<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2026.1.2. -->
<schedule>
    <generator name="pretalx" version="2026.1.2" />
    <version>0.4</version>
    <conference>
        <title>Call For Paper - Workshops</title>
        <acronym>call-for-paper-workshops-2026</acronym>
        <start>2026-09-11</start>
        <end>2026-09-11</end>
        <days>1</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://cfp.bsidesfrankfurt.org</base_url>
        <logo>https://cfp.bsidesfrankfurt.org/media/call-for-paper-workshops-2026/img/website-qr-code_ZAljNd8.png</logo>
        <time_zone_name>Europe/Berlin</time_zone_name>
        
        
    </conference>
    <day index='1' date='2026-09-11' start='2026-09-11T04:00:00+02:00' end='2026-09-12T03:59:00+02:00'>
        <room name='Uni Campus Seminarhaus 1' guid='7cce13f8-2262-5fb0-abbf-f376f8591a72'>
            <event guid='c2eb8f1f-0293-587d-8b07-8b52e03da7fe' id='19' code='3D797U'>
                <room>Uni Campus Seminarhaus 1</room>
                <title>Cryptography: An Evolutionary Tale</title>
                <subtitle></subtitle>
                <type>Workshop (4 hours)</type>
                <date>2026-09-11T09:00:00+02:00</date>
                <start>09:00</start>
                <duration>04:00</duration>
                <abstract>Cryptography is the invisible shield of the digital world, but its roots stretch back through millennia of human history. This workshop, indeed, offers a hands-on retrospective of this fascinating field. In four hours, we will journey from the simple yet effective Caesar cipher to the mind-bending principles of quantum cryptography. Participants will not only learn the historical and theoretical underpinnings of these cryptographic systems but will actively engage with them through a series of hands-on challenges. We will explore the cat-and-mouse game of code-makers and code-breakers, understanding how vulnerabilities in one generation of cryptography spurred the innovations of the next. The workshop is designed to be accessible to those with a foundational understanding of security concepts, providing a tangible and discursive look at how we&apos;ve protected our secrets through the ages and what the future holds for this critical domain. Attendees will leave with a richer appreciation for the elegant mathematics and clever designs that secure our digital lives.</abstract>
                <slug>call-for-paper-workshops-2026-19-cryptography-an-evolutionary-tale</slug>
                <track></track>
                
                <persons>
                    <person id='16'>Alessio Di Santo</person><person id='37'>Gabriella Lanziani</person><person id='105'>Dajana Cassioli</person>
                </persons>
                <language>en</language>
                <description>This workshop is a deep dive into the art and science of cryptography, charting its evolution from antiquity to the cutting edge of modern research. The session is structured as a chronological and interactive exploration, tailored for the hands-on and intellectually curious audience. The four hours are segmented to cover distinct eras of cryptographic development, each combining a theoretical overview with practical application.

Part 1: The Age of Classical Ciphers (Hands-On)

We begin our journey in the ancient world, with some of the earliest recorded uses of cryptography. Participants will get their hands dirty with classical &quot;pen-and-paper&quot; ciphers, starting with the famed Caesar cipher, a simple substitution method used by Julius Caesar for his private correspondence. We&apos;ll discuss the vulnerabilities of these early systems, such as their susceptibility to frequency analysis (a groundbreaking cryptanalytic technique developed by Arab scholar Al-Kindi around the 9th century). This section will involve hands-on exercises where attendees will encrypt and decrypt messages using these classical methods and even attempt to break them.

Part 2: The Mechanical and Early Digital Revolution (Demonstration and Puzzles)

This segment explores the leap to more complex cryptographic machinery. We will discuss the pivotal role of devices like the Enigma machine during World War II and the monumental efforts to crack its codes, which laid some of the foundational theory for modern computing. The workshop will then transition to the dawn of the digital age with the introduction of the Data Encryption Standard (DES), the first cryptosystem certified for use by the US Government. To make this era tangible, we will engage with interactive puzzles that simulate the logic of these more complex systems.

