{"id":864,"date":"2026-07-03T14:53:46","date_gmt":"2026-07-03T18:53:46","guid":{"rendered":"https:\/\/bsidesmtl.ca\/?page_id=864"},"modified":"2026-07-30T21:20:18","modified_gmt":"2026-07-31T01:20:18","slug":"programme-2026-fr","status":"publish","type":"page","link":"https:\/\/bsidesmtl.ca\/fr\/programme-2026-fr\/","title":{"rendered":"\u2014 Programme 2026 | FR \u2014"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"864\" class=\"elementor elementor-864\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-407f24ac e-flex e-con-boxed e-con e-parent\" data-id=\"407f24ac\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2c5ebab0 elementor-widget elementor-widget-heading\" data-id=\"2c5ebab0\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">2026 Horaire | 19 Septembre | Biblioth\u00e8que et Archives nationales du Qu\u00e9bec<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-708ec494 elementor-widget elementor-widget-text-editor\" data-id=\"708ec494\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\">8:30AM | Ouverture des portes &#8211; d\u00e9jeuner et caf\u00e9 servis<br \/><\/span><\/span><\/span><\/strong><\/p><p><strong><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\">\u00a0<\/span><\/span><\/span><\/strong><\/p><p><strong><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\">9:00AM \u2013 9:05AM | Mot d&rsquo;ouverture<\/span><\/span><\/span><\/strong><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>\u00a0<\/b><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>9:05AM \u2013 9:30AM | <\/b><\/span><\/span><\/span><span style=\"color: #244084; font-family: Montserrat, serif; font-size: small;\"><b>Authorization phishing: phishing, but without the creds<br \/><\/b><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Luke Jennings<br \/><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/span><\/p><p><strong><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\">9:30AM &#8211; 9:55AM | 2,000 Packages Later: What Continuous npm Scanning Reveals About Supply Chain Attackers<br \/><\/span><\/span><\/span><\/strong><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Alessandra Rizzo<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>9:55AM \u2013 10:20AM | Pwning Dashcams<br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">dead1nfluence<\/span><\/p><p>\u00a0<\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>10:20AM \u2013 10:45AM | Breaking Backup: Attacking the Last Line of Defence<br \/><\/b><\/span><\/span><\/span><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Chris McDonald<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>10:45AM \u2013 11:05AM | PAUSE-CAF\u00c9<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b><br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>\u00a0<\/b><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>11:05AM \u2013 11:30AM | Entra conditional access pLOLicies<br \/><\/b><\/span><\/span><\/span><b><\/b><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Filip Jodoin<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>11:30AM \u2013 11:55AM | Rewiring the SOC: From Detection-as-Code to Agentic MDR in Production<br \/><\/b><\/span><\/span><\/span><b><\/b><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Pierre Collard<br \/><\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>11:55AM \u2013 12:20PM | Can LLMs Really Find IDORs? Limits of AI Security Reasoning<br \/><\/b><\/span><\/span><\/span><b><\/b><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Vasilii Ermilov<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>12:20PM \u2013 1:20PM | LUNCH &#8211; Offert sur place<\/b><\/span><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b><br \/><\/b><\/span><\/span><\/span><\/span><\/p><p>\u00a0<\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>1:20PM \u2013 1:45PM | Self-Infected Prompt Kiddies: From Script Kiddies to Prompt Kiddies, AI-Powered Cybercrime in the Wild Monday<br \/><\/b><\/span><\/span><\/span><\/span><b><\/b><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Ali Alame<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>1:45PM \u2013 2:10PM | Why I Go to the Dark Web Every Day<br \/><\/b><\/span><\/span><\/span><b><\/b><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Alex Holden<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>2:10PM \u2013 2:35PM | Threat Hunting Was Always the Answer &#8211; It Just Couldn&rsquo;t Scale<br \/><\/b><\/span><\/span><\/span><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">Faan Rossouw<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>2:35PM \u2013 3:00PM | Headline Hijacking: Catching Scam Infrastructure Built by AI in the Window Between Headline and Victim<br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"color: #244084; font-family: Montserrat, serif; font-size: small;\">Andre Piazza<\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>3:00PM \u2013 3:20PM | PAUSE-CAF\u00c9<\/b><\/span><\/span><\/span><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b><br \/><\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>3:20PM \u2013 3:45PM | Diversity Is a Security Control: Reducing Cognitive Blind Spots Through Diverse Perspectives<br \/><\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\"><span lang=\"fr-CA\">Chaimaa Mhab<\/span><\/span><\/p><p><b style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\">\u00a0<\/b><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>3:45PM \u2013 4:10PM | Automatiser un test d&rsquo;intrusion avec un LLM local : jusqu&rsquo;o\u00f9 peut-on aller sans le cloud ?<br \/><\/b><\/span><\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\"><span lang=\"fr-CA\">Victor Aurora<\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/p><p><span lang=\"fr-CA\"><b style=\"color: #244084; font-family: Montserrat, serif; font-size: small;\">4:10PM \u2013 4:35PM | S\u00e9curit\u00e9 physique &#8211; Une approche purple<br \/><\/b><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\"><span lang=\"fr-CA\">Francis Venne<\/span><\/span><\/p><p><span style=\"font-size: small; font-family: Montserrat, serif; color: #244084;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>4:35PM \u2013 4:40PM | Allocution de cl\u00f4ture<\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>\u00a0<\/b><\/span><\/span><\/span><\/span><\/p><p><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><span lang=\"fr-CA\"><b>4:40PM \u2013 8:00PM | Cocktail<\/b><\/span><\/span><\/span><\/span><b><\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1ef952a0 e-flex e-con-boxed e-con e-parent\" data-id=\"1ef952a0\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-10c96726 elementor-widget elementor-widget-heading\" data-id=\"10c96726\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">2026 Horaire \u2015 Programme d\u00e9taill\u00e9<\/h2>\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-6430c682 e-con-full e-flex e-con e-child\" data-id=\"6430c682\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4af586b elementor-widget elementor-widget-image\" data-id=\"4af586b\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/can-llms-really-rp914hy6pgm90bojexsy8d3grlddyu3hfk9em3hqo4.png\" title=\"can llms really\" alt=\"can llms really\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-57bacc1a elementor-widget elementor-widget-heading\" data-id=\"57bacc1a\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Vasilii Ermilov<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5e9cedb1 elementor-widget elementor-widget-heading\" data-id=\"5e9cedb1\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Can LLMs Really Find IDORs? Limits of AI Security Reasoning<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-244e5d36 elementor-widget elementor-widget-text-editor\" data-id=\"244e5d36\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Can AI actually find IDORs in real code? We tested top coding agents against real-world apps\u2014and the results were mixed. The models discovered genuine vulnerabilities, but also generated large numbers of false positives and inconsistent findings. LLMs show strong intuition for contextual bugs, but struggle with deeper dataflow and multi-file reasoning, often producing noisy or inconsistent results. A single prompt can yield different answers from run to run, making reliable benchmarking both essential and uniquely challenging. By dissecting results across multiple authorization complexity levels, we show where LLMs shine, where they fail, and why IDORs remain a uniquely hard class of bugs for AI to reason about. Expect real examples, surprising failure modes, and practical lessons for anyone considering AI as a security testing assistant. Attendees will leave with a grounded, data-driven understanding of where AI coding agents shine today, where they fail, and what it will take to reliably use LLMs for vulnerability discovery going forward.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-24b0a8ad elementor-widget elementor-widget-heading\" data-id=\"24b0a8ad\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-204464d4 elementor-widget elementor-widget-text-editor\" data-id=\"204464d4\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p dir=\"ltr\">Vasilii Ermilov (@ermil0v) is a Senior Security Researcher at Semgrep, a startup working on open source static analysis tools that fit the modern developer workflow. Vasilii spends his time digging through large attack surfaces, combining automation with hands-on testing to uncover real, exploitable issues. He\u2019s interested in how AI can actually help find and validate real bugs, not just generate convincing-looking noise. Having more than a decade of experience in web application development for enterprises, governments and startups he now uses his knowledge for identifying weak and vulnerable parts in other people&rsquo;s code. He has also shared his research and practical insights at international security conferences, including BSides Seattle, BSides Singapore, and OWASP SnowFroc. His talks focus on bridging the gap between theory and practice, demonstrating how modern security tooling can be applied to uncover meaningful vulnerabilities at scale. He is particularly interested in making security research actionable for developers, helping teams integrate security testing into everyday workflows without slowing down development velocity.