadership have led to a spectacular downfall and disintegration of the entire collective. As of the beginning of this year, Killnet changed drastically, leaving behind remnants of a group once synonymous with disruptive hacktivism. Our small push against Killnet set forth a chain of events changing the trajectory of the group and leaving it far removed from its former destructive pursuits. Join me as I unravel the complex narrative of Killnet, offering insights into the evolution of cyber warfare and the enduring struggle to combat malicious actors in the world of cyber warfare and disruptive hacktivism.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-561e7e7 elementor-widget elementor-widget-heading\" data-id=\"561e7e7\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a2ddda7 elementor-widget elementor-widget-text-editor\" data-id=\"a2ddda7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><b>Alex Holden <\/b>is the founder and Chief Information Security Officer (CISO) of Hold Security, LLC. Under his leadership, Hold Security played a pivotal role in information security and threat intelligence becoming one of the most recognizable names in its field. Mr. Holden researches minds and techniques of cyber criminals and helps our society to build better defenses against cyber-attacks. Mr. Holden has been credited in uncovering high-profile breaches such as Adobe Systems, Target, J.P. Morgan Chase, parts of the Equifax breach, and many others. Mr. Holden has spearheaded efforts to infiltrate, monitor, and disrupt various ransomware gangs, including Trickbot and Conti. As an expert in his field, Alex Holden is continuously sharing his original research at numerous cybersecurity conferences and has provided expert commentary in prominent media outlets including CNN, The New York Times, Forbes Magazine, and The Wall Street Journal. His insights into current cybersecurity events and the evolving threat landscape are regularly featured in lectures available on Hold Security&rsquo;s channel on the BrightTalk platform.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-376c6e2 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"376c6e2\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-b6f74a4 e-con-full e-flex e-con e-child\" data-id=\"b6f74a4\" data-element_type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-e9d88f8 e-con-full e-flex e-con e-child\" data-id=\"e9d88f8\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-de3eaeb elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"de3eaeb\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/gary-rcnumaj7omsma7ydl6mr6kre6jrnhsnf4jk5wxzcqs.jpg\" title=\"gary.jpg\" alt=\"gary.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f985112 elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"f985112\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/valcourt-rcnumaj7omsma7ydl6mr6kre6jrnhsnf4jk5wxzcqs.jpg\" title=\"valcourt.jpg\" alt=\"valcourt.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cd5ae9d elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"cd5ae9d\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/lindsay-rcnumbh1vgtwltx0fp1dr2iurxn0phr5go7ne7xykk.jpeg\" title=\"lindsay.jpeg\" alt=\"lindsay.jpeg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-96ced14 elementor-widget elementor-widget-heading\" data-id=\"96ced14\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Gary Cantrell, Scott Valcourt &amp; Linday Jamieson<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1d1aa68 elementor-widget elementor-widget-heading\" data-id=\"1d1aa68\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Experience Report: Running a Cybersecurity Camp for 13\u201315-year-olds in Maine<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-736feff elementor-widget elementor-widget-text-editor\" data-id=\"736feff\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Approaching its tenth year of funding by the United States National Security Agency, the GenCyber Camp program seeks to create the next generation of cybersecurity stars through an investment in summer camp programs for students and teachers across the US. In the summer of 2024, the speakers developed and presented two one-week residential camps for 13\u201315-year-old children focused on cybersecurity concepts. These camps were funded through the GenCyber program, and were held in Portland, Maine, USA for children from any area in Maine with no restriction on knowledge and experience levels before camp.\u00a0 This camp was the first of its kind ever held in Maine.\u00a0 One week of the camp was open to all, the other was specifically focused on underrepresented groups in Computer Science and cybersecurity. The funding agency also required a pre-camp and post-camp activity to coincide with the week-long camp program.\u00a0 These pre-camp activities had a vision and objectives for learning and observations from these activities will also be presented. We will reflect on the experience and share lessons learned at the camp including those specific to the resources available in Maine and those that may appeal to any location.\u00a0 Our presentation reflections will include an overview of the key cybersecurity concepts covered at the camp as well as demonstrations of activities that worked well and those that need to be revisited.\u00a0 Speakers will include cookbooks with procedures and materials needed to replicate those activities, allowing anyone to use our learning approaches in their own outreach endeavors.\u00a0 We will discuss the differences observed by the organizers in the two weeks of camp and provide some insights as to observable considerations that ought to be adhered when planning a similar program. The speakers will address the objectives, which were met, and which were not met, and any reflections as to adjustments that would need to be made for a subsequent program delivery.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-32953b5 elementor-widget elementor-widget-heading\" data-id=\"32953b5\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a0393af elementor-widget elementor-widget-text-editor\" data-id=\"a0393af\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Gary Cantrell<\/strong> is a native of the Deep South. He was born and raised in the northeast corner of Mississippi. He spent many years moving around the state going between two different careers. He spent 4 years as a computer scientist working for the US government. This includes time working for the Navy, the Army, and a few months for the Air Force. The rest of his career has been spent in computer science and digital forensics education including over 4 years training law enforcement with the National Forensic Training Center at Mississippi State University. After reaching ABD(All But Dissertation) status in 2010, he took a job with Dixie State University in southern Utah. After a year he received his Ph.D. in computer science and remained at DSU as a tenure track professor. During this time he was instrumental in establishing the DSU Computer Crime Institute. With the DSU-CCI he consulted on digital forensics exams and trained law enforcement, but his main role was the developer and principle faculty for Dixie State University\u2019s digital forensics academic programs. After spending 2 years as a tenured professor at DSU Gary decided to expand out from digital forensics and searched for an opportunity teaching in core computer science. This prompted a move to nearby Southern Utah University where he served as a tenure track faculty member for the Computer Science and Information Systems, CSIS, department. In the summer of 2022, he moved to Portland Maine where he teaches for Northeastern University at the Roux Institute. He teaches in the amazing align program helping students who do not have BS degrees in CS cross train and earn a MS degree in CS. In addition, he teaches electives in Software Engineering, Security, and Digital Forensics. Dr. Cantrell\u2019s primary teaching experiences include: Java I,II, C++, software engineering, computational theory, capstone courses, computational theory, operating system basics, digital forensics, computer crime, hardware basics, file systems, coding, using digital forensics tools (FTK, X-Ways, and various open source tools), small device forensics, and using Linux to make life easier. His research interests include digital forensics, digital triage, digital forensics education, steganography, and computer security.<\/p><p><strong>Scott Valcourt<\/strong> is an associate teaching professor within the Khoury College of Computer Sciences at Northeastern University\u2019s the Roux Institute in Portland, ME. He serves as the Global Network Course Coordinator for the CS Align course CS5008 Algorithms, Data Structures, and their Applications in Computer Systems. As a national research leader in cyberinfrastructure, Valcourt has been part of the development of more than a dozen worldwide networking technologies, causing NetworkWorld magazine to name him \u201cone of the most powerful people in networking\u201d in 2001. Valcourt began as a student and eventually became the second director of the world-renowned University of New Hampshire InterOperability Laboratory (UNH-IOL) from 1993-2004. He served as the principal investigator (PI) in 2010-2014 of Network NH Now, a collaboration of public and private partners that constructed critically needed broadband expansion across NH through more than 750 miles of new and existing fiber and microwave technologies. Simultaneously, Valcourt was the co-PI of the New Hampshire Broadband Mapping and Planning Program (NHBMPP) which continues to focus on NH broadband mapping. Valcourt has developed and managed over $100 million in grant funds focused on the creation of next generation infrastructure and applications utilizing broadband across the region. His current research areas involve data analysis and broadband expansion in support of smart communities and telehealth. Valcourt has a BA in computer science with a mathematics emphasis, cum laude, from Saint Anselm College in Manchester, NH. He also has a Master\u2019s of Science in computer science and a PhD in engineering: systems design with a Cognate in College Teaching from the University of New Hampshire.