{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.1.2"}, "schedule": {"url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/schedule/", "version": "0.4", "base_url": "https://cfp.bsidesfrankfurt.org", "conference": {"acronym": "call-for-paper-workshops-2026", "title": "Call For Paper - Workshops", "start": "2026-09-11", "end": "2026-09-11", "daysCount": 1, "timeslot_duration": "00:05", "time_zone_name": "Europe/Berlin", "colors": {"primary": "#404040"}, "rooms": [{"name": "Uni Campus Seminarhaus 1", "slug": "2-uni-campus-seminarhaus-1", "guid": "7cce13f8-2262-5fb0-abbf-f376f8591a72", "description": null, "capacity": 25}, {"name": "Uni Campus Seminarhaus 2", "slug": "3-uni-campus-seminarhaus-2", "guid": "41d98ac0-b29b-56ec-88d3-348ea4747f47", "description": null, "capacity": 25}, {"name": "Uni Campus Seminarhaus 3", "slug": "4-uni-campus-seminarhaus-3", "guid": "9d30d8ff-77dc-5836-a98a-1c7c1be1fe7d", "description": null, "capacity": 25}, {"name": "Uni Campus Seminarhaus 4", "slug": "5-uni-campus-seminarhaus-4", "guid": "0b658738-690d-5dd9-9423-590d96b894a5", "description": null, "capacity": 25}], "tracks": [], "days": [{"index": 1, "date": "2026-09-11", "day_start": "2026-09-11T04:00:00+02:00", "day_end": "2026-09-12T03:59:00+02:00", "rooms": {"Uni Campus Seminarhaus 1": [{"guid": "c2eb8f1f-0293-587d-8b07-8b52e03da7fe", "code": "3D797U", "id": 19, "logo": null, "date": "2026-09-11T09:00:00+02:00", "start": "09:00", "duration": "04:00", "room": "Uni Campus Seminarhaus 1", "slug": "call-for-paper-workshops-2026-19-cryptography-an-evolutionary-tale", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/3D797U/", "title": "Cryptography: An Evolutionary Tale", "subtitle": "", "track": null, "type": "Workshop (4 hours)", "language": "en", "abstract": "Cryptography is the invisible shield of the digital world, but its roots stretch back through millennia of human history. This workshop, indeed, offers a hands-on retrospective of this fascinating field. In four hours, we will journey from the simple yet effective Caesar cipher to the mind-bending principles of quantum cryptography. Participants will not only learn the historical and theoretical underpinnings of these cryptographic systems but will actively engage with them through a series of hands-on challenges. We will explore the cat-and-mouse game of code-makers and code-breakers, understanding how vulnerabilities in one generation of cryptography spurred the innovations of the next. The workshop is designed to be accessible to those with a foundational understanding of security concepts, providing a tangible and discursive look at how we've protected our secrets through the ages and what the future holds for this critical domain. Attendees will leave with a richer appreciation for the elegant mathematics and clever designs that secure our digital lives.", "description": "This workshop is a deep dive into the art and science of cryptography, charting its evolution from antiquity to the cutting edge of modern research. The session is structured as a chronological and interactive exploration, tailored for the hands-on and intellectually curious audience. The four hours are segmented to cover distinct eras of cryptographic development, each combining a theoretical overview with practical application.\r\n\r\nPart 1: The Age of Classical Ciphers (Hands-On)\r\n\r\nWe begin our journey in the ancient world, with some of the earliest recorded uses of cryptography. Participants will get their hands dirty with classical \"pen-and-paper\" ciphers, starting with the famed Caesar cipher, a simple substitution method used by Julius Caesar for his private correspondence. We'll discuss the vulnerabilities of these early systems, such as their susceptibility to frequency analysis (a groundbreaking cryptanalytic technique developed by Arab scholar Al-Kindi around the 9th century). This section will involve hands-on exercises where attendees will encrypt and decrypt messages using these classical methods and even attempt to break them.\r\n\r\nPart 2: The Mechanical and Early Digital Revolution (Demonstration and Puzzles)\r\n\r\nThis segment explores the leap to more complex cryptographic machinery. We will discuss the pivotal role of devices like the Enigma machine during World War II and the monumental efforts to crack its codes, which laid some of the foundational theory for modern computing. The workshop will then transition to the dawn of the digital age with the introduction of the Data Encryption Standard (DES), the first cryptosystem certified for use by the US Government. To make this era tangible, we will engage with interactive puzzles that simulate the logic of these more complex systems.