Presentations & Talks

Conference talks, webinars, and technical sessions from our team.

Busting Mainframe Pentest Myths: What Really Happens  Start to Finish
VSC 2026

Philip Young

Busting Mainframe Pentest Myths: What Really Happens Start to Finish

At VSC 2026, NetSPI's Mainframe Director Philip Young shares a clear picture of what a modern mainframe pentest looks like, how to...

Teaching AI to Hack CICS: Hack3270, MCP, and Source-Assisted Pentesting
VSC 2026

David Bryan

Michelle Eggers

Teaching AI to Hack CICS: Hack3270, MCP, and Source-Assisted Pentesting

At VSC 2026, NetSPI Mainframe experts Michelle Eggers & David Bryan cover how MCP interacts with live TN3270 sessions, what prompting strategies...

Same Findings, Different Mainframes: z/OS Security Trends from 2026
VSC 2026

Philip Young

David Bryan

Same Findings, Different Mainframes: z/OS Security Trends from 2026

NetSPI Mainframe experts Phil Young & David Bryan explore why fundamental security controls remain poorly implemented despite being technically feasible for decades....

Breaking the Oracle: Building an Offensive Security Toolkit for OCI
OCInferno
DEF CON 34

Scott Weston

Breaking the Oracle: Building an Offensive Security Toolkit for OCI

Oracle Cloud Infrastructure (OCI) is arguably one of the lesser-explored major cloud platforms from an offensive security perspective. While OCI shares many...

Ham Radio – Licensed to Experiment by Dan Norte | HRV @ DEF CON 34
DEF CON 34

Dan Norte

Ham Radio – Licensed to Experiment by Dan Norte | HRV @ DEF CON 34

The most common question we hear in the village is, “What can I do now that I’m licensed?” N0OPS and W0BDP attempt...

Modern Adventures in Azure Privilege Escalation
TROOPERS26

Karl Fosaaen

Thomas Elling

Modern Adventures in Azure Privilege Escalation

The increase in hybrid cloud adoption over the last decade has extended traditional Active Directory domain environments into the Azure (and Entra...

OCInferno: An Offensive Security Toolkit for OCI
OCInferno
fwd:cloudsec North America 2026

Scott Weston

OCInferno: An Offensive Security Toolkit for OCI

At Def Con 32, NetSPI Senior Security Consultant Scott Weston talked about his new tool, GCPwn. Get full access to his slide...

Breaking the Oracle: Building an Offensive Security Toolkit for OCI
OCInferno
BSides San Diego 2026

Scott Weston

Breaking the Oracle: Building an Offensive Security Toolkit for OCI

Oracle Cloud Infrastructure (OCI) delivers a cloud platform comparable to AWS and Google Cloud, yet its IAM and security model seems to...

CCC 2025 – Laser Beams & Light Streams: Building Affordable Light-Based Hardware Security Tooling
Laser Beams
CCC (39C3) 2025

Larry Trowell

Sam. Beaumont

CCC 2025 – Laser Beams & Light Streams: Building Affordable Light-Based Hardware Security Tooling

At the Chaos Communication Congress (39C3), NetSPI's Sam Beaumont and Larry Trowell demonstrated RayV Lite, bringing affordable laser fault injection within reach...

SSH-nanigans: Busting Open Mainframes Iron Fortress with Unix
DEF CON 33

Philip Young

Chad Rikansrud

SSH-nanigans: Busting Open Mainframes Iron Fortress with Unix

At DEF CON 33, NetSPI's Philip Young and Broadcom's Chad Rikansrud took mainframe exploitation to the z/OS Unix side with live demos...

We Know What You Did (in Azure) Last Summer
DEF CON 33

Karl Fosaaen

Thomas Elling

We Know What You Did (in Azure) Last Summer

At DEF CON 33, NetSPI's Karl Fosaaen and Thomas Elling revealed how Azure resources leak ownership information at scale and shared a...

So You Want to Give A Talk: How to Write a CFP
BSides Las Vegas 2025

Philip Young

So You Want to Give A Talk: How to Write a CFP

At BSides Las Vegas 2025, NetSPI's Philip Young broke down how to write a winning conference CFP and start giving talks.

Unix Underworld: The Dark Side of z/OS
Black Hat USA 2025

Philip Young

Chad Rikansrud

Unix Underworld: The Dark Side of z/OS

At Black Hat USA 2025, NetSPI's Philip Young and Broadcom's Chad Rikansrud explored the dark side of z/OS Unix System Services.