<\/p><p><strong>Lindsay Jamieson<\/strong> is a teaching professor at the Khoury College of Computer Sciences at Northeastern University. Her area of research focuses on algorithms and theory. Additionally, Jamieson is a part of the Executive Committee for ACM-W North America, which supports, celebrates and advocates internationally for the full engagement of women in all aspects of the computing field.\u00a0Jamieson earned her doctorate in computer science from Clemson University and her bachelor\u2019s in computer science from DePauw University. Prior to joining Northeastern in 2021, she was an associate professor of computer science at St. Mary\u2019s College of Maryland.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-999d101 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"999d101\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-c408df8 e-con-full e-flex e-con e-child\" data-id=\"c408df8\" data-element_type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-790d6d4 e-con-full e-flex e-con e-child\" data-id=\"790d6d4\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-dd85c77 elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"dd85c77\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/francois-rcnumbh1vgtwltx0fp1dr2iurxn0phr5go7ne7xykk.jpg\" title=\"francois.jpg\" alt=\"francois.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fcc621c elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"fcc621c\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/mathieu-rcnumcew2av6xfvna7g0bkabdbidx6uvssv4vhwkec.jpg\" title=\"mathieu.jpg\" alt=\"mathieu.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7335c8a elementor-widget elementor-widget-heading\" data-id=\"7335c8a\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Fran\u00e7ois Allard &amp; Mathieu Larose<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8de8fe0 elementor-widget elementor-widget-heading\" data-id=\"8de8fe0\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Prot\u00e9gez vos pipelines CI\/CD dans Github Actions avec Bullfrog<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4ed6036 elementor-widget elementor-widget-text-editor\" data-id=\"4ed6036\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<div>Le d\u00e9veloppement moderne de logiciels repose largement sur l&rsquo;int\u00e9gration de code tiers dans les pipelines CI\/CD (par exemple, GitHub Actions, packages npm, images Docker). Bien que ces outils acc\u00e9l\u00e8rent le d\u00e9veloppement, ils introduisent \u00e9galement des risques de s\u00e9curit\u00e9.\u00a0Cette pr\u00e9sentation par Fran\u00e7ois et Mathieu explorera un vecteur d&rsquo;attaque critique souvent n\u00e9glig\u00e9 dans les pipelines CI\/CD: le compromis de code tiers entra\u00eenant le vol d&rsquo;informations au sein de votre organisation.\u00a0Pour faire face \u00e0 cette menace, ils montreront comment prot\u00e9ger votre pipeline CI\/CD en utilisant Bullfrog, un outil de s\u00e9curit\u00e9 open-source qu&rsquo;ils ont d\u00e9velopp\u00e9. Ils expliqueront comment l&rsquo;int\u00e9grer dans vos workflows GitHub et fourniront des d\u00e9tails sur son architecture.<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-caa9fe3 elementor-widget elementor-widget-heading\" data-id=\"caa9fe3\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a06f05e elementor-widget elementor-widget-text-editor\" data-id=\"a06f05e\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Fran\u00e7ois Allard<\/strong> est un ing\u00e9nieur en fiabilit\u00e9 de site accompli avec une solide exp\u00e9rience en ing\u00e9nierie logicielle et en meilleures pratiques de DevSecOps. Il est reconnu pour son expertise en ing\u00e9nierie de la s\u00e9curit\u00e9, la s\u00e9curit\u00e9 des pipelines CI\/CD ainsi que la s\u00e9curit\u00e9 de l\u2019infrastructure cloud. Bullfrog est le projet open-source le plus important de Fran\u00e7ois \u00e0 ce jour. Il est dipl\u00f4m\u00e9 en ing\u00e9nierie logicielle de Polytechnique de Montr\u00e9al et a obtenu une ma\u00eetrise en commerce \u00e9lectronique \u00e0 HEC Montr\u00e9al.<\/p><p><strong>Mathieu Larose<\/strong> est un professionnel chevronn\u00e9 de la technologie avec plus de dix ans d&rsquo;exp\u00e9rience dans l&rsquo;industrie du logiciel. Il se sp\u00e9cialise dans la construction de syst\u00e8mes back-end s\u00e9curis\u00e9s, robustes et \u00e9volutifs, en s&rsquo;appuyant sur ses connaissances approfondies pour stimuler l&rsquo;innovation et l&rsquo;efficacit\u00e9 dans le d\u00e9veloppement de logiciels. Il est titulaire d&rsquo;un baccalaur\u00e9at et d&rsquo;une ma\u00eetrise en informatique, ainsi que d&rsquo;un DESS en gestion.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f19bcb3 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"f19bcb3\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-c077bf1 e-con-full e-flex e-con e-child\" data-id=\"c077bf1\" data-element_type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-fbfe665 e-con-full e-flex e-con e-child\" data-id=\"fbfe665\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4c2e80c elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"4c2e80c\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/AMF2-rcnumcew2av6xfvna7g0bkabdbidx6uvssv4vhwkec.jpg\" title=\"AMF2.jpg\" alt=\"AMF2.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0152e51 elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"0152e51\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/JT2-rcnumcew2av6xfvna7g0bkabdbidx6uvssv4vhwkec.jpg\" title=\"JT2.jpg\" alt=\"JT2.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-254bbcd elementor-widget elementor-widget-heading\" data-id=\"254bbcd\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Anne-Marie Faber &amp; Julien Turcot<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5dc9ecf elementor-widget elementor-widget-heading\" data-id=\"5dc9ecf\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Maslow's Pyramid to Craft an Efficient Cybersecurity Spending Strategy<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7e4d940 elementor-widget elementor-widget-text-editor\" data-id=\"7e4d940\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Embark on our &lsquo;Maslow&rsquo;s Pyramid for Efficient Cybersecurity Spending&rsquo; journey, inspired by grocery shopping, prioritizing cybersecurity. Explore the Pyramid, optimize spending, enhance user-centric security, and fortify digital defenses. This session offers practical guidance for a cost-effective, strong cybersecurity strategy. In the dynamic realm of cybersecurity resource management, our session presents a novel blend of Abraham Maslow&rsquo;s psychological theory and cybersecurity strategies. This innovative approach redefines how organizations safeguard their digital assets efficiently.\u00a0<\/p><ul><li>Efficient Resource Allocation: Learn techniques for optimizing cybersecurity spending by aligning resources with fundamental needs, ensuring informed decision-making similar to comparing prices and quality while shopping.<\/li><li>Real-Life Case Studies: Discover real-world examples showcasing challenges, solutions, and benefits derived from applying the grocery shopping analogy in cybersecurity strategies, making the concept relatable and actionable.<\/li><li>Risk Mitigation and Incident Response: Learn how the analogy enhances risk mitigation and incident response strategies, enabling swift and effective responses to cyber threats, akin to addressing urgent needs during a crisis grocery run.<\/li><li>Strategic Resource Planning: Gain insights into aligning cybersecurity investments with core security needs, akin to aligning purchases with essential requirements during shopping.<\/li><li>Enhanced Incident Response: Learn techniques to prioritize security measures based on Maslow&rsquo;s Pyramid and respond promptly to cyber incidents, similar to addressing urgent grocery needs.<\/li><li>Cost Optimization: Discover methods to optimize cybersecurity costs by investing in impactful solutions, akin to budget-conscious grocery shopping.<\/li><li>User-Centric Security: Implement user-centric security measures aligned with human psychological needs, creating a secure digital environment, akin to ensuring a comfortable shopping experience for customers.\u00a0<\/li><\/ul><p>Join us for this transformative session, bridging psychological theory, practical cybersecurity applications, and the familiar grocery shopping experience. Gain actionable insights to revolutionize your organization&rsquo;s cybersecurity posture, making it robust, cost-effective, and aligned with your digital ecosystem&rsquo;s fundamental needs.