\r\n\r\nPart 3: The Dawn of Public-Key Cryptography (Conceptual and Practical)\r\n\r\nA revolutionary shift in cryptography came with the concept of asymmetric keys. We will demystify public-key cryptography, explaining how the use of a public and private key pair solved the age-old problem of secure key exchange. The principles behind RSA and Diffie-Hellman will be explained in an accessible manner, focusing on the one-way mathematical functions that make them secure. Participants will engage in a practical exercise to understand how public and private keys are used to encrypt and decrypt information, providing a foundational understanding of the technology that underpins much of modern secure communication, including TLS/SSL.\r\n\r\nPart 4: The Quantum Frontier (Discursive and Forward-Looking)\r\n\r\nThe final hour will be a discursive exploration of the future of cryptography in the face of quantum computing. We will discuss why current cryptographic standards like RSA and AES are vulnerable to the power of quantum computers. The session will introduce the fundamental concepts of quantum cryptography and Quantum Key Distribution (QKD), explaining how they leverage the principles of quantum mechanics to offer a new paradigm of secure communication. The aim is to provide an intuitive, high-level understanding of this next evolution in cryptography, sparking a conversation about the challenges and opportunities that lie ahead.\r\n\r\nThroughout the workshop, the emphasis will be on interaction, discussion, and hands-on learning. Participants will leave not only with a historical perspective but also with a practical feel for the cryptographic concepts that have shaped and will continue to shape our world.", "recording_license": "", "do_not_record": true, "persons": [{"code": "EASADJ", "name": "Alessio Di Santo", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/EASADJ_KV6lyof.png", "biography": "Alessio Di Santo is a Cybersecurity Professional and Doctoral Candidate with a focus on cryptography and digital forensics. He holds both a Bachelor's Degree in Information Engineering and a Master's Degree in Computer and Automation Engineering from the Universit\u00e0 degli Studi dell'Aquila, where his research concentrated on Cryptographic Fairness and Forensic Acquisition for IT/OT systems, respectively. Since 2020, Alessio has worked in the cybersecurity industry as a Cyber Threat Intelligence Analyst, Incident Responder, and Malware Analyst. He is currently completing his Ph.D. under the supervision of Prof. Dajana Cassioli (co-tutor Walter Tiberti) and working as a Senior Information Security Specialist at Deutsche Boerse.", "public_name": "Alessio Di Santo", "guid": "5bf3015a-08c8-5604-a361-76b074fccf56", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/EASADJ/"}, {"code": "XEVTBJ", "name": "Gabriella Lanziani", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/XEVTBJ_YjoRC24.jpeg", "biography": ".", "public_name": "Gabriella Lanziani", "guid": "fc331b86-66ae-5d40-a0c0-407776a5d361", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/XEVTBJ/"}, {"code": "MYKY99", "name": "Dajana Cassioli", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/MYKY99_ut45RKq.PNG", "biography": "Dajana Cassioli (Senior Member, IEEE) is an Associate Professor of Telecommunications Engineering with the University of L\u2019Aquila, L\u2019Aquila, Italy, where she served as the Elected Head for the Study Program in \u201cTelecommunications Engineering: Advanced Technologies and Services\u201d from 2021 to 2024. She co-authored more than 100 articles published in the most renowned international journals, magazines, and conference proceedings. She was a Summer Manager with the Wireless Systems Research Department, AT&T Laboratories-Research, NJ, USA, in 2000. She was a Short-Term Visiting Scholar with the University of Southern California, Los Angeles, CA, USA, hosted by Prof. Andy Molisch, in 2022. Her main research interests are in wireless communications, 5G/B5G networks and cybersecurity. \r\nDr. Cassioli is the Chair of the Technical Working Group (TWG) on \u201cPropagation Channels for Next Generation Wireless Systems and Emerging Deployment Scenarios\u201d and Chair of the SiG on Distributed and Massive MIMO of the IEEE P1944 Standard for Channel Models of Wireless Systems, both within the IEEE Communications Society. She also serves as the Diversity, Equity and Inclusion Activity Coordinator of the IEEE Italy Section. She is the Past Chair of the IEEE WIE AG Italy Section from 2016 to 2022 and the IEEE VT06/COM19 Italy Chapter from 2011 to 2017. She served as the Chair of the IEEE ComSoc RCC SiG on Propagation Channels for 5G&B from 2021 to 2025. Since 2015, she is the Coordinator of the University of L\u2019Aquila Node of the CINI National Laboratory of Cybersecurity, where she led the CyberEquality WG from 2020 to 2021. She has