BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidesfrankfurt.org//call-for-paper-workshops-2026//
 speaker//AZCMAT
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-call-for-paper-workshops-2026-KPBKUP@cfp.bsidesfrankfurt.org
DTSTART;TZID=CET:20260911T090000
DTEND;TZID=CET:20260911T130000
DESCRIPTION:Microsoft Entra ID is a major target for attackers and a core p
 art of modern incident response. SOC analysts must understand cloud identi
 ty from initial access\, persistence\, privilege abuse\, and lateral movem
 ent. Understanding Active Directory alone is not enough.\n\nThis 4-hour se
 ssion gives defenders a practical understanding of how Entra ID works and 
 how it is abused. It covers identity types\, hybrid authentication\, OAuth
  and OIDC\, application objects and service principals\, token types\, Con
 ditional Access\, and key attack paths including device code phishing\, at
 tacker-in-the-middle\, and refresh token replay. It also discusses Entra s
 ign-in logs\, the Graph API and its logs\, sign-in session tracking\, and 
 practical KQL-based hunting.\n\nAttendees will run KQL queries to identify
  suspicious activity and execute 'attacks' in a lab environment.
DTSTAMP:20260921T165835Z
LOCATION:Uni Campus Seminarhaus 3
SUMMARY:Defending Microsoft Entra ID: Common Attacks\, Tokens\, and Respons
 e Planning - Ethan Bowen
URL:https://cfp.bsidesfrankfurt.org/call-for-paper-workshops-2026/talk/KPBK
 UP/
END:VEVENT
END:VCALENDAR
