Presentations & Talks
Conference talks, webinars, and technical sessions from our team.
Philip Young
At VSC 2026, NetSPI's Mainframe Director Philip Young shares a clear picture of what a modern mainframe pentest looks like, how to...
David Bryan
Michelle Eggers
At VSC 2026, NetSPI Mainframe experts Michelle Eggers & David Bryan cover how MCP interacts with live TN3270 sessions, what prompting strategies...
Philip Young
David Bryan
NetSPI Mainframe experts Phil Young & David Bryan explore why fundamental security controls remain poorly implemented despite being technically feasible for decades....
Scott Weston
Oracle Cloud Infrastructure (OCI) is arguably one of the lesser-explored major cloud platforms from an offensive security perspective. While OCI shares many...
Dan Norte
The most common question we hear in the village is, “What can I do now that I’m licensed?” N0OPS and W0BDP attempt...
Karl Fosaaen
Thomas Elling
The increase in hybrid cloud adoption over the last decade has extended traditional Active Directory domain environments into the Azure (and Entra...
Scott Weston
At Def Con 32, NetSPI Senior Security Consultant Scott Weston talked about his new tool, GCPwn. Get full access to his slide...
Scott Weston
Oracle Cloud Infrastructure (OCI) delivers a cloud platform comparable to AWS and Google Cloud, yet its IAM and security model seems to...
Larry Trowell
Sam. Beaumont
At the Chaos Communication Congress (39C3), NetSPI's Sam Beaumont and Larry Trowell demonstrated RayV Lite, bringing affordable laser fault injection within reach...
Philip Young
Chad Rikansrud
At DEF CON 33, NetSPI's Philip Young and Broadcom's Chad Rikansrud took mainframe exploitation to the z/OS Unix side with live demos...
Karl Fosaaen
Thomas Elling
At DEF CON 33, NetSPI's Karl Fosaaen and Thomas Elling revealed how Azure resources leak ownership information at scale and shared a...
Philip Young
At BSides Las Vegas 2025, NetSPI's Philip Young broke down how to write a winning conference CFP and start giving talks.
Philip Young
Chad Rikansrud
At Black Hat USA 2025, NetSPI's Philip Young and Broadcom's Chad Rikansrud explored the dark side of z/OS Unix System Services.
Scott Sutherland
Jake Karnes
At Black Hat USA 2025, NetSPI's Scott Sutherland and Jake Karnes made the case for moving from reactive defense to proactive threat...
Larry Trowell
Sam. Beaumont
At BSides Las Vegas 2025, NetSPI's Sam Beaumont and Larry Trowell demonstrated affordable, light-based hardware attack tooling, putting laser fault injection within...
NetSPI Labs
At BSides Las Vegas 2025, NetSPI's Leo Pate III shared how to make the leap from individual contributor to cybersecurity leader.
Joe Evangelisto
At the International Cyber Risk Summit 2025, NetSPI's Joe Evangelisto detailed the principles and practices of Continuous Threat Exposure Management (CTEM) for...
Sam Kirkman
At Infosecurity Europe 2025, NetSPI's Sam Kirkman made the case for Continuous Threat Exposure Management (CTEM) over reactive, 'thoughts and prayers' security.
Larry Trowell
Sam. Beaumont
At BSides Tokyo 2025, NetSPI's Sam Beaumont and Larry Trowell demonstrated affordable, light-based hardware attack tooling that rivals far more expensive lab...
Scott Sutherland
At SpecterOps SO-CON 2025, NetSPI's Scott Sutherland shared data-driven techniques to identify, attack, and remediate SMB shares in Active Directory using PowerHuntShares.
Nick Lynch
At the Cloud & Cyber Security Expo 2025, NetSPI's Nicholas Lynch shared proactive cloud security strategies and real-world attack scenarios for securing...
Kurtis Shelton
At the Aprés Cyber Slopes Summit 2025, NetSPI's Kurtis Shelton reframed AI vulnerabilities as gradients rather than absolutes and made the case...
Sam Kirkman
At Black Hat Europe 2024, NetSPI's Sam Kirkman laid out a proactive security playbook for moving beyond reactive, alert-driven programs toward lasting...
Sam Kirkman
At the Enterprise AI Security Transformation Assembly Europe 2024, NetSPI's Sam Kirkman charted a course toward proactive security and away from reactive,...
Team NetSPI
At BSides Portland 2024, NetSPI's Shane Kell showed how to proxy and manipulate traffic on a smart rowing machine to expose its...
Karl Fosaaen
Thomas Elling
At BSides Portland 2024, NetSPI's Karl Fosaaen and Thomas Elling dove into Azure Function App security, privilege escalation paths, and a tool...
Michelle Eggers
Over the years mainframe developers have seen fit to make almost everything a web app. From Abend Aid to z/OSMF, there’s no...
Nabil Hannan
At InfoSec World 2024, NetSPI Field CISO Nabil Hannan broke down how attackers trick AI/ML systems and how to elevate your security...
Philip Young
At Vanguard Security & Compliance 2024, NetSPI's Philip Young delivered a keynote on a decade of mainframe hacking research and how the...
Michelle Eggers
At Vanguard Security & Compliance 2024, NetSPI's Michelle Eggers explored how web applications on the mainframe introduce OWASP-style risks that can lead...
Philip Young
At Vanguard Security & Compliance 2024, NetSPI's Philip Young demonstrated CICS application penetration testing using the open-source hack3270 tool against the Damn...
Philip Young
NetSPI's Philip Young showed that mainframe buffer overflows are real, demonstrating how to hunt and exploit them in APF-authorized libraries.
Michelle Eggers
In this presentation from BSides Saskatoon 2024, security consultant Michelle Eggers explores the practical application of ethical hacking through the lens of...
Michelle Eggers
At Def Con 32, NetSPI Security Consultant Michelle Eggers made the case for why mainframes remain mission-critical today and shared five trusted...
Scott Weston
At Def Con 32, NetSPI Senior Security Consultant Scott Weston talked about his new tool, GCPwn. Get full access to his slide...
Karl Fosaaen
At Def Con 32, NetSPI VP of Research Karl Fosaaen explored the risks hiding inside Azure Managed Identities and demonstrated a tool...
Michelle Eggers
At BSides Las Vegas 2024, NetSPI's Michelle Eggers made the case for why mainframes remain mission-critical today and shared five trusted solutions...
Larry Trowell
Sam. Beaumont
At Black Hat USA 2024, NetSPI's Sam Beaumont and Larry Trowell demonstrated affordable, light-based hardware attack tooling that puts laser fault injection...
Vinay Anand
Tom Parker
At Black Hat USA 2024, NetSPI's Vinay Anand and Tom Parker showed how pairing EASM with CAASM advances continuous threat and exposure...
Dan Norte
Amateur radio websites / web applications are notorious for terrible / non-existence information security practices and there’s normally no budget to get...