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-205d9ccb elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"205d9ccb\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-367f91db e-con-full e-flex e-con e-child\" data-id=\"367f91db\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5b688066 elementor-widget elementor-widget-image\" data-id=\"5b688066\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/2000-packages-later-rp914h0cimkyoppwkfebnvc067i0r4zr3flx4tj4uc.png\" title=\"2000 packages later\" alt=\"2000 packages later\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-53287328 elementor-widget elementor-widget-heading\" data-id=\"53287328\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Alessandra Rizzo<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-661c532b elementor-widget elementor-widget-heading\" data-id=\"661c532b\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">2,000 Packages Later: What Continuous npm Scanning Reveals About Supply Chain Attackers<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1ecb8b7e elementor-widget elementor-widget-text-editor\" data-id=\"1ecb8b7e\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Since November 2025, we&rsquo;ve been continuously scanning the npm registry for malicious packages using a detection pipeline that combines static analysis and YARA signatures with LLM-assisted triage. To date, the scanner has flagged over 2,000 malicious packages.<\/p><p>Credential stealers and infostealers make up the majority, but the dataset tells a bigger story: npm is no longer just a typosquatting problem. It&rsquo;s a multi-actor battleground where nation-states, criminal MaaS operators, and infrastructure-focused attackers all converge on the same entry point: npm install.<\/p><p>This talk breaks down what we learned by watching the registry at scale. We cover the landscape, including category breakdowns, monthly publication trends, and the exfiltration infrastructure we mapped, ranging from disposable webhooks to blockchain-based C2. We then deep-dive into three campaigns that illustrate where supply chain attacks are heading and how different threat actors are exploiting the same ecosystem for very different objectives.<\/p><p>The first is Koalemos, a modular RAT distributed under impersonated developer identities from a major US financial institution, with DNS-gated execution restricting payloads to the institution&rsquo;s internal network. We assessed with moderate confidence that it is linked to the DPRK-attributed Contagious Interview campaign based on overlapping obfuscation techniques, distribution tactics, and identity spoofing patterns.<\/p><p>The second is Ghost Loader, a criminal MaaS infostealer operation that stores its C2 configuration in Binance Smart Chain smart contracts, uses split-key encryption with dead drop retrieval, and routes stolen credentials through partner-specific Telegram bots.<\/p><p>The third is Tunnel Vision, a cross-ecosystem attack published simultaneously to npm and PyPI that hides its entire payload in a precompiled binary disguised as a Node.js addon, deploying a Cloudflare-fronted reverse tunnel with SOCKS5 and SSH\/SFTP access into the victim&rsquo;s network before self-destructing within seconds.<\/p><p>Each campaign represents a different class of threat actor and a different end goal, but all three exploit the implicit trust developers place in package registries. Attendees will leave with a concrete understanding of the current npm threat landscape, the novel techniques defenders should be looking for, and actionable detection strategies for each campaign.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-404c2813 elementor-widget elementor-widget-heading\" data-id=\"404c2813\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3a0bcf1c elementor-widget elementor-widget-text-editor\" data-id=\"3a0bcf1c\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<main id=\"content\"><div class=\"card mb-3 speaker-card\"><div class=\"card-body\"><div class=\"card-text speaker-detail\"><p>Alessandra Rizzo is a Senior Threat Researcher at Panther, where she builds detection content and researches emerging cloud and supply chain threats. She currently leads Panther&rsquo;s npm registry scanning operation, which has flagged over 2,000 malicious packages since November 2025 and uncovered campaigns attributed to nation-state actors, criminal MaaS operators, and infrastructure-focused attackers. Her research has been covered by The Hacker News and other major security publications. Before joining Panther, Alessandra worked as a Threat Detection Engineer at Sysdig, where she focused on Linux and container security and investigated nation-state malware and botnets targeting cloud workloads. Prior to that, she served as a threat intelligence consultant for premier European financial institutions, investigating APTs and malware campaigns targeting the financial sector. Her current research interests span cloud security, software supply chain threats, and the intersection of LLMs with both offensive and defensive security. Alessandra holds an MSc in Advanced Cybersecurity from King&rsquo;s College London.<\/p><\/div><\/div><\/div><\/main>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-114e9079 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"114e9079\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-274ba1f1 e-con-full e-flex e-con e-child\" data-id=\"274ba1f1\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-431f2b8b elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"431f2b8b\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/jodoin22-rr3lrvvpz4lee023e6fluk72gv973ea62vnid66on8.png\" title=\"jodoin22\" alt=\"jodoin22\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2d68ddf9 elementor-widget elementor-widget-heading\" data-id=\"2d68ddf9\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Filip Jodoin<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-706bd525 elementor-widget elementor-widget-heading\" data-id=\"706bd525\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Entra conditional access pLOLicies<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4019504f elementor-widget elementor-widget-text-editor\" data-id=\"4019504f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>\u00ab\u00a0Multifactor Authentication blocks 99% of attacks\u00a0\u00bb \u2014 but only when a Conditional Access Policy (CAP) actually fires. Microsoft built CAPs to give IT teams fine-grained control over how MFA is enforced across resources, identities, workloads, and actions.<\/p><p>This talk walks through CAP circumventions across the Microsoft 365 application umbrella. The goal is to help administrators develop a deeper understanding of \u00ab\u00a0weak\u00a0\u00bb vs. \u00ab\u00a0strong\u00a0\u00bb CAPs, as well as when additional controls must be imposed (e.g. through Entra, Intune and SharePoint).<\/p><p>CAPs 101: A primer on Conditional Access Policies: their predecessor (per-user MFA), how CAPs are enforced, what they can target, and how they fit into a modern architecture. This section grounds the audience in how CAPs should be reasoned about and highlights the configuration choices that matter most when locking down MFA for specific resources, identities, workloads, and actions. Understanding these building blocks is essential for spotting where the cracks form.<\/p><p>What Lives Under the Microsoft 365 Umbrella: The \u00ab\u00a0Office 365&Prime; CAP resource is vague, and you have to dig through Microsoft&rsquo;s documentation to understand which applications the O365 \u201cresource\u201d actually covers. What may fly under the radar is that the scopes requested when authenticating against the Microsoft Graph can be manipulated \u2014 omit the right ones through an O365 app, and the \u201cOffice 365\u00a0\u00bb CAP may not trigger at all. This section dissects how that manipulation works and what an attacker can access as a result.<\/p><p>SharePoint Online \u201cRestrictions\u00a0\u00bb: When imposing restrictions on SharePoint Online through CAPs and\/or SharePoint Online (SPO) configurations, it is important to remember that the Microsoft Graph API may not be bound by them, as it is an entirely different resource. Some restrictions, such as the SPO sharing feature, enforced through SharePoint Online configurations, can be circumvented entirely via the Microsoft Graph API<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e8acb68 elementor-widget elementor-widget-heading\" data-id=\"e8acb68\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6ef437ae elementor-widget elementor-widget-text-editor\" data-id=\"6ef437ae\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Filip Jodoin is a Montreal-based offensive security professional and member of the Ordre des ing\u00e9nieurs du Qu\u00e9bec (ing.) specializing in cloud adversary emulation and identity attack techniques.\u00a0Over the course of his career he has worked across the public sector, consulting, and financial services, building expertise across blue, red, and purple teaming with a focus on cloud security and hybrid infrastructures. Alongside his full-time work, he instructs in offensive cloud and identity security. Filip holds a Bachelor of Engineering in Computer Engineering from Concordia University (Montreal).