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6d58e66 elementor-widget elementor-widget-heading\" data-id=\"6d58e66\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e912a54 elementor-widget elementor-widget-text-editor\" data-id=\"e912a54\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Julien Turcot<\/strong> is a recognized Information Security executive leader with more than 20 years of experience in driving large scale technology security initiatives, cyber resiliency programs and risk management. He has helped organizations, large and small and across the public and private sector, to understand risk posture and put in place strategies and the right architecture to manage it. He is widely acknowledged as an industry thought leader and experienced practitioner, capable of translating technology challenges into actionable business solutions and is a renowned public speaker at international cyber security conferences. Results oriented and highly motivated, Mr. Turcot has effectively positioned and deployed industry leading IT solutions across all major verticals throughout Canada. Leveraging his experience and business acumen, he has helped organizations significantly increase their Security and Data Center efficiencies, while at the same time effectively reduce their TCO. Mr. Turcot is a natural leader and a very positive individual. He loves to be challenged as he is performing very well under pressure. He has the ability to lead multiple projects and tasks simultaneously. He deeply believes that all problems do have solutions and he is interested in helping you and your organization to reach maturity in the IT Security. With his strong background in Next Generation Platforms and Software Defined Data Centres, and unique ability to identify and understand the needs of his clients, he has effectively built up the brand and territories for every organization he has been a part of. Specialties: Complex Sales &#8211; Consistently deliver over target results &#8211; Enterprise solution sales &#8211; Territory development &#8211; Channel Marketing and Management &#8211; Executive Presentations &#8211; Public Speaking.<\/p><p>\u00a0<\/p><p>As the Chief Marketing Officer at GoSecure, a leading provider of cybersecurity solutions, <strong>Anne-Marie Faber<\/strong> leverages her 15+ years of experience in the IT industry and her MBA degree to drive the company&rsquo;s growth and differentiation in the market. I have a proven track record of helping various companies evolve into market leaders with double digit revenue growth, thanks to my strategic planning and business strategy skills. I oversee all aspects of GoSecure&rsquo;s marketing strategy, including corporate messaging, branding, communications, digital demand generation, field and channel marketing. I believe in the importance of a close partnership with all sales channels, direct and indirect, and the ability to think creatively and differently than competitors. I also lead a talented and diverse team of marketing professionals who share my passion and vision for security innovation and customer success. GoSecure is a cybersecurity enterprise that specializes in providing managed Extended Detection and Response (MXDR) solutions as well as expert advisory services. The company offers integrated security solutions through their GoSecure Titan suite, delivering multi-vector protection to combat contemporary cyber threats.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-23bd6ab elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"23bd6ab\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-96a6eac e-con-full e-flex e-con e-child\" data-id=\"96a6eac\" data-element_type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-0de0394 e-con-full e-flex e-con e-child\" data-id=\"0de0394\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-67a793d elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"67a793d\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/Naveen-rcnumdcq94wh91ua4pumw21rypdr4vym4ximcrv684.jpg\" title=\"Naveen.jpg\" alt=\"Naveen.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3ec39b9 elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"3ec39b9\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/Mohan-rcnumdcq94wh91ua4pumw21rypdr4vym4ximcrv684.jpg\" title=\"Mohan.jpg\" alt=\"Mohan.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3877aec elementor-widget elementor-widget-heading\" data-id=\"3877aec\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Naveen Konrajankuppam Mahavishnu &amp; Mohankumar Vengatachalam <\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ccbc119 elementor-widget elementor-widget-heading\" data-id=\"ccbc119\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Beyond Interactions: Hacking Chatbots Like a Pro<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a7d4eaa elementor-widget elementor-widget-text-editor\" data-id=\"a7d4eaa\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>In today&rsquo;s digital age, AI-driven chatbots have become an integral part of our daily routines, seamlessly blending into various aspects of our lives. The arrival of Large Language Models (LLMs) has revolutionized the field of conversational AI, enabling chatbots to engage users in more natural and contextually relevant conversations. This advancement has empowered businesses to deliver enhanced customer experiences and streamline their operations. However, amidst the convenience and innovation, it is crucial to recognize the inherent risks associated with these AI-powered chatbots. In this submission, we aim to dive into the realm of LLM chatbot hacking, shedding light on the vulnerabilities and potential exploits associated with these advanced systems. By dissecting the underlying mechanisms of LLM-based chatbots, we seek to raise awareness about the security risks they pose and equip participants with the knowledge to mitigate these threats effectively. During our tech talk, we will embark on a journey through the fundamentals of AI, providing attendees with a comprehensive understanding of the underlying principles driving chatbots. We will then pivot to an exploration of common vulnerabilities encountered in AI chatbots, highlighting the top two categories most susceptible to exploitation. Through a combination of live hacking demonstrations and real-world attack scenarios, we will illustrate how malicious actors leverage these vulnerabilities to compromise sensitive information, infringe upon users&rsquo; privacy, and propagate misinformation. By immersing participants in simulated hacking scenarios, we aim to provide a hands-on learning experience that will enhance their understanding of the evolving threat landscape. Furthermore, we will explore a range of security measures designed to mitigate these risks and promote a more secure integration of AI chatbots into our daily lives. We will discuss practical strategies for safeguarding chatbot systems against potential threats. By the conclusion of our talk, participants will have gained a deeper awareness of the challenges inherent in securing AI chatbots and will be equipped with actionable insights to bolster their defenses. We will also extend an invitation to participants to use our lab, where they can further explore and exploit additional attack paths beyond those covered in the talk.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6d44b36 elementor-widget elementor-widget-heading\" data-id=\"6d44b36\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e6bb45e elementor-widget elementor-widget-text-editor\" data-id=\"e6bb45e\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Naveen Konrajankuppam Mahavishnuis<\/strong> a Security Researcher with over 7 years of expertise specializing in AI, application, and cloud security. He possesses extensive knowledge in all aspects of product security, including threat modeling, DevSecOps, API security, and penetration testing. He is passionate about integrating security into the SDLC from design to deployment, ensuring the early detection and mitigation of vulnerabilities.<\/p><p><strong>Mohan Vengatachalam<\/strong> is a security leader with over a decade of experience in security architecture, engineering, and operations. He has a strong interest in developing security programs and a proven track record of creating proactive security roadmaps and strategies aligned with business objectives. He constantly seeks ways to elevate security processes and culture to the next level.