Uploaded April 2025 | Updated September 2026, 2 weeks ago
🔗 Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences — wildwesthackinfest.com
🔗 Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com
Over the years, I've managed to get into numerous security and other conferences, and this talk will share some of the most intriguing stories of how I did it.
By using a mix of social engineering, reconnaissance, insider knowledge, and quick thinking, I was able to navigate these events successfully.
Social engineering played a key role, where I manipulated human psychology to gain access, often by exploiting the natural tendency to trust authority or the desire to be helpful.
Reconnaissance was crucial, as gathering information about the event and its organizers helped me identify potential entry points.
Quick thinking allowed me to adapt to unexpected situations, such as changes in security protocols.
Throughout these experiences, I carefully considered the ethical implications, ensuring my actions didn't harm others or violate laws.
I'll share specific stories where I gained entry by posing as an authority figure or creating a believable scenario to gain trust.
Each experience taught me valuable lessons about human behavior and security vulnerabilities, highlighting the need for increased awareness and training in cybersecurity to defend against such tactics. This talk emphasizes the importance of ethical considerations in using social engineering techniques.
00:00 - Welcome, intro
02:41 - Agenda
02:53 - AWS Reinvent Dave Kennedy impersonation
03:14 - Social Engineering basics
03:53 - Impersonation
09:48 - Kevin Mitnick interview - impersonating the Press
12:47 - Ethical considerations
13:33 - Professional ethics / reputation
13:59 - Benefits of paying
14:33 - Psycological Factors
16:05 - Emotional Toll
20:04 - Technical Tactics
21:27 - Ethical and Practical Summary
22:43 - Story Time - Jason Street, Diet Soda explosion
23:57 - B-Sides Pool Party
25:15 - Trespassed at MJBizCon
27:40 - Q&A - Most recent exploit?
30:26 - Q&A - When were you most nervous about being caught?
33:35 - Q&A - Scary stories where you went too far?
36:05 - Q&A - It hurts to get caught lying
36:24 - Q&A - Faking a QR Code badge
37:18 - Q&A - Sneaking into a boring, formal FedCon
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
🔗 Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences — wildwesthackinfest.com
🔗 Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com
Over the years, I've managed to get into numerous security and other conferences, and this talk will share some of the most intriguing stories of how I did it.
By using a mix of social engineering, reconnaissance, insider knowledge, and quick thinking, I was able to navigate these events successfully.
Social engineering played a key role, where I manipulated human psychology to gain access, often by exploiting the natural tendency to trust authority or the desire to be helpful.
Reconnaissance was crucial, as gathering information about the event and its organizers helped me identify potential entry points.
Quick thinking allowed me to adapt to unexpected situations, such as changes in security protocols.
Throughout these experiences, I carefully considered the ethical implications, ensuring my actions didn't harm others or violate laws.
I'll share specific stories where I gained entry by posing as an authority figure or creating a believable scenario to gain trust.
Each experience taught me valuable lessons about human behavior and security vulnerabilities, highlighting the need for increased awareness and training in cybersecurity to defend against such tactics. This talk emphasizes the importance of ethical considerations in using social engineering techniques.
00:00 - Welcome, intro
02:41 - Agenda
02:53 - AWS Reinvent Dave Kennedy impersonation
03:14 - Social Engineering basics
03:53 - Impersonation
09:48 - Kevin Mitnick interview - impersonating the Press
12:47 - Ethical considerations
13:33 - Professional ethics / reputation
13:59 - Benefits of paying
14:33 - Psycological Factors
16:05 - Emotional Toll
20:04 - Technical Tactics
21:27 - Ethical and Practical Summary
22:43 - Story Time - Jason Street, Diet Soda explosion
23:57 - B-Sides Pool Party
25:15 - Trespassed at MJBizCon
27:40 - Q&A - Most recent exploit?
30:26 - Q&A - When were you most nervous about being caught?
33:35 - Q&A - Scary stories where you went too far?
36:05 - Q&A - It hurts to get caught lying
36:24 - Q&A - Faking a QR Code badge
37:18 - Q&A - Sneaking into a boring, formal FedCon
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com