Part 3: The Dawn of Public-Key Cryptography (Conceptual and Practical)

A revolutionary shift in cryptography came with the concept of asymmetric keys. We will demystify public-key cryptography, explaining how the use of a public and private key pair solved the age-old problem of secure key exchange. The principles behind RSA and Diffie-Hellman will be explained in an accessible manner, focusing on the one-way mathematical functions that make them secure. Participants will engage in a practical exercise to understand how public and private keys are used to encrypt and decrypt information, providing a foundational understanding of the technology that underpins much of modern secure communication, including TLS/SSL.

Part 4: The Quantum Frontier (Discursive and Forward-Looking)

The final hour will be a discursive exploration of the future of cryptography in the face of quantum computing. We will discuss why current cryptographic standards like RSA and AES are vulnerable to the power of quantum computers. The session will introduce the fundamental concepts of quantum cryptography and Quantum Key Distribution (QKD), explaining how they leverage the principles of quantum mechanics to offer a new paradigm of secure communication. The aim is to provide an intuitive, high-level understanding of this next evolution in cryptography, sparking a conversation about the challenges and opportunities that lie ahead.

Throughout the workshop, the emphasis will be on interaction, discussion, and hands-on learning. Participants will leave not only with a historical perspective but also with a practical feel for the cryptographic concepts that have shaped and will continue to shape our world.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/3D797U/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/3D797U/feedback/</feedback_url>
            </event>
            <event guid='777d5c17-7c3c-5f01-8666-5e6ff9542d98' id='7' code='QPQTVJ'>
                <room>Uni Campus Seminarhaus 1</room>
                <title>A phishing trip with Fancy Bear - Let&apos;s analyze APT malware together!</title>
                <subtitle></subtitle>
                <type>Workshop (4 hours)</type>
                <date>2026-09-11T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>04:00</duration>
                <abstract>In this beginner-friendly, hands-on workshop, participants will walk through the full attack chain of a real-world Fancy Bear (APT28/GRU) intrusion - from the initial phishing email to command &amp; control - guided by a purpose-built interactive training platform.

What to expect:
The workshop is structured across five chapters, each building on the last: threat actor background, payload delivery, exploitation, persistence &amp; installation, and command &amp; control. Participants work hands-on with real artefacts (phishing email headers, a weaponised RTF document, malware samples, and a C2 implant) and answer quiz questions via an interactive platform to validate their findings along the way - making progress immediately visible and keeping the session engaging for all skill levels.

What you will learn:
- How to analyse phishing emails and extract indicators from mail headers
- How to identify and dissect malicious Office documents (including MIME type mismatches and OLE/COM object abuse triggering CVE-2026-21509)
- Persistence techniques: file staging, scheduled task abuse, and LSB steganography in PNG files
- How to reverse simple string obfuscation (XOR + Base64) using CyberChef
- How threat actors repurpose legitimate open-source tools (Covenant C2 framework) and abuse trusted cloud services to blend into normal traffic
- All tools demoed/used throughout the workshop (e.g. oletools, CyberChef, and Covenant) are free and open-source, making every technique immediately reproducible.

Who should attend:
No prior malware analysis experience is required. Basic familiarity with the command line and a curiosity for how attacks actually work is all you need. Security students, CTF players, sysadmins, and blue teamers looking to build intuition for real-world threat actor tradecraft will get the most out of this session.

What to bring:
A laptop with a browser and internet access. All you need is a web brower, a text editor and an archive tool to unpack ZIP (AES-256) archives - other than that, no prior setup is required.</abstract>
                <slug>call-for-paper-workshops-2026-7-a-phishing-trip-with-fancy-bear-let-s-analyze-apt-malware-together</slug>
                <track></track>
                
                <persons>
                    <person id='4'>Marius Genheimer</person>
                </persons>
                <language>en</language>
                <description>This workshop does not depend on domain-specific knowledge, we will try to break the steps down as far as possible. Attendees will follow along through small exercises, with the opportunity to compare their solution through a validation system.

