Loading…
Attending this event?
Streaming: https://mssvideo.vcu.edu/RVAsec
101 [clear filter]
Tuesday, June 4
 

11:00am EDT

Secure Legends GameDay - A Cloud Security Danger Room
The Secure Legends GameDay experience provides an interactive learning exercise for security professionals to develop practical skills for protecting cloud environments. We will explore real-world security scenarios that might include compromised credentials, data leaks, instance breaches, infrastructure attacks, and vulnerable CI/CD pipelines.

During this session, we’ll solve one of the challenges together in realtime and I’ll explain the mitigation tactics as you work in your own environments. No cloud environments needed, no cloud bill to pay at the end, and no sign up necessary! You’ll get temporary access to a real environment where you can actually build.

As an added bonus, you’ll also get to walk away with limited-time access to that cloud account and to additional challenges you can solve after the session!  

Speakers
avatar for AM Grobelny

AM Grobelny

Developer Advocate, Amazon Web Services
I've spent the past 10+ years working on or helping people work on software. I was also a professional educator previously in my career, so I have a particular passion for helping people more easily understand difficult concepts. I currently work at AWS, and I'm focused on helping... Read More →


Tuesday June 4, 2024 11:00am - 11:15am EDT
1st Floor, Magnolia Room

1:00pm EDT

Its Coming From Inside the House: A Guide to Physical Facility Penetration Testing
Physical security is crucial to any organization; however, physical security sometimes takes a back seat. Many companies still maintain a physical office presence, and protecting employees working from the office, along with other critical assets is vitally important as protecting networks. An attacker gaining access into a building through social engineering or other means of physical entry could jeopardize those critical assets and employee’s safety. Attackers may access unattended workstations, open file cabinets, server rooms, or other information inside the organization. Skilled attackers may only need a few moments to slip into a building and plant a remote access device on the network without anyone noticing they were in the building.

Speakers
avatar for Ariyan Suroosh

Ariyan Suroosh

Senior Security Consultant, Optiv
Ariyan Bakhti-Suroosh is a senior security consultant on the Attack and Penetration team under Optiv’s Threat Management divison. Ariyan has a diverse background in information technology caused by an exigent curiosity for how things work. Ariyan has over 5 years of experience in... Read More →


Tuesday June 4, 2024 1:00pm - 1:50pm EDT
1st Floor, Magnolia Room

2:00pm EDT

The ABCs of DevSecOps
Application Security is the most oft-ignored, yet critically vulnerable attack vector in many businesses today.  Development teams are encouraged to create new features first and foremost, at the expense of fixing vulnerabilities.  It’s not until a breach or an audit finding when they pay attention to patching security holes.  

So how does a thoughtful CISO get in front of this?

Application security has to exist across the application lifecycle. DevSecOps is the philosophy of imbuing proper security controls at every stage of the Software Development Lifecycle (SDLC).  This session will introduce you to core DevSecOps concepts so you can bring them back to your company and make some proactive changes to “drive defects left” and reduce the risk of a catastrophic security breach in your applications

Speakers
avatar for Steve Pressman

Steve Pressman

President and CTO, Alpine Cyber Solutions
Steve is an experienced computer systems and security architect with a passion for standards-based security and compliance; cloud computing; and DevSecOps. He brings over a decade of experience in the defense industry, working for multiple federal defense contractors, and has directly... Read More →


Tuesday June 4, 2024 2:00pm - 2:50pm EDT
Ballroom A/B

3:00pm EDT

Embracing My Inner Cyber Wizard To Defeat Impostor Syndrome
Impostor syndrome is a psychological phenomenon that makes you feel like a fraud, despite your achievements and qualifications. It can affect your confidence, performance, and well-being. In this talk, We will discuss Impostor Syndrome and I will share my Infosec journey and how I’ve worked on minimizing the effects of Impostor Syndrome over the course of my career. I will go into detail about the concept of the Hacker Grimoire and how it and a focus on documentation in general helped me to challenge my Impostor Syndrome. Additionally, We’ll take a peek into my Hacker Grimoire and also give you tips on how to get started with your own.

Speakers
avatar for Corey Brennan

Corey Brennan

Sr. Information Security Engineer, Virginia529
Ever since he blew a capacitor installing a Cd drive and causing a small fire in his first self-built computer, Corey has been obsessed with computer systems and how they work. After 13 years in the Infosec industry wearing just about every hat, from being in a SOC to hunting threats... Read More →


Tuesday June 4, 2024 3:00pm - 3:50pm EDT
Ballroom C/D

4:00pm EDT

Improv Comedy for Social Engineering
This workshop that introduces the techniques used in Improv Comedy and applies them to skills used in the OFFSEC field to enable the participants to better communicate, think on their feet, and gain confidence when operating in the unknown.

