Exploring attack paths across AWS, Azure, GCP and OCI. Learn to dissect misconfigurations through graph-mode visualization, map potential attack paths, and implement practical mitigation using open-source tools. Elevate your defense strategy and fortify cloud environments against evolving threats.
I've been working as Head of Identity Threat Labs and Global Product Advocate at Segura, Founder at Black&White Technology, Cybersecurity Advocate, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies... Read More →
Friday May 9, 2025 9:00am - 9:45am EDT The Mill & Mine227 W Depot Ave, Knoxville, TN 37917
How can security teams stay ahead of 24/7 cyber threats? This talk explores AI-driven SOAR tools that combine intelligent decision-making with automation. Learn how AI enables dynamic workflows, automates after-hours responses, and empowers SOCs to reduce alert fatigue and improve response times.
Kevin Sistrunk is an accomplished cybersecurity professional with extensive experience in Security Orchestration, Automation, and Response (SOAR), incident response, and IT security engineering. Throughout his career, Kevin has worked with high-profile organizations such as Synchrony... Read More →
Friday May 9, 2025 9:00am - 9:45am EDT Regas Square Events333 W Depot Ave, Suite 120, Knoxville, TN 37917
After a decade in consulting roles like software engineer and penetration tester, I joined an open-source company to secure its 300+ repositories across numerous platforms. This session highlights key vulnerabilities and lessons learned, with actionable advice for attendees of all backgrounds.
Lorenzo is currently a Staff Product Security Engineer at Mattermost where his responsibilities include security testing, security reviews, secure coding training, bug bounty program, security champions program, security automation, and more. Prior to his role at Mattermost he spent... Read More →
Friday May 9, 2025 10:00am - 10:45am EDT The Mill & Mine227 W Depot Ave, Knoxville, TN 37917
Your Active Directory environment is a vast dungeon filled with hidden traps, cursed artifacts, and deceptive illusion spells. This talk uncovers lesser-known attack paths that let adversaries bypass defenses and plunder your domain's treasures. Will you be the DM - or the next victim of a TPK?
Eric Kuehn is a Principal security consultant at Secure Ideas, where he leverages his extensive experience with Microsoft infrastructures and Active Directory to perform penetration tests and red team assessments. He also teaches a course, Red Team Fundamentals for Active Directory... Read More →
Friday May 9, 2025 10:00am - 10:45am EDT Regas Square Events333 W Depot Ave, Suite 120, Knoxville, TN 37917
For years, cybersecurity leaders have been caught in a cycle of compliance—chasing checkboxes, aligning to frameworks, and struggling to keep up with ever-changing regulations. But here’s the real question: Are these standards making us more secure, or just more compliant?
Russell is a Managing Partner at Cyverity, an information security consulting firm specializing in governance and fractional CISO based in Venice, Florida. He is the former CIO and CISO of the Federal Reserve Bank of Atlanta and Principal Instructor and Author with the SANS Institute... Read More →
Friday May 9, 2025 11:00am - 11:15am EDT The Mill & Mine227 W Depot Ave, Knoxville, TN 37917
"The Digital Certificate is like your Driver's License" This short talk goes into some common misconfigurations of Digital Certificates found in the wild. Quick Examples: Exposed Mail Servers, HTTP redirects, and faulty firewalls.
As a technical trainer and security researcher, it is my goal to spread awareness and knowledge. Experience includes: lecturing about cybersecurity, moderating open discussions about vulnerabilities, and building hacking labs for students. Like many others, I often delve too deep... Read More →
Friday May 9, 2025 11:00am - 11:45am EDT Regas Square Events333 W Depot Ave, Suite 120, Knoxville, TN 37917
Ready to reign in rogue robots? Let's use our hive mind to sting them where it hurts in the circuits. Fuzz sensors, pwn software, lace AI with venom. Crack firmware hives, jam RF, shred control loops. Join the swarm at BSides Knoxville for an electrifying hack fest that'll make bots scatter!
KweenB is an ethical hacker and security researcher with a passion for buzzing into the frontiers of cybersecurity. Known for her hands-on research into vulnerabilities, KweenB fuels a hive mind of inspiration, sparking bold, visionary ideas that elevate the hacking community. With... Read More →
Friday May 9, 2025 11:15am - 11:30am EDT The Mill & Mine227 W Depot Ave, Knoxville, TN 37917
Dave has 30 years of industry experience. He has extensive experience in IT security operations and management. Dave is the Global Advisory CISO for 1Password.He is the founder of the security site Liquidmatrix Security Digest & podcast. He is currently a member of the board of directors... Read More →
Friday May 9, 2025 1:00pm - 1:45pm EDT The Mill & Mine227 W Depot Ave, Knoxville, TN 37917
Tired of running the same commands over and over? Wish your notes didn't look like a crime scene? Bash scripting can automate the boring, streamline engagements, and save your butt when things go sideways. Come learn how to hack smarter, not harder, because pentesting should be fun, not tedious!
Adam Compton has been a programmer, researcher, instructor, professional pentester, father, husband, and farmer. Adam has over 2 decades of programming, network security, incident response, security assessment, and penetration testing experience. Throughout Adam's career, he has worked... Read More →
Friday May 9, 2025 2:00pm - 2:45pm EDT The Mill & Mine227 W Depot Ave, Knoxville, TN 37917
Watch a deepfake built live on stage—and understand what you're really up against. This practical, technical session reveals the nuts-and-bolts of deepfake creation, uncovers security implications, and arms you with actionable strategies for detection and defense.