Important for message for attendees: If you would like to follow along, please bring laptop with a charged battery. You will be handling real-world malware (you act at your own risk; No backup, no pity). I recommend to use a virtual machine (e.g. FLARE-VM, Remnux). No special tooling is required, make sure to have the basics (Text and Hex Editor, Browser, ZIP utility) installed. No photos during the workshop please, you will receive a copy of the slides.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/QPQTVJ/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/QPQTVJ/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Uni Campus Seminarhaus 2' guid='41d98ac0-b29b-56ec-88d3-348ea4747f47'>
            <event guid='15515d7e-884c-54f3-8212-c7c12914a21d' id='81' code='PZBMJX'>
                <room>Uni Campus Seminarhaus 2</room>
                <title>Introduction to Physical Security Testing</title>
                <subtitle></subtitle>
                <type>Workshop (4 hours)</type>
                <date>2026-09-11T09:00:00+02:00</date>
                <start>09:00</start>
                <duration>04:00</duration>
                <abstract>Join us for an interactive half-day workshop where you&apos;ll learn the essential techniques of physical security testing. This session covers key skills such as lock picking, door bypass methods, and cloning insecure access cards. Gain hands-on experience as you practice these techniques and hear real-world access attempts from experienced Red Teamers. Enhance your understanding of physical security measures and test your newfound skills on our Cover Access Vault (CAV).</abstract>
                <slug>call-for-paper-workshops-2026-81-introduction-to-physical-security-testing</slug>
                <track></track>
                
                <persons>
                    <person id='79'>Nico Leidecker</person><person id='80'>Harris Nuhanovi&#263;</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/PZBMJX/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/PZBMJX/feedback/</feedback_url>
            </event>
            <event guid='127e58af-aac9-599b-afe4-ed5048e05522' id='86' code='39S7AD'>
                <room>Uni Campus Seminarhaus 2</room>
                <title>Desktop Application Pentesting 101 for Security Professionals</title>
                <subtitle></subtitle>
                <type>Workshop (4 hours)</type>
                <date>2026-09-11T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>04:00</duration>
                <abstract>Desktop applications, also known as fat or thick clients, remain a business-critical attack surface in many enterprise environments, especially in finance, insurance, and pharmaceuticals. Testing them requires a different approach than classic web application testing: reverse engineering client-side functionality, understanding proprietary protocols, and analyzing backend communication. This hands-on training introduces a practical methodology for assessing Java desktop applications from initial analysis to backend exploitation. Participants will reverse engineer a demo application, inspect its network communication, build a custom pentest client, and use it to identify and exploit server-side vulnerabilities.</abstract>
                <slug>call-for-paper-workshops-2026-86-desktop-application-pentesting-101-for-security-professionals</slug>
                <track></track>
                
                <persons>
                    <person id='87'>Jakob Steeg</person><person id='106'>Tim Kranz</person>
                </persons>
                <language>en</language>
                <description>This workshop gives security professionals practical experience with desktop application penetration testing. After a short introduction and environment setup, participants learn how to fingerprint technologies, decompile a Java client, analyze client-server communication, and understand why backend systems often represent the real security boundary. The core hands-on part focuses on building a custom client that communicates directly with the backend, bypassing limitations of the original application. Participants then use this client and the knowledge gained from static and network-level analysis to hunt for vulnerabilities and exploit them in a realistic lab environment.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/39S7AD/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/39S7AD/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Uni Campus Seminarhaus 3' guid='9d30d8ff-77dc-5836-a98a-1c7c1be1fe7d'>
            <event guid='b55daae2-1343-5550-ab02-c2cf1277c45a' id='88' code='KPBKUP'>
                <room>Uni Campus Seminarhaus 3</room>
                <title>Defending Microsoft Entra ID: Common Attacks, Tokens, and Response Planning</title>
                <subtitle></subtitle>
                <type>Workshop (4 hours)</type>
                <date>2026-09-11T09:00:00+02:00</date>
                <start>09:00</start>
                <duration>04:00</duration>
                <abstract>Microsoft Entra ID is a major target for attackers and a core part of modern incident response. SOC analysts must understand cloud identity from initial access, persistence, privilege abuse, and lateral movement. Understanding Active Directory alone is not enough.

This 4-hour session gives defenders a practical understanding of how Entra ID works and how it is abused. It covers identity types, hybrid authentication, OAuth and OIDC, application objects and service principals, token types, Conditional Access, and key attack paths including device code phishing, attacker-in-the-middle, and refresh token replay. It also discusses Entra sign-in logs, the Graph API and its logs, sign-in session tracking, and practical KQL-based hunting.

