<?xml version='1.0' encoding='utf-8' ?>
<iCalendar xmlns:pentabarf='http://pentabarf.org' xmlns:xCal='urn:ietf:params:xml:ns:xcal'>
    <vcalendar>
        <version>2.0</version>
        <prodid>-//Pentabarf//Schedule//EN</prodid>
        <x-wr-caldesc></x-wr-caldesc>
        <x-wr-calname></x-wr-calname>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>3D797U@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-3D797U</pentabarf:event-slug>
            <pentabarf:title>Cryptography: An Evolutionary Tale</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260911T090000</dtstart>
            <dtend>20260911T130000</dtend>
            <duration>040000</duration>
            <summary>Cryptography: An Evolutionary Tale</summary>
            <description>This workshop is a deep dive into the art and science of cryptography, charting its evolution from antiquity to the cutting edge of modern research. The session is structured as a chronological and interactive exploration, tailored for the hands-on and intellectually curious audience. The four hours are segmented to cover distinct eras of cryptographic development, each combining a theoretical overview with practical application.

Part 1: The Age of Classical Ciphers (Hands-On)

We begin our journey in the ancient world, with some of the earliest recorded uses of cryptography. Participants will get their hands dirty with classical &quot;pen-and-paper&quot; ciphers, starting with the famed Caesar cipher, a simple substitution method used by Julius Caesar for his private correspondence. We&#x27;ll discuss the vulnerabilities of these early systems, such as their susceptibility to frequency analysis (a groundbreaking cryptanalytic technique developed by Arab scholar Al-Kindi around the 9th century). This section will involve hands-on exercises where attendees will encrypt and decrypt messages using these classical methods and even attempt to break them.

Part 2: The Mechanical and Early Digital Revolution (Demonstration and Puzzles)

This segment explores the leap to more complex cryptographic machinery. We will discuss the pivotal role of devices like the Enigma machine during World War II and the monumental efforts to crack its codes, which laid some of the foundational theory for modern computing. The workshop will then transition to the dawn of the digital age with the introduction of the Data Encryption Standard (DES), the first cryptosystem certified for use by the US Government. To make this era tangible, we will engage with interactive puzzles that simulate the logic of these more complex systems.

Part 3: The Dawn of Public-Key Cryptography (Conceptual and Practical)

A revolutionary shift in cryptography came with the concept of asymmetric keys. We will demystify public-key cryptography, explaining how the use of a public and private key pair solved the age-old problem of secure key exchange. The principles behind RSA and Diffie-Hellman will be explained in an accessible manner, focusing on the one-way mathematical functions that make them secure. Participants will engage in a practical exercise to understand how public and private keys are used to encrypt and decrypt information, providing a foundational understanding of the technology that underpins much of modern secure communication, including TLS/SSL.

Part 4: The Quantum Frontier (Discursive and Forward-Looking)

The final hour will be a discursive exploration of the future of cryptography in the face of quantum computing. We will discuss why current cryptographic standards like RSA and AES are vulnerable to the power of quantum computers. The session will introduce the fundamental concepts of quantum cryptography and Quantum Key Distribution (QKD), explaining how they leverage the principles of quantum mechanics to offer a new paradigm of secure communication. The aim is to provide an intuitive, high-level understanding of this next evolution in cryptography, sparking a conversation about the challenges and opportunities that lie ahead.

Throughout the workshop, the emphasis will be on interaction, discussion, and hands-on learning. Participants will leave not only with a historical perspective but also with a practical feel for the cryptographic concepts that have shaped and will continue to shape our world.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop (4 hours)</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/3D797U/</url>
            <location>Uni Campus Seminarhaus 1</location>
            
            <attendee>Alessio Di Santo</attendee>
            
            <attendee>Gabriella Lanziani</attendee>
            
            <attendee>Dajana Cassioli</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>QPQTVJ@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-QPQTVJ</pentabarf:event-slug>
            <pentabarf:title>A phishing trip with Fancy Bear - Let&#x27;s analyze APT malware together!</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260911T140000</dtstart>
            <dtend>20260911T180000</dtend>
            <duration>040000</duration>
            <summary>A phishing trip with Fancy Bear - Let&#x27;s analyze APT malware together!</summary>
            <description>This workshop does not depend on domain-specific knowledge, we will try to break the steps down as far as possible. Attendees will follow along through small exercises, with the opportunity to compare their solution through a validation system.