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-42b7e68 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"42b7e68\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-814f010 e-con-full e-flex e-con e-child\" data-id=\"814f010\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-95a0bfe elementor-widget elementor-widget-image\" data-id=\"95a0bfe\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/Adrien-rcnumeakfyxrknswz899gjt8k394cl2ch263u1ts1w.jpeg\" title=\"Adrien.jpeg\" alt=\"Adrien.jpeg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d227878 elementor-widget elementor-widget-heading\" data-id=\"d227878\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Adrien Lasalle<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-581af23 elementor-widget elementor-widget-heading\" data-id=\"581af23\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Dump me if you can - Hardware Hacking<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f8a11ae elementor-widget elementor-widget-text-editor\" data-id=\"f8a11ae\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>I would like to discuss a rather technical but essential topic in this field: the extraction, analysis, and exploitation of firmware in embedded devices. First, I will explain the main concepts and definitions of how these devices operate, emphasizing that they are more vulnerable than one might think, with techniques used for vulnerability research (with or without having the device in hand). It is also important to discuss the different components found in these devices, their functionalities\/specifications, and the secrets that attackers can exploit. Then, it\u2019s also important to talk about all the tools and requirements that would be necessary if you want to dive into this amazing field. Next, I will talk about several methods of firmware extraction, ranging from downloading the binary file from the manufacturer&rsquo;s website, which remains the most effective method but is starting to have its limitations with the latest \u00ab\u00a0cloud\u00a0\u00bb update methods, to extraction requiring physical access to a device using communication ports like UART or JTAG. The final method involves extracting the firmware directly from the Flash chip. Depending on the setup, I am willing to perform a live demonstration for each method that I talk about with different devices and tools. Of course, this talk aims to demonstrate the basics for those who wish to embark on this adventure. I will guide participants as best as possible with documented methods while addressing the risks associated with hardware hacking, both from an ethical and safety perspective, especially regarding the handling of electrical components or the use of a soldering iron.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-39f090a elementor-widget elementor-widget-heading\" data-id=\"39f090a\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7e4d4da elementor-widget elementor-widget-text-editor\" data-id=\"7e4d4da\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Formerly a firefighter volunteer in France for 4 years,\u00a0<strong>Adrien Lasalle<\/strong>\u00a0decided to pursue my passion for IT and especially offensive cybersecurity. I&rsquo;m now working as an Offensive Security Advisor in Desjardins and an active member of the hacking community with many talks and volunteer work at different events. I am gradually specializing in internal network intrusion testing but also in Hardware Hacking a domain that I particularly appreciate for its technical nature, but also for the diversity of possible research and exploitation combining several skills in offensive security. Do not hesitate to check my work and post (be aware of memes) on my LinkedIn profile, My personal blog or some of my cybersecurity related project on my Github Account : https:\/\/alrikrr.github.io\/. Sharing our passion for this field, whether for awareness or education, is an important mission for me!<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4d350a4 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"4d350a4\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5981515 e-con-full e-flex e-con e-child\" data-id=\"5981515\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4cc9c53 elementor-widget elementor-widget-image\" data-id=\"4cc9c53\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/jonathan-rcnumeakfyxrknswz899gjt8k394cl2ch263u1ts1w.jpg\" title=\"jonathan.jpg\" alt=\"jonathan.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c5bf896 elementor-widget elementor-widget-heading\" data-id=\"c5bf896\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Jonathan Nomed<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9e28676 elementor-widget elementor-widget-heading\" data-id=\"9e28676\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Cybers\u00e9curit\u00e9 et triche dans les jeux vid\u00e9o : un danger insoup\u00e7onn\u00e9<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0c6a2ea elementor-widget elementor-widget-text-editor\" data-id=\"0c6a2ea\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>En tant que pentester et ancien analyste au CERT, j&rsquo;ai une passion pour la cybers\u00e9curit\u00e9 et les jeux vid\u00e9o. Mon exp\u00e9rience m&rsquo;a permis de voir de pr\u00e8s l&rsquo;\u00e9volution des menaces et des technologies dans ces domaines. Aujourd&rsquo;hui, je souhaite partager mes connaissances sur un sujet crucial: la triche dans les jeux vid\u00e9o et son impact sur la cybers\u00e9curit\u00e9. Tout d\u2019abord la triche dans les jeux vid\u00e9o a \u00e9volu\u00e9 de simples modifications de scores \u00e0 des attaques sophistiqu\u00e9es affectant la cybers\u00e9curit\u00e9. Les premi\u00e8res tentatives impliquaient des modifications de scores, signalant la n\u00e9cessit\u00e9 d\u2019une protection. Avec l\u2019\u00e9volution des jeux en ligne, les attaques se sont diversifi\u00e9es, exploitant la relation serveur-client pour des cheats comme les aimbots et wallhacks. Les attaquants n\u2019hesitent pas \u00e0 cibler des plateformes comme PSNetwork pic Games et Steam. De plus, pour contrer ces menaces, des m\u00e9thodes avanc\u00e9es de d\u00e9tection de triche ont \u00e9t\u00e9 d\u00e9velopp\u00e9es. Valve Anti-Cheat, Easy Anti-Cheat, BattlEye et bien d\u2019autres jouent un r\u00f4le crucial, bien que confront\u00e9s \u00e0 des d\u00e9fis constants dus \u00e0 l\u2019\u00e9volution des m\u00e9thodes de triche et aux impacts sur les performances des jeux. Les cons\u00e9quences de la triche vont au-del\u00e0 des jeux, affectant la confiance des utilisateurs et les finances des d\u00e9veloppeurs. Les techniques de triche se transforment en cybercrimes plus graves, mena\u00e7ant la s\u00e9curit\u00e9 globale. Pour illustrer mes propos je pr\u00e9senterai \u00e9galement une \u00e9tude de cas. Enfin, des contre-mesures innovantes montrent l\u2019importance de l&rsquo;ing\u00e9niosit\u00e9 dans la lutte contre la triche. L\u2019exemple de Counter-Strike, o\u00f9 les d\u00e9veloppeurs ont utilis\u00e9 des m\u00e9thodes cr\u00e9atives pour contrer les tricheurs, et le cas de Game Dev Tycoon, illustrent ces efforts. En conclusion, la bataille contre la triche est un enjeu majeur pour la cybers\u00e9curit\u00e9. Il est essentiel de rester vigilant et de d\u00e9velopper des solutions innovantes pour prot\u00e9ger les jeux et les plateformes.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-37ac412 elementor-widget elementor-widget-heading\" data-id=\"37ac412\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2230137 elementor-widget elementor-widget-text-editor\" data-id=\"2230137\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>En tant que pentester et ancien analyste au sein d&rsquo;un CERT, <strong>Jonathan Nomed<\/strong> a d\u00e9velopp\u00e9 une passion profonde pour la cybers\u00e9curit\u00e9 ainsi que pour les jeux vid\u00e9o. Mon parcours professionnel m&rsquo;a permis d&rsquo;observer de pr\u00e8s l&rsquo;\u00e9volution rapide et constante des menaces et des technologies dans ces domaines passionnants. Pendant ces ann\u00e9es, j&rsquo;ai acquis une expertise pr\u00e9cieuse en observant l\u2019identification des vuln\u00e9rabilit\u00e9s et des strat\u00e9gies pour les contrer. Bien que je n&rsquo;aie pas encore eu l&rsquo;opportunit\u00e9 de partager mes connaissances \u00e0 travers des conf\u00e9rences, je suis fermement d\u00e9termin\u00e9 \u00e0 d\u00e9buter dans ce domaine. Je souhaite communiquer sur un sujet crucial : la triche dans les jeux vid\u00e9o et son impact sur la cybers\u00e9curit\u00e9. Cette question, souvent sous-estim\u00e9e, m\u00e9rite une attention particuli\u00e8re car elle touche \u00e0 la fois les joueurs et les infrastructures de s\u00e9curit\u00e9 num\u00e9rique. Mon objectif est de sensibiliser, informer et \u00e9duquer un large public sur les dangers r\u00e9els et potentiels de la triche dans les jeux vid\u00e9o. En explorant comment ces pratiques peuvent compromettre la s\u00e9curit\u00e9 globale des syst\u00e8mes informatiques, j&rsquo;esp\u00e8re contribuer \u00e0 une prise de conscience.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7847607 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"7847607\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-fbe2bbf e-con-full e-flex e-con e-child\" data-id=\"fbe2bbf\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a597faf elementor-widget elementor-widget-image\" data-id=\"a597faf\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/niharika-rcnumeakfyxrknswz899gjt8k394cl2ch263u1ts1w.jpeg\" title=\"niharika.jpeg\" alt=\"niharika.jpeg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c5c2133 elementor-widget elementor-widget-heading\" data-id=\"c5c2133\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Niharika Gehani<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-783de23 elementor-widget elementor-widget-heading\" data-id=\"783de23\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Deciphering Threat Modeling: Balancing Tools and Manual Approaches for Effective Security<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c2842cf elementor-widget elementor-widget-text-editor\" data-id=\"c2842cf\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>In the ever-evolving landscape of cybersecurity, threat modeling has become a cornerstone for identifying, assessing, and mitigating potential security risks. The process involves various techniques, each with its own set of advantages and limitations. This talk, titled \u00ab\u00a0Deciphering Threat Modeling: Balancing Tools and Manual Approaches for Effective Security,\u00a0\u00bb delves into the