{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.1.2"}, "schedule": {"url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/schedule/", "version": "0.6", "base_url": "https://cfp.bsidesfrankfurt.org", "conference": {"acronym": "call-for-paper-presentations-2026", "title": "Call For Paper - Presentations", "start": "2026-09-10", "end": "2026-09-10", "daysCount": 1, "timeslot_duration": "00:05", "time_zone_name": "Europe/Berlin", "colors": {"primary": "#454747"}, "rooms": [{"name": "Gro\u00dfer Saal", "slug": "1-groer-saal", "guid": "0991b703-0b77-5b23-a0ca-abfbae39950f", "description": "1 OG to the right", "capacity": 200}], "tracks": [{"name": "Main Track", "slug": "1-main-track", "color": "#2e3d41"}], "days": [{"index": 1, "date": "2026-09-10", "day_start": "2026-09-10T04:00:00+02:00", "day_end": "2026-09-11T03:59:00+02:00", "rooms": {"Gro\u00dfer Saal": [{"guid": "3418d1a3-c38b-5b7a-874b-5b05815aad7c", "code": "ZTPWJS", "id": 108, "logo": null, "date": "2026-09-10T09:20:00+02:00", "start": "09:20", "duration": "00:10", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-108-intro", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZTPWJS/", "title": "Intro", "subtitle": "", "track": "Main Track", "type": "Short-Talk", "language": "en", "abstract": "Intro", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZTPWJS/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZTPWJS/", "attachments": []}, {"guid": "4a64a37e-a20d-5f97-998a-c07727755fdb", "code": "7ZNYWP", "id": 106, "logo": null, "date": "2026-09-10T09:30:00+02:00", "start": "09:30", "duration": "00:40", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-106-keynote-jorn-schneeweisz", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/7ZNYWP/", "title": "Keynote (J\u00f6rn Schneeweisz)", "subtitle": "", "track": "Main Track", "type": "Talk", "language": "en", "abstract": "Keynote", "description": "J\u00f6rn Schneeweisz is a Principal Security Engineer at GitLab who managed to turn a decade of breaking other people's broken Ruby on Rails code into a legitimate corporate career, because apparently, getting paid to tell companies how bad their security is qualifies as a real job.", "recording_license": "", "do_not_record": false, "persons": [{"code": "TJKWGD", "name": "Joernchen", "avatar": null, "biography": null, "public_name": "Joernchen", "guid": "549fb959-5263-56dc-9481-8ae72ae0cf9b", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/speaker/TJKWGD/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/7ZNYWP/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/7ZNYWP/", "attachments": []}, {"guid": "638e15d9-dfb7-56b1-82be-7f5437359dbd", "code": "KVLR3V", "id": 100, "logo": null, "date": "2026-09-10T10:10:00+02:00", "start": "10:10", "duration": "00:55", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-100-welcome-to-hybrid-hell-breaking-entrpise-identity-beyond-active-directory", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/KVLR3V/", "title": "Welcome to Hybrid Hell - Breaking Entrpise Identity beyond Active Directory", "subtitle": "", "track": "Main Track", "type": "Talk", "language": "en", "abstract": "Enterprise identity has fundamentally changed.\r\n\r\nLarge organisations no longer rely on a single identity system. Instead, Active Directory, Microsoft Entra ID, Azure, Microsoft 365, SaaS applications, identity synchronisation, third-party identity providers and cross-tenant trust relationships have evolved into a single interconnected identity architecture.\r\n\r\nUnfortunately, attackers don\u2019t think in terms of \u201con-premises\u201d or \u201ccloud.\u201d They follow trust relationships.\r\n\r\nWhile organisations often assess Active Directory and cloud environments separately, the most valuable attack paths increasingly exist between them. Hybrid identity, multi-forests, multiple Entra ID tenants, synchronisation services, service principals, managed identities and delegated administration all contribute to an enterprise identity attack surface that is significantly larger, and far less understood, than many organisations realise.\r\n\r\nThis session explores enterprise identity architecture from an attacker\u2019s perspective. Rather than focusing on individual attack techniques, it examines how identity systems interact, where trust boundaries actually exist, and how seemingly isolated weaknesses can be chained together across on-premises and cloud environments.