What Trading Systems Taught Me About Breaking (And Defending) Infrastructure - Mert SatilmazSteelCon2026-09-20 | What Trading Systems Taught Me About Breaking (And Defending) Infrastructure - Mert SatilmazWere In... Jail.A Collection Of Stories Of Cyber Criminals Failing To Crime by Scott McGreadySteelCon2023-08-13 | ...Closing Ceremony by SteelCon OrganisersSteelCon2023-08-07 | ...Im In Your Pipes, Stealing Your Secrets by Iain SmartSteelCon2023-08-07 | ...Detecting And Blocking With BPF Via YAML by Kev SheldrakeSteelCon2023-08-07 | ...Raiders Of The Lost Arts by Stefan HagerSteelCon2023-08-07 | ...An Offensive Perspective Of Ransomware Operations by Chris TruncerSteelCon2023-08-07 | ...Nuclear Hack Simulation With Airbus Protects CyberRange by Nathan PooleySteelCon2023-08-07 | ...Hunting For Bugs That Scanners Miss, And WAFs Fail To Detect by Ayoub SafaSteelCon2023-08-07 | ...The Non-Tech Stuff I Wasnt Prepared For by Ian DaviesSteelCon2023-08-07 | ...You Missed A Period Dont Panic Why Words Matter by Alice McGreadySteelCon2023-08-07 | ...Decoding The Maze Of Malware Detection by Sarah WhiteSteelCon2023-08-07 | ...Beyond Microsoft IIS Short File Name Disclosure by Soroush DaliliSteelCon2023-08-07 | ...Protecting Kubernetes Clusters With Object Validation & Admission Controllers by Nishaanth KumarSteelCon2023-08-07 | ...How Being A Javascript CTF Challenge Creator Has Helped Me At Reverse-Engineering by Maya BoeckhSteelCon2023-08-07 | ...Adversaries Have It Easy. Live FAFO Pnwing A Network by Andy Gill & Neil LinesSteelCon2023-08-07 | This video contains some very strong language.Opening by SteelCon OrganizersSteelCon2023-08-07 | ...Delivering The Fail, The Post Office IT Scandal by Brian WheltonSteelCon2023-07-16 | ...Hacking A Treadmill For Fame And Profit by Soroush DaliliSteelCon2022-07-26 | When lockdown happened, Treadmills were like gold dust as people were trying to avoid all public places to remain safe. Although some 31337 people could attend work events (i.e. partied hard), almost everyone else had to obey the law; so many of us were looking for exercise devices inside our safe places to remain sane & perhaps healthy. I finally found a treadmill which had all my favourite features such as Netflix support & a placeholder for my burger & coke, but soon I realised Disney+ is the one I really needed which was unfortunately missing. This talk is a fun walk through of me figuring out how to use a treadmill, how I performed an environmental breakout to get root access to the device, and how I managed to completely pwn its control server and got my treadmill’s cost back by reporting its vulnerabilities to its bug bounty program.Debugging Cordava Applications by Nishaanth Kumar GSteelCon2022-07-26 | Being able to develop reliable, stealthy and size efficient malware is something that has been necessary during our various offensive security engagements. In this talk we will go through how we systematically improved our offensive capabilities in order to successfully bypass and subvert industry leading EDR solutions. We will take you through the various steps we have taken in order to write smaller sized payloads, whilst maintaining stealth and reliability. This talk should help our audience design and start building more efficient payloads that can be used safely, with a very small chance of detection.Closing by SteelCon OrganizersSteelCon2022-07-26 | Closing talk, prize give aways, thank yous and general silliness.Murder! Mossad? Watching SE Experts, Literally Getting Away With Murder by Chris PritchardSteelCon2022-07-26 | We’re often asked, how can I watch or see Social Engineering (SE) in person so I can learn from an expert. The answer is, with difficultly. Until now. In 2010, what appears to be Mossad performed an operation in a foreign country. Most of which was captured on CCTV and published.
We’ve taken the CCTV footage and broken down multiple sections to highlight and show various SE techniques in the wild. These are important, but also simple techniques that really work. They worked so well that they literally got away with murder.
Some key points that will be covered are matching dress styles (to look like a hotel employee), reconnaissance, building your pre-text (and matching outfit to support that pre-text) and interacting with other people (members of the public and hotel staff) to prevent access to areas the attackers wanted kept quiet.
All of these are important tools to learn and use, which can help you make a start in social engineering and are the exact tools I’ve used many times to successfully gain access to places I definitely shouldn’t be.How To Enhance Your Cybersecurity Career Through Regional Alliances by Gary HibbardSteelCon2022-07-26 | Gary Hibberd of UKC3 and the YCSC will discuss how your involvement in regional cyber security clusters can help with peer-to-peer networking, knowledge-sharing, and the formation of strategic partnerships. Giving you access to the best cyber security opportunities in your region to help accelerate your career.Taming Horses For Combat by Sina KheirkhahSteelCon2022-07-26 | Memory horse is a method of fileless attack which removes the traditional web shell file upload, this technique introduces memory webshell abusing runtime components, the concepts is applicable Java, PHP, Python, and more, this technique is not limited to one language.Security Vulnerabilities That (Mostly) Aren’t by David LodgeSteelCon2022-07-26 | The penetration testing industry has a problem, one that is not only ignored by people within the industry but actively exploited: a lot of its output is rubbish. We have testers taught to list vulnerabilities that aretheoretical, have never been exploitable or are no longer relevant. Our tools aid in this by looking for these cheap findings and inflating their risk scores.