been awarded the ERC StG VISION (Video-oriented UWB-based Intelligent Ubiquitous Sensing) in 2010 and the ERC PoC Grant iCARE (MobIle health-Care system for monitoring toxicity and symptoms in Cancer patients Receiving Disease-Oriented Therapy) in 2016. She was the CEO in 2014\u20132018, and 2019 of the spin-off of the University of L\u2019Aquila \u201cSmartly: Natives of Smart Living srl,\u201d which designs and markets advanced ICT solutions to improve the quality of life. She served as the Co-Chair for Globecom 2025 WC, ICC 2024 MWN, ICC 2023 CISS, PIMRC2018 Industry, RTSI WIE Chair in 2018, 2019, and 2020, MELECON2020 and MetroInd4.0, and the TPC member of several International Conferences, including ICC, PIMRC, VTC, and GLOBECOM. She participated in the definition of the standard channel model for the IEEE 802.15.4 standard in 2005. She is an Associate Editor of IET Electronic Letters, and an Executive Editor of WILEY INTERNET TECHNOLOGY LETTERS and Transactions on Emerging Telecommunications Technology and served as an Associate Editor for IEEE COMMUNICATIONS LETTERS from 2018 to 2022.", "public_name": "Dajana Cassioli", "guid": "cfce33ee-1c86-52cc-9872-c7d04c71871a", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/MYKY99/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/3D797U/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/3D797U/", "attachments": []}, {"guid": "777d5c17-7c3c-5f01-8666-5e6ff9542d98", "code": "QPQTVJ", "id": 7, "logo": null, "date": "2026-09-11T14:00:00+02:00", "start": "14:00", "duration": "04:00", "room": "Uni Campus Seminarhaus 1", "slug": "call-for-paper-workshops-2026-7-a-phishing-trip-with-fancy-bear-let-s-analyze-apt-malware-together", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/QPQTVJ/", "title": "A phishing trip with Fancy Bear - Let's analyze APT malware together!", "subtitle": "", "track": null, "type": "Workshop (4 hours)", "language": "en", "abstract": "In this beginner-friendly, hands-on workshop, participants will walk through the full attack chain of a real-world Fancy Bear (APT28/GRU) intrusion - from the initial phishing email to command & control - guided by a purpose-built interactive training platform.\r\n\r\nWhat to expect:\r\nThe workshop is structured across five chapters, each building on the last: threat actor background, payload delivery, exploitation, persistence & installation, and command & control. Participants work hands-on with real artefacts (phishing email headers, a weaponised RTF document, malware samples, and a C2 implant) and answer quiz questions via an interactive platform to validate their findings along the way - making progress immediately visible and keeping the session engaging for all skill levels.\r\n\r\nWhat you will learn:\r\n- How to analyse phishing emails and extract indicators from mail headers\r\n- How to identify and dissect malicious Office documents (including MIME type mismatches and OLE/COM object abuse triggering CVE-2026-21509)\r\n- Persistence techniques: file staging, scheduled task abuse, and LSB steganography in PNG files\r\n- How to reverse simple string obfuscation (XOR + Base64) using CyberChef\r\n- How threat actors repurpose legitimate open-source tools (Covenant C2 framework) and abuse trusted cloud services to blend into normal traffic\r\n- All tools demoed/used throughout the workshop (e.g. oletools, CyberChef, and Covenant) are free and open-source, making every technique immediately reproducible.\r\n\r\nWho should attend:\r\nNo prior malware analysis experience is required. Basic familiarity with the command line and a curiosity for how attacks actually work is all you need. Security students, CTF players, sysadmins, and blue teamers looking to build intuition for real-world threat actor tradecraft will get the most out of this session.\r\n\r\nWhat to bring:\r\nA laptop with a browser and internet access. All you need is a web brower, a text editor and an archive tool to unpack ZIP (AES-256) archives - other than that, no prior setup is required.", "description": "This workshop does not depend on domain-specific knowledge, we will try to break the steps down as far as possible. Attendees will follow along through small exercises, with the opportunity to compare their solution through a validation system.