\r\n\r\nAttendees will leave with a practical approach to identifying enterprise identity attack paths, defining realistic assessment scopes, and understanding why the biggest identity risks often exist in the connections between systems,not the systems themselves.", "description": "Enterprise identity is no longer defined by a single directory service. Modern organisations operate complex identity architectures spanning Active Directory, Microsoft Entra ID, Azure, Microsoft 365, SaaS platforms, synchronisation services, multiple identity providers and increasingly multiple business units, subsidiaries and cloud tenants. Every integration introduces new trust relationships. Every trust relationship introduces new attack paths.\r\n\r\nThis session approaches enterprise identity from the perspective that matters most during an assessment: the attacker\u2019s.\r\n\r\nRather than presenting a catalogue of Active Directory or Entra ID attack techniques, the talk focuses on how modern enterprise identity is constructed, why traditional assessment methodologies frequently fail to capture the complete attack surface, and how attackers move across identity boundaries by abusing trust instead of exploiting individual technologies.\r\n\r\nUsing realistic enterprise architectures, practical demonstrations and real-world attack scenarios, the session examines common challenges encountered during offensive security engagements, including hybrid identity deployments, synchronisation, multi-forest environments, multiple Entra ID tenants, delegated administration, identity trust relationships and assessment scoping. The audience will see how architectural decisions influence attack paths, why trust relationships become the true security boundary, and how weaknesses in one part of the identity architecture can create unexpected consequences elsewhere.\r\n\r\nThe presentation concludes with a practical framework for mapping enterprise identity architecture from an attacker\u2019s perspective, enabling security teams to define more realistic assessment scopes, prioritise the trust relationships that matter most, and better understand how identity has become one of the largest and least visible enterprise attack surfaces.\r\n\r\nKey takeaways\r\n\r\n* Understand how enterprise identity has evolved beyond a single directory service.\r\n* Learn why attackers focus on trust relationships rather than technology boundaries.\r\n* Identify common architectural patterns that expand the enterprise identity attack surface.\r\n* Recognise the challenges of scoping and assessing complex hybrid identity environments.\r\n* Apply an attacker-focused methodology for analysing enterprise identity architecture and prioritising risk.", "recording_license": "", "do_not_record": false, "persons": [{"code": "WLCTVY", "name": "georg", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/WLCTVY_FTZsXiv.PNG", "biography": "Georg Heise is a Senior Offensive Security Consultant and security researcher at Lufthansa Industry Solutions, specialising in enterprise offensive security, identity security and AI-driven security research. His work focuses on helping large organisations understand and assess complex enterprise environments, ranging from Active Directory and Microsoft Entra ID to modern AI systems and autonomous security agents.\r\n\r\nAlongside his role at Lufthansa Industry Solutions, Georg serves as a strategic advisor to the shareholders of an international logistics and holding group, advising on information security, digitalisation and technology strategy across a diverse portfolio of companies. This combination of hands-on offensive security and strategic advisory work provides a unique perspective on the challenges faced by large enterprise environments.\r\n\r\nOver the past decade, Georg has led and contributed to hundreds of security assessments, including Active Directory, cloud, web application and Red Team engagements for Fortune 500 companies, government organisations and operators of critical infrastructure. His current research focuses on enterprise identity architecture, AI-assisted offensive security and autonomous security agents. He regularly shares his research through conference talks, technical publications and open-source projects.