<?xml version='1.0' encoding='utf-8' ?>
<iCalendar xmlns:pentabarf='http://pentabarf.org' xmlns:xCal='urn:ietf:params:xml:ns:xcal'>
    <vcalendar>
        <version>2.0</version>
        <prodid>-//Pentabarf//Schedule//EN</prodid>
        <x-wr-caldesc></x-wr-caldesc>
        <x-wr-calname></x-wr-calname>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>ZTPWJS@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-ZTPWJS</pentabarf:event-slug>
            <pentabarf:title>Intro</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T092000</dtstart>
            <dtend>20260910T093000</dtend>
            <duration>001000</duration>
            <summary>Intro</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Short-Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZTPWJS/</url>
            <location>Großer Saal</location>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7ZNYWP@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-7ZNYWP</pentabarf:event-slug>
            <pentabarf:title>Keynote (Jörn Schneeweisz)</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T093000</dtstart>
            <dtend>20260910T101000</dtend>
            <duration>004000</duration>
            <summary>Keynote (Jörn Schneeweisz)</summary>
            <description>Jörn Schneeweisz is a Principal Security Engineer at GitLab who managed to turn a decade of breaking other people&#x27;s broken Ruby on Rails code into a legitimate corporate career, because apparently, getting paid to tell companies how bad their security is qualifies as a real job.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/7ZNYWP/</url>
            <location>Großer Saal</location>
            
            <attendee>Joernchen</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>KVLR3V@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-KVLR3V</pentabarf:event-slug>
            <pentabarf:title>Welcome to Hybrid Hell - Breaking Entrpise Identity beyond Active Directory</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T101000</dtstart>
            <dtend>20260910T110500</dtend>
            <duration>005500</duration>
            <summary>Welcome to Hybrid Hell - Breaking Entrpise Identity beyond Active Directory</summary>
            <description>Enterprise identity is no longer defined by a single directory service. Modern organisations operate complex identity architectures spanning Active Directory, Microsoft Entra ID, Azure, Microsoft 365, SaaS platforms, synchronisation services, multiple identity providers and increasingly multiple business units, subsidiaries and cloud tenants. Every integration introduces new trust relationships. Every trust relationship introduces new attack paths.

This session approaches enterprise identity from the perspective that matters most during an assessment: the attacker’s.

Rather than presenting a catalogue of Active Directory or Entra ID attack techniques, the talk focuses on how modern enterprise identity is constructed, why traditional assessment methodologies frequently fail to capture the complete attack surface, and how attackers move across identity boundaries by abusing trust instead of exploiting individual technologies.

Using realistic enterprise architectures, practical demonstrations and real-world attack scenarios, the session examines common challenges encountered during offensive security engagements, including hybrid identity deployments, synchronisation, multi-forest environments, multiple Entra ID tenants, delegated administration, identity trust relationships and assessment scoping. The audience will see how architectural decisions influence attack paths, why trust relationships become the true security boundary, and how weaknesses in one part of the identity architecture can create unexpected consequences elsewhere.

The presentation concludes with a practical framework for mapping enterprise identity architecture from an attacker’s perspective, enabling security teams to define more realistic assessment scopes, prioritise the trust relationships that matter most, and better understand how identity has become one of the largest and least visible enterprise attack surfaces.

Key takeaways

* Understand how enterprise identity has evolved beyond a single directory service.
* Learn why attackers focus on trust relationships rather than technology boundaries.
* Identify common architectural patterns that expand the enterprise identity attack surface.
* Recognise the challenges of scoping and assessing complex hybrid identity environments.
* Apply an attacker-focused methodology for analysing enterprise identity architecture and prioritising risk.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/KVLR3V/</url>
            <location>Großer Saal</location>
            