intricacies of threat modeling by exploring both automated tools and manual methodologies. We will begin by examining the core principles of threat modeling and its significance in today\u2019s security ecosystem. This section will emphasize how threat modeling improves security and distinguishes itself from other security testing methodologies such as SAST and DAST. The discussion will then pivot to the indispensable value of manual threat modeling techniques. We will explore scenarios where human intuition and expertise are paramount, and how manual techniques can uncover nuanced threats that automated tools might overlook. This section will explain the benefits of adhering to the basic, straightforward nature of threat modeling, which has become complex over time, giving rise to automated tools. Conversely, the talk will also address the efficiency of the automated approach using the latest tools available, highlighting their capabilities in streamlining and enhancing the threat modeling process. Participants will gain insights into how these tools can automate complex tasks, increase accuracy, and save valuable time. Following this, we will demonstrate the complementary nature of both methods. While manual approaches may overlook certain threats, automated tools can generate excessive information or noise, leading to the de-prioritization of risks and an ineffective remediation strategy. Attendees will leave with a comprehensive understanding of how to effectively integrate tools and manual approaches to build a robust threat modeling strategy. This balanced approach ensures a more resilient security posture, capable of adapting to diverse and sophisticated threats. Join us to decipher the art and science of threat modeling, and learn how to strike the perfect balance between technological innovation and human insight for superior security outcomes.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2c73d0f elementor-widget elementor-widget-heading\" data-id=\"2c73d0f\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d59fe4d elementor-widget elementor-widget-text-editor\" data-id=\"d59fe4d\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Niharika Gehani<\/strong> is a seasoned cybersecurity professional with over 10 years of experience in application security and a deep interest in security threat modeling. Currently residing in Ottawa, Canada, she works with EPAM Systems as a Senior Security Systems Engineer. In her current role, Niharika conducts threat modeling for applications in the healthcare industry, addressing unique challenges and ensuring robust security measures. Her work involves analyzing potential threats, identifying vulnerabilities, doing risk analysis, and implementing effective security strategies to protect sensitive healthcare data. Throughout her career, Niharika has developed a comprehensive understanding of the complexities involved in securing applications and mitigating potential threats. Her passion for threat modeling has driven her to explore both manual and automated approaches, striving to create a resilient security posture that adapts to the evolving threat landscape. This is my first time as a speaker, and I am excited to share my knowledge and insights with a broader audience. I hope that my talk will provide valuable perspectives and practical strategies to enhance security practices in today&rsquo;s rapidly evolving digital landscape. My goal is to help others understand the importance of threat modeling and how it can be effectively integrated into their security frameworks to protect against sophisticated cyber threats.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-831945d elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"831945d\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-edd975d e-con-full e-flex e-con e-child\" data-id=\"edd975d\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3a368c0 elementor-widget elementor-widget-image\" data-id=\"3a368c0\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/andreanne-rcnumf8emsz1w9rjtqnw11kp5h4hka62t6tlbbsdvo.jpg\" title=\"andreanne.jpg\" alt=\"andreanne.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bec77ed elementor-widget elementor-widget-heading\" data-id=\"bec77ed\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Andr\u00e9anne Bergeron<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a7d1064 elementor-widget elementor-widget-heading\" data-id=\"a7d1064\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Reconsidering Cybercriminal Expertise Through their Behavior with Command-Line Interface VS Graphical User interface<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a60e837 elementor-widget elementor-widget-text-editor\" data-id=\"a60e837\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>This presentation explores the prevalent notion of cyber attackers&rsquo; mastery of terminal-based operations. Departing from conventional portrayals, which often depict attackers as skilled coders and command-line virtuosos, our research offers a nuanced perspective on the actual sophistication and capabilities of these individuals. We created a dataset composed of 454 remote desktop protocol connections initiated by attackers on our honeypots, spanning an extensive timeframe from January 2020 to March 2022. This exhaustive examination, encompassing over 100 hours of video footage, aims to uncover unforeseen trends and behavioral patterns. Notably, our findings challenge prevailing assumptions, revealing that a mere fraction\u2014just 8%\u2014of recorded sessions involved the use of command-line interface. This revelation disrupts long-standing notions about attackers&rsquo; heavy reliance on command prompt rather than graphical user interfaces, drawing a fundamental reevaluation of existing perceptions. Our in-depth analysis resulted in the observations of disparities between the actions undertaken within terminal sessions and those executed in environments exclusively utilizing graphical user interfaces. While certain common actions such as password changes remain prevalent across both sets, terminal sessions exhibit a distinct emphasis on tasks such as seeking IP information, accompanied by a notable reduction in reliance on automated tools. This suggests a simpler, less mechanized approach to attacks within terminal-based environments. Moreover, our sophistication scoring system, designed to assess the level of expertise demonstrated by attackers, illuminates a conspicuous absence of highly proficient individuals. Instead, the majority of attackers exhibit rudimentary skills, with only a minority demonstrating moderate levels of sophistication. This groundbreaking study challenges entrenched assumptions regarding attackers&rsquo; technical prowess and underscores the paramount importance of nuanced understanding within the realm of cybersecurity research. While proficiency in coding and terminal operations undoubtedly offers certain advantages, our findings suggest that a considerable number of attackers operate at a less sophisticated level than commonly perceived, necessitating a recalibration of prevailing perspectives.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fb705d2 elementor-widget elementor-widget-heading\" data-id=\"fb705d2\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-98ec575 elementor-widget elementor-widget-text-editor\" data-id=\"98ec575\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Andr\u00e9anne Bergeron<\/strong>, PhD, is the director of research at GoSecure, specializing in online attackers&rsquo; behaviors. Her expertise delves into the intersection of criminology and cybersecurity. In addition, Andr\u00e9anne holds an esteemed position as an affiliated professor in the Department of Criminology of Montreal University, bridging academia and industry. Her commitment to provide a unique perspective on the human element behind digital threats reflects a holistic approach, enriched by theoretical depth and real-world applicability. While her PhD thesis focused on applying game theory to understand the dynamics of police interrogation with online offenders, her research extended to encompass a broader scope, including investigations into cryptomarkets, cybersecurity, and the behavior of malicious hackers. Andr\u00e9anne has showcased her research at prestigious conferences such as BlackHat USA, Defcon, CypherCon, and ShmooCon. Active in her community, Andr\u00e9anne serves as one of the board members of the Canadian Cybersecurity Network and holds the position of co-Vice President of Engagement and Outreach at NorthSec.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-257a901 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"257a901\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-0e745b7 e-con-full e-flex e-con e-child\" data-id=\"0e745b7\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ebe5c39 elementor-widget elementor-widget-image\" data-id=\"ebe5c39\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/l0gan-rcnumf8emsz1w9rjtqnw11kp5h4hka62t6tlbbsdvo.jpg\" title=\"l0gan.jpg\" alt=\"l0gan.