{"title":"Trainings","description":"\u003ch5\u003eJoin us at Exhibition World Bahrain for two-day and three-day courses on November 8-10.\u003c\/h5\u003e\n\u003ch5\u003eQuestions? Email training@defcon.org\u003c\/h5\u003e","products":[{"product_id":"deep-dive-into-the-dark-web","title":"Deep Dive into the Dark Web","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Deep Dive into the Dark Web\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Robert Weiss\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 800 BHD\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eParticipants will understand where Tor fits in the ecosystem of privacy and anonymity tools, the Tor protocol in detail, how to operate on Tor, how Hidden Services work in detail, and what can be learned about the Dark Web.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eThe recent expansion of Uncrewed Autonomous Systems (UAS) across various sectors presents significant security challenges, as rapid adoption often outpaces critical cybersecurity security engineering, leaving many of these systems vulnerable. The Dark Wolf Hacking Our Drone Workshop provides participants a comprehensive, hands-on understanding of drone security vulnerabilities and the techniques to assess and mitigate them. This intensive two-day program offers a deep dive into drone hacking, equipping cyber professionals with the practical skills and theoretical knowledge necessary to evaluate and secure autonomous systems.\u003c\/p\u003e\n\u003cp\u003eThe curriculum spans the UAS architecture and includes an Unmanned Aerial Vehicle (UAV), a Ground Control Station (GCS) system, RF communication protocols, payloads, and log analysis. Through a combination of expert-led instruction and extensive practical lab exercises, participants will gain proficiency in identifying, exploiting, and reporting vulnerabilities across these diverse components. The workshop concludes with a focus on risk assessment, mitigation strategies, and industry best practices for securing drone operations, ensuring attendees leave equipped to proactively identify and secure autonomous systems against evolving cyber threats.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eSection 1: Introduction to Privacy (1 Hour)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e Why Privacy is Important\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Tor’s Core Philosophy on Privacy\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.1.3\u003c\/strong\u003e Anonymity Networks\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.1.4\u003c\/strong\u003e Comparison of Anonymity Networks\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.1.5\u003c\/strong\u003e What is the Dark Web?\u003c\/p\u003e\n\u003ch3\u003eSection 2: Anonymity, Privacy and Security Tools (1.5 Hours)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.1\u003c\/strong\u003e Secure Messaging Applications\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.2\u003c\/strong\u003e Privacy Focused Search Engines\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.3\u003c\/strong\u003e Privacy Focused Browsers\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.4\u003c\/strong\u003e Proton Mail\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.5\u003c\/strong\u003e Privacy Focused Distros\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.6\u003c\/strong\u003e Other\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.7\u003c\/strong\u003e Improving personal privacy can be daunting\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.8\u003c\/strong\u003e Phase 1: Low-effort, high-impact changes\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.9\u003c\/strong\u003e Phase 2: Changing services and habits\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.10\u003c\/strong\u003e Phase 3: Infrastructure changes\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.11\u003c\/strong\u003e Phase 4: Advanced practices\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.2.12\u003c\/strong\u003e Phase 5: Extreme privacy measures\u003c\/p\u003e\n\u003ch3\u003eSection 3: Tor Project (2 Hours)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.3.1\u003c\/strong\u003e Tor Project History\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.3.2\u003c\/strong\u003e How protocols evolve\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.3.3\u003c\/strong\u003e High-level overview of Tor\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.3.4\u003c\/strong\u003e Tor Project\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.3.5\u003c\/strong\u003e Tor Browser\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.3.6\u003c\/strong\u003e LAB: Get Tor (Laptop and Phone)\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.3.7\u003c\/strong\u003e Tor Circuits: How Tor works\u003c\/p\u003e\n\u003ch3\u003eSection 4: Tor in More Detail (4 Hours)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.1\u003c\/strong\u003e Centralized Services\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.2\u003c\/strong\u003e Tor Citizenship\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.3\u003c\/strong\u003e Life cycle of a Node\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.4\u003c\/strong\u003e LAB: Launch a