\r\n\r\nBorn in Germany with Australian roots, Georg studied, worked and completed two university degrees in Australia before returning to Europe. His goal is to bridge the gap between enterprise offensive security and the next generation of AI-powered security tooling, helping organisations prepare for an attacker that is becoming increasingly autonomous.", "public_name": "georg", "guid": "ab8cff7a-d5f2-5169-91de-0d8129cd1637", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/speaker/WLCTVY/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/KVLR3V/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/KVLR3V/", "attachments": []}, {"guid": "af22faf4-606b-50bc-bfcf-27921ee84f73", "code": "QDB7NB", "id": 25, "logo": null, "date": "2026-09-10T11:05:00+02:00", "start": "11:05", "duration": "00:55", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-25-what-windows-11-remembers-and-most-investigators-miss", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/QDB7NB/", "title": "What Windows 11 Remembers (And Most Investigators Miss)", "subtitle": "", "track": "Main Track", "type": "Talk", "language": "en", "abstract": "Every Windows release quietly introduces new places where the operating system writes things down, and Windows 11 is no exception. While most DFIR playbooks still lean on the same artifacts we've relied on for a decade, the modern Windows stack has been busy generating evidence in places few investigators routinely check. Timelines end up with gaps that didn't need to be there, and execution evidence sits untouched on disk.\r\n\r\nDrawing on recurring patterns across hundreds of Windows 11 investigations, this talk maps the evidence surface that standard triage misses. We'll spend time with Recall and the near-continuous record it keeps of user activity on Copilot+ devices, follow the SMS and call history that Phone Link pulls from paired Android phones onto the Windows host, and read through Copilot conversations where user intent is often spelled out in plain English. From there we'll move into the secondary telemetry channels that keep writing long after Event Logs are cleared.\r\n\r\nFor each artifact, we'll cover where it lives, what it records, how long it persists, and the common misreadings that lead investigators astray. Attendees will leave with a mental model for where Windows 11 records user activity outside the classic artifact set, a working understanding of how to parse each source, and a feel for the interpretation pitfalls that matter most at triage time.", "description": "", "recording_license": "", "do_not_record": true, "persons": [{"code": "XJ8C7D", "name": "Maurice Fielenbach", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/XJ8C7D_Tw45U4A.jpg", "biography": "With over 10 years of experience in cybersecurity, Maurice Fielenbach started on the offensive side before moving into defensive security. He has worked hundreds of cyber investigations, including major ransomware and APT cases across industries affecting millions of people. Among them was one of the largest ransomware incidents in German history, targeting a communal IT service provider and disrupting public infrastructure at scale.\r\n\r\nToday he focuses primarily on threat intelligence and malware analysis. He is the founder of Hexastrike Cybersecurity, where he trains blue teams in digital forensics, malware analysis, and threat hunting through hands-on, scenario-driven sessions built from real incidents.\r\n\r\nHis research is regularly featured in leading cybersecurity publications and cited by industry peers. He speaks at security conferences and contributes open-source tooling and detection content used by security teams worldwide.", "public_name": "Maurice Fielenbach", "guid": "e078cedc-50a0-5cc2-9057-4b13f1f729dc", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/speaker/XJ8C7D/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/QDB7NB/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/QDB7NB/", "attachments": []}, {"guid": "d3e6975b-d68b-5956-a157-91fe048a66af", "code": "AXSXQW", "id": 27, "logo": "https://cfp.bsidesfrankfurt.org/media/call-for-paper-presentations-2026/submissions/AXSXQW/image_zIXnT09.webp", "date": "2026-09-10T13:00:00+02:00", "start": "13:00", "duration": "00:55", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-27-hacking-consumer-drones-from-flash-dumping-to-root-exploits", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/AXSXQW/", "title": "Hacking Consumer Drones: From Flash Dumping to Root Exploits", "subtitle": "", "track": "Main Track", "type": "Talk", "language": "en", "abstract": "Hacking the Potensic Atom 2 consumer drone, including a full walkthrough of the process of disassembling the drone, dumping the firmware, reverse-engineering its long-range RF control protocol, finding vulnerabilities, and exploiting them to take over the drone remotely.", "description": "This talk tracks an IT security researcher\u2019s journey through the process of disassembling, dumping and exploiting the Potensic Atom 2 consumer drone. We\u2019ll follow the full lifecycle of a hardware exploit: Starting with low-level chip identification and flash desoldering, we make a detour into recovering heavily corrupted flash firmware by reverse engineering error correction codes.