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-942bc8e elementor-widget elementor-widget-heading\" data-id=\"942bc8e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">L0gan<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3bd9648 elementor-widget elementor-widget-heading\" data-id=\"3bd9648\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">MacOS Red Team on Corporate Scenarios<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d61fc2f elementor-widget elementor-widget-text-editor\" data-id=\"d61fc2f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>In this research businesses and organizations continue to adopt more advanced security measures to protect against cyber-attacks on your macOS endpoints, attackers are constantly evolving their techniques to bypass these measures. In this presentation, we will demonstrate real-world attack scenarios and reveal common vulnerabilities, as well as provide insights on how to exploit them. \u00ab\u00a0macOS Red Team on Corporate Scenarios\u00a0\u00bb is the result of years of research and dedicated work in testing macOS environments. Its main objective is to provide a comprehensive view of the security surrounding Apple&rsquo;s operating system, demonstrating how potential vulnerabilities can be exploited. The adopted approach assumes the perspective of an insider attacker or during a Red Team simulation. The research will delve into various security features embedded within macOS, such as SIP (System Integrity Protection), TCC (Transparency, Consent, and Control), FileVault, SSV (System Software Version), Gatekeeper, XProtect, and Secure Boot. These components play crucial roles in safeguarding the integrity, privacy, and overall security posture of the macOS operating system. The research will also delve into the tactics, techniques, and procedures (TTPs) recommended by the MITRE ATT&amp;CK framework for macOS systems to assist in conducting red team simulations. This exploration aims to provide insights into the methodologies and strategies employed by attackers, enhancing the effectiveness of defensive strategies and improving overall cybersecurity posture in macOS environments. At the conclusion of the presentation, we will demonstrate how to perform a bypass of a vulnerability discovered in the macOS Transparency, Consent, and Control (TCC) framework. This vulnerability has been reported to Apple for investigation and mitigation. We will also discuss the process of how Apple has handled the vulnerability disclosure and the steps taken by the company to address the issue.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fc8a656 elementor-widget elementor-widget-heading\" data-id=\"fc8a656\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-46ebdc4 elementor-widget elementor-widget-text-editor\" data-id=\"46ebdc4\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>L0gan<\/strong> is a security researcher with extensive experience in enterprise networks and enthusiastic on malware research, pentest and reverse engineering. I have been focused on the last years in research for vulnerability and malware for macOS environment. For many years I have worked with solutions like: Siem solutions for real-time correlation, threat hunting and triage advanced persistent threats to mitigation and endpoint protection. I also have worked with development and design of vulnerability scanner and code analysis with open source tools for automation of the task. In the recent years of my career (last 3 years), I have been serving as a manager of an of-fensive security and application security (AppSec) team. I have been speaking at several security conferences like H2HC (Hackers to Hackers Con-ference (SP Brazil), Ekoparty(Argentina), Andsec(Argentina), BsideSP(SP Brazil), Roadsec(CE Brazil), BHack(MG Brazil), Nullbyte(BA Brazil).In Brazil, I am part of the staff for some security conferences organizations such as H2HC (Hackers to Hackers Conference, BsideSP and SlackShow\/Slackzine Community. In 2019 I helped to organize a bug bounty program for BYOS Company in Las Vegas during Defcon event. I am also a Member of the CTF team RTFM (Red Team Freakin&rsquo; Maniacs), we are playing a lot of CTF and organizing CTFs in Brazil, Argentina and Chile.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f90fff3 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"f90fff3\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-998d1a8 e-con-full e-flex e-con e-child\" data-id=\"998d1a8\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-37c2686 elementor-widget elementor-widget-image\" data-id=\"37c2686\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/tammy-rcnumg68tn0c7vq6o92iljc5quzurz9t5bh2slqzpg.jpg\" title=\"tammy.jpg\" alt=\"tammy.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0702c15 elementor-widget elementor-widget-heading\" data-id=\"0702c15\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Tammy Harper<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-17eb3c4 elementor-widget elementor-widget-heading\" data-id=\"17eb3c4\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Persona Theory: Infiltration &amp; Deception of Emerging Threat Groups<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-18de601 elementor-widget elementor-widget-text-editor\" data-id=\"18de601\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Our personas are fabrications and constructions of our inner self that we project outwards. We do this through various means and influences such as race, gender, sex, ability, age, culture, religion, norms, class, and status. For the \u201creal world\u201d aka \u201cirl\u201d we do all this by expression in our clothing, makeup, hairstyling, our hobbies, our network of friends, colleagues, and acquaintances. We leverage all of these facets and we create masks, personas, that we think will best interact with the world around us. The same concepts apply when creating personas for infiltrating online communities. In this talk we will take a look at what makes a good persona and what makes a bad persona. Persona\u2019s can vary wildly in quality, many factors contribute to the quality of a persona, for example how tailor is it to the mission, how good is the operational security of the account, how good are you at managing it and leveraging it to establish yourself in a community. We will also look at understanding what you can construct and where limitations lie. If you know nothing about the community you are trying to infiltrate you will have a hard time establishing a foothold even more so any significant persistence in the community. Third, we will look at tools, OpSec, and timezone shifting. We will go over some tools that will help you create, build, and maintain quality personas on the dark web. Finally, we will look at what is your mission, and executing your mission. It is just as important to know how to exit as it is how to infiltrate. For example, do you want to keep your persona in good standing so it can be reused on another mission? Are you going to burn it? Knowing when to retire a persona is a good skill to have.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-83a0442 elementor-widget elementor-widget-heading\" data-id=\"83a0442\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1948562 elementor-widget elementor-widget-text-editor\" data-id=\"1948562\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Tammy Harper<\/strong> is a Senior Threat Intelligence Researcher and Certified Dark Web Investigator at Flare and studied Advanced Cybersecurity at York University in Toronto, Ontario. She is currently an admin and volunteer researcher for the open-source project RansomLook and a contributor to the DeepDarkCTI open-source research project. Since 2022, she&rsquo;s been volunteering at her local Women in Tech group, helping mentor women in cybersecurity, threat intelligence, and the dark web. When she isn&rsquo;t researching communities on the deep and dark web, she listens to techno\/ambient music and sips a delicious matcha latte. Her other hobbies include photography, reading, googology (the study of really really large numbers), astronomy,\u00a0 and listening to true crime podcasts. Tammy was featured on the June 2023 Privacy Files Podcast: Dark Web Crimes Episode (available on most podcast streaming platforms), where she discussed cybercrime, major breaches in the news, and how the threat landscape is evolving at an ever-accelerating pace.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4914086 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"4914086\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7621d58 e-con-full e-flex e-con e-child\" data-id=\"7621d58\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-890aeea elementor-widget elementor-widget-image\" data-id=\"890aeea\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/constance-rcnumg68tn0c7vq6o92iljc5quzurz9t5bh2slqzpg.jpg\" title=\"constance.jpg\" alt=\"constance.