Important for message for attendees: If you would like to follow along, please bring laptop with a charged battery. You will be handling real-world malware (you act at your own risk; No backup, no pity). I recommend to use a virtual machine (e.g. FLARE-VM, Remnux). No special tooling is required, make sure to have the basics (Text and Hex Editor, Browser, ZIP utility) installed. No photos during the workshop please, you will receive a copy of the slides.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop (4 hours)</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/QPQTVJ/</url>
            <location>Uni Campus Seminarhaus 1</location>
            
            <attendee>Marius Genheimer</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>PZBMJX@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-PZBMJX</pentabarf:event-slug>
            <pentabarf:title>Introduction to Physical Security Testing</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260911T090000</dtstart>
            <dtend>20260911T130000</dtend>
            <duration>040000</duration>
            <summary>Introduction to Physical Security Testing</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop (4 hours)</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/PZBMJX/</url>
            <location>Uni Campus Seminarhaus 2</location>
            
            <attendee>Nico Leidecker</attendee>
            
            <attendee>Harris Nuhanović</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>39S7AD@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-39S7AD</pentabarf:event-slug>
            <pentabarf:title>Desktop Application Pentesting 101 for Security Professionals</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260911T140000</dtstart>
            <dtend>20260911T180000</dtend>
            <duration>040000</duration>
            <summary>Desktop Application Pentesting 101 for Security Professionals</summary>
            <description>This workshop gives security professionals practical experience with desktop application penetration testing. After a short introduction and environment setup, participants learn how to fingerprint technologies, decompile a Java client, analyze client-server communication, and understand why backend systems often represent the real security boundary. The core hands-on part focuses on building a custom client that communicates directly with the backend, bypassing limitations of the original application. Participants then use this client and the knowledge gained from static and network-level analysis to hunt for vulnerabilities and exploit them in a realistic lab environment.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop (4 hours)</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/39S7AD/</url>
            <location>Uni Campus Seminarhaus 2</location>
            
            <attendee>Jakob Steeg</attendee>
            
            <attendee>Tim Kranz</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>KPBKUP@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-KPBKUP</pentabarf:event-slug>
            <pentabarf:title>Defending Microsoft Entra ID: Common Attacks, Tokens, and Response Planning</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260911T090000</dtstart>
            <dtend>20260911T130000</dtend>
            <duration>040000</duration>
            <summary>Defending Microsoft Entra ID: Common Attacks, Tokens, and Response Planning</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop (4 hours)</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/KPBKUP/</url>
            <location>Uni Campus Seminarhaus 3</location>
            
            <attendee>Ethan Bowen</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>AGWT9L@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-AGWT9L</pentabarf:event-slug>
            <pentabarf:title>Hunting Supply Chain Attacks: Hands-on Anaysis of npm, PyPI, and VS Code Threats</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260911T090000</dtstart>
            <dtend>20260911T130000</dtend>
            <duration>040000</duration>
            <summary>Hunting Supply Chain Attacks: Hands-on Anaysis of npm, PyPI, and VS Code Threats</summary>
            <description>Participants will work directly with sanitized samples from active campaigns including Contagious Interview (BeaverTail/InvisibleFerret), Glassworm, and TeamPCP/Miasma.  The attendees will analyze malicious artifacts across four major attack surfaces: npm, PyPI, GitHub, and VS Code extensions. Beyond technical analysis, attendees will learn the trainers custom software supply chain CTI workflow: extracting IOCs,  pivoting across infrastructure to identify campaign scope, attributing activity to threat actors, , producing actionable reports and alerting the community to the threats you expose. The training culminates with a live hunting session where participants apply their new skills to hunt for real threats and document findings using professional intelligence standards.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop (4 hours)</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/AGWT9L/</url>
            <location>Uni Campus Seminarhaus 4</location>
            
            <attendee>Paul McCarty</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>DQTFAG@@cfp.bsidesfrankfurt.org</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-DQTFAG</pentabarf:event-slug>
            <pentabarf:title>Rustacean Introduction to Shellcoding</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20260911T140000</dtstart>
            <dtend>20260911T180000</dtend>
            <duration>040000</duration>
            <summary>Rustacean Introduction to Shellcoding</summary>
            <description>How to implement your next shellcode or implant using the Rust programming language. The workshop will cover the following:

- A brief introduction to Rust.
- Key challenges during shellcode development and how to resolve them.
- A brief introduction to Windows and parsing PE headers.
- Short introduction on loader design.
- Creation of fully position-independent code (PIC).

**What do you need and what will be provided:**
- Baseline library code will be provided. 
- Basic ability to write and read Rust code will be helpful but is not required.
- You will need to bring a Windows VM to the workshop. 
- This VM should have X64dbg (64-bit) installed. 
- You will also need the ability to transfer files from and to it. 
- A development container (Docker) for cross-compiling Rust will be provided.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop (4 hours)</category>
            <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/DQTFAG/</url>
            <location>Uni Campus Seminarhaus 4</location>
            
            <attendee>Ben</attendee>
            
        </vevent>
        
    </vcalendar>
</iCalendar>