\r\n\r\nFrom there, we pivot to the software, reverse-engineering the binary firmware to uncover hidden backdoors in the drone's control protocol. Ending with a presentation of a custom exploit designed to hijack the drone and gain full root access. Whether you're interested in hardware RE or binary exploitation, this is a fast-paced look at every stage of the IoT research process.", "recording_license": "", "do_not_record": false, "persons": [{"code": "FSEHLJ", "name": "Tim Schmidt", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/FSEHLJ_IO25ouI.jpg", "biography": "Tim Schmidt is an IT security researcher and penetration tester at Neodyme AG with over a decade of experience in competitive Capture The Flag (CTF) environments. While his core expertise lies in web and application penetration testing, his technical background also spans IoT and embedded reverse engineering and smart contract audits. An avid builder, Tim frequently develops software projects and custom IoT appliances from scratch in his free time.\r\n\r\nAs an educator, he has delivered specialized trainings on modern authentication technologies and cryptographic attacks for corporate clients in Germany and at international security conferences, such as HITB Amsterdam.", "public_name": "Tim Schmidt", "guid": "52e4a53c-f0e7-52eb-a75a-2797b5ea3907", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/speaker/FSEHLJ/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/AXSXQW/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/AXSXQW/", "attachments": []}, {"guid": "71749803-b166-5515-b5eb-44d927cc1085", "code": "ZETL7P", "id": 74, "logo": null, "date": "2026-09-10T14:00:00+02:00", "start": "14:00", "duration": "00:55", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-74-deconstructing-modern-macos-initial-access-vectors", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZETL7P/", "title": "Deconstructing Modern macOS Initial Access Vectors", "subtitle": "", "track": "Main Track", "type": "Talk", "language": "en", "abstract": "For years, a persistent myth suggested that macOS was inherently immune to malware. Today, threat actors are aggressively shattering that illusion by deploying sophisticated initial access chains tailored to bypass macOS defenses. This talk provides a deep-dive analysis of how modern adversaries gain their first foothold on Apple hardware.\r\n\r\nWe will dissect the entire initial access pipeline, starting with Infection Vectors like deceptive Google Ads, malicious ClickFix campaigns, and sophisticated malvertising that trick users into lowering their guard. From there, we explore the Execution Phase, analyzing how attackers weaponize scripting languages, including traditional Bash and Python, as well as native AppleScript, Compiled AppleScript, Perl, and JavaScript for Automation (JXA). Finally, we will examine the delivery mechanisms, contrasting the abuse of native Binaries (Mach-O, Platypus-packaged apps, and Electron frameworks) with the trojanization of Storage and Installer Formats (DMGs and PKGs).\r\n\r\nAttendees will walk away with a technical understanding of contemporary macOS tradecraft, real-world attacker methodologies, and the insights needed to hunt for and defend against modern Mac-focused threats.", "description": "We begin by exploring the top of the funnel. Attackers have moved far beyond easily identifiable spam. We will deconstruct recent campaigns to show how adversaries are successfully lowering user guard through:\r\n\r\nHow threat actors weaponize Google Ads to push malicious software disguised as legitimate enterprise tools (e.g., Slack, Notion, or VPN clients).\r\nA deep dive into localized, highly convincing fake browser updates and system notification campaigns that socially engineer users into bypassing native warnings.\r\n\r\nOnce the user interacts with the lure, how does the malware actually run? macOS is a rich Unix-based environment with multiple scripting avenues. We will analyze the \"Living off the Land\" (LotL) techniques currently dominating the macOS threat landscape, including:\r\n\r\nThe use of Bash, Zsh, and legacy Python/Perl scripts to establish persistence and pull down secondary payloads.