\u00a0His certifications and training reflect a stubborn attempt at staying ahead of the curve. Filip is a seasoned debater; forged at weekly family Sunday dinners. He approaches his craft with the same relentless curiosity and passion.\u00a0Outside of work, he enjoys spicy Southeast Asian food and pumping iron. Filip would not be where he is today without the support of his loving fianc\u00e9e and family.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-79a3db61 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"79a3db61\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-c8ea8a8 e-con-full e-flex e-con e-child\" data-id=\"c8ea8a8\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-165d3a4c elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"165d3a4c\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/dead1-rpvjsd4qhj4pfkhk4tq4ix06t5t61q0t6aempka7gk.png\" title=\"dead1\" alt=\"dead1\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-487b2297 elementor-widget elementor-widget-heading\" data-id=\"487b2297\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">dead1nfluence<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-52db2761 elementor-widget elementor-widget-heading\" data-id=\"52db2761\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Pwning Dashcams<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-328c9fb1 elementor-widget elementor-widget-text-editor\" data-id=\"328c9fb1\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>In this presentation we will evaluate the security of one of the most popular dash cams on Amazon, with the goal of answering the question, \u201cCould we, as an unauthenticated attacker, disrupt the video communications in a temporary or permanent way?\u201d Julian will take you through his journey of reverse engineering a high-end dash cam, the vulnerabilities he discovered along the way, and the surprising discovery that this research affects an unknown number of other popular dash cams. You will walk away from this presentation with a deeper understanding of hardware hacking, reverse engineering, and the risks posed by insecure consumer-grade devices.<\/p><p>While many new cars are now shipping with built-in cameras to automatically record incidents, help in insurance claims, or to surveil driver awareness levels, not all do. Consequently, many car owners have turned to dash cams to help protect their vehicles. According to market research firm Grand View Horizon, these concerns have been reflected in steady market growth with the dash cam industry in the Canada expected to grow at a rate of 9 percent a year over the next four years.<\/p><p>These small devices provide numerous benefits; they may help determine responsibility in the event of an accident, help fight traffic tickets, or catch crazy road incidents that get uploaded to YouTube and attract millions of views resulting in untold fame and fortune for the owner!<\/p><p>It was with this in mind that we decided to investigate the security of one of Amazon\u2019s most popular high-end dash cams.<\/p><p>This presentation will detail my research conducted over a year on one of the highest end dash cams available on Amazon. Discovering over 20 vulnerabilities that affected not only this brand, but countless others because of white labeling, I will demonstrate how even \u00ab\u00a0the best of the best\u00a0\u00bb in consumer-grade IoT devices lack even the most fundamental security.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-33f74a74 elementor-widget elementor-widget-heading\" data-id=\"33f74a74\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2b4e4ec elementor-widget elementor-widget-text-editor\" data-id=\"2b4e4ec\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>As a Penetration Tester at Software Secured, Julian hunts for vulnerabilities across a range of clients and products. Off hours, he spends his time performing vulnerability research against IoT devices and FOSS, amassing over 40 CVEs in the past several years. Previous work includes exploiting the Furbo devices, to find 20+ vulnerabilities, discovering\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=https%3A\/\/www.404media.co\/more-than-130-000-claude-grok-chatgpt-and-other-llm-chats-readable-on-archive-org\/%3ACWIaI3y_Lf4aKiFg3LlNc0Q9XW_nzkk6bT1U4ZOqhso\" target=\"_blank\" rel=\"noopener\">more than 130,000 Claude, Grok, ChatGPT, and Other LLM Chats Readable on Archive.org<\/a>, as well as being featured by 404Media in the article:\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=https%3A\/\/www.404media.co\/grok-exposes-underlying-prompts-for-its-ai-personas-even-putting-things-in-your-ass\/%3Ag2mEghXhjM-TP4wukYA-_BTN7JdExPSKWyaYhlIxEF4\" target=\"_blank\" rel=\"noopener\">Grok Exposes Underlying Prompts for Its AI Personas: \u2018EVEN PUTTING THINGS IN YOUR ***\u2019<\/a><\/p><p>Previously a speaker at the following conferences:<br \/>Speaker at:<br \/>&#8211; BSides Vancouver 2023 &amp; 2024<br \/>&#8211; BSides Montreal 2023<br \/>&#8211; BSides Athens 2023<br \/>&#8211; BSides Copenhagen 2023<br \/>&#8211; BSides Bern 2024<br \/>&#8211; DeepSec 2022, 2023, 2024, 2025<br \/>&#8211; DeepIntel 2023, 2024<br \/>&#8211; Knock in the Night 2024<br \/>&#8211; BSides Toronto 2025<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c228b82 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"c228b82\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-74e35f12 e-con-full e-flex e-con e-child\" data-id=\"74e35f12\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-68066899 elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"68066899\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/self-infected-prompts-rp914e6ty4h3pvu00w6fye1me1vx41ok31ngoznbd0.png\" title=\"self-infected prompts\" alt=\"self-infected prompts\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-59c77d7e elementor-widget elementor-widget-heading\" data-id=\"59c77d7e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Ali Alame<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2c1e2390 elementor-widget elementor-widget-heading\" data-id=\"2c1e2390\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Self-Infected Prompt Kiddies: From Script Kiddies to Prompt Kiddies, AI-Powered Cybercrime in the Wild Monday<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-43229468 elementor-widget elementor-widget-text-editor\" data-id=\"43229468\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>In the age of AI, truth is becoming optional, and cybercriminals are taking full advantage.<\/p><p>Today&rsquo;s threat actors are no longer limited to purchasing phishing kits, reusing commodity malware, or relying on pre-written attack templates. They are actively leveraging artificial intelligence to increase the speed, scale, and sophistication of their operations. AI is being used to write highly convincing phishing emails, generate malicious code, troubleshoot malware, translate scams into multiple languages, create realistic social engineering content, and rapidly iterate campaigns in ways that closely resemble modern software development practices.<\/p><p>What once required a team of skilled operators can now be accomplished by a single individual armed with the right AI tools. The result is a significant reduction in the barrier to entry for cybercrime and an increase in the volume and quality of attacks targeting organizations of all sizes.<\/p><p>This session provides a rare behind-the-scenes look at what defenders seldom get to see: pre-breach threat intelligence artifacts collected from real-world criminal testing environments. Before launching large-scale campaigns, many threat actors test their malware, phishing infrastructure, credential harvesting pages, and social engineering content. These trial runs often leave behind valuable evidence that defenders can collect, analyze, and use to gain insight into emerging threats before they become widespread incidents.<\/p><p>Drawing from real-world observations and investigations, we will explore:<\/p><p>* AI-generated phishing emails, landing pages, and social engineering scripts<br \/>* Infostealer malware development patterns that strongly suggest LLM involvement<br \/>* Prompt-driven iteration and how attackers use AI to debug, improve, and optimize campaigns<br \/>* The fingerprints AI leaves behind in code, language, structure, and infrastructure<br \/>* Emerging trends in AI-assisted cybercrime and what defenders should expect next<br \/>* Practical detection opportunities for security operations, threat hunting, and incident response teams<\/p><p>Attendees will leave with a deeper understanding of how AI is reshaping the threat landscape, how cybercriminals are operationalizing these technologies, and how defenders can identify and respond to the subtle indicators left behind by AI-assisted attacks before they evolve into full-scale compromises.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5c91daa6 elementor-widget elementor-widget-heading\" data-id=\"5c91daa6\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-34fae8af elementor-widget elementor-widget-text-editor\" data-id=\"34fae8af\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Ali Alame is a cybersecurity professional, threat hunter, and co-founder of CyberArmor, where he leads initiatives focused on identifying cyber threats before they become full-scale incidents. His work specializes in pre-breach intelligence, including the discovery of phishing kits, compromised credentials, infostealer malware activity, exposed cloud assets, and threat actor infrastructure before the data reaches underground markets or the dark web.