/con_things

Public talks, rants, and other musings

Upcoming

Purple Hats 2023

You Want Us to Emulate What!?! (Agenda)

PH23

Past

RSAC Adversary Sandbox 2023

Dressing Adversary Emulation in Business Attire: Outcomes and Successes (Slides in /docs)

RSAC

Atomics on a Friday

APT29 Emulation Plan Part 1 (Video) and Part 2 (Video) w/ @burning_pm & @M_haggis

Atomics

Detection: Challenging Paradigms (DCP) Podcast

Episodes 24 (Video) and Episode 26 (Video) w/ @jaredcatkinson, @jsecurity101, & @v3r5ace

DCP

UNICON 2022

Should Your Red Team Really Care About Detection Data Sources? What ATT&CK Can Show Us…(Video)

UNICON

MITRE Engenuity Threat-Informed Defense User Conference

The Purple Elephant in the Room w/ Michael Long & Steve Luke (Video)

CTID_PURPLE

MITRE Engenuity Threat-Informed Defense User Conference

Sharing is Caring and Awkward Conversations That Bring Us Together w/ @FrankDuff (Video)

CTID_EVALS

Roundup by Wild West Hackin' Fest: Purple Team

A Look at ATT&CK Evaluations Through Purple Colored Glasses w/ @FrankDuff (Video)

WWHF

DEF CON 29 Adversary Village

Panel discussion: Is Adversary Emulation Too ___ For You? w/ @FrankDuff, Michael Long, @teschulz, @coolestcatiknow, & Jose Barajas (Video)

DC_PURPLE

SANS Purple Team Summit 2021

Which Came First: The Phish or the Opportunity to Defend Against It w/ @thecookiewanter (Video)

SANS_PRE

SANS CloudSecNext Summit 2021

Which way is the SolarWind Blowing? Techniques are changing…are you ready? w/ @stromcoffee (Video)

SANS_CLOUD

SANS Blueprint Podcast

Episode 20: Adversary Emulation w/ @SecHubb (Audio)

SANS_BP

MITRE ATT&CKcon Power Hour 2020

Putting the PRE into ATT&CK w/ @thecookiewanter (Video)

PRE

SANS Threat Hunting & IR Summit 2020

Started from the Bottom: Exploiting Data Sources to Uncover ATT&CK Behaviors w/ @Cyb3rPanda (Video)

SANS_THIR

GRIMMCon 0x2

Reaping What They Sow - Hard Lessons Learned Emulating Threat Actors (Video)

Grimm

Virtual SOURCE Boston 2020

Getting Bear-y Cozy with PowerShell: Defensive Lessons Learned from Emulating the Dukes w/ @thecookiewanter (Slides)

Cozy

BSidesLV 2019

ATT&CKing Your Adversaries -- Operationalizing cyber intelligence in your own environment for better sleep and a safer tomorrow w/ @sarah__yoder (Video)

BSLV

x33fcon 2019

APT ATT&CK - Threat-based Purple Teaming (Continued) w/ @d4weiss (Video)

X33f

SANS Blue Team Summit 2019

To Blue with ATT&CK-Flavored Love (Video)

SANS_Blue

BSides DC 2018

One technique, two techniques, red technique, blue technique w/ @d4weiss (Video)

BSDC