\r\nHow attackers weaponize Apple\u2019s native automation languages to silently interact with system APIs, bypass sandbox restrictions, and generate convincing fake credential prompts.\r\nTechniques used by threat actors to obfuscate their code, making static analysis incredibly difficult for defenders.\r\n\r\nFinally, we will break down how these threats are packaged to evade Gatekeeper and initial static analysis. We will compare and contrast real-world samples across:\r\n\r\nThe weaponization of standard Apple Disk Images (.dmg) and Installer Packages (.pkg), including pre-install/post-install script abuse.\r\nThe shift from standalone Mach-O binaries to hiding malicious routines inside Platypus-packaged applications and bloated Electron frameworks, which are notoriously difficult for traditional AV to parse effectively.", "recording_license": "", "do_not_record": false, "persons": [{"code": "ADZVWX", "name": "Stephan Berger", "avatar": null, "biography": "Stephan Berger is the Head of Investigations for an Incident Response team at InfoGuard, a Swiss-based cybersecurity firm. With over a decade of experience investigating complex network compromises, he specializes in the technical intersection of offensive tradecraft and defensive forensics. Stephan is the author of the DFIR.ch technical blog and is a regular speaker at international security conferences, including FIRST, Troopers, and hack.lu. He holds a Bachelor\u2019s degree in Computer Science and a Master\u2019s degree in Engineering and is the founder of Malmium, a specialized technical training provider.", "public_name": "Stephan Berger", "guid": "698cb298-5b68-5675-9e3e-3de45ac23fff", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/speaker/ADZVWX/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZETL7P/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZETL7P/", "attachments": []}, {"guid": "05e18fc1-b4c1-5cbd-9f5d-0a2868f65926", "code": "XPLEJW", "id": 15, "logo": null, "date": "2026-09-10T15:25:00+02:00", "start": "15:25", "duration": "00:55", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-15-lessons-learned-while-building-an-agentic-soc-the-good-the-bad-and-the-scary", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/XPLEJW/", "title": "Lessons learned while building an Agentic SOC: The good, the bad, and the scary.", "subtitle": "", "track": "Main Track", "type": "Talk", "language": "en", "abstract": "The AI powered SOC is coming whether you are ready or not, as attackers use AI to accelerate their operations we have to also go faster. Moving from a traditional SOC to an \"Agentic\" SOC is often pitched as a magic bullet for SOC automation, but because you can't stop your SOC sometimes the process feels like upgrading your engine while going 200 km/h on the Autobahn, and the upgrades you make are sometimes superseded the moment you add it. \r\n\r\nThis talk bypasses the AI hype to share the real internal journey at Elastic as we integrated AI agents and processes into our daily SecOps. I'll talk about the Agentic Boundary: the point where the agent stops and the human starts, the lessons learned when building the agents, and how to connect your data to the agents. I'll cover the 'good' where AI Agents are doing amazing things like L1 triage and timeline creation, the 'bad' where agents used a bunch of time and tokens to provide mediocre or wrong results, and some of the 'scary' such as how AI agents can turn on you to be the cause of a security incident instead of a helper. This talk will also address the scariest AI topic of them all: 'will this replace me?'", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "U7UVEJ", "name": "Aaron Jewitt", "avatar": null, "biography": "Aaron Jewitt is a Principal Detection Engineer on the Elastic Infosec team. A 20-year security veteran with 10 years of offensive experience at the NSA and 10 years of experience defending networks, he specializes in detection engineering and high-velocity automation. Aaron is currently leading internal efforts to integrate AI agents into daily SecOps. Aaron lives in Germany and is a two-time speaker at BSides Frankfurt, dedicated to sharing practical, real-world lessons from the front lines of defense.", "public_name": "Aaron Jewitt", "guid": "4c7d669f-e3f5-570d-85c3-7ac4bbf773b1", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/speaker/U7UVEJ/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/XPLEJW/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/XPLEJW/", "attachments": []}, {"guid": "2f5ba4ab-2c20-550e-b09a-f5bdd9cb1a6d", "code": "3WDFBK", "id": 