            <attendee>georg</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>QDB7NB@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-QDB7NB</pentabarf:event-slug>
            <pentabarf:title>What Windows 11 Remembers (And Most Investigators Miss)</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T110500</dtstart>
            <dtend>20260910T120000</dtend>
            <duration>005500</duration>
            <summary>What Windows 11 Remembers (And Most Investigators Miss)</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/QDB7NB/</url>
            <location>Großer Saal</location>
            
            <attendee>Maurice Fielenbach</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>AXSXQW@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-AXSXQW</pentabarf:event-slug>
            <pentabarf:title>Hacking Consumer Drones: From Flash Dumping to Root Exploits</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T130000</dtstart>
            <dtend>20260910T135500</dtend>
            <duration>005500</duration>
            <summary>Hacking Consumer Drones: From Flash Dumping to Root Exploits</summary>
            <description>This talk tracks an IT security researcher’s journey through the process of disassembling, dumping and exploiting the Potensic Atom 2 consumer drone. We’ll follow the full lifecycle of a hardware exploit: Starting with low-level chip identification and flash desoldering, we make a detour into recovering heavily corrupted flash firmware by reverse engineering error correction codes.

From there, we pivot to the software, reverse-engineering the binary firmware to uncover hidden backdoors in the drone&#x27;s control protocol. Ending with a presentation of a custom exploit designed to hijack the drone and gain full root access. Whether you&#x27;re interested in hardware RE or binary exploitation, this is a fast-paced look at every stage of the IoT research process.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/AXSXQW/</url>
            <location>Großer Saal</location>
            
            <attendee>Tim Schmidt</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>ZETL7P@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-ZETL7P</pentabarf:event-slug>
            <pentabarf:title>Deconstructing Modern macOS Initial Access Vectors</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T140000</dtstart>
            <dtend>20260910T145500</dtend>
            <duration>005500</duration>
            <summary>Deconstructing Modern macOS Initial Access Vectors</summary>
            <description>We begin by exploring the top of the funnel. Attackers have moved far beyond easily identifiable spam. We will deconstruct recent campaigns to show how adversaries are successfully lowering user guard through:

How threat actors weaponize Google Ads to push malicious software disguised as legitimate enterprise tools (e.g., Slack, Notion, or VPN clients).
A deep dive into localized, highly convincing fake browser updates and system notification campaigns that socially engineer users into bypassing native warnings.

Once the user interacts with the lure, how does the malware actually run? macOS is a rich Unix-based environment with multiple scripting avenues. We will analyze the &quot;Living off the Land&quot; (LotL) techniques currently dominating the macOS threat landscape, including:

The use of Bash, Zsh, and legacy Python/Perl scripts to establish persistence and pull down secondary payloads.
How attackers weaponize Apple’s native automation languages to silently interact with system APIs, bypass sandbox restrictions, and generate convincing fake credential prompts.
Techniques used by threat actors to obfuscate their code, making static analysis incredibly difficult for defenders.

Finally, we will break down how these threats are packaged to evade Gatekeeper and initial static analysis. We will compare and contrast real-world samples across:

The weaponization of standard Apple Disk Images (.dmg) and Installer Packages (.pkg), including pre-install/post-install script abuse.
The shift from standalone Mach-O binaries to hiding malicious routines inside Platypus-packaged applications and bloated Electron frameworks, which are notoriously difficult for traditional AV to parse effectively.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZETL7P/</url>
            <location>Großer Saal</location>
            
            <attendee>Stephan Berger</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>XPLEJW@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-XPLEJW</pentabarf:event-slug>
            <pentabarf:title>Lessons learned while building an Agentic SOC: The good, the bad, and the scary.</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T152500</dtstart>
            <dtend>20260910T162000</dtend>
            <duration>005500</duration>
            <summary>Lessons learned while building an Agentic SOC: The good, the bad, and the scary.</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/XPLEJW/</url>
            <location>Großer Saal</location>
            