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-30ac339 elementor-widget elementor-widget-heading\" data-id=\"30ac339\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Constance Prevot<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-110d6d5 elementor-widget elementor-widget-heading\" data-id=\"110d6d5\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Hide and Seek: Chasing Cybercriminals Around the World<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-70c8fea elementor-widget elementor-widget-text-editor\" data-id=\"70c8fea\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Attributing the geographic identities of online attackers poses significant challenges due to their use of various proxy technologies that obfuscate true locations. These proxies, which range from Virtual Private Networks (VPNs) and Tor nodes to compromised endpoints, effectively blur attribution efforts by masking the original IP addresses of the attackers. This obfuscation technique is a key strategy employed by cybercriminals to evade detection and complicate tracing efforts. The complexity of this issue is further compounded by inconsistencies among different IP information sources, making the identification process highly unreliable and challenging for cybersecurity professionals. In this study, we undertake a comprehensive comparison of information from three primary sources: government-provided data, paid commercial databases, and freely accessible open-source information. Each of these sources has its own strengths and weaknesses in accurately determining the geographic origins of cyberattacks. Government data, while often comprehensive, may be limited in scope or accessibility. Paid commercial databases offer extensive data but come with significant costs and potential biases. Open-source information, on the other hand, is widely available but may lack the precision and reliability needed for accurate attribution. By critically evaluating these sources, we aim to identify the most reliable approach for geographic attribution, considering factors such as accuracy, cost, and accessibility. Subsequently, we delve into the analysis of attack techniques, demonstrating that these techniques exhibit distinct patterns based on the geographic origins of IP addresses. Our findings reveal intriguing insights, such as certain hacking tools and methodologies being commonly shared among countries. This suggests possible cooperation or shared resources in cyberattacks, highlighting the global and collaborative nature of modern cyber threats. The insights gained from this research not only enhance our understanding of the cyber threat landscape but also underscore the importance of improved methodologies in geographic attribution. By refining these attribution techniques, we can better identify and respond to cyber threats, ultimately bolstering cybersecurity defenses on a global scale. This study not only provides a clearer picture of how attackers operate across different regions but also offers practical recommendations for leveraging diverse data sources to achieve more accurate geographic attribution. These advancements are crucial for developing more effective strategies to combat cybercrime and enhance international cybersecurity collaboration.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a7dbc4e elementor-widget elementor-widget-heading\" data-id=\"a7dbc4e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d218a1a elementor-widget elementor-widget-text-editor\" data-id=\"d218a1a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Constance Prevot<\/strong> is an undergraduate student pursuing Software Engineering at Concordia University in Montreal, with a keen interest in cybersecurity. Currently engaged in a part-time role at a SOC following her initial internship there, she has also gained experience at GoSecure&rsquo;s research department during the Summer of 2024. Actively involved in Montreal&rsquo;s cybersecurity community, Constance has competed in numerous CTFs, including notable events like NorthSec, Hackfest, and Cyber-Sci&rsquo;s national edition in the Women\u2019s team. She has further contributed to the community by organizing events such as UnitedCTF, @hackCTF, and the 2024 CS Games. Committed to promoting equality, she has served as a mentor for WomenInEngineering at Concordia. Finally, she now leads as President of SCS Concordia, ensuring the club&rsquo;s strong presence and participation in various events. <br \/>This project was completed as part of a summer research internship at GoSecure. During this internship, Constance played a pivotal role, leveraging her specialized skill set to gather extensive information about IP addresses from across the internet. She adeptly managed and processed massive datasets, meticulously analyzing various sources of IP information to uncover patterns and inconsistencies.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7f5dc86 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"7f5dc86\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5cf422f e-con-full e-flex e-con e-child\" data-id=\"5cf422f\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1453777 elementor-widget elementor-widget-image\" data-id=\"1453777\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/zuz2-rcnumh430h1mjhotirh5613mc8v7zodjhg4k9vplj8.jpg\" title=\"zuz2.jpg\" alt=\"zuz2.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-508cb83 elementor-widget elementor-widget-heading\" data-id=\"508cb83\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Zuzanna Chociej<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8305658 elementor-widget elementor-widget-heading\" data-id=\"8305658\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Applying Edward Tufte's Design Principles in Cybersecurity and OSINT Reporting<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7786cf4 elementor-widget elementor-widget-text-editor\" data-id=\"7786cf4\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Edward Tufte is a statistician and professor emeritus of political science, statistics, and computer science at Yale University. He is best known for his work in the field of data visualization and information design. Tufte is the author of several influential books on data visualization, including \u00ab\u00a0The Visual Display of Quantitative Information,\u00a0\u00bb \u00ab\u00a0Envisioning Information,\u00a0\u00bb \u00ab\u00a0Visual Explanations,\u00a0\u00bb and \u00ab\u00a0Beautiful Evidence.\u00a0\u00bb These books are significant drivers of impact in the fields of information design, data visualization, and statistical graphics. The principles of his work \u2013 clarity, simplicity, and effectiveness \u2013 have applications across fields of expertise and impact the actionability of research on a global scale. He advocates for the use of minimalistic design, clear labeling, and maximizing the data-ink ratio to create visualizations that effectively convey complex information to viewers. Visualizations in the field of cybersecurity, which I am taking to include general industry reporting as well as the user interfaces of cybersecurity platforms, often reflect an overwhelming amount of information that can mar relevance and impede actionability. Other challenging features of software and reporting are listed below.<\/p><p>\u00a0<\/p><p>&#8211; Overwhelming Complexity: Dashboards may become cluttered with too much information, making it difficult for users to identify critical issues amidst the noise.<\/p><p>&#8211; Lack of Context: Visualizations may lack context or fail to provide sufficient explanation of the data, leading to misinterpretation or confusion among users.<\/p><p>&#8211; Poor Data Quality: Inaccurate or incomplete data can undermine the credibility of dashboard visualizations and lead to incorrect conclusions or ineffective decision-making.<\/p><p>&#8211; Limited Interactivity: Dashboards that lack interactive features or drill-down functionality may restrict users&rsquo; ability to explore data further and gain deeper insights into security issues.<\/p><p>&#8211; Ineffective Visualization Choices: Poorly chosen visualization types or ineffective use of color, layout, and labeling can hinder understanding and make it harder for users to extract meaningful insights from the data.<\/p><p>&#8211; Failure to Prioritize Actionable Insights: Dashboards may fail to highlight actionable insights or prioritize critical security issues, leading to a lack of focus and dilution of attention on less important metrics.<\/p><p>&#8211; Inadequate Customization: Lack of customization options can limit the relevance of dashboard visualizations to specific user roles or organizational priorities, reducing their effectiveness in driving action.<\/p><p>&#8211; Insufficient Integration with Workflow: Dashboards that do not integrate seamlessly with users&rsquo; workflow or existing tools may fail to facilitate timely response to security incidents or vulnerabilities.<\/p><p>&#8211; Poor Performance and Reliability: Dashboards that are slow to load or prone to technical issues can undermine user trust and discourage regular usage.<\/p><p>&#8211; Failure to Align with User Needs: Dashboards may not adequately address the needs and preferences of their intended audience, resulting in low user adoption and limited impact on decision-making processes.<\/p><p>\u00a0<\/p><p>This session will focus on Tufte&rsquo;s design principles and their utility in cybersecurity reporting. We will explore how the applications of these principles can help bridge the gap between technical findings and actionable insights. By presenting information clearly, providing context, and encouraging intuitive engagement with visualizations, cybersecurity reports can empower stakeholders to make informed decisions and take proactive measures to improve cybersecurity posture and resilience.