Node\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.5\u003c\/strong\u003e Get a list of nodes\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.6\u003c\/strong\u003e Tor Metrics\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.7\u003c\/strong\u003e Torify\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.8\u003c\/strong\u003e Stem: Control Tor with Python\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.9\u003c\/strong\u003e How Tor Works (in detail)\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.10\u003c\/strong\u003e Control Messages\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.11\u003c\/strong\u003e LAB: View Control Messages\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.12\u003c\/strong\u003e Open Source\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.13\u003c\/strong\u003e Tor Protocol Documentation\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.4.14\u003c\/strong\u003e Anti-Censorship Features\u003c\/p\u003e\n\u003ch3\u003eSection 5: Hidden Services (The Dark Web) (4 Hours)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.1\u003c\/strong\u003e Hidden Services\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.2\u003c\/strong\u003e Hidden Service Descriptors\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.3\u003c\/strong\u003e Rendezvous Protocol\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.4\u003c\/strong\u003e Hidden Service Advantages\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.5\u003c\/strong\u003e Hardening a Hidden Service Server\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.6\u003c\/strong\u003e LAB: Launch a Hidden Service\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.7\u003c\/strong\u003e Onion Balance\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.8\u003c\/strong\u003e Onionshare\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.9\u003c\/strong\u003e Securedrop\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.10\u003c\/strong\u003e Tor testnet\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.5.11\u003c\/strong\u003e Attacks on Tor\u003c\/p\u003e\n\u003ch3\u003eSection 6: Dark Web Content (4 Hours)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.6.1\u003c\/strong\u003e Finding Sites and Services\u003cbr\u003e\u003cstrong\u003e\u003cmeta charset=\"utf-8\"\u003e3.6.2\u003c\/strong\u003e Dark Web Content\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eBeginner - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eThe course is accessible to those with a Beginner knowledge. Students should bring a basic knowledge of Linux.\u003c\/p\u003e\n\u003cp\u003eThere are no prerequisites, but a basic knowledge of Linux and a general idea of how public key cryptography works will be helpful.\u003c\/p\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cp\u003eTo get full value from the labs, a student should have a Linux laptop on which they can install Tor or a laptop that supports a Linux virtual machine on which they can install Tor.\u003c\/p\u003e\n\u003cp\u003eA phone on which they can install the Tor Browser application is also useful.\u003c\/p\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003eWe will provide scripts necessary to execute the labs.\u003c\/p\u003e\n\u003ch2\u003e8. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3\u003eRobert Weiss\u003c\/h3\u003e\n\u003cp\u003eRobert Weiss [pwcrack] has over two decades of experience in information security as a penetration tester. With a specialty in cryptography he has been researching the Dark Web for the last six years. A hacker conference addict, he is currently DEF CON lead CFP and Speaker Operations Goon.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8 \u003c\/strong\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49908105740531,"sku":null,"price":800.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/head_shot_PWCrack.webp?v=1786559848"},{"product_id":"attacking-defending-ai-systems-mcp-rag-ai-agents-through-aigoat","title":"Attacking \u0026 Defending AI Systems, MCP, RAG, AI Agents through AIGoat","description":"\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eName of Training:\u003c\/b\u003e Attacking \u0026amp; Defending AI Systems: MCP, RAG, AI Agents and Agentic Kill Chains through AIGoat \u003cbr\u003e\u003cb\u003eTrainer(s):\u003c\/b\u003e Nalinikanth Meesala, Farooq Mohammad \u003cbr\u003e\u003cb\u003eDates:\u003c\/b\u003e November 08 – 09, 2026 \u003cbr\u003e\u003cb\u003eTime:\u003c\/b\u003e 9:00 am – 5:00 pm \u003cbr\u003e\u003cb\u003eVenue:\u003c\/b\u003e Exhibition World Bahrain \u003cbr\u003e\u003cb\u003eCost:\u003c\/b\u003e 1200 BHD\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eEveryone is building with LLMs. Very few are asking, “How do we break this?”\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003ePrompt injection is trivially exploitable in most production AI systems. RAG pipelines leak context they were never supposed to expose. AI agents with tool access are a privilege escalation waiting to happen. Model Context Protocol is an attack surface most teams haven't even started thinking about. The vulnerability classes are real, the potential impact is significant, yet the industry is still largely operating without clear visibility into them.