\r\n\r\nImportant for message for attendees: If you would like to follow along, please bring laptop with a charged battery. You will be handling real-world malware (you act at your own risk; No backup, no pity). I recommend to use a virtual machine (e.g. FLARE-VM, Remnux). No special tooling is required, make sure to have the basics (Text and Hex Editor, Browser, ZIP utility) installed. No photos during the workshop please, you will receive a copy of the slides.", "recording_license": "", "do_not_record": true, "persons": [{"code": "E37GKV", "name": "Marius Genheimer", "avatar": null, "biography": "Marius Genheimer is a DFIR Specialist and Threat Researcher with the SECUINFRA Falcon Team. He specializes in malware analysis and defensive security training.", "public_name": "Marius Genheimer", "guid": "4a19fab7-2477-59fb-a716-efc172e516f8", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/E37GKV/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/QPQTVJ/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/QPQTVJ/", "attachments": []}], "Uni Campus Seminarhaus 2": [{"guid": "15515d7e-884c-54f3-8212-c7c12914a21d", "code": "PZBMJX", "id": 81, "logo": null, "date": "2026-09-11T09:00:00+02:00", "start": "09:00", "duration": "04:00", "room": "Uni Campus Seminarhaus 2", "slug": "call-for-paper-workshops-2026-81-introduction-to-physical-security-testing", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/PZBMJX/", "title": "Introduction to Physical Security Testing", "subtitle": "", "track": null, "type": "Workshop (4 hours)", "language": "en", "abstract": "Join us for an interactive half-day workshop where you'll learn the essential techniques of physical security testing. This session covers key skills such as lock picking, door bypass methods, and cloning insecure access cards. Gain hands-on experience as you practice these techniques and hear real-world access attempts from experienced Red Teamers. Enhance your understanding of physical security measures and test your newfound skills on our Cover Access Vault (CAV).", "description": "", "recording_license": "", "do_not_record": true, "persons": [{"code": "KTQZXE", "name": "Nico Leidecker", "avatar": null, "biography": "Nico Leidecker leads NVISO's offensive security team. With more than 20 years of hands-on experience in security testing, red teaming, and adversarial simulation, he specializes in designing tailored engagements that help organizations assess and strengthen their resilience against targeted threats. His work combines realistic attacker emulation with practical insights into how organizations can improve their defensive posture. He and his team conduct multiple red team engagements each year, often including physical security attack vectors.", "public_name": "Nico Leidecker", "guid": "01c7b517-93b4-5e54-81fe-b68839d35ca6", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/KTQZXE/"}, {"code": "UXMZPD", "name": "Harris Nuhanovi\u0107", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/UXMZPD_3GuMFLT.webp", "biography": "Harris Nuhanovi\u0107 is a Red Team Operator on NVISO\u2019s ARES team, specializing in physical intrusion testing and adversary emulation. He regularly conducts red team engagements involving physical security attack vectors, from lock picking, access control and door bypasses to badge cloning.", "public_name": "Harris Nuhanovi\u0107", "guid": "9906fa31-97e8-5f2a-8740-8d6f08c1f03e", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/UXMZPD/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/PZBMJX/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/PZBMJX/", "attachments": []}, {"guid": "127e58af-aac9-599b-afe4-ed5048e05522", "code": "39S7AD", "id": 86, "logo": null, "date": "2026-09-11T14:00:00+02:00", "start": "14:00", "duration": "04:00", "room": "Uni Campus Seminarhaus 2", "slug": "call-for-paper-workshops-2026-86-desktop-application-pentesting-101-for-security-professionals", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/39S7AD/", "title": "Desktop Application Pentesting 101 for Security Professionals", "subtitle": "", "track": null, "type": "Workshop (4 hours)", "language": "en", "abstract": "Desktop applications, also known as fat or thick clients, remain a business-critical attack surface in many enterprise environments, especially in finance, insurance, and pharmaceuticals. Testing them requires a different approach than classic web application testing: reverse engineering client-side functionality, understanding proprietary protocols, and analyzing backend communication. This hands-on training introduces a practical methodology for assessing Java desktop applications from initial analysis to backend exploitation. Participants will reverse engineer a demo application, inspect its network communication, build a custom pentest client, and use it to identify and exploit server-side vulnerabilities.", "description": "This workshop gives security professionals practical experience with desktop application penetration testing. After a short introduction and environment setup, participants learn how to fingerprint technologies, decompile a Java client, analyze client-server communication, and understand why backend systems often represent the real security boundary. The core hands-on part focuses on building a custom client that