\u00a0With experience spanning enterprise, financial services, retail, and higher education, Ali has held cybersecurity and technology roles at IBM, Lululemon, the University of British Columbia (UBC), and the Royal Bank of Canada (RBC). Throughout his career, he has worked on security operations, threat detection, incident response, identity security, and cloud security initiatives supporting large-scale environments.\u00a0Ali is a frequent speaker at cybersecurity conferences, industry meetups, and community events, where he shares practical insights from frontline investigations and threat-hunting operations. His presentations focus on emerging threats, cybercrime trends, identity compromise, and the growing role of artificial intelligence in both offensive and defensive security. By combining technical research with real-world case studies, Ali helps organizations better understand how modern threat actors operate and how defenders can identify indicators of compromise before attacks escalate into major security incidents.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2e1aece6 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"2e1aece6\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-2b149b83 e-con-full e-flex e-con e-child\" data-id=\"2b149b83\" data-element_type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-48cb277b e-con-full e-flex e-con e-child\" data-id=\"48cb277b\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1e1ee0e7 elementor-widget__width-auto elementor-widget elementor-widget-image\" data-id=\"1e1ee0e7\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/cmd-rr3m5xkw3ztnw7njd90w40l2260o4k1rcemqk1cvno.png\" title=\"cmd\" alt=\"cmd\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-296eb88c elementor-widget elementor-widget-heading\" data-id=\"296eb88c\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Chris McDonald<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e99cede elementor-widget elementor-widget-heading\" data-id=\"e99cede\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Breaking Backup: Attacking the Last Line of Defence<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3c08a476 elementor-widget elementor-widget-text-editor\" data-id=\"3c08a476\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Backups are widely treated as the last line of defence against ransomware and destructive attacks. In practice, they are often among the first systems deliberately targeted once an attacker gains a foothold in an environment. This talk explores how modern adversaries identify, access, and ultimately compromise backup infrastructure using techniques that are broadly applicable across enterprise platforms, regardless of vendor or architecture.<\/p><p>We begin by examining how backup systems are discovered through common enterprise artifacts, including Active Directory enumeration, service account analysis, DNS and naming conventions, and opportunistic network scanning. These methods frequently reveal high-value systems that are insufficiently segmented or monitored. From there, we walk through realistic attack paths that exploit weak identity boundaries, overprivileged service accounts, and insecure credential storage mechanisms commonly found in backup environments.<\/p><p>We will discuss how a low-privileged domain user can escalate access to the backup control plane by extracting stored credentials and abusing management interfaces. We then highlight how attackers leverage legitimate administrative functionality\u2014such as APIs, scripting interfaces, and job management tools\u2014to silently delete backup chains, alter retention policies, or degrade recovery capabilities over time. Because these actions closely resemble normal administrative behaviour, they often evade traditional detection controls and generate little to no actionable telemetry.<\/p><p>The talk also explores data-plane attacks against backup repositories, including direct file manipulation, snapshot and version deletion in object storage, and timing-based strategies designed to bypass retention and immutability safeguards. We highlight lesser-known failure modes, such as delayed destruction and incremental chain corruption, which can leave organizations with a false sense of recoverability until recovery is actually required.<\/p><p>In addition to offensive techniques, we place a strong emphasis on defensive engineering and layered protection strategies. We will discuss how to design backup environments that can withstand these attack paths through identity isolation, strict least-privilege models, resilient immutability configurations, and independent control planes. We will also cover practical detection approaches, including monitoring for anomalous administrative actions, API abuse, and mass deletion events, as well as strategies for validating recovery integrity through continuous testing.<\/p><p>Attendees will leave with a deeper understanding of the backup attack surface, how these attacks unfold in real environments, and concrete, vendor-neutral approaches to protect and harden their backup and recovery strategy against a determined adversary.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-45d5302f elementor-widget elementor-widget-heading\" data-id=\"45d5302f\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7fbb2161 elementor-widget elementor-widget-text-editor\" data-id=\"7fbb2161\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Chris is a Principal Systems Engineer at Veeam, where he partners with organizations to strengthen their data resilience and cyber resiliency strategies in an increasingly complex threat landscape. With deep expertise across data protection, cloud technologies, and modern IT infrastructure, Chris works closely with both commercial and enterprise customers\u2014engaging everyone from technical teams to senior leadership and C-level executives\u2014to design and implement strategies that safeguard critical data from evolving cyber threats, including ransomware and insider risk.\u00a0Blending technical depth with real-world experience, Chris is known for delivering engaging, highly practical sessions that resonate with diverse audiences. He translates complex concepts into clear, actionable guidance, helping organizations move beyond theory to implement resilient, secure, and scalable data protection frameworks. His approach emphasizes not just recovery, but readiness\u2014ensuring businesses can maintain operations and trust even in the face of disruption.\u00a0Driven by a passion for education and customer success, Chris is a trusted voice on topics ranging from backup and recovery to advanced cyber resiliency best practices. He is committed to helping organizations stay one step ahead of cyber adversaries while building lasting confidence in their data protection strategies.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-69ac3fad elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"69ac3fad\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-49c6af43 e-con-full e-flex e-con e-child\" data-id=\"49c6af43\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-780f97a1 elementor-widget elementor-widget-image\" data-id=\"780f97a1\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/why-i-go-to-rp914bdbdmd8r1y3hcyk8wr8lw9tgydd2np095rhvo.png\" title=\"why i go to\" alt=\"why i go to\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3fb24281 elementor-widget elementor-widget-heading\" data-id=\"3fb24281\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Alex Holden<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-61e2b49d elementor-widget elementor-widget-heading\" data-id=\"61e2b49d\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Why I Go to the Dark Web Every Day<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4953c946 elementor-widget elementor-widget-text-editor\" data-id=\"4953c946\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>What do you actually need before stepping into the Dark Web? It is not just tooling. It is understanding how these ecosystems really function under pressure. Language, culture, trust models, reputation, and how quickly you can get identified as an outsider if you get any of it wrong.<\/p><p>This talk is built on real operations, not theory. We walk through practical examples where direct engagement and intelligence collection stopped Russian hacktivist activity such as Killnet, significantly slowed down Chinese pig butchering operations, and drove outcomes that had measurable impact beyond a single target or campaign. Using Dark Web-derived intelligence to make a small or a global change is not easy but it is a lofty goal that is attenable for many. These are not passive observations. These are cases where understanding the adversary environment allowed us to influence it.<\/p><p>You will see how access is gained, how credibility is established, and how conversations evolve when you are dealing with threat actors who assume you are one of them. We will break down mistakes that expose investigators instantly, signals that indicate you are being tested, and moments where a single wrong response ends the operation.<\/p><p>From there, we map out the meta-types of actors you will encounter. Not just roles, but behaviors. The opportunists, the professionals, the ideologues, and the ones who are just there for the chaos. How they communicate, how they validate each other, and how they decide who to trust. More importantly, how you can use that against them.<\/p><p>This is not a tour. It is not screenshots of forums. It is what actually happens when you are inside and the stakes are real.<\/p><p>No fluff. No recycled reporting. Just field-tested methods, failures, and outcomes.<\/p><p>Final takeaway is simple. Know your enemy. Know their tools. Stop the threat actor. Stop the crime.