Hunt or Be Hunted: Moving from Reactive Defense to Proactive Threat & Exposure Management
Black Hat USA 2025

Scott Sutherland

Jake Karnes

Hunt or Be Hunted: Moving from Reactive Defense to Proactive Threat & Exposure Management

At Black Hat USA 2025, NetSPI's Scott Sutherland and Jake Karnes made the case for moving from reactive defense to proactive threat...

Laser Beams & Light Streams: Letting Hackers Go Pew Pew
Laser Beams
BSides Las Vegas 2025

Larry Trowell

Sam. Beaumont

Laser Beams & Light Streams: Letting Hackers Go Pew Pew

At BSides Las Vegas 2025, NetSPI's Sam Beaumont and Larry Trowell demonstrated affordable, light-based hardware attack tooling, putting laser fault injection within...

Beyond the Command Line: Transitioning from Individual Contributor to Leader
BSides Las Vegas 2025

NetSPI Labs

Beyond the Command Line: Transitioning from Individual Contributor to Leader

At BSides Las Vegas 2025, NetSPI's Leo Pate III shared how to make the leap from individual contributor to cybersecurity leader.

Proactive Defense: Mastering CTEM | Joe Evangelisto (CISO)
International Cyber Risk Summit 2025

Joe Evangelisto

Proactive Defense: Mastering CTEM | Joe Evangelisto (CISO)

At the International Cyber Risk Summit 2025, NetSPI's Joe Evangelisto detailed the principles and practices of Continuous Threat Exposure Management (CTEM) for...

Threat Exposure Management: Because ‘Thoughts & Prayers’ Isn’t a Security Strategy
Infosecurity Europe 2025

Sam Kirkman

Threat Exposure Management: Because ‘Thoughts & Prayers’ Isn’t a Security Strategy

At Infosecurity Europe 2025, NetSPI's Sam Kirkman made the case for Continuous Threat Exposure Management (CTEM) over reactive, 'thoughts and prayers' security.

Laser Beams & Light Streams: Building Affordable Light-Based Hardware Security Tools
Laser Beams
BSides Tokyo 2025

Larry Trowell

Sam. Beaumont

Laser Beams & Light Streams: Building Affordable Light-Based Hardware Security Tools

At BSides Tokyo 2025, NetSPI's Sam Beaumont and Larry Trowell demonstrated affordable, light-based hardware attack tooling that rivals far more expensive lab...

SpecterOps SO-CON 2025 – Hunting SMB Shares | Scott Sutherland
SpecterOps SO-CON 2025

Scott Sutherland

SpecterOps SO-CON 2025 – Hunting SMB Shares | Scott Sutherland

At SpecterOps SO-CON 2025, NetSPI's Scott Sutherland shared data-driven techniques to identify, attack, and remediate SMB shares in Active Directory using PowerHuntShares.

AI-pocalypse Averted: Proactive Cloud Security Strategies
Cloud & Cyber Security Expo 2025

Nick Lynch

AI-pocalypse Averted: Proactive Cloud Security Strategies

At the Cloud & Cyber Security Expo 2025, NetSPI's Nicholas Lynch shared proactive cloud security strategies and real-world attack scenarios for securing...

Understanding the Gradient of AI Vulnerabilities
Aprés Cyber Slopes Summit 2025

Kurtis Shelton

Understanding the Gradient of AI Vulnerabilities

At the Aprés Cyber Slopes Summit 2025, NetSPI's Kurtis Shelton reframed AI vulnerabilities as gradients rather than absolutes and made the case...

Building a Proactive Security Playbook for Lasting Cyber Resilience
Black Hat Europe 2024

Sam Kirkman

Building a Proactive Security Playbook for Lasting Cyber Resilience

At Black Hat Europe 2024, NetSPI's Sam Kirkman laid out a proactive security playbook for moving beyond reactive, alert-driven programs toward lasting...

Charting the Course: Navigating Proactive Security | Sam Kirkman
Enterprise AI Securit Assembly Europe 2024

Sam Kirkman

Charting the Course: Navigating Proactive Security | Sam Kirkman

At the Enterprise AI Security Transformation Assembly Europe 2024, NetSPI's Sam Kirkman charted a course toward proactive security and away from reactive,...

Rudder Nonsense: Steering Smart Rowers Off Course
BSides Portland 2024

Team NetSPI

Rudder Nonsense: Steering Smart Rowers Off Course

At BSides Portland 2024, NetSPI's Shane Kell showed how to proxy and manipulate traffic on a smart rowing machine to expose its...

What the Function: A Deep Dive into Azure Function App Security
BSides Portland 2024

Karl Fosaaen

Thomas Elling

What the Function: A Deep Dive into Azure Function App Security

At BSides Portland 2024, NetSPI's Karl Fosaaen and Thomas Elling dove into Azure Function App security, privilege escalation paths, and a tool...