communicates directly with the backend, bypassing limitations of the original application. Participants then use this client and the knowledge gained from static and network-level analysis to hunt for vulnerabilities and exploit them in a realistic lab environment.", "recording_license": "", "do_not_record": true, "persons": [{"code": "EJBJD9", "name": "Jakob Steeg", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/EJBJD9_tUE6EmJ.jpg", "biography": "Jakob Steeg is a security consultant and penetration tester at usd AG with several years of experience in planning and executing penetration tests across web applications, APIs, cloud environments, Kubernetes, Windows/Active Directory, mobile platforms, and native/thick client applications. He specializes in the security assessment of desktop clients and proprietary or binary protocols, applying his strong software development background to build custom testing tools and analyze complex systems. His expertise includes cryptographic mechanisms, secure software development, public key infrastructures, and modern network architectures. Jakob holds a Master\u2019s degree in IT Security from TU Darmstadt, is OSCP and OSWE certified, and has published multiple CVE-listed vulnerabilities.", "public_name": "Jakob Steeg", "guid": "fdd874bc-0cd9-5d8e-8dc4-cc8531923519", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/EJBJD9/"}, {"code": "78JECL", "name": "Tim Kranz", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/78JECL_W4UhJox.webp", "biography": "Tim Kranz is a managing consultant and penetration tester at usd AG.", "public_name": "Tim Kranz", "guid": "247b3ec1-3fe1-5070-93a2-690aee2251c7", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/78JECL/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/39S7AD/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/39S7AD/", "attachments": []}], "Uni Campus Seminarhaus 3": [{"guid": "b55daae2-1343-5550-ab02-c2cf1277c45a", "code": "KPBKUP", "id": 88, "logo": null, "date": "2026-09-11T09:00:00+02:00", "start": "09:00", "duration": "04:00", "room": "Uni Campus Seminarhaus 3", "slug": "call-for-paper-workshops-2026-88-defending-microsoft-entra-id-common-attacks-tokens-and-response-planning", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/KPBKUP/", "title": "Defending Microsoft Entra ID: Common Attacks, Tokens, and Response Planning", "subtitle": "", "track": null, "type": "Workshop (4 hours)", "language": "en", "abstract": "Microsoft Entra ID is a major target for attackers and a core part of modern incident response. SOC analysts must understand cloud identity from initial access, persistence, privilege abuse, and lateral movement. Understanding Active Directory alone is not enough.\r\n\r\nThis 4-hour session gives defenders a practical understanding of how Entra ID works and how it is abused. It covers identity types, hybrid authentication, OAuth and OIDC, application objects and service principals, token types, Conditional Access, and key attack paths including device code phishing, attacker-in-the-middle, and refresh token replay. It also discusses Entra sign-in logs, the Graph API and its logs, sign-in session tracking, and practical KQL-based hunting.\r\n\r\nAttendees will run KQL queries to identify suspicious activity and execute 'attacks' in a lab environment.", "description": "", "recording_license": "", "do_not_record": true, "persons": [{"code": "AZCMAT", "name": "Ethan Bowen", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/AZCMAT_772WEP0.jpeg", "biography": "Ethan Bowen is a Security Solutions Architect at NVISO, where he helps organizations solve complex SOC challenges. He brings more than 10 years of blue team experience across consulting, financial services, federal government, and technology sectors, with a focus on detection engineering, incident response, threat hunting, and Microsoft security technologies.\r\n\r\nBefore joining NVISO, Ethan worked at Deutsche Bank, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Microsoft, Pacific Northwest National Laboratory, and the U.S. Department of Defense. \r\n\r\nEthan holds a Bachelor of Science in Cybersecurity from Penn State University. He also holds multiple industry certifications, including GREM, GCFA, CISSP, and multiple Microsoft certifications. Outside of work, Ethan enjoys running and playing board games.", "public_name": "Ethan Bowen", "guid": "fb05534f-2638-59ee-883d-ef9a0486e092", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/AZCMAT/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/KPBKUP/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/KPBKUP/", "attachments": []}], "Uni Campus Seminarhaus 4": [{"guid": "5dfa0a55-c300-54a8-b524-15e9a0eeee6f", "code": "AGWT9L", "id": 