\u003cspan style=\"background: yellow; mso-highlight: yellow;\"\u003e\u003c\/span\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eThis is two days of fixing that.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eAIGoat is an open-source platform of deliberately vulnerable LLM pipelines, real prompt processing, real RAG, real tool-calling workflows, RAG, AI agents, all built to be broken. Every topic follows the same rhythm: exploit it, understand exactly why it works, then build and test the defense yourself. You will be attacking and defending real AI system architectures from the first hour.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003ePrompt Injection:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e You bypass content restrictions and system instructions with plain-English prompts, covering direct and indirect techniques. Then you explore the defenses: examining strict prompt templates, input whitelists, and post-response filters, and immediately testing how well those mitigations hold up against the attacks.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eJailbreaking \u0026amp; Excessive Agency:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e You force an AI assistant to violate its role and reach external systems it was never supposed to touch. Then you lock it down: capability isolation, output moderation APIs, retrieval-guard policies. You will see exactly how much the attack surface disappears when an agent is scoped correctly.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eRAG Pipeline Poisoning \u0026amp; Data Poisoning:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e You inject malicious content into retrieval pipelines and fine-tuning data to manipulate model behavior. Then you implement the countermeasures, content moderation queues, trust scoring, segregated pipelines and verify they actually catch what you just did.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eSensitive Data \u0026amp; System Prompt Exfiltration:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e You trigger hidden prompt leakage and secret exfiltration through debug modes and adversarial probing. Then you apply redaction, secrets store separation, and environment-specific access controls and probe \u003c\/span\u003ethe defenses to confirm they hold.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eAI Agent Exploitation:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e Goal hijacking, tool misuse, identity and privilege abuse, agentic supply chain vulnerabilities. You work through each attack path against live agent architectures, then implement memory isolation and capability segmentation to contain the blast radius. You will leave understanding exactly how much damage a compromised agent can do and what it actually takes to limit it.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eMCP Exploitation:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e Model Context Protocol is the newest and least-understood attack surface in AI systems. You will exploit it hands-on and understand the architectural patterns that constrain it.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eThreat Modeling for AIsystems (LLMs, RAG, MCP, Agents)\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e: Before chaining anything, you learn to predict chains. Most AI threat modeling stops at the component level STRIDE, MITRE ATLAS, MAESTRO which is precisely why chained compromise gets missed in review after review. You model the four boundaries that actually matter (context, retrieval, tool\/action, memory) and reason in paths rather than components, Then take the method back and apply those learnings to the AI solutions you’re building.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eThe Agentic Kill Chain.\u003c\/b\u003e This is the module that sets this course apart, drawn directly from our conference research on chained agentic compromise. You run a complete five-stage chain - \u003cb\u003e\u003cspan style=\"font-family: 'Arial Unicode MS'; mso-fareast-font-family: 'Arial Unicode MS'; mso-bidi-font-family: 'Arial Unicode MS';\"\u003eRecon → Poison → Hijack → Persist → Impact\u003c\/span\u003e\u003c\/b\u003e end to end against a live recruiting-copilot agent. A single uploaded document delivers indirect prompt injection, a poisoned MCP tool description, and a memory sleeper payload. The result is two separate breaches from one artifact: an immediate integrity failure, and a delayed confidentiality breach that fires on a scheduled job long after the attacker is gone. You then map the chain against OWASP Agentic AI Top 10 (ASI01–ASI10) and identify which single control breaks it.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eComposite chains across tenant boundaries.\u003c\/b\u003e The advanced extension: how isolation controls in multi-tenant agentic platforms fail \u003ci\u003ecompositionally\u003c\/i\u003e. Lateral movement through shared vector memory, agent-to-agent trust abuse, and persistent memory write-back where every individual boundary holds when tested alone, and the chain still gets through. You will learn the distinction between \u003cb\u003eboundary-independent\u003c\/b\u003e and \u003cb\u003eboundary-assuming\u003c\/b\u003e controls, and why most platform security reviews only test the latter.