Attendees will run KQL queries to identify suspicious activity and execute &apos;attacks&apos; in a lab environment.</abstract>
                <slug>call-for-paper-workshops-2026-88-defending-microsoft-entra-id-common-attacks-tokens-and-response-planning</slug>
                <track></track>
                
                <persons>
                    <person id='89'>Ethan Bowen</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/KPBKUP/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/KPBKUP/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Uni Campus Seminarhaus 4' guid='0b658738-690d-5dd9-9423-590d96b894a5'>
            <event guid='5dfa0a55-c300-54a8-b524-15e9a0eeee6f' id='53' code='AGWT9L'>
                <room>Uni Campus Seminarhaus 4</room>
                <title>Hunting Supply Chain Attacks: Hands-on Anaysis of npm, PyPI, and VS Code Threats</title>
                <subtitle></subtitle>
                <type>Workshop (4 hours)</type>
                <date>2026-09-11T09:00:00+02:00</date>
                <start>09:00</start>
                <duration>04:00</duration>
                <abstract>Software supply chain attacks have become one of the most significant threats to organizations, with nation-state actors like DPRK&apos;s Lazarus Group, and TeamPCP actively compromising npm packages, PyPI libraries, GitHub repositories, and VS Code extensions to target developers and steal credentials, cryptocurrency, and source code. This hands-on training equips security teams with practical skills to detect, analyze, and extract actionable threat intelligence from real-world supply chain malware&#8212;turning raw malware samples into finished intelligence products.</abstract>
                <slug>call-for-paper-workshops-2026-53-hunting-supply-chain-attacks-hands-on-anaysis-of-npm-pypi-and-vs-code-threats</slug>
                <track></track>
                <logo>/media/call-for-paper-workshops-2026/submissions/AGWT9L/Screenshot_2026_hFzI1i1.png</logo>
                <persons>
                    <person id='57'>Paul McCarty</person>
                </persons>
                <language>en</language>
                <description>Participants will work directly with sanitized samples from active campaigns including Contagious Interview (BeaverTail/InvisibleFerret), Glassworm, and TeamPCP/Miasma.  The attendees will analyze malicious artifacts across four major attack surfaces: npm, PyPI, GitHub, and VS Code extensions. Beyond technical analysis, attendees will learn the trainers custom software supply chain CTI workflow: extracting IOCs,  pivoting across infrastructure to identify campaign scope, attributing activity to threat actors, , producing actionable reports and alerting the community to the threats you expose. The training culminates with a live hunting session where participants apply their new skills to hunt for real threats and document findings using professional intelligence standards.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/AGWT9L/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/AGWT9L/feedback/</feedback_url>
            </event>
            <event guid='d7ae9b3f-b7b2-50b4-a362-0bccda80bcbc' id='55' code='DQTFAG'>
                <room>Uni Campus Seminarhaus 4</room>
                <title>Rustacean Introduction to Shellcoding</title>
                <subtitle></subtitle>
                <type>Workshop (4 hours)</type>
                <date>2026-09-11T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>04:00</duration>
                <abstract>Write your first position-independent implant with the Rust programming language from scratch! Learn how to resolve common issues, parse PE headers, and leave with your code at the end.</abstract>
                <slug>call-for-paper-workshops-2026-55-rustacean-introduction-to-shellcoding</slug>
                <track></track>
                
                <persons>
                    <person id='53'>Ben</person>
                </persons>
                <language>en</language>
                <description>How to implement your next shellcode or implant using the Rust programming language. The workshop will cover the following:

- A brief introduction to Rust.
- Key challenges during shellcode development and how to resolve them.
- A brief introduction to Windows and parsing PE headers.
- Short introduction on loader design.
- Creation of fully position-independent code (PIC).

**What do you need and what will be provided:**
- Baseline library code will be provided. 
- Basic ability to write and read Rust code will be helpful but is not required.
- You will need to bring a Windows VM to the workshop. 
- This VM should have X64dbg (64-bit) installed. 
- You will also need the ability to transfer files from and to it. 
- A development container (Docker) for cross-compiling Rust will be provided.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/DQTFAG/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/DQTFAG/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