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bb96a71 elementor-widget elementor-widget-heading\" data-id=\"bb96a71\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-11ebfbd0 elementor-widget elementor-widget-text-editor\" data-id=\"11ebfbd0\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Alex Holden is the founder and Chief Information Security Officer (CISO) of Hold Security, LLC. Under his leadership, Hold Security played a pivotal role in information security and threat intelligence becoming one of the most recognizable names in its field. Mr. Holden researches minds and techniques of cyber criminals and helps our society to build better defenses against cyber-attacks. Mr. Holden has been credited in uncovering high-profile breaches such as Adobe Systems, Target, J.P. Morgan Chase, parts of the Equifax breach, and many others. Mr. Holden has spearheaded efforts to infiltrate, monitor, and disrupt various ransomware gangs, including Trickbot and Conti. As an expert in his field, Alex Holden is continuously sharing his original research at numerous cybersecurity conferences and has provided expert commentary in prominent media outlets including CNN, The New York Times, Forbes Magazine, and The Wall Street Journal. His insights into current cybersecurity events and the evolving threat landscape are regularly featured in lectures available on Hold Security&rsquo;s channel on the BrightTalk platform.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-add0bca elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"add0bca\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-54a19a66 e-con-full e-flex e-con e-child\" data-id=\"54a19a66\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1b2795c2 elementor-widget elementor-widget-image\" data-id=\"1b2795c2\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/threat-hunting-rp914afh6sbyffzgmujxoezs0ieg999mqj1irvsw1w.png\" title=\"threat hunting\" alt=\"threat hunting\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-65df2264 elementor-widget elementor-widget-heading\" data-id=\"65df2264\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Faan Rossouw<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e7d9efa elementor-widget elementor-widget-heading\" data-id=\"e7d9efa\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Threat Hunting Was Always the Answer - It Just Couldn't Scale<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-30f1a686 elementor-widget elementor-widget-text-editor\" data-id=\"30f1a686\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Threat hunting has always been the most effective approach to improving organizational security posture. The evidence has been there for years: organizations that hunt consistently find threats faster, build better detections, and develop institutional knowledge that compounds over time.<\/p><p>So why isn&rsquo;t everyone doing it? Why is Threat Hunting still seen as a luxury, why is it gravy and not potatoes? Quite simply &#8211; hunting doesn&rsquo;t scale. Even the most skilled analyst can only cover so much ground, investigate so many leads, hold so much context in their head at once. The blueprint is right, but its been limited by the constraint of human bandwidth, and every attempt to \u00ab\u00a0automate\u00a0\u00bb hunting just turned it back into alerting with extra steps.<\/p><p>Agentic AI changes that equation. Not by replacing the hunter, but by removing the constraint that held hunting back for over a decade. Agents can investigate candidates in parallel, carry structured context across every analysis, follow formalized hunting procedures consistently, and build on each other&rsquo;s findings through shared memory &#8211; all while the human retains direction and judgment.<\/p><p>But getting real results from agents requires more than dropping an LLM into your SOC. It requires engineering the complete environment the agent operates in &#8211; what the field calls harness engineering. The difference between an agent that produces useful investigations and one that hallucinate its way through your logs has almost nothing to do with the model, it has everything to do with the harness: how you prepare the data before agents see it, what context you deliver at inference time, how you structure hunting knowledge into executable procedures, and how you route outcomes back to improve the system.<\/p><p>This talk walks through the architecture of a purpose-built agentic hunting system &#8211; where deterministic code handles what it does best, agents handle the interpretive work, and humans direct and judge.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-21e18f19 elementor-widget elementor-widget-heading\" data-id=\"21e18f19\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e96120c elementor-widget elementor-widget-text-editor\" data-id=\"e96120c\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Independent Researcher, Instructor @ AntiSyphon Training, Builder\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=http%3A\/\/AionSec.ai%3ARUzkI-NMUNW31NDTrlW2JrRFf2oByDcxzs7ZxxjCqAI\" target=\"_blank\" rel=\"noopener\">AionSec.ai<\/a><\/p><p>Faan Rossouw is a threat hunting researcher and educator who has taught thousands of students how to find adversaries in network and endpoint telemetry. He instructs at Antisyphon Training, where he teaches courses on threat hunting and offensive security tooling. He sees the AI era as a genuine inflection point for threat hunting, and has built\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=http%3A\/\/AionSec.ai%3ARUzkI-NMUNW31NDTrlW2JrRFf2oByDcxzs7ZxxjCqAI\" target=\"_blank\" rel=\"noopener\">AionSec.ai<\/a>\u00a0to empower defenders for this new aeon &#8211; designing courses that help security practitioners leverage AI agents in their work. His current focus is on applied harness engineering: building the architecture that makes agentic AI actually useful for defensive operations, rather than just another layer of alerting. Originally from South Africa, Faan is now based in Val-David, Quebec.<\/p><p>Links:<br \/>&#8211;\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=https%3A\/\/aionsec.ai%3AshK3ZYBIhBXFBJvYq6qmHX9P5-ybqz8gzmOled3zYhA\" target=\"_blank\" rel=\"noopener\">AionSec<\/a><br \/>&#8211;\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=https%3A\/\/www.linkedin.com\/in\/faan-rossouw%3AtR0vSLANLrmI-hHB2vNNzOG7GL48iRVLD_7o_ADyXCY\" target=\"_blank\" rel=\"noopener\">LinkedIn<\/a><br \/>&#8211;\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=https%3A\/\/github.com\/faanross%3ABLojgmM-dbXyS16Ws6fQey5r1ss0y0ve2Hcj8ziKiY8\" target=\"_blank\" rel=\"noopener\">GitHub<\/a><br \/>&#8211;\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=https%3A\/\/x.com\/faanross%3A-hcAGvJk_ESHEXDaE3mb_fHRGOOq2eKKH5NBDuGokhE\" target=\"_blank\" rel=\"noopener\">X<\/a><br \/>&#8211;\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=https%3A\/\/youtube.com\/%40faanross%3AindQVG8sogM5LsmBCD2KwSdsB9aj3aFhn0QYABJALFQ\" target=\"_blank\" rel=\"noopener\">YouTube<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1fb071b1 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"1fb071b1\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-54a8141f e-con-full e-flex e-con e-child\" data-id=\"54a8141f\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-196d93c2 elementor-widget elementor-widget-image\" data-id=\"196d93c2\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/Diversity-is-a-security-rp9bqjgohblruoqsk2u3nyg0pic2i2rzahu0mt19ok.png\" title=\"Diversity is a security\" alt=\"Diversity is a security\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3b4fae56 elementor-widget elementor-widget-heading\" data-id=\"3b4fae56\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Chaimaa Mhab<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4d48fee1 elementor-widget elementor-widget-heading\" data-id=\"4d48fee1\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Diversity Is a Security Control: Reducing Cognitive Blind Spots Through Diverse Perspectives<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-57b22cc9 elementor-widget elementor-widget-text-editor\" data-id=\"57b22cc9\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Cybersecurity teams invest heavily in technologies designed to detect, prevent, and respond to threats. We patch vulnerabilities, harden infrastructure, deploy advanced monitoring tools, and continuously improve technical controls. Yet one critical attack surface often remains overlooked: the human dynamics within the security team itself.<\/p><p>When teams are composed of individuals with similar educational backgrounds, career paths, problem-solving styles, or perspectives, they often develop shared assumptions about risk, threats, and response strategies. While alignment can improve speed and coordination, excessive homogeneity can create dangerous blind spots. Teams that think alike may investigate alike, escalate alike, and ultimately miss the same signals.<\/p><p>In cybersecurity, where adversaries constantly adapt and exploit overlooked weaknesses, these blind spots can become material business risks.<\/p><p>This talk explores diversity not as a human resources initiative, but as a strategic security control. More specifically, it examines how cognitive diversity, the presence of different ways of thinking, questioning, analyzing, and communicating, can strengthen security operations and improve organizational resilience.<\/p><p>Drawing from real-world observations in Business Information Security Office (BISO) functions and cross-functional security collaboration, this presentation will examine how diverse perspectives improve critical security outcomes, including threat modeling, incident response, risk communication, and decision-making under pressure. The session will also explore how organizational culture influences whether team members feel empowered to challenge assumptions, escalate concerns, or voice dissenting opinions during high-stakes situations.