\u003cspan style=\"color: #212121;\"\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eWe close with a timed 8–10 challenge CTF where the techniques become targets. No walkthroughs, no safety net - just you, the attack surface, and the clock.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eYou leave with a forkable AIGoat lab, The AI Attack \u0026amp; Defense Playbook, a red-team checklist, kill-chain worksheet, and framework mappings. So that you can take the attacks home and start breaking, defending, and testing your own AI systems the week you get back.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cbr\u003e\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003eDay 1\u003c\/span\u003e\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_bg7wg7v6yqae\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.1 Welcome, Setup \u0026amp; AIGoat Onboarding\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eWorkshop goals, agenda, AIGoat account creation, environment health-check, sandbox access verified.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_nz3q9xi2g93s\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.2 LLM \u0026amp; AI Foundations \u003c\/span\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: black; background: yellow; mso-highlight: yellow;\"\u003e\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eHow LLMs differ from traditional applications from an attacker's perspective. Tokenization, context windows, system vs. user prompts, why deterministic security assumptions break down. Live demo of an LLM behaving unpredictably under adversarial input.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_ockbkwfyeros\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: black;\"\u003e3.3 Basics of RAG, AI Agents \u0026amp; Model Context Protocol (MCP)\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003eHow retrieval pipelines, tool-calling, and agent orchestration expand the attack surface. Live demo: agent calling an external API, MCP server interaction. \u003cspan style=\"background: yellow; mso-highlight: yellow;\"\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: #212121;\"\u003e3.4 OWASP LLM Top 10: Mapped to Real Architectures\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eWalk through each category with a real-world breach scenario. Quick quiz to anchor the framework before labs begin.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\n\u003ca name=\"_wzhuh99gnc3w\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: #212121;\"\u003e3.5 Threat Modeling AI Systems\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eThis module teaches you to model \u003cb\u003ehow an attacker moves across an AI system\u003c\/b\u003e, not just what can go wrong inside each component because traditional threat modeling can under-serve AI systems where behavior is non-deterministic, data can become instructions, trust boundaries shift at runtime, and the same artifact can act as both content and control flow.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eThink in attack paths, not isolated findings:\u003c\/b\u003e use STRIDE, MITRE ATLAS, and MAESTRO where they help, then connect findings across boundaries to uncover chained compromise.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eLab:\u003c\/b\u003e Threat-model a live AIGoat agent architecture. Map assets, attacker-controlled inputs, trust boundaries, and abuse paths; identify where one weakness can become the entry point for the next, then turn those paths into testable attack hypotheses.\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_47i0qikjfzk3\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.6 BREAK THE BOUNDARY\u003c\/span\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: black;\"\u003e\u003cbr\u003e\u003c\/span\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eCompromise what the AI sees, trusts, and depends on. \u003c\/span\u003e\n\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_j9wv52jim7do\"\u003e\u003c\/a\u003e\u003ci\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eLLM01 Prompt Injection, LLM04 Supply Chain, LLM08 Hidden Context Exposure \u003c\/span\u003e\u003c\/i\u003e\n\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_724p75ygyoda\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eLearn how attackers establish influence over an AI system by compromising its dependencies, manipulating retrieval, injecting instructions, and exposing hidden context. The focus is on finding the boundaries where data becomes instructions, trusted content becomes attacker-controlled content, and one weakness becomes the entry point for the next.\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_69fst14m5xes\"\u003e\u003c\/a\u003e\u003cb\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eAttack:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003e Attack the AI's supply chain, vector and retrieval layer, prompt\/context boundary, and hidden application context. Chain supply-chain compromise, RAG manipulation, prompt injection, and context extraction to establish a foothold and uncover the system's capabilities and trust boundaries.