72, "logo": null, "date": "2026-09-10T16:20:00+02:00", "start": "16:20", "duration": "00:25", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-72-keyless-entry-hacking-switchbot-smartlocks", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/3WDFBK/", "title": "Keyless Entry: Hacking SwitchBot Smartlocks", "subtitle": "", "track": "Main Track", "type": "Short-Talk", "language": "en", "abstract": "Smart locks are rapidly replacing physical keys, but trusting your front door to an IoT device still comes with significant risks. In this talk, we will dissect the highly rated SwitchBot Lock Pro and demonstrate how a classic cryptographic implementation flaw allowed anyone to silently unlock the door without an physical tampering. By reverse-engineering the firmware and analyzing the custom Bluetooth Low Energy (BLE) protocol between the outdoor keypad and the indoor actuator, we discovered the system relies on AES in Counter (CTR) mode with zero integrity checks. We will demonstrate how we exploited this to create a universal, software-only UNLOCK payload. Join us as we showcase the live exploit, break down the vendor's flawed patch, explain how backward compatibility significantly delayed the patch, and celebrate our massive 100\u20ac bug bounty.", "description": "While selecting targets for a team IoT hacking event, the SwitchBot Lock Pro Combo stood out: it is one of the most sold smart locks on the market, offering PIN, fingerprint, NFC, and app-based entry. The hardware consists of an indoor actuator that turns the physical key and an outdoor keypad. However, our initial recon of the Android app revealed, that the outdoor keypad holds the decision-making logic and sends execution commands to the indoor actuator over unprotected BLE, relying entirely on a custom application-layer encrypted protocol.\r\n\r\nDiving deeper into this custom protocol, we discovered a fatal cryptographic failure. The devices negotiate a secret key and a nonce, but they encrypt their commands using AES in Counter (CTR) mode. Because CTR mode turns a block cipher into a stream cipher and lacks any integrity protection (like a MAC), bit-flips in the ciphertext propagate directly to the plaintext upon decryption without an opportunity to detect the manipulation.\r\n\r\nIn this 30-minute presentation, we will walk the audience through how we weaponized this exact flaw. Because a keypad's LOCK button always broadcasts an encrypted command, an attacker only needs to sniff it. We will explain the math behind our \"master key\", which only required a pre-computed XOR between encrypted LOCK and UNLOCK commands that is identical across all sessions and locks. By simply applying this to any sniffed LOCK ciphertext, we can instantly forge a valid UNLOCK command and open the door. We will give a live demonstration of this software-only attack in action.\r\n\r\nFinally, we will detail our responsible disclosure journey, which serves as a perfect case study in the difficulties of patching IoT ecosystems. The vendor's initial beta patch attempted to add a 2-byte truncated MD5 \"YOLO hash\" for integrity verification. However, because updating the entire ecosystem takes time, the lock still had to accept legacy commands from the smartphone app. We will show how we trivially bypassed the new patch by simply spoofing the smartphone app, ignoring the checksum entirely.", "recording_license": "", "do_not_record": false, "persons": [{"code": "PHF9EW", "name": "Kolja Grassmann", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/PHF9EW_okx2Vza.png", "biography": "Kolja is a Security Researcher and Trainer at Neodyme. He specializes in Windows and Active Directory security. He has found vulnerabilities in widely used security products and has extensive exploit development, pentesting, and red teaming experience.", "public_name": "Kolja Grassmann", "guid": "236c9e83-b2d1-5fa9-a87c-13a88aea88ad", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/speaker/PHF9EW/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/3WDFBK/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/3WDFBK/", "attachments": []}, {"guid": "a2b5cbde-90ee-5ce2-b4ae-afa89d1843ca", "code": "ZCPUYM", "id": 43, "logo": null, "date": "2026-09-10T16:45:00+02:00", "start": "16:45", "duration": "00:55", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-43-pentesting-in-the-age-of-ai-where-are-we", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZCPUYM/", "title": "Pentesting in the age of AI - where are we?", "subtitle": "", "track": "Main Track", "type": "Talk", "language": "en", "abstract": "This talk focuses on the opportunities, limitations, and practical results of using AI in penetration testing.