Speakers
avatar for Ross Merritt

Ross Merritt

Security Consultant, Blue Bastion
Ross Merritt is a U.S. Marine Corps Veteran, Former Private Investigator, Performing Comedian, and a Cyber Security Consultant at Blue Bastion specializing in Social Engineering and OSINT.


Tuesday June 4, 2024 4:00pm - 4:50pm EDT
1st Floor, Magnolia Room
 
Wednesday, June 5
 

10:30am EDT

Quickstart To Building Your Own Private AI Chat
Join our quick start guide to building your very own Private AI! In this presentation, we'll explore the key differences between Public and Private AI and the components needed for success. You'll get hands-on experience setting up your development environment, preparing data for training, and using popular libraries to train a simple AI model. We'll also discuss best practices in AI development and provide guidance on evaluating and fine-tuning performance. Don't miss this opportunity to take control of your very own AI and build a system tailored to your unique needs and goals. Join us for an engaging and informative session that will empower you to start building your Private AI today!

Speakers
avatar for Samuel Panicker

Samuel Panicker

Chief Information Security Officer, Networking Technologies and Support
Samuel S. Panicker specializes in cyber security and data protection. He is currently the CISO for NTS with over twenty-six years of experience in the field. Sam has authored several security awareness programs for SANS and Black Hat including “A healthy level of paranoia”.


Wednesday June 5, 2024 10:30am - 11:20am EDT
Ballroom C

11:30am EDT

Mindfulness, Meditation, and Cybersecurity
We are meant to enjoy our lives; both personal, and professional. As human beings, and as professionals, we all have to learn how to cultivate even-mindedness, balance, and fortitude to meet life/work challenges. Cybersecurity is fascinating because it requires us to constantly learn, and find ways to optimize our process. Burnout is a huge problem many fields, but especially in Cybersecurity. Cultivating a mindfulness or meditation practice is one of the most efficient ways we can support our process, and manage the stress and anxiety that comes with our professional and personal lives.

The focus of this talk is not specifically on work, because it addresses thoughtful ways to approach every aspect of our lives from our mental and physical health, to our relationships both personally and professionally. Whether new to the industry or a seasoned veteran, this talk with give you some insights, guidance, and the opportunity to practice.

Speakers
avatar for Aqeel Yaseen

Aqeel Yaseen

Associate Security Consultant, Blue Bastion / Ideal Integrations
Aqeel Yaseen transitioned into Offensive Security from over a decade of teaching yoga professionally, and is currently working with Blue Bastion Security. That might seem like a curious combination, but Pentesting and teaching yoga both help people cultivate awareness of blind spots... Read More →


Wednesday June 5, 2024 11:30am - 12:20pm EDT
Ballroom D

1:00pm EDT

Social Engineering the Social Engineers: How To Not Suck at Buying Software
There is a huge gap in security and that gap is understanding the process for acquiring security tools. After buying security tools as an architect and selling as a sales engineer I know the process, pitfalls and gaps in the process. We will dive into the process for both sides. You will learn how you should be architecting your program and winning budget for those tools. We will also explore what happens on the sales side of deal. I will explain what to look out for and what you can take advantage of and the common mistakes we make.

Sales people are top tier social engineers we will explore how to hack them.

Speakers
avatar for David Girvin

David Girvin

Senior solutions engineer, sumo logic
Hacker, BJJ enthusiast, world traveler and surfer. I am a giant weirdo who somehow found my niche in offensive security. I have been blessed getting to build AppSec programs for companies like 1Password and Red Canary. I have an extremely diverse background and hope I can relate and... Read More →


Wednesday June 5, 2024 1:00pm - 1:50pm EDT
1st Floor, Magnolia Room

2:00pm EDT

API-ocalypse
Get ready for a wild ride as Jennifer Shannon, a Senior Security Consultant at Secure Ideas, takes the stage to present "API-ocalypse" In this thrilling and entertaining session, Jennifer will showcase the vulnerabilities lurking within APIs and the havoc they can wreak if left unaddressed. Through live pentesting demos, she will demonstrate jaw-dropping exploits, mind-bending injection attacks, and authentication bypass techniques that will leave you on the edge of your seat. Join Jennifer as she navigates the dark side of API’s to help you understand and fortify your attack surface in order to prevent the impending API-ocalypse.

Speakers
avatar for Jennifer Shannon

Jennifer Shannon

Senior Security Consultant, Secure Ideas, LLC
Jennifer Shannon is a Senior Security Consultant at Secure Ideas with a background in malware analysis, penetration testing, and training. An avid computer geek for most of her life, she began her journey in cybersecurity as a SOC Analyst where she showed an aptitude for both penetration... Read More →


Wednesday June 5, 2024 2:00pm - 2:50pm EDT
1st Floor, Magnolia Room
 
Filter sessions
Apply filters to sessions.