\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_j3jw31h507fk\"\u003e\u003c\/a\u003e\u003cb\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eDefend:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003e Explore provenance and integrity controls, retrieval isolation, content and instruction separation, context minimization, authorization boundaries, and trust controls. Re-run the attack paths to understand which defenses break the chain and where attackers can move around them.\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\n\u003ca name=\"_xr3y3vrsds33\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: #212121;\"\u003e3.7 CORRUPT THE MIND: Data, Model \u0026amp; RAG systems\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 17.0pt; line-height: 115%;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-top: 14.0pt;\"\u003e\u003cspan style=\"color: black;\"\u003eManipulate what the AI knows, believes, and reveals. \u003cbr\u003e\u003c\/span\u003e\u003ci\u003eLLM02 Sensitive Information Disclosure, LLM05 Data \u0026amp; Model Poisoning, LLM07 Misinformation, LLM09 Vector \u0026amp; Embedding Weaknesses.\u003c\/i\u003e\u003cbr\u003e\u003cbr\u003eExplore what happens after an attacker gains influence: corrupt the information the AI relies on, make it produce misleading results, or extract information it should never reveal. Learn how poisoning, misinformation, and disclosure can reinforce each other across RAG, memory, and multi-step AI workflows.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003ePoison knowledge sources and persistent data, manipulate model outputs, induce false or misleading decisions, and extract sensitive information from prompts, context, retrieval, memory, and responses. Chain these weaknesses to turn a seemingly harmless manipulation into persistent compromise or data exposure.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore data provenance, retrieval authorization, validation, grounding, evidence verification, output controls, data minimization, and memory isolation. Re-test the same attack chains to understand whether the defenses prevent corruption, limit disclosure, or merely contain the impact.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; mso-pagination: widow-orphan; page-break-after: auto; border: none; mso-padding-alt: 31.0pt 31.0pt 31.0pt 31.0pt; mso-border-shadow: yes;\"\u003e\n\u003ca name=\"_jy8u0vax1yaw\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: #212121;\"\u003e3.8 WEAPONIZE THE ACTION\u003c\/span\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-top: 14.0pt;\"\u003e\u003ci\u003e\u003cspan style=\"color: black;\"\u003eTurn AI influence into real-world impact.\u003cb\u003e \u003c\/b\u003e\u003c\/span\u003e\u003c\/i\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-top: 14.0pt;\"\u003eLLM03 Excessive Agency, LLM06 Unbounded Consumption, LLM10 Improper Output Handling\u003cbr\u003e\u003cb\u003e\u003cbr\u003e\u003c\/b\u003eMove from compromising the model to compromising what the system can do. Explore how excessive permissions, unsafe tool use, unvalidated model output, and uncontrolled resource consumption allow an attacker to turn AI influence into actions against real systems.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003eChain prompt injection or misinformation into tool invocation, privilege abuse, unsafe downstream execution, MCP interactions, code execution, data exfiltration, or resource exhaustion. Follow the attack across the AI's tool, identity, and downstream system boundaries.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore least-privilege capabilities, tool and identity isolation, scoped authorization, approval gates, output validation, execution boundaries, rate limits, circuit breakers, and runtime controls. Re-run the attack chains to determine whether the defenses stop the action, contain the blast radius, or simply move the attack to the next boundary.\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_5bdjpsrnkhvb\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.9 Wrap-Up \u0026amp; Q\u0026amp;A\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003e3.9.1\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e Recap the attacker methodology built so far.\u003cbr\u003e\u003cb\u003e3.9.2\u003c\/b\u003e Preview Day 2's deeper attack surfaces. \u003cbr\u003e\u003cb\u003e3.9.3 \u003c\/b\u003eOpen Q\u0026amp;A.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-top: 14.0pt; line-height: 170%; background: white;\"\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e3.10 Day 1 Recap \u003cbr\u003e\u003c\/span\u003eQuick group exercise: threat-model an AI agentic feature using only what you learned yesterday. Sets the lens for Day 2's deeper attack surfaces.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_y4ijjwvsz5ei\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e3.11 Attack \u0026amp; Defend: MCP Systems\u003c\/span\u003e\u003cspan style=\"background: #FF9900;\"\u003e\u003c\/span\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003eExplore MCP as the bridge between an AI model and the systems it can act upon. Learn how seemingly trusted tools, tool descriptions, parameters and MCP servers can become attack surfaces turning model influence into unauthorized actions.