<\/p><p>The talk will highlight how strong team dynamics, open communication, and inclusive collaboration can reduce security risk and enhance security posture, even in technically mature organizations. Through practical examples, attendees will see how diverse perspectives help surface overlooked signals earlier, improve response speed, and strengthen decision-making and prioritization during security operations.<\/p><p>This session is intended for security practitioners, analysts, leaders, and anyone involved in cybersecurity and organizational resilience. Attendees will leave with a practical framework for recognizing and leveraging cognitive diversity within their teams, along with actionable ideas to foster stronger collaboration across technical and non-technical disciplines.<\/p><p>In an industry focused on securing systems, it is equally important to consider how we structure the teams responsible for defending them. Diversity of thought is not simply beneficial\u2014it is a powerful enabler of stronger cyber resilience and more effective security outcomes.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2fccb19d elementor-widget elementor-widget-heading\" data-id=\"2fccb19d\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-28342930 elementor-widget elementor-widget-text-editor\" data-id=\"28342930\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Chaimaa Mhab is a Global Cybersecurity Advisor at CAE, where she has demonstrated strong technical growth, leadership capabilities, and a deep commitment to cybersecurity culture both inside and outside the organization. Her contributions have strengthened operational processes, enhanced cybersecurity training programs, elevated security testing strategies, and increased CAE\u2019s visibility within the broader cybersecurity ecosystem.\u00a0Chaimaa is also a strong advocate for inclusion, education, and collaboration. As an active member of CAE\u2019s Women in Cyber group, she champions greater representation and supports initiatives that foster belonging and professional growth within cybersecurity. She has organized and participated in multiple initiatives aimed at encouraging women and introducing youth to the field. Her perspective is shaped by a unique combination of business education, cybersecurity expertise, and community engagement.\u00a0In recognition of her contributions to cybersecurity education and outreach, Chaimaa received the 2025 CyberCap Educational Trophy. Her experience provides a compelling foundation for a talk on how diversity can be leveraged as a force multiplier in modern cybersecurity teams.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2362a5cb elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"2362a5cb\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1b1fd2cd e-con-full e-flex e-con e-child\" data-id=\"1b1fd2cd\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-461c9c83 elementor-widget elementor-widget-image\" data-id=\"461c9c83\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/piazza222-rr02gkydf6eb3pk8o0qmu53mhlrwikvv9msi7dw8jo.png\" title=\"piazza222\" alt=\"piazza222\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-696a4412 elementor-widget elementor-widget-heading\" data-id=\"696a4412\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Andre Piazza<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e86817c elementor-widget elementor-widget-heading\" data-id=\"e86817c\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Headline Hijacking: Catching Scam Infrastructure Built by AI in the Window Between Headline and Victim<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3917a496 elementor-widget elementor-widget-text-editor\" data-id=\"3917a496\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>When a crisis breaks, a second wave follows within hours. Wildfires, floods, viral political feuds: each one opens an information void and an emotional spike that traditional detect and respond defenses can&rsquo;t keep pace with. Attackers now use AI to register, clone, and rotate scam infrastructure at speed and scale inside that window. By the time a fraudulent relief site or lookalike donation page gets reported, the campaign has already run its course, and a domain generation algorithm (DGA) is already staging the next one.<\/p><p>I stay left of that boom: the window where infrastructure is staged but hasn&rsquo;t gone live with content yet. Inspired by published threat research covering the 2025 Los Angeles wildfires, the Texas floods, and the Trump \/ Musk feud crypto scams (<a href=\"https:\/\/pretalx.com\/redirect\/?url=http%3A\/\/tremp.xyz%3AhLaDbRQVkVHfxeToRBmJHXG_H39TVRTWCdWkwayN-kY\" target=\"_blank\" rel=\"noopener\">tremp.xyz<\/a>\u00a0and\u00a0<a href=\"https:\/\/pretalx.com\/redirect\/?url=http%3A\/\/noooo.meme%3Abd02eYcmGspUx8svAiOEKjqFaY0irC6zXnTfbJgniwY\" target=\"_blank\" rel=\"noopener\">noooo.meme<\/a>\u00a0among them), I walk through the behavioral signals that let defenders flag and disrupt these campaigns before victims exist: bulk registration patterns, hosting, content cloning from the real organizations being impersonated, and DGA naming patterns tied to a specific news event. I&rsquo;ll also unpack the criminal AI arsenal behind the speed: automated reconnaissance scraping public data for victim profiles, generative tools producing convincing lures and cloned sites, and point-and-click dark web kits that put all of this in reach of low skill actors.<\/p><p>The second half of the talk is about why these campaigns work on people, not just on infrastructure: the specific emotional levers (fear, sympathy, urgency, tribal identity and belonging) that scammers exploit at each stage of a news cycle, and how that maps to the choices defenders should make about the warnings users actually see, not just blocklists.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-63a71b00 elementor-widget elementor-widget-heading\" data-id=\"63a71b00\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-36d0e8a7 elementor-widget elementor-widget-text-editor\" data-id=\"36d0e8a7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<div class=\"card-text speaker-detail\"><p>Andre Piazza is a cybersecurity strategist at BforeAI, focused on catching adversary infrastructure during its staging window, left of boom, before ransomware, account fraud, or brand and supplier impersonation reaches a target. His approach treats attacks as infrastructure and behavior, not just content: the catchable signal usually appears while a campaign is still being built. He works from public signals like WHOIS, DNS, certificate transparency, and ASN data, linking domains by registration velocity, shared certificate fingerprints, and hosting overlap rather than by name alone, to surface lookalike and impersonation infrastructure before it goes live. His talks span verification fraud, impersonation built with AI across browsers and aviation, scams that spin up around breaking news, and operational technology, and they give as much weight to the human trust attackers exploit as to the technology. He turns published threat research into methods practitioners can use the next day, built into hands-on, interactive sessions. A regular speaker at the SANS AI Cybersecurity Summit, BSides (Seattle, Charm, and others), Hou.Sec.Con, and Cybr.Hak.Con, Andre cares about growing security awareness and a more resilient community.<\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-388bb107 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"388bb107\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-6cd6601a e-con-full e-flex e-con e-child\" data-id=\"6cd6601a\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-616ec65 elementor-widget elementor-widget-image\" data-id=\"616ec65\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/collard-rr4hpem7z678uebd02ck5henipeyhrsrgh6gt9s37o.png\" title=\"collard\" alt=\"collard\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4ec19ce7 elementor-widget elementor-widget-heading\" data-id=\"4ec19ce7\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Pierre Collard<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b43422d elementor-widget elementor-widget-heading\" data-id=\"b43422d\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Rewiring the SOC: From Detection-as-Code to Agentic MDR in Production<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2c735ed9 elementor-widget elementor-widget-text-editor\" data-id=\"2c735ed9\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The SOC has always evolved to keep pace with attacker speed. Detection-as-Code introduced engineering discipline and version control to threat coverage. SOAR platforms brought automation to response playbooks. Yet neither approach was built for the challenges defenders face today: alert volumes that far exceed analyst capacity, adversaries leveraging AI to iterate faster than rule writers can respond, and a persistent industry-wide shortage of senior investigation talent.<br \/>The next fundamental shift is already happening in production environments: the Agentic SOC. In this model, purpose-built AI agents autonomously handle alert triage, investigation enrichment, evidence correlation, and initial containment actions. This frees human analysts to focus exclusively on high-judgment decisions, complex threat hunting, and strategic improvements. This is not a vendor roadmap or future speculation. These capabilities are live today inside mature Managed Detection and Response practices.