53, "logo": "https://cfp.bsidesfrankfurt.org/media/call-for-paper-workshops-2026/submissions/AGWT9L/Screenshot_2026_hFzI1i1.png", "date": "2026-09-11T09:00:00+02:00", "start": "09:00", "duration": "04:00", "room": "Uni Campus Seminarhaus 4", "slug": "call-for-paper-workshops-2026-53-hunting-supply-chain-attacks-hands-on-anaysis-of-npm-pypi-and-vs-code-threats", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/AGWT9L/", "title": "Hunting Supply Chain Attacks: Hands-on Anaysis of npm, PyPI, and VS Code Threats", "subtitle": "", "track": null, "type": "Workshop (4 hours)", "language": "en", "abstract": "Software supply chain attacks have become one of the most significant threats to organizations, with nation-state actors like DPRK's Lazarus Group, and TeamPCP actively compromising npm packages, PyPI libraries, GitHub repositories, and VS Code extensions to target developers and steal credentials, cryptocurrency, and source code. This hands-on training equips security teams with practical skills to detect, analyze, and extract actionable threat intelligence from real-world supply chain malware\u2014turning raw malware samples into finished intelligence products.", "description": "Participants will work directly with sanitized samples from active campaigns including Contagious Interview (BeaverTail/InvisibleFerret), Glassworm, and TeamPCP/Miasma.  The attendees will analyze malicious artifacts across four major attack surfaces: npm, PyPI, GitHub, and VS Code extensions. Beyond technical analysis, attendees will learn the trainers custom software supply chain CTI workflow: extracting IOCs,  pivoting across infrastructure to identify campaign scope, attributing activity to threat actors, , producing actionable reports and alerting the community to the threats you expose. The training culminates with a live hunting session where participants apply their new skills to hunt for real threats and document findings using professional intelligence standards.", "recording_license": "", "do_not_record": true, "persons": [{"code": "XXRWGT", "name": "Paul McCarty", "avatar": null, "biography": null, "public_name": "Paul McCarty", "guid": "dc3fd57b-500c-57fe-93bf-5738143fbab9", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/XXRWGT/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/AGWT9L/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/AGWT9L/", "attachments": []}, {"guid": "d7ae9b3f-b7b2-50b4-a362-0bccda80bcbc", "code": "DQTFAG", "id": 55, "logo": null, "date": "2026-09-11T14:00:00+02:00", "start": "14:00", "duration": "04:00", "room": "Uni Campus Seminarhaus 4", "slug": "call-for-paper-workshops-2026-55-rustacean-introduction-to-shellcoding", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/DQTFAG/", "title": "Rustacean Introduction to Shellcoding", "subtitle": "", "track": null, "type": "Workshop (4 hours)", "language": "en", "abstract": "Write your first position-independent implant with the Rust programming language from scratch! Learn how to resolve common issues, parse PE headers, and leave with your code at the end.", "description": "How to implement your next shellcode or implant using the Rust programming language. The workshop will cover the following:\r\n\r\n- A brief introduction to Rust.\r\n- Key challenges during shellcode development and how to resolve them.\r\n- A brief introduction to Windows and parsing PE headers.\r\n- Short introduction on loader design.\r\n- Creation of fully position-independent code (PIC).\r\n\r\n**What do you need and what will be provided:**\r\n- Baseline library code will be provided. \r\n- Basic ability to write and read Rust code will be helpful but is not required.\r\n- You will need to bring a Windows VM to the workshop. \r\n- This VM should have X64dbg (64-bit) installed. \r\n- You will also need the ability to transfer files from and to it. \r\n- A development container (Docker) for cross-compiling Rust will be provided.", "recording_license": "", "do_not_record": true, "persons": [{"code": "DLWJUT", "name": "Ben", "avatar": "https://cfp.bsidesfrankfurt.org/media/avatars/DLWJUT_o1bTURg.jpeg", "biography": "Ben Stuart is an offensive security consultant based in Wiesbaden, Germany, and a Rustacean since 1.0, back when he was doing embedded and microcontroller work at university, long before it was a fashionable choice for offensive tooling. He holds the OSCE3 (OSCP, OSEP, OSWE, OSED) and runs his own company, Wisp Security GmbH, doing penetration testing and offensive security development.", "public_name": "Ben", "guid": "0db79937-f758-5929-952a-d00cbe6c03b2", "url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/speaker/DLWJUT/"}], "links": [], "feedback_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/DQTFAG/feedback/", "origin_url": "https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/DQTFAG/", "attachments": []}]}}]}}}