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003eMCP tool poisoning, malicious tool descriptions, indirect prompt injection through MCP, tool parameter manipulation, unauthorized tool invocation, excessive tool permissions, MCP server impersonation, malicious third-party packages, cross-tool attacks, and tool-call flooding. Chain untrusted content through MCP into privileged downstream actions.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore MCP server and tool provenance, tool allowlisting, capability restrictions, authentication and authorization, parameter validation, least-privilege identities, approval gates, tool-call limits and runtime monitoring. Re-run the attacks to test whether the controls actually prevent the tool from becoming the attacker's bridge into the system.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_4izo8ovq0ucd\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e3.12 Attack \u0026amp; Defend: Hijacking AI Agents\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 17.0pt; line-height: 170%;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003eASI01 Agent Goal Hijack, ASI06 Memory \u0026amp; Context Poisoning, ASI07 Insecure Inter-Agent Communication, ASI09 Human-Agent Trust Exploitation, ASI10 Rogue Agents\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003eExplore how attackers manipulate an agent's \u003cb\u003egoals, context, memory and decisions\u003c\/b\u003e. Learn how indirect instructions, poisoned memory, hidden context and compromised agent-to-agent communication can gradually move an agent away from its intended objective.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003eAgent goal hijacking, indirect prompt injection, memory and context poisoning, hidden-context extraction, false or manipulated information, inter-agent instruction manipulation, persistent attacks and rogue-agent behavior. Chain seemingly low-impact manipulations across context and memory to influence future decisions.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore context isolation, memory-write controls, instruction hierarchy, provenance, agent identity, inter-agent trust boundaries, behavioral monitoring and human verification. Re-run the attack chains to understand where the agent can be brought back within its intended boundaries.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_br7220z536jz\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e3.13 Attack \u0026amp; Defend: Weaponizing AI Agents\u003c\/span\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003eASI02 Tool Misuse \u0026amp; Exploitation, ASI03 Identity \u0026amp; Privilege Abuse, ASI05 Unexpected Code Execution, ASI08 Cascading Failures, ASI09 Human-Agent Trust Exploitation\u003cbr\u003e\u003cb\u003e\u003cbr\u003e\u003c\/b\u003eOnce an attacker controls an agent's behavior, the next question is \u003cb\u003ewhat can the agent actually do?\u003c\/b\u003e Explore how tools, identities, permissions and autonomous actions can turn a manipulated agent into a pathway to real-world impact.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003eTool misuse, excessive permissions, identity and privilege abuse, MCP tool exploitation, unsafe output reaching downstream systems, command execution, unauthorized actions, recursive tool calls, resource exhaustion and cascading failures.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore least-privilege capabilities, scoped identities, tool isolation, authorization boundaries, output validation, execution sandboxes, approval gates, action limits, circuit breakers and runtime monitoring. Re-run the same attack chains to determine whether the controls stop the action or merely move the attacker to another capability.\u003cspan style=\"color: #212121;\"\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_25a5ns5m3s0c\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: black;\"\u003e3.14 The Agentic Kill Chain - Break the Chain\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 13.0pt; line-height: 115%; color: #212121;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003ci\u003e\u003cspan style=\"color: #212121;\"\u003eMaps: ASI01–ASI10 + MITRE ATLAS\u003c\/span\u003e\u003c\/i\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eForget isolated vulnerabilities. \u003cb\u003eAttackers don't stop at the first finding. They chain them.\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eThe Agentic Kill Chain compresses the traditional cyber kill chain into five stages:\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"font-family: 'Arial Unicode MS'; mso-fareast-font-family: 'Arial Unicode MS'; mso-bidi-font-family: 'Arial Unicode MS'; color: #212121;\"\u003eRECON → POISON → HIJACK → PERSIST → IMPACT\u003c\/span\u003e\u003cspan style=\"color: #212121;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eYou’ll learn how a single malicious artifact can move through an agent's context, memory, tools and trust boundaries - and how \u003cb\u003ebreaking just one link can break the entire attack\u003c\/b\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eEach stage maps to the relevant ASI categories and MITRE ATLAS techniques, giving you a common language for describing agentic attacks, assessing them, and reporting them inside your organization.