<br \/>In this practitioner-led session, I will share a real-world account of leading this transition as Head of Managed Detection and Response at Sopra Steria North America. I will discuss the architectural decisions required to layer agentic capabilities onto existing SIEM and SOAR infrastructure, the tooling trade-offs we evaluated, integration challenges, and the operational realities that rarely appear in marketing presentations. Topics will include how to define clear human-machine handoff points, how to maintain governance and auditability when agents take autonomous action, and how to measure success beyond simple alert reduction metrics.<br \/>Attendees will gain a practical understanding of what the agentic layer looks like in daily MDR operations, including real examples of agents performing initial incident scoping and enrichment while escalating only high-fidelity cases to analysts. The talk will also address the risks, failure modes, and current limitations of agentic systems, providing an honest view of where human expertise remains irreplaceable.<\/p><p>Key takeaways for attendees:<\/p><ul><li>A practical framework for evaluating AI agent maturity across SOC and MDR workflows<\/li><li>Clear decision criteria to guide the transition from Detection-as-Code to agentic operations<\/li><li>An honest assessment of current technical and operational boundaries, including what agentic SOC cannot yet handle reliably<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-da84cca elementor-widget elementor-widget-heading\" data-id=\"da84cca\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1e391a3f elementor-widget elementor-widget-text-editor\" data-id=\"1e391a3f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Pierre Collard (CISSP \/ CCIE) is the Head of Detection &amp; Response for Sopra Steria North America. He leads the teams responsible for threat detection, incident response, and security operations for enterprise and public sector clients across Canada and the USA. Prior to Sopra Steria, Pierre held technical security leadership roles at AWS, where he worked with federal government agencies and the Department of National Defense (DND). Over his career, he has built and scaled security operations programs in complex, highly regulated environments. This includes developing intelligence-driven detection capabilities and leading incident response for major incidents. His focus has been on moving organizations from reactive security postures to structured, proactive detection and response programs.<br \/>In the past two years, Pierre has focused on integrating AI into SOC and MDR workflows. He currently leads the development and deployment of agentic capabilities in production environments, while also advising clients on AI risk management and governance.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5501d317 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"5501d317\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-11228326 e-con-full e-flex e-con e-child\" data-id=\"11228326\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4ea14469 elementor-widget elementor-widget-image\" data-id=\"4ea14469\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/luke-rr4iwrw5azkiipbirb7vp1fa7pnmn0yx34ryxvh64k.png\" title=\"luke\" alt=\"luke\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b9dbd4 elementor-widget elementor-widget-heading\" data-id=\"4b9dbd4\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Luke Jennings<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-140de015 elementor-widget elementor-widget-heading\" data-id=\"140de015\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Authorization phishing: phishing, but without the creds<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7dbba1e9 elementor-widget elementor-widget-text-editor\" data-id=\"7dbba1e9\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<div class=\"gs\"><div class=\"\"><div id=\":3vb\" class=\"ii gt adO\"><div id=\":3vc\" class=\"a3s aiL \"><div dir=\"ltr\"><p>Credential phishing used to be simple: trick a victim into typing their password into a fake login page, then reuse it later. Then we introduced MFA, so a password alone was no longer enough. Attackers responded with real-time proxies to steal valid sessions via Attacker-in-the-Middle (AITM) phishing. Then we began deploying passkeys, the \u00ab\u00a0unphishable\u00a0\u00bb authentication factor, and attackers responded with MFA downgrade attacks to compromise weaker backup methods still tied to the account.<\/p><p>But what if attackers could convince their targets to grant access to their accounts without ever touching their credentials? And what if it didn&rsquo;t matter whether the victim had MFA, or even passkeys, because the login was never the target at all? Each defensive advance has simply pushed attackers to a softer part of the same system, and authorization is the latest to come under pressure.<\/p><p>Authorization phishing is a growing class of attack that abuses OAuth authorization flows rather than authentication. The growing umbrella includes techniques like consent phishing, device code phishing, and ConsentFix. These are being mass-adopted by attackers as authentication controls mature and passkey adoption accelerates, giving attackers a technical advantage as well as a human one. Victims and defenders alike are far less familiar with these flows than with a fake login page, so the usual instincts and warning signs don&rsquo;t fire. In particular, device code phishing has exploded from tiny volumes to a tier-1 threat in early 2026, while ConsentFix was newly discovered in late 2025 following a Russia-linked campaign. These attacks remain unfamiliar territory for most defenders, and the techniques are still evolving quickly.<\/p><p>This talk will cover the history that led us to this point, technical details and live demos of every attack, in-the-wild examples, and practical guidance on how organizations can prevent and detect them.<\/p><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3b45a668 elementor-widget elementor-widget-heading\" data-id=\"3b45a668\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5440a4e9 elementor-widget elementor-widget-text-editor\" data-id=\"5440a4e9\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Luke Jennings is a security researcher from the UK. He spent most of his early career focused on red teaming and offensive security research. This included releasing the popular open-source tool Incognito, for manipulating Windows access tokens for post-exploitation in Active Directory environments, which went on to be integrated into Metasploit&rsquo;s Meterpreter implant.\u00a0He later moved on to developing new detection and response techniques and designing EDR software, spending many years detecting and responding to real-world attacks by drawing on his own knowledge of how to conduct them. That combination of offensive and defensive experience has shaped how he approaches research ever since.\u00a0He has now pivoted away from the endpoint to focus on browser and identity attacks as VP of R&amp;D at Push Security, and is the primary author and maintainer of the popular Browser and Identity Attacks matrix, a reference framework for the techniques used against browsers and identity systems.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-238de1f6 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"238de1f6\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-15129712 e-con-full e-flex e-con e-child\" data-id=\"15129712\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7662284b elementor-widget elementor-widget-image\" data-id=\"7662284b\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/aurora-rr4hweiyurs39w5g538kppu6pyxbsnktr40lffekw4.png\" title=\"aurora\" alt=\"aurora\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2cc68617 elementor-widget elementor-widget-heading\" data-id=\"2cc68617\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Victor Aurora<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-601e7706 elementor-widget elementor-widget-heading\" data-id=\"601e7706\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Automatiser un test d'intrusion avec un LLM local : jusqu'o\u00f9 peut-on aller sans le cloud ?<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3a822574 elementor-widget elementor-widget-text-editor\" data-id=\"3a822574\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Les outils de test d&rsquo;intrusion reposant sur des agents IA, comme CAI, obtiennent aujourd&rsquo;hui des r\u00e9sultats remarquables. Ces frameworks r\u00e9partissent le travail entre plusieurs agents sp\u00e9cialis\u00e9s, chacun responsable d&rsquo;une \u00e9tape du test : reconnaissance, cartographie des services, recherche de vuln\u00e9rabilit\u00e9s, puis exploitation. Leur fonctionnement d\u00e9pend toutefois presque toujours des mod\u00e8les de langage les plus puissants, accessibles uniquement dans le cloud.<\/p><p>Cette d\u00e9pendance pose un probl\u00e8me concret dans de nombreuses organisations. Confier un test d&rsquo;intrusion \u00e0 un service externe suppose de lui transmettre des informations sensibles sur l&rsquo;infrastructure cibl\u00e9e, ce que la confidentialit\u00e9 des donn\u00e9es, les obligations r\u00e9glementaires ou les environnements isol\u00e9s du r\u00e9seau interdisent souvent. La question centrale de cette pr\u00e9sentation est donc la suivante : peut-on ex\u00e9cuter ces outils enti\u00e8rement en local, sur des LLM plus modestes que l&rsquo;on h\u00e9berge soi-m\u00eame ?<\/p><p>La difficult\u00e9 ne vient pas d&rsquo;un manque de connaissances de ces mod\u00e8les. Sur le papier, ils ma\u00eetrisent les techniques et les outils. Le probl\u00e8me se situe dans leur fiabilit\u00e9 une fois lanc\u00e9s sur un test complet, qui s&rsquo;\u00e9tend sur de nombreuses \u00e9tapes. Ils produisent des r\u00e9sultats erron\u00e9s, perdent le fil des informations d\u00e9j\u00e0 collect\u00e9es, r\u00e9p\u00e8tent les m\u00eames actions sans progresser et signalent des vuln\u00e9rabilit\u00e9s qui n&rsquo;existent pas. Plus le test est long, plus ces erreurs s&rsquo;accumulent.