David Hawthorne is Director of Cloud Engineering at O3 Solutions, a growth stage SaaS startup, where he oversees cloud, data, DevOps, security, and compliance. Before joining O3, he served as a data architect for a SaaS healthcare venture. When he’s not coding cloud infrastructure... Read More →
Friday May 9, 2025 2:00pm - 2:45pm EDT Regas Square Events333 W Depot Ave, Suite 120, Knoxville, TN 37917
The misuse of open-source red-teaming tools by cybercriminals and nation-states is rising, turning security assets into attack vectors. Tools like Sliver are exploited for advanced threats. Our AI methodology analyzes high-risk tools, enabling organizations to detect/mitigate threats proactively.
Stephen Hilt is a Sr. Threat Researcher at Trend Micro. Stephen focuses on General Security Research, Threat Actors, Malware behind attacks, and Industrial Control System Security. Stephen enjoys breaking things and putting them back together with a few extra parts to spare. Stephen... Read More →
Friday May 9, 2025 3:00pm - 3:45pm EDT The Mill & Mine227 W Depot Ave, Knoxville, TN 37917
Are the kids alright? Get a look behind the curtain at what attacks are seen in local K12 schools and how schools can defend with limited staffing and limited budgets. We'll look at insider attacks, recon, enumeration, password spray, MFA sweep, and a demo of bypassing MFA with stolen cookies.
Friday May 9, 2025 3:00pm - 3:45pm EDT Regas Square Events333 W Depot Ave, Suite 120, Knoxville, TN 37917
Modern disassemblers are awesome, but assemblers today are little better than they were in the nineties. I'm fixing that by writing one that easily ports to new architectures, saving me a ton of work in embedded systems exploitation.
Grateful to be back in Knoxville, Travis Goodspeed spends his days reverse engineering electronics and editing the International Journal of PoC||GTFO. He drives a fleet of Studebakers and enjoys developing X-rays in his home dark room.
Friday May 9, 2025 4:00pm - 4:45pm EDT The Mill & Mine227 W Depot Ave, Knoxville, TN 37917
The cyber talent shortage is a lie. Orgs can't hire and retain enough cyber talent because they're wasting it. Engineers are burning out because they're doing the wrong kinds of work. In this talk, we show security leaders and engineers how to think differently and fix this problem forever.
Alex Humphrey is a passionate cybersecurity leader and speaker who spent the last 10 years enabling organizations to achieve their business goals securely. He specializes in understanding and solving complex security problems by taking in to account their proper organizational context... Read More →
Friday May 9, 2025 4:00pm - 4:45pm EDT Regas Square Events333 W Depot Ave, Suite 120, Knoxville, TN 37917
In an era of increasing data breaches, inadequate security isn't just a technical gap, it's a legal ticking time bomb. Learn how seemingly small oversights in access control and data protection can expose businesses to crippling liability, and discover practical steps to minimize your risk.
## Introduction
Businesses of every size are under mounting pressure to protect sensitive data. When an organization's security posture is weak, especially in areas like access control or policy enforcement, the legal consequences can be swift and severe. In this talk, we'll dissect the intersection of cybersecurity and liability, revealing the most common pitfalls that can leave businesses exposed to lawsuits, regulatory fines, and reputational damage.
## Why This Topic Matters
The growing complexity of cybersecurity means that many organizations overlook the legal implications of their security posture. Often, executives view security as a purely technical concern, until an incident happens, and the legal fallout is severe. This session aims to illuminate how specific security failures, especially around access control and privilege management, can directly translate into legal liability.
## What You'll Learn
1. Legal Frameworks & Regulations
Overview of relevant U.S. and international laws, from data protection regulations (GDPR, HIPAA) to newer legislation targeting corporate accountability (such as the SEC's cybersecurity rules).
2. Common Failure Points
How poorly enforced access policies, insider threats, and deficient incident response protocols create liability.
3. Case Studies & Lessons Learned
Real-world examples showcasing the severe financial, operational, and reputational consequences for companies that failed to protect sensitive data.
4. Risk Mitigation Tactics
Best practices for building robust access controls, continuous monitoring, and governance frameworks that stand up in court and regulatory investigations.
## Who Should Attend?
This talk is geared toward anyone responsible for or interested in cybersecurity risk management, security engineers, IT managers, CISOs, compliance officers, and legal professionals. By integrating both the technical and legal viewpoints, attendees will gain a holistic understanding of the steps required to protect not just their data, but their entire organization from crippling liability.
Phishing attacks remain one of the most successful tactics used to get into an organization. In this presentation, we'll dive into the art and science of building an engaging, effective phishing program. The presentation will include real-world examples and stories from running and internal program.
Senior Software Security Engineer, Exploring Information Security
In the vast, uncharted expanse of the digital frontier, I proudly hold the title of Head of Security Exploration and Innovation at Exploring Information Security. Think of me as the cybersecurity equivalent of an intergalactic explorer, but with fewer spaceships and more firewalls... Read More →
Friday May 9, 2025 5:00pm - 5:45pm EDT Regas Square Events333 W Depot Ave, Suite 120, Knoxville, TN 37917