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_ejv6vc4ch5g3\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: black;\"\u003e3.1\u003c\/span\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e5\u003cspan style=\"color: black;\"\u003e Full Chain Lab\u003c\/span\u003e - \u003cspan style=\"color: black;\"\u003eBreak an Agent, Then Break the Chain\u003c\/span\u003e\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 13.0pt; line-height: 170%; color: #212121;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003ci\u003e\u003cspan style=\"color: #212121;\"\u003eMaps: ASI01, ASI02, ASI04, ASI06, ASI09\u003c\/span\u003e\u003c\/i\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eThis is where everything comes together.\u003c\/span\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eYou get a live recruiting copilot with résumé ingestion, an MCP-connected enrichment tool, and persistent candidate memory.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eRecon\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Find the agent's tools, memory boundaries and scheduled jobs.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003ePoison\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Plant an indirect prompt injection in a résumé and compromise the agent through a poisoned MCP tool description.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eHijack\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Turn the agent against its own ranking logic and trigger a visible integrity failure.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003ePersist\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Plant a sleeper payload in memory that survives the session.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eImpact\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Trigger the scheduled digest and watch the attack reach the candidate database \u003cb\u003elong after the original attacker is gone.\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eThen switch sides.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eRun the chain again with defenses enabled - \u003cb\u003eone control at a time\u003c\/b\u003e - and discover which control actually breaks the chain, which only slows it down, and which \u003ci\u003elooks\u003c\/i\u003e protective but changes nothing.\u003cspan style=\"background: yellow; mso-highlight: yellow;\"\u003e\u003c\/span\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_86trmfgdvfrw\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.16 CTF Briefing\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eRules, scoring, challenge categories.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eTake off the gloves: 8 –10 timed challenges, spanning the OWASP LLM Top 10, RAG, MCP and agents. Attack. Chain it. Beat the clock. Climb the live scoreboard.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_40qgstctlm28\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.17 Awards, Takeaways \u0026amp; Wrap-Up\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eWalk through winning solutions, highlight novel approaches. Distribute the Guardrail Playbook and Red-Team Checklist. AIGoat access details. Open Q\u0026amp;A and closing.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eIntermediate\u003c\/b\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eNo AI security or ML background is required. Day 1 opens with a ground-up primer on LLMs, RAG, agents, and MCP. If you have done web application penetration testing or application security work and can read code, you will be exactly where you need to be.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eStudents should be comfortable with:\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo2; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eWeb application fundamentals:\u003c\/b\u003e HTTP, REST APIs, JSON payloads\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eA terminal:\u003c\/b\u003e running Docker, executing scripts, basic Linux commands\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo2; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eReading Python:\u003c\/b\u003e you will modify short scripts (10–40 lines), not write from scratch\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eOptional pre-work (~1 hour):\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l1 level1 lfo1; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eSkim the OWASP Top 10 for Large Language Model Applications:\u003ca href=\"https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/\"\u003e\u003cspan style=\"color: windowtext; text-decoration: none; text-underline: none;\"\u003e \u003c\/span\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/\u003c\/span\u003e\u003c\/a\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l1 level1 lfo1; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eClone and skim AIGoat:\u003ca href=\"https:\/\/github.com\/AISecurityConsortium\/AIGoat\"\u003e\u003cspan style=\"color: windowtext; text-decoration: none; text-underline: none;\"\u003e \u003c\/span\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/github.com\/AISecurityConsortium\/AIGoat\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/github.com\/AISecurityConsortium\/AIGoat\u003c\/span\u003e\u003c\/a\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\"\u003eThat is genuinely all. Everything else is taught from the ground up.