This practice wastes hours across the industry in documenting, screenshotting, writing reports, justifying, Googling and fixing. Yet it ultimately does not improve security.
This talk will go through some of the most common “useless” findings explaining the history, problem and what we, as an industry, need to evaluate to make our jobs more worthwhile. And also, when it is actually appropriate to raise these findings.
Expect disparaging of HTTP headers, CVSS scoring, tools with banners, TLS ciphers and other sundry security findings.Writing Tiny, Efficient, And Reliable Malware by Rad KawarSteelCon2022-07-26 | Being able to develop reliable, stealthy and size efficient malware is something that has been necessary during our various offensive security engagements. In this talk we will go through how we systematically improved our offensive capabilities in order to successfully bypass and subvert industry leading EDR solutions. We will take you through the various steps we have taken in order to write smaller sized payloads, whilst maintaining stealth and reliability. This talk should help our audience design and start building more efficient payloads that can be used safely, with a very small chance of detection.Deep Dive Into Kubernetes Attack Surface & How To Defend Against Cloud Native Ecosystem by Sadi ZaneSteelCon2022-07-26 | Attacking and defending on-premises and cloud-based Kubernetes services. This talk discusses Kubernetes security and several attack vectors that could allow an attacker to compromise an on-premises, managed cloud-based Kubernetes services. The goal with this talk is to demonstrate how an attacker and defend against attacks an on-premises, cloud-based Kubernetes services.Finding Zero Days In WordPress Plugins And Themes And Testing Beyond WPScan by Noman RiffatSteelCon2022-07-26 | WordPress compromises 43% of World Wide Web Applications and testing a WordPress based site is very common during client engagement. Most pentesters rely on WPScan and OSINT for WordPress but is that it? An above average pentester will replicate the installed WordPress and Plugins on local environment and try to look for vulnerabilities. This talk will be very beneficial for those pentesters as I will narrow down thousands of lines of codes to specific functions and hooks to look for when doing code review. Majority of the WordPress plugins and themes exploits are based on the techniques that will be discussed along with test cases.Catch Me If You Can: Hiding Web Shell From WAF by Manish Kishan TanwarSteelCon2022-07-26 | Being able to develop reliable, stealthy and size efficient malware is something that has been necessary during our various offensive security engagements. In this talk we will go through how we systematically improved our offensive capabilities in order to successfully bypass and subvert industry leading EDR solutions. We will take you through the various steps we have taken in order to write smaller sized payloads, whilst maintaining stealth and reliability. This talk should help our audience design and start building more efficient payloads that can be used safely, with a very small chance of detection.P4ssw0rds!!!!111 by Richard HicksSteelCon2022-07-26 | Your company has a cracking rig with some chunky GPUs and you’ve obtained some hashes. So you grab your largest wordlists, your biggest mutation rule sets, and you kick off a job, returning a few hours later to collect your rewards.
If this sounds like you, maybe you’ll benefit from a different approach. As someone who used to help run and maintain his previous employer’s cracking rig, Rich is no stranger to the horrors hidden in the depths of the assumed knowledge that is password cracking. Join him as he boldly goes where many password crackers may have gone before. Yep, this probably isn’t going to be groundbreaking stuff here, but I hope at least some aspect of it will be useful for you. We’ll briefly cover why’s and basics for those not familiar with some of the tooling, get into it with dictionaries and run through some other tools and techniques you may want to consider using along with covering some of the benefits of auditing password hygiene within your corporate estate. I hope after the 50 minutes is up you’ll walk away with some cool new tidbit to add into your password cracking methodology.X-Com: Editing Savegame Files Is Still Strategy: Redux by Paul WilliamsSteelCon2022-07-26 | A Talk on the process of reverse engineering the old school XCOM save game file format to make it easier to win… who says tampering with the save isn’t a legit strategy“I’ll Take Hacking For $100.” Keeping Your CTF Costs Out Of Jeopardy by James BolandSteelCon2022-07-26 | Running a capture the flag event can look intimidating and complex, there’s so many things to keep track of, and worst of all it costs a fortune! With real life experiences I will demonstrate that you don’t need a family member’s inheritance to fund your idea.
This talk will cover aspects of running a CTF including, scope, design, infrastructure, and logistics. We’ll go though untangling the complexities of running an event without being overly technical. Using my experiences and painful life lessons, I will demonstrate my CTF successes and failures over the years. On top of all that, I have some neat tricks on how to save money.
If you’ve ever been interested in what it takes to start a CTF from the beginning, all the way to closing ceremonies and beyond, this talk is for you.Friend Or Foe? by Jess AmerySteelCon2022-07-26 | Do you think you could tell the difference between a real and artificial face? With social engineering attempts taking common place in our day-to-day lives we have to ask ourselves who really is behind the profile picture.