            <attendee>Aaron Jewitt</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>3WDFBK@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-3WDFBK</pentabarf:event-slug>
            <pentabarf:title>Keyless Entry: Hacking SwitchBot Smartlocks</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T162000</dtstart>
            <dtend>20260910T164500</dtend>
            <duration>002500</duration>
            <summary>Keyless Entry: Hacking SwitchBot Smartlocks</summary>
            <description>While selecting targets for a team IoT hacking event, the SwitchBot Lock Pro Combo stood out: it is one of the most sold smart locks on the market, offering PIN, fingerprint, NFC, and app-based entry. The hardware consists of an indoor actuator that turns the physical key and an outdoor keypad. However, our initial recon of the Android app revealed, that the outdoor keypad holds the decision-making logic and sends execution commands to the indoor actuator over unprotected BLE, relying entirely on a custom application-layer encrypted protocol.

Diving deeper into this custom protocol, we discovered a fatal cryptographic failure. The devices negotiate a secret key and a nonce, but they encrypt their commands using AES in Counter (CTR) mode. Because CTR mode turns a block cipher into a stream cipher and lacks any integrity protection (like a MAC), bit-flips in the ciphertext propagate directly to the plaintext upon decryption without an opportunity to detect the manipulation.

In this 30-minute presentation, we will walk the audience through how we weaponized this exact flaw. Because a keypad&#x27;s LOCK button always broadcasts an encrypted command, an attacker only needs to sniff it. We will explain the math behind our &quot;master key&quot;, which only required a pre-computed XOR between encrypted LOCK and UNLOCK commands that is identical across all sessions and locks. By simply applying this to any sniffed LOCK ciphertext, we can instantly forge a valid UNLOCK command and open the door. We will give a live demonstration of this software-only attack in action.

Finally, we will detail our responsible disclosure journey, which serves as a perfect case study in the difficulties of patching IoT ecosystems. The vendor&#x27;s initial beta patch attempted to add a 2-byte truncated MD5 &quot;YOLO hash&quot; for integrity verification. However, because updating the entire ecosystem takes time, the lock still had to accept legacy commands from the smartphone app. We will show how we trivially bypassed the new patch by simply spoofing the smartphone app, ignoring the checksum entirely.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Short-Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/3WDFBK/</url>
            <location>Großer Saal</location>
            
            <attendee>Kolja Grassmann</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>ZCPUYM@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-ZCPUYM</pentabarf:event-slug>
            <pentabarf:title>Pentesting in the age of AI - where are we?</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T164500</dtstart>
            <dtend>20260910T174000</dtend>
            <duration>005500</duration>
            <summary>Pentesting in the age of AI - where are we?</summary>
            <description>An AI agent for a few hundred euros doing the job of a highly skilled senior penetration tester? That sounds great. But are we actually there yet?

This talk explores different ways of using AI for static and dynamic security analysis. We will look at AI as the pentester, AI as an assistant for validating tool output, and AI as the convenient interface for people who are too lazy to read the manual.

Evaluating the results of today’s AI-based pentesting projects can feel familiar to anyone who has reviewed a junior tester’s first report: some valid findings, some interesting ideas, some missing context, and a few confidently incorrect conclusions.

So what is the real issue? Is AI still not good enough, or is the person in front of the prompt part of the problem?

Focusing on Static Application Security Testing and Dynamic Application Security Testing, this talk presents practical examples, real-world observations, and a sober assessment of where AI can support penetration testing today. We will discuss what works, what fails, and why blindly trusting AI-generated security results is still a bad idea.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZCPUYM/</url>
            <location>Großer Saal</location>
            
            <attendee>Christian Biehler</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>ELHBVZ@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-ELHBVZ</pentabarf:event-slug>
            <pentabarf:title>Outro</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260910T174000</dtstart>
            <dtend>20260910T175500</dtend>
            <duration>001500</duration>
            <summary>Outro</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Short-Talk</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ELHBVZ/</url>
            <location>Großer Saal</location>
            
        </vevent>
        
    </vcalendar>
</iCalendar>