Shared Threats: Web Application Vulnerabilities and the z/OS Environment
TechXchange 2024

Michelle Eggers

Shared Threats: Web Application Vulnerabilities and the z/OS Environment

Over the years mainframe developers have seen fit to make almost everything a web app. From Abend Aid to z/OSMF, there’s no...

GenAI Gone Wild: How Threat Actors Attack AI and How You Can Stop Them
InfoSec World 2024

Nabil Hannan

GenAI Gone Wild: How Threat Actors Attack AI and How You Can Stop Them

At InfoSec World 2024, NetSPI Field CISO Nabil Hannan broke down how attackers trick AI/ML systems and how to elevate your security...

10 Years of Mainframe Hacking (Keynote) | Philip Young
VSC 2024

Philip Young

10 Years of Mainframe Hacking (Keynote) | Philip Young

At Vanguard Security & Compliance 2024, NetSPI's Philip Young delivered a keynote on a decade of mainframe hacking research and how the...

Web Based Penetration Testing
VSC 2024

Michelle Eggers

Web Based Penetration Testing

At Vanguard Security & Compliance 2024, NetSPI's Michelle Eggers explored how web applications on the mainframe introduce OWASP-style risks that can lead...

CICS Application Penetration Testing
VSC 2024

Philip Young

CICS Application Penetration Testing

At Vanguard Security & Compliance 2024, NetSPI's Philip Young demonstrated CICS application penetration testing using the open-source hack3270 tool against the Damn...

No Longer a Myth: A Guide to Mainframe Buffer Overflows
VSC 2024

Philip Young

No Longer a Myth: A Guide to Mainframe Buffer Overflows

NetSPI's Philip Young showed that mainframe buffer overflows are real, demonstrating how to hunt and exploit them in APF-authorized libraries.

Hunting for Crits on Adventure Mode | BSidesYXE
BSides Saskatoon 2024

Michelle Eggers

Hunting for Crits on Adventure Mode | BSidesYXE

In this presentation from BSides Saskatoon 2024, security consultant Michelle Eggers explores the practical application of ethical hacking through the lens of...

The Immortal Retrofuturism of Mainframe Computers & How to Keep Them Safe
Mainframe Retrofuturism
DEF CON 32

Michelle Eggers

The Immortal Retrofuturism of Mainframe Computers & How to Keep Them Safe

At Def Con 32, NetSPI Security Consultant Michelle Eggers made the case for why mainframes remain mission-critical today and shared five trusted...

Def Con 32 – GCPwn | Scott Weston
DEF CON 32

Scott Weston

Def Con 32 – GCPwn | Scott Weston

At Def Con 32, NetSPI Senior Security Consultant Scott Weston talked about his new tool, GCPwn. Get full access to his slide...

DEF CON 32 | Identity Theft is Not a Joke, Azure!
DEF CON 32

Karl Fosaaen

DEF CON 32 | Identity Theft is Not a Joke, Azure!

At Def Con 32, NetSPI VP of Research Karl Fosaaen explored the risks hiding inside Azure Managed Identities and demonstrated a tool...

The Immortal Retrofuturism of Mainframe Computers & How to Keep Them Safe
Mainframe Retrofuturism
BSides Las Vegas 2024

Michelle Eggers

The Immortal Retrofuturism of Mainframe Computers & How to Keep Them Safe

At BSides Las Vegas 2024, NetSPI's Michelle Eggers made the case for why mainframes remain mission-critical today and shared five trusted solutions...

Laser Beams & Light Streams: Hackers Go Pew Pew
Laser Beams
Black Hat USA 2024

Larry Trowell

Sam. Beaumont

Laser Beams & Light Streams: Hackers Go Pew Pew

At Black Hat USA 2024, NetSPI's Sam Beaumont and Larry Trowell demonstrated affordable, light-based hardware attack tooling that puts laser fault injection...

The Tale of Two ASMs: EASM + CAASM
Black Hat USA 2024

Vinay Anand

Tom Parker

The Tale of Two ASMs: EASM + CAASM

At Black Hat USA 2024, NetSPI's Vinay Anand and Tom Parker showed how pairing EASM with CAASM advances continuous threat and exposure...

My Callsign Is My Passport Responsible Testing & Disclosure Of Amateur Radio Websites
DEF CON 31

Dan Norte

My Callsign Is My Passport Responsible Testing & Disclosure Of Amateur Radio Websites

Amateur radio websites / web applications are notorious for terrible / non-existence information security practices and there’s normally no budget to get...