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ee1f5ee elementor-widget elementor-widget-heading\" data-id=\"ee1f5ee\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-85b9b30 elementor-widget elementor-widget-text-editor\" data-id=\"85b9b30\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Zuzanna Chociej<\/strong> is a Manager with MNP\u2019s Forensic and Litigation Support Services practice in Toronto. She is an accomplished open-source investigator with a passion for information security and open-source analysis. With a deep understanding of technology and a keen eye for detail, she specializes in gathering, analyzing, and interpreting open-source intelligence (OSINT) to provide valuable context and insight for informed risk mitigation. With over a decade of experience, Zuzanna has worked in an intelligence and research capacity for various government and private sector organizations. This is in addition to her experience in the private sector as a risk analyst and investigator. Zuzanna communicates her findings through a systems-oriented perspective, which you will find reflected in her cyber threat and OSINT work at MNP. Her increasing proficiency with penetration testing, red teaming and vulnerability assessment further add to the insightfulness of her intelligence products. Zuzanna has supported clients across industries, focusing on the public sector, business and professional services, and finance. In addition to holding several GIAC certifications (GCIH, GSEC, GFACT), she holds a Master of Arts in Philosophy from McMaster University, as well as a post-graduate diploma from the United Nations University \u2013 Institute for Water Environment and Health.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-28de6bd elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"28de6bd\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-3755b4d e-con-full e-flex e-con e-child\" data-id=\"3755b4d\" data-element_type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-b4bf81b e-con-full e-flex e-con e-child\" data-id=\"b4bf81b\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a910388 elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"a910388\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/mt2-rcnumh430h1mjhotirh5613mc8v7zodjhg4k9vplj8.jpg\" title=\"mt2.jpg\" alt=\"mt2.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e5d9c2f elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"e5d9c2f\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/mf2-rcnumi1x7b2wv3ngd9vrqiv2xmql7dh9tks1r5o7d0.jpg\" title=\"mf2.jpg\" alt=\"mf2.jpg\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-06cdfba elementor-widget elementor-widget-heading\" data-id=\"06cdfba\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Mathieu Tartare &amp; Matthieu Faou<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1dd80dd elementor-widget elementor-widget-heading\" data-id=\"1dd80dd\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Panorama des menaces num\u00e9riques li\u00e9es \u00e0 la Chine<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-888aad2 elementor-widget elementor-widget-text-editor\" data-id=\"888aad2\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Dans les derni\u00e8res ann\u00e9es, l\u2019ing\u00e9rence chinoise au Canada a \u00e9t\u00e9 au c\u0153ur de l\u2019actualit\u00e9. Du c\u00f4t\u00e9 num\u00e9rique, les groupes d\u2019attaquants \u00ab APT \u00bb li\u00e9s \u00e0 la Chine ont \u00e9t\u00e9 particuli\u00e8rement actifs, conduisant de nombreuses op\u00e9rations de cyberespionnage. Les chercheurs d\u2019ESET \u2013 un fournisseur majeur de solutions de s\u00e9curit\u00e9 ayant un bureau de recherche \u00e0 Montr\u00e9al \u2013 ont acquis une expertise dans l\u2019analyse et le renseignement des cyberattaques attribu\u00e9es \u00e0 la Chine. Nous avons ainsi identifi\u00e9 des op\u00e9rations de cyberespionnage contre des gouvernements, des entreprises strat\u00e9giques (secteur de la d\u00e9fense ou de hautes technologies par exemple) et des individus li\u00e9s aux \u00ab cinq poisons \u00bb (militants pour l\u2019ind\u00e9pendance de Ta\u00efwan, les Ou\u00efghours, les Tib\u00e9tains, le Falun Gong et les militants prod\u00e9mocratie). Les groupes d\u2019attaquants li\u00e9s \u00e0 la Chine sont particuli\u00e8rement actifs en Asie et en Europe, mais \u00e9galement en Am\u00e9rique du Nord. Dans cette pr\u00e9sentation, nous allons faire un panorama des menaces des groupes li\u00e9s \u00e0 la Chine, \u00e0 partir de plusieurs \u00e9tudes de cas o\u00f9 nous \u00e9voquerons diff\u00e9rents groupes APT et leurs sp\u00e9cificit\u00e9s. En particulier, nous nous int\u00e9resserons \u00e0 des groupes ciblant diff\u00e9rents secteurs ou groupes d&rsquo;individus et nous exposerons les diff\u00e9rents modes op\u00e9ratoires employ\u00e9s afin de mener \u00e0 bien leurs op\u00e9rations. Nous pr\u00e9senterons \u00e9galement l&rsquo;\u00e9cosyst\u00e8me cyber auquel appartiennent ces groupes. En effet, les op\u00e9rations de cyberespionnage chinois sont men\u00e9es essentiellement en lien avec trois entit\u00e9s distinctes ayant diff\u00e9rentes responsabilit\u00e9s et objectifs : l&rsquo;arm\u00e9e populaire de lib\u00e9ration (PLA), le minist\u00e8re de la S\u00e9curit\u00e9 d&rsquo;\u00c9tat (MSS) et le minist\u00e8re de la S\u00e9curit\u00e9 publique (MPS). Nous montrerons comment ces organisations sous-traitent une partie de leurs op\u00e9rations de cyberespionnage \u00e0 des entreprises priv\u00e9es en revenant notamment sur le cas de la r\u00e9cente fuite de documents internes de la compagnie i-Soon sur GitHub. Cette fuite a mis en lumi\u00e8re les activit\u00e9s de cyberespionnage de cette compagnie sp\u00e9cialis\u00e9e dans la s\u00e9curit\u00e9 informatique, sous-traitant pour l&rsquo;appareil s\u00e9curitaire chinois. Par ailleurs, nous attribuons \u00e0 i-Soon les campagnes men\u00e9es par le groupe APT Fishmonger, dont nous avons document\u00e9 les activit\u00e9s d\u00e8s 2020 lors d&rsquo;une campagne ciblant les universit\u00e9s hongkongaises lors des manifestations de 2019.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d1adb77 elementor-widget elementor-widget-heading\" data-id=\"d1adb77\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-92ef294 elementor-widget elementor-widget-text-editor\" data-id=\"92ef294\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Mathieu Tartare<\/strong> est chercheur senior en logiciels malveillants \u00e0 ESET o\u00f9 il a commenc\u00e9 sa carri\u00e8re en cybers\u00e9curit\u00e9 en 2018 apr\u00e8s avoir obtenu son doctorat en astrophysique et travaill\u00e9 dans le calcul haute performance. Ses recherches actuelles portent principalement sur les groupes de cyberespionnage en lien avec la Chine et il dirige une des \u00e9quipes de recherche du centre de R &amp; D d&rsquo;ESET \u00e0 Montr\u00e9al.<\/p><p>\u00a0<\/p><p><strong>Matthieu Faou<\/strong> est chercheur senior en logiciels malveillants chez ESET o\u00f9 il se sp\u00e9cialise dans l\u2019analyse des attaques cibl\u00e9es. Ses principales t\u00e2ches comprennent le suivi de groupes de cyberespionnage et la r\u00e9tro-ing\u00e9nierie de logiciels malveillants. Il a compl\u00e9t\u00e9 sa ma\u00eetrise en informatique \u00e0 l\u2019\u00c9cole Polytechnique de Montr\u00e9al et \u00e0 l\u2019\u00c9cole des Mines de Nancy en 2016. Dans le pass\u00e9, il a pr\u00e9sent\u00e9 \u00e0 plusieurs conf\u00e9rences, notamment Black Hat USA, BlueHat, Botconf, CYBERWARCON, RECON et Virus Bulletin.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-332cfef e-flex e-con-boxed e-con e-parent\" data-id=\"332cfef\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ceec0b6 elementor-widget elementor-widget-heading\" data-id=\"ceec0b6\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Comit\u00e9 scientifique<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-44dcf7a elementor-widget elementor-widget-text-editor\" data-id=\"44dcf7a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<pre><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>Dave Lewis | 1Password<\/b><\/span><\/span><\/span>\n<span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>Julien Richard | Lastwall Networks<br \/><\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>Marc-Etienne L\u00e9veill\u00e9 | ESET<\/b><\/span><\/span><\/span>\n<span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>Masarah Paquet-Clouston | Universit\u00e9 de Montr\u00e9al<\/b><\/span><\/span><\/span>\n<span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>Mathilde Conseil | BDC<\/b><\/span><\/span><\/span>\n<span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>Pierre-Marc Bureau | Google Canada<\/b><\/span><\/span><\/span>\n<\/pre>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>2024 Horaire| 14 Septembre | Biblioth\u00e8que et Archives nationales du Qu\u00e9bec 8:30AM | Ouverture des portes et caf\u00e9 \u00a0 9:00AM \u2013 9:05AM | Mot d&rsquo;ouverture \u00a0 9:05AM \u2013 11:00AM |\u00a0Workshop \u00ab\u00a0Intro to Windows Forensics for Insider Threat\u00a0\u00bb 9:05AM \u2013 9:30AM | Reconsidering Cybercriminal Expertise Through Their Behavior With Command-Line Interface vs Graphical User Interface Andr\u00e9anne [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":452,"parent":392,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","footnotes":""},"class_list":["post-437","page","type-page","status-publish","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/pages\/437","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/comments?post=437"}],"version-history":[{"count":4,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/pages\/437\/revisions"}],"predecessor-version":[{"id":475,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/pages\/437\/revisions\/475"}],"up":[{"embeddable":true,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/pages\/392"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/media\/452"}],"wp:attachment":[{"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/media?parent=437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}