/talks_etc

List of some talks I've done and other "merit badges."

talks_etc

List of some talks I've done and other "merit badges."

Local talk about pentesting methodology in the cloud:

WebAuthN talk I gave at BSidesKC in 2021

Blog from a unique red team phishing engagement. Skewed a little towards a blue team successes, but still feels good to have your work be blogworthy

Ran an application security training class at BSidesKC 2021.

Ran an application security training class at KernelCon 2020 and 2021.

Assorted blog posts I have made. The one about reverse engineering an ATM skimmer I found was especially popular.

2018 local talk I presented about QubesOS

Tool I developed for Blackhat Arsenal 2017. Simple premise and design, but the tool is actually pretty popular.

Tool I helped develop for Blackhat Arsenal 2015. The idea was decent, but the tool is a huge memory hog.

Couple of small potatoes CVEs that aren't worth bragging about:

  • CVE-2017-17698 : Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec
  • CVE-2016-9274 : Vulnerability Discovered in Git Bash for Windows

Certs:

  • Offensive Security Certified Professional (OSCP) : Issued Oct 2018
  • AWS Certified Security – Specialty : Issued Apr 2021
  • CREST Practitioner Security Analyst (CPSA) : Issued Feb 2020
  • CREST Registered Penetration Tester : Issued Feb 2020