<\/p><p>L&rsquo;approche pr\u00e9sent\u00e9e ne cherche pas \u00e0 obtenir un mod\u00e8le plus performant, mais \u00e0 encadrer un mod\u00e8le limit\u00e9. Elle ajoute autour de lui une couche de contr\u00f4le qui v\u00e9rifie la coh\u00e9rence des actions propos\u00e9es avant leur ex\u00e9cution, conserve un \u00e9tat fiable de la progression du test, et rep\u00e8re les comportements r\u00e9p\u00e9titifs ou improductifs pour les interrompre.<\/p><p>L&rsquo;objectif n&rsquo;est pas de pr\u00e9senter une solution d\u00e9finitive. Il s&rsquo;agit d&rsquo;\u00e9tablir un constat mesur\u00e9 et honn\u00eate : ce qui fonctionne, ce qui \u00e9choue encore, et la distance qui s\u00e9pare aujourd&rsquo;hui un LLM local d&rsquo;un outil de test r\u00e9ellement fiable et utilisable en conditions r\u00e9elles.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1684949d elementor-widget elementor-widget-heading\" data-id=\"1684949d\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-27cdb0aa elementor-widget elementor-widget-text-editor\" data-id=\"27cdb0aa\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Je suis Lead Pentester chez Act Digital Canada, o\u00f9 je dirige des mandats de tests d&rsquo;intrusion et d&rsquo;audits de s\u00e9curit\u00e9 pour des clients de divers secteurs. Au cours de ma carri\u00e8re, j&rsquo;ai r\u00e9alis\u00e9 plus de 200 tests d&rsquo;intrusion dans des environnements vari\u00e9s (web, externe, interne, Wi-Fi, cloud, physique\u2026). Titulaire d&rsquo;une ma\u00eetrise (M. Sc. A.) en cybers\u00e9curit\u00e9 de Polytechnique Montr\u00e9al et d&rsquo;un dipl\u00f4me d&rsquo;ing\u00e9nieur en informatique (France), j&rsquo;ai men\u00e9 des travaux de recherche durant ma ma\u00eetrise portant sur la classification automatique de cyberattaques. Ces travaux ont men\u00e9 \u00e0 la publication d&rsquo;un article scientifique, \u00ab\u00a0Unsupervised Clustering of Honeypot Attacks by Deep HTTP Packet Inspection\u00a0\u00bb, accept\u00e9 dans les actes de la conf\u00e9rence FPS 2023. J&rsquo;ai \u00e9galement \u00e9t\u00e9 responsable d&rsquo;un cours de ma\u00eetrise \u00e0 Polytechnique Montr\u00e9al portant exclusivement sur les tests d&rsquo;intrusion, o\u00f9 j&rsquo;assurais l&rsquo;ensemble de la charge de cours (conception du contenu, enseignement et \u00e9valuation). Je d\u00e9tiens par ailleurs les certifications suivantes :<\/p><div class=\"card mb-3 speaker-card\"><div class=\"card-body\"><div class=\"card-text speaker-detail\"><ul><li>OSCP (Offensive Security Certified Professional)<\/li><li>CRTO (Certified Red Team Operator)<\/li><li>AWS Certified Security \u2013 Specialty<\/li><li>AWS Certified Solutions Architect \u2013 Associate<\/li><li>AWS Certified Cloud Practitioner<\/li><\/ul><\/div><\/div><\/div><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-45534d43 elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"45534d43\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-2782bcd7 e-con-full e-flex e-con e-child\" data-id=\"2782bcd7\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e513dbc elementor-widget elementor-widget-image\" data-id=\"e513dbc\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/bsidesmtl.ca\/wp-content\/uploads\/elementor\/thumbs\/freddy-rr5cbcqs32onp9oaedz99ese8i1ybmgeym2qv7wsp0.png\" title=\"freddy\" alt=\"freddy\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-66920e42 elementor-widget elementor-widget-heading\" data-id=\"66920e42\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Francis Venne<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2671c229 elementor-widget elementor-widget-heading\" data-id=\"2671c229\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">S\u00e9curit\u00e9 physique - Une approche purple<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-39220d8 elementor-widget elementor-widget-text-editor\" data-id=\"39220d8\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<div class=\"gs\"><div class=\"\"><div id=\":3vb\" class=\"ii gt adO\"><div id=\":3vc\" class=\"a3s aiL \"><div dir=\"ltr\"><p>La s\u00e9curit\u00e9 physique est un \u00e9l\u00e9ment qui se retrouve parfois dans la cour des \u00e9quipes TI puisqu&rsquo;elles sont responsable des audits et de l&rsquo;achat de mat\u00e9riel. Malheureusement, j&rsquo;ai souvent remarqu\u00e9 que les \u00e9quipes internes n\u2019avaient pas les connaissances minimales pour s\u00e9curiser leurs sites et prot\u00e9ger ad\u00e9quatement les actifs de leur entreprise. C\u2019est aussi un volet qui est peu document\u00e9 dans les certifications et les programmes d\u2019\u00e9tudes en informatique\/cybers\u00e9curit\u00e9. Plut\u00f4t que de surfer sur ce faux sentiment de s\u00e9curit\u00e9 ou d\u2019assumer que c\u2019est la job de quelqu\u2019un d\u2019autre, je vous propose une approche orient\u00e9e \u00ab purple team \u00bb afin de gagner en comp\u00e9tence tout en utilisant les ressources \u00e0 votre disposition. Apr\u00e8s tout, lorsque l&rsquo;\u00e9quipe rouge et l&rsquo;\u00e9quipe bleu travaillent en silo, les \u00e9carts deviennent des chemins d&rsquo;attaque pour les acteurs de la menace.\u00a0Les personnes aux \u00e9tudes et les membres d\u2019\u00e9quipes bleues vont pouvoir jeter un \u0153il sur les techniques de contournement de l\u2019\u00e9quipe rouge. Les pentesters applicatifs vont peut-\u00eatre gagner la fibre pour les intrusions physique.<\/p><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6d58bbed elementor-widget elementor-widget-heading\" data-id=\"6d58bbed\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Bio<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5f54bfc0 elementor-widget elementor-widget-text-editor\" data-id=\"5f54bfc0\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Actuellement responsable de la s\u00e9curit\u00e9 informatique (RSI) pour le groupe Wepoint Canada, je cumule plus de 13 ans dans le domaine des TI. Mon travail consiste principalement \u00e0 identifier et mitiger les risques pour mon entreprise et les clients que nous desservons.\u00a0Initialement du monde du d\u00e9veloppement logiciel, j\u2019ai fait le saut vers la s\u00e9curit\u00e9 applicative en m\u00eame temps de poursuivre mes \u00e9tudes universitaires en cybers\u00e9curit\u00e9 \u00e0 l\u2019\u00c9cole Polytechnique de Montr\u00e9al. Je suis actuellement \u00e9tudiant \u00e0 la ma\u00eetrise en informatique option cybers\u00e9curit\u00e9 \u00e0 l\u2019Universit\u00e9 de Sherbrooke.\u00a0Curieux de nature et convaincu que l&rsquo;apprentissage est un processus continu, je m\u2019efforce d\u2019explorer la s\u00e9curit\u00e9 sous toutes ses formes. C&rsquo;est d&rsquo;abord le crochetage de serrures qui m&rsquo;a fait r\u00e9aliser qu&rsquo;un m\u00e9canisme de s\u00e9curit\u00e9 physique n&rsquo;est pas toujours aussi robuste qu&rsquo;on le croit.\u00a0Je participe souvent comme spectateur aux diff\u00e9rentes conf\u00e9rences de la province, mais il s\u2019agit de ma premi\u00e8re fois \u00e0 titre de conf\u00e9rencier \u00e0 vie.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-60b802fc elementor-widget-divider--view-line_icon elementor-view-default elementor-widget-divider--element-align-center elementor-widget elementor-widget-divider\" data-id=\"60b802fc\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon elementor-divider__element\">\n\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-far-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8zm0 448c-110.5 0-200-89.5-200-200S145.5 56 256 56s200 89.5 200 200-89.5 200-200 200z\"><\/path><\/svg><\/div>\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5d03e0ae e-flex e-con-boxed e-con e-parent\" data-id=\"5d03e0ae\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6d043030 elementor-widget elementor-widget-heading\" data-id=\"6d043030\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Comit\u00e9 scientifique<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-55e8bafa elementor-widget elementor-widget-text-editor\" data-id=\"55e8bafa\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<pre><span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>Alain Yamin | Priv\u00e9<br>Alex Bouffard | Flare<br>Hugo Genesse | GE Vernova<\/b><\/span><\/span><\/span>\n<span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>Matthieu Faou | ESET<br>Michael Joyce | Universit\u00e9 de Montr\u00e9al<\/b><\/span><\/span><\/span>\n<span style=\"color: #244084;\"><span style=\"font-family: Montserrat, serif;\"><span style=\"font-size: small;\"><b>Pierre-Marc Bureau | Sabbatique<br>Thierry Marier-Bienvenue | Desjardins<\/b><\/span><\/span><\/span>\n<\/pre>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>2026 Horaire | 19 Septembre | Biblioth\u00e8que et Archives nationales du Qu\u00e9bec 8:30AM | Ouverture des portes &#8211; d\u00e9jeuner et caf\u00e9 servis \u00a0 9:00AM \u2013 9:05AM | Mot d&rsquo;ouverture \u00a0 9:05AM \u2013 9:30AM | Authorization phishing: phishing, but without the creds Luke Jennings \u00a0 9:30AM &#8211; 9:55AM | 2,000 Packages Later: What Continuous npm Scanning [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","footnotes":""},"class_list":["post-864","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/pages\/864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/comments?post=864"}],"version-history":[{"count":6,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/pages\/864\/revisions"}],"predecessor-version":[{"id":906,"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/pages\/864\/revisions\/906"}],"wp:attachment":[{"href":"https:\/\/bsidesmtl.ca\/fr\/wp-json\/wp\/v2\/media?parent=864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}