While you can now generate an entirely new online persona with the click of a button this presentation will take a deep dive into advancements in artificially-generated imagery. We will look at how easy it truly is to differentiate between real and fake faces, how we can use technology to detect Friend’s from Foe’s and how current advancements in neural networks and artificially-generated imagery may change social engineering as we, currently, recognise it.Can You Detect This? Inside The Ransomware Operator’s Toolkit by Peter OSteelCon2022-07-26 | Have you ever wondered how those indicators of compromise relate to a ransomware attack? This talk will provide practical guidance on common ransomware tools and techniques observed from The DFIR Report Cases. I’ll share detection opportunities and some threat hunting techniques for detecting attacker hands-on keyboard activities.
This presentation will not provide academic thoughts or theory. All details are based on ‘Real Intrusions by Real Attackers, The Truth Behind the Intrusion’. It will serve as a practical guide for defenders to understand a typical attack, the common tools utilised by ransomware operators throughout the intrusion, why tools are utilised, and the different techniques leveraged. I’ll share some of the detection quick wins, and resources that are available to assist and prepare against ransomware attacks.
The topics we will explore are:
* Review of common tools and techniques * Ransomware attack objectives * Mapping an attack to detection opportunities * Understanding human behaviours * Spotting the adversary… unusual activities * Useful resources for defenders * This presentation will benefit both newcomers and experienced professionals who need to understand the ransomware threat and how to detect and respond to intrusions.Windows Credential Theft: A Primer by Keith LearmonthSteelCon2022-07-26 | Once an attacker has entered an environment, usually the most important step for them is to start stealing credentials. This gives them leverage over the network: they can pivot across the infrastructure, get higher privileges, maintain persistence, etc. This talk is an introduction to the various components that make up Windows credentials (hashes, tickets, tokens, etc), how attackers steal and use them (with some real-world examples) and some of the ways Windows has added protections from XP onwards. All levels of experience welcome!How To Kill A Russian Commander In 20 Minutes Or Less by Ian Thornton-Trump and Philip IngramSteelCon2022-07-26 | Russian Commanders have been successfully eliminated by Ukraine forces at an astounding success rate – this success is likely the result of NATO/EU “behind the scenes” assistance in Intelligence Surveillance Targeting and Reconnaissance (ISTAR) missions combined with other Electronic Warfare and Ukraine cyber capabilities. Join Phat_Hobbt for his talk which explains the electronic & cyber battlefield and how after years of tracking & eliminating insurgency and terrorist leaders the same techniques were unleashed on the unsuspecting Russian Commanders. Within this talk “Commander” Hobbit will discuss the Russian Global Cyber War that never – we hope – happened.Paving The Way To DA: A Live (Hopefully) Path Of Pwnage by Andy Gill And Neil LinesSteelCon2022-07-26 | While the security world lusts over the latest and greatest exploits and techniques, some old but gold techniques continue to work and allow attackers on your network to elevate, traverse and attack critical systems. This talk will take you, the audience, through various paths to elevated positions within a network; the aim is to perform several attack paths as live demos(we’ll record some ahead of time in case the demo gods hate us! or the world burns down during our talk).
Andy and Neil will walk through some familiar and lesser-known attacks in a live hack scenario environment simulating an insider threat within a fictional network of a fictional corp. They will discuss and show some techniques for data harvesting, traversal and exploitation of misconfigurations in the said environment to gain the Crown Jewels of sensitive information and domain/enterprise administrator.Intro And Welcome by SteelCon OrganizersSteelCon2022-07-26 | Welcome to SteelCon 2022SteelCon 2019 LT: Novel VM Detection Tricks - Graham SutherlandSteelCon2019-07-15 | ...SteelCon 2019 LT: People Are The Solution! - Scot StoreySteelCon2019-07-15 | ...SteelCon 2019 LT: The Problem With DNS - Joshua GregorySteelCon2019-07-15 | ...SteelCon 2019: How Not To Be As Stupid As Ransomware Authors - Sarah WhiteSteelCon2019-07-15 | ...SteelCon 2019: Closing - SteelCon OrganizersSteelCon2019-07-15 | ...SteelCon 2019: Rage Against The FUD - The Beer FarmersSteelCon2019-07-15 | ...SteelCon 2019: Getting Splunky With Kerberos - Ross Bingham and Tom MacDonaldSteelCon2019-07-14 | ...SteelCon 2019: The LANs That Time Forgot - Brian WheltonSteelCon2019-07-14 | ...SteelCon 2019 Track 2SteelCon2019-07-14 | Live stream of track 2 of SteelCon 2019 Schedule: steelcon.info/the-event/talk-scheduleSteelCon 2019: TLS 1.3 For Penetration Testers - Richard MooreSteelCon2019-07-13 | ...SteelCon 2019: State Of Cybersecurity Report - Extended Play - Dan RaywoodSteelCon2019-07-13 | ...SteelCon 2019: Using Networking With People - Stuart SmilesSteelCon2019-07-13 | ...SteelCon 2019: Steal These Ideas - Stefan HagerSteelCon2019-07-13 | ...