Uploaded April 2025 | Updated September 2026, 2 weeks ago
🔗 Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences — wildwesthackinfest.com
🔗 Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com
This talk shares our journey building a custom SOAR-like solution for Microsoft Sentinel that 1) combines full-code flexibility with low-code simplicity, and 2) overcomes the limitations of Logic Apps in performance, maintainability, and debugging. Learn about architecture and design decisions, integrations, limitations and other lessons we learned when building our SOAR.
00:00 - Welcome, Intro
00:47 - Automation in Sentinel (Microsoft’s SIEM)
01:21 - Sending Sentinel incidents to SNOW with LogicApps
01:58 - LogicApp pitfalls
02:53 - Difficult to debug
03:03 - Stability issues
04:08 - Variable email times
05:10 - How to do it better
09:59 - Architecture Iteration 1 overview
11:41 - Architecture Iteration 1 issues not fixed
12:44 - New issues introduced
13:27 - Sentinel Automation limitations and workarounds
16:24 - Architecture Iteration 2 overview
16:41 - Architecture Iteration 2 results
18:09 - Architecture Iteration 3 overview
20:11 - Architecture Iteration 3 results
21:16 - Storing enrichment data in Sentinel
23:51 - Entity normalization
28:57 - Caching considerations
32:03 - Architecture Iteration 4 goals and explanations
33:13 - Triggering custom actions from the dashboard
35:27 - Recursive enrichments
36:20 - Playbook support
36:35 - JINT
37:18 - Improve reliability
38:15 - Polly
40:05 - Conclusion
40:54 - Q&A - How much is written in LogicApps?
41:16 - Q&A - Azure spend - LogicApps vs code
41:47 - Q&A - What does Microsoft say about the unreliability of LogicApps?
42:14 - Q&A - How to handle sentinel delaying the addition of entities to an incident or alert?
42:58 - Q&A - What was the transition process? How long did it take?
43:41 - Q&A - Are customers surprised at the amount of Sentinel automation required?
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
🔗 Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences — wildwesthackinfest.com
🔗 Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com
This talk shares our journey building a custom SOAR-like solution for Microsoft Sentinel that 1) combines full-code flexibility with low-code simplicity, and 2) overcomes the limitations of Logic Apps in performance, maintainability, and debugging. Learn about architecture and design decisions, integrations, limitations and other lessons we learned when building our SOAR.
00:00 - Welcome, Intro
00:47 - Automation in Sentinel (Microsoft’s SIEM)
01:21 - Sending Sentinel incidents to SNOW with LogicApps
01:58 - LogicApp pitfalls
02:53 - Difficult to debug
03:03 - Stability issues
04:08 - Variable email times
05:10 - How to do it better
09:59 - Architecture Iteration 1 overview
11:41 - Architecture Iteration 1 issues not fixed
12:44 - New issues introduced
13:27 - Sentinel Automation limitations and workarounds
16:24 - Architecture Iteration 2 overview
16:41 - Architecture Iteration 2 results
18:09 - Architecture Iteration 3 overview
20:11 - Architecture Iteration 3 results
21:16 - Storing enrichment data in Sentinel
23:51 - Entity normalization
28:57 - Caching considerations
32:03 - Architecture Iteration 4 goals and explanations
33:13 - Triggering custom actions from the dashboard
35:27 - Recursive enrichments
36:20 - Playbook support
36:35 - JINT
37:18 - Improve reliability
38:15 - Polly
40:05 - Conclusion
40:54 - Q&A - How much is written in LogicApps?
41:16 - Q&A - Azure spend - LogicApps vs code
41:47 - Q&A - What does Microsoft say about the unreliability of LogicApps?
42:14 - Q&A - How to handle sentinel delaying the addition of entities to an incident or alert?
42:58 - Q&A - What was the transition process? How long did it take?
43:41 - Q&A - Are customers surprised at the amount of Sentinel automation required?
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
![Build your Sh*tty Add-On With KiCad For Your Electronic Badges! | Adrien Lasalle
Build your Sh*tty Add-On With KiCad For Your Electronic Badges!
Speaker: Adrien Lasalle, NetRunSecurity
Learn how to use KiCad, the free and open-source PCB design software, to create Shitty Add-Ons (SAOs) — fun, custom PCBs that enhance cybersecurity conference badges and hardware hacking projects.
This session is perfect for anyone interested in DIY electronics, badge hacking, and PCB design for beginners. Step by step, you’ll go from an idea to a fully orderable PCB you can solder, light up, and show off.
What You’ll Learn in This KiCad Tutorial 🎓
• Designing Schematics in KiCad – start building your custom circuits
• PCB Layout Techniques – create neat, functional PCBs for SAOs
️ • SAO Design Rules – understand constraints for badge mods
• Exporting Gerber Files – prepare files for PCB manufacturing
• Ordering Your PCB – get it delivered to your door, ready to solder
Who This Session is For
• Beginners learning KiCad and PCB design
• Hardware hackers and makers creating custom badge add-ons
• Electronics enthusiasts exploring DIY electronics, open-source hardware, and PCB prototyping
By the end, you’ll know how to design SAOs that light up, stand out, or just make people laugh — perfect for hardware villages, hacker meetups, and cybersecurity cons.
00:00 Introduction – Building SAOs with KiCad
00:50 Talk Overview & Agenda
01:11 What is KiCad? Open-Source PCB Design
03:07 What is a Shitty Add-On (SAO)?
06:49 Planning Your SAO Design
07:10 Starting a KiCad Project
08:04 Creating the Schematic in KiCad
09:32 Assigning Component Footprints
10:25 Importing the Schematic into the PCB Editor
10:10 SAO Connector Considerations
11:49 Routing Connections on the PCB
13:19 Exporting Gerber Files for Fabrication
15:41 Hardware Orientation & Assembly Considerations
19:03 Audience Q&A and Final Discussion
Register for Wild West Hackin’ Fest Denver 2026 🏔️
Join us at one of the most hands-on cybersecurity conferences for makers, hackers, and electronics enthusiasts!
👉 Registration: [Wild West Hackin Fest @ Mile High 2026 - Wild West Hackin Fest]
https://wildwesthackinfest.com/register
#KiCad #PCBDesign #SAO #ShittyAddon #BadgeLife #BadgeHacking #HardwareHacking #CybersecurityConference #DIYElectronics #MakerCommunity #OpenSourceHardware #PCBLayout #GerberFiles #ElectronicsDIY #WildWestHackinFest #WWFHF2026
///Black Hills Infosec Socials
Twitter: https://twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: https://www.linkedin.com/company/antisyphon-training
Discord: https://discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: https://www.blackhillsinfosec.com/services/active-soc/
Penetration Testing: https://www.blackhillsinfosec.com/services/
Incident Response: https://www.blackhillsinfosec.com/services/incident-response/
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: https://www.backdoorsandbreaches.com/
Play B&B Online: https://play.backdoorsandbreaches.com/
///Antisyphon Training
Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/
Live Training: https://www.antisyphontraining.com/course-catalog/
On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/
Antisyphon Discord: https://discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/
Wild West Hackin Fest YouTube: https://www.youtube.com/wildwesthackinfest
Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining
Active Countermeasures YouTube: https://youtube.com/activecountermeasures
Threat Hunter Community Discord: https://discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin Fest: https://wildwesthackinfest.com/ Build your Sh*tty Add-On With KiCad For Your Electronic Badges! | Adrien Lasalle](https://i.ytimg.com/vi/zWdMP8SkagY/mqdefault.jpg)