DEF CON

Conference talks, webinars, and technical sessions from our team.

Breaking the Oracle: Building an Offensive Security Toolkit for OCI
OCInferno
DEF CON 34

Scott Weston

Breaking the Oracle: Building an Offensive Security Toolkit for OCI

Oracle Cloud Infrastructure (OCI) is arguably one of the lesser-explored major cloud platforms from an offensive security perspective. While OCI shares many...

Ham Radio – Licensed to Experiment by Dan Norte | HRV @ DEF CON 34
DEF CON 34

Dan Norte

Ham Radio – Licensed to Experiment by Dan Norte | HRV @ DEF CON 34

The most common question we hear in the village is, “What can I do now that I’m licensed?” N0OPS and W0BDP attempt...

We Know What You Did (in Azure) Last Summer
DEF CON 33

Karl Fosaaen

Thomas Elling

We Know What You Did (in Azure) Last Summer

At DEF CON 33, NetSPI's Karl Fosaaen and Thomas Elling revealed how Azure resources leak ownership information at scale and shared a...

SSH-nanigans: Busting Open Mainframes Iron Fortress with Unix
DEF CON 33

Philip Young

Chad Rikansrud

SSH-nanigans: Busting Open Mainframes Iron Fortress with Unix

At DEF CON 33, NetSPI's Philip Young and Broadcom's Chad Rikansrud took mainframe exploitation to the z/OS Unix side with live demos...

Def Con 32 – GCPwn | Scott Weston
DEF CON 32

Scott Weston

Def Con 32 – GCPwn | Scott Weston

At Def Con 32, NetSPI Senior Security Consultant Scott Weston talked about his new tool, GCPwn. Get full access to his slide...

The Immortal Retrofuturism of Mainframe Computers & How to Keep Them Safe
Mainframe Retrofuturism
DEF CON 32

Michelle Eggers

The Immortal Retrofuturism of Mainframe Computers & How to Keep Them Safe

At Def Con 32, NetSPI Security Consultant Michelle Eggers made the case for why mainframes remain mission-critical today and shared five trusted...

DEF CON 32 | Identity Theft is Not a Joke, Azure!
DEF CON 32

Karl Fosaaen

DEF CON 32 | Identity Theft is Not a Joke, Azure!

At Def Con 32, NetSPI VP of Research Karl Fosaaen explored the risks hiding inside Azure Managed Identities and demonstrated a tool...

My Callsign Is My Passport Responsible Testing & Disclosure Of Amateur Radio Websites
DEF CON 31

Dan Norte

My Callsign Is My Passport Responsible Testing & Disclosure Of Amateur Radio Websites

Amateur radio websites / web applications are notorious for terrible / non-existence information security practices and there’s normally no budget to get...