\r\n\r\nWe will compare different approaches to application security testing, including static and dynamic analysis, and examine where AI can provide value in each of them. In particular, we will look at several modes of AI-assisted security testing:\r\n\r\n* AI-driven source code analysis\r\n* AI-assisted verification of static analysis tool findings\r\n* AI-driven runtime analysis using custom scripts\r\n* AI-assisted verification of results from established security tools\r\n\r\nThe effectiveness of these approaches varies significantly depending on the selected method, model, tooling, and target environment.\r\n\r\nInstead of relying on idealized lab scenarios, this talk presents real-world results from practical security testing. Beyond classical web application penetration testing, an area where AI already performs comparatively well, we will also explore the use of AI in Active Directory and Windows environment exploitation.\r\n\r\nThe audience will leave with a realistic understanding of where AI can currently support penetration testers, where it still falls short, and which workflows are most promising in practice.", "description": "An AI agent for a few hundred euros doing the job of a highly skilled senior penetration tester? That sounds great. But are we actually there yet?\r\n\r\nThis talk explores different ways of using AI for static and dynamic security analysis. We will look at AI as the pentester, AI as an assistant for validating tool output, and AI as the convenient interface for people who are too lazy to read the manual.\r\n\r\nEvaluating the results of today\u2019s AI-based pentesting projects can feel familiar to anyone who has reviewed a junior tester\u2019s first report: some valid findings, some interesting ideas, some missing context, and a few confidently incorrect conclusions.\r\n\r\nSo what is the real issue? Is AI still not good enough, or is the person in front of the prompt part of the problem?\r\n\r\nFocusing on Static Application Security Testing and Dynamic Application Security Testing, this talk presents practical examples, real-world observations, and a sober assessment of where AI can support penetration testing today. We will discuss what works, what fails, and why blindly trusting AI-generated security results is still a bad idea.", "recording_license": "", "do_not_record": false, "persons": [{"code": "EH88J3", "name": "Christian Biehler", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/EH88J3_nIb9WVe.jpg", "biography": "With over a decade of experience in the field, Christian Biehler is a seasoned IT security expert who combines the perspectives of a hacker, penetration tester, consultant, and trainer. His technical focus lies in securing Windows infrastructures and the Microsoft Cloud stack, including Entra ID, Azure, and M365.\r\n\r\nChristian holds a Master\u2019s degree in IT Security and the CISSP certification. He has successfully delivered over 300 projects across diverse sectors, establishing deep expertise in security architecture, risk management, and penetration testing for web, mobile, and operating systems.\r\n\r\nSince 2019, Christian has been the Managing Director of bi-sec GmbH, leading a firm dedicated to expert consulting, rigorous penetration testing, and specialized security training.", "public_name": "Christian Biehler", "guid": "88340ebd-daf2-54c7-8f24-aeef57844183", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/speaker/EH88J3/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZCPUYM/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZCPUYM/", "attachments": []}, {"guid": "0324faf3-a98b-5f86-935e-8b2658dc855b", "code": "ELHBVZ", "id": 107, "logo": null, "date": "2026-09-10T17:40:00+02:00", "start": "17:40", "duration": "00:15", "room": "Gro\u00dfer Saal", "slug": "call-for-paper-presentations-2026-107-outro", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ELHBVZ/", "title": "Outro", "subtitle": "", "track": "Main Track", "type": "Short-Talk", "language": "en", "abstract": "Closing", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ELHBVZ/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ELHBVZ/", "attachments": []}]}}]}}}