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\n\u003cspan style=\"font-size: 16.5pt; line-height: 115%; color: #212121;\"\u003e6. What Students Should Bring\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 17.0pt; line-height: 115%;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eLaptop running Windows 10\/11, macOS 12+, or a recent Linux distribution\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e8 GB RAM minimum (16 GB recommended)\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e20 GB free disk space\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eModern web browser (Chrome or Firefox)\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eAbility to install a small set of free tools listed in pre-work (terminal client, code editor)\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eInternet access - the labs are cloud-hosted, and all heavy compute runs in the instructor-provided environment. No local GPU or local model required.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eNote on corporate devices:\u003c\/b\u003e students must be able to reach the cloud lab. Corporate-locked laptops that block outbound traffic to non-approved domains may not work. If in doubt, bring a personal device.\u003c\/p\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eParticipants leave with a practical \u003cb\u003eAI Attack \u0026amp; Defense Toolkit\u003c\/b\u003e they can take back and apply to their own AI solutions:\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l1 level1 lfo2; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eCertification of participation verifiable on \u003ca href=\"https:\/\/aigoat.co.in\/\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/aigoat.co.in\/\u003c\/span\u003e\u003c\/a\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eSlides + Reading List\u003c\/b\u003e - course material and curated resources for continuing the learning journey.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eWorkshop Playbook\u003c\/b\u003e - Documentation of the two day workshop activities and exercises\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eForkable AIGoat Lab\u003c\/b\u003e - the complete hands-on environment to continue experimenting after the training.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eAI Attack \u0026amp; Defense Playbook\u003c\/b\u003e - practical attack patterns, defensive approaches, and re-test guidance across LLMs, RAG, MCP and Agents.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eRed-Team Checklist\u003c\/b\u003e - a repeatable checklist for assessing AI applications and identifying attack paths.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eKill Chain Worksheet\u003c\/b\u003e - map individual findings into end-to-end attack chains across context, retrieval, memory, tools and agents.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-bidi-font-weight: bold;\"\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eThreat modelling Workbook \u003c\/b\u003e- a template to perform threat modelling for AI systems\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003ch2\u003e7. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3 style=\"margin-top: 14.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\u003cb\u003e\u003cspan style=\"font-size: 13.0pt; line-height: 115%; color: black;\"\u003eNalinikanth Meesala\u003c\/span\u003e\u003c\/b\u003e\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eNalinikanth Meesala is Head of Security, AI Products at Thoughtworks and co-creator of AIGoat, an open-source deliberately vulnerable AI system. With over 13 years in cybersecurity and product security engineering, his work centres on AI security, adversarial testing, and secure architecture for AI-driven systems.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eHis research targets attack surfaces unique to modern AI systems: prompt injection, RAG poisoning, Model Context Protocol exploitation, AI agent abuse, and AI supply-chain vulnerabilities. His current work on composite kill chains examines how isolation controls in multi-tenant agentic AI platforms fail when an attacker pivots across multiple trust boundaries in sequence - research presented at Black Hat and derived from a comparative security review of thirteen production and open-source agentic platforms.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eHe has delivered talks and hands-on training at DEF CON Training Middle East, Black Hat, XConf, Seasides, SecConf, OWASP meetups, and null community chapters, focusing on helping engineers and security professionals understand how to exploit modern AI systems and how to build them securely.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eWhen he is not breaking AI systems (ethically), he enjoys painting and sport, bringing the same curiosity and creativity into both art and cybersecurity.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eLinkedIn:\u003c\/b\u003e\u003ca href=\"https:\/\/www.linkedin.com\/in\/nalinikanth-m\/\"\u003e\u003cspan style=\"color: windowtext; text-decoration: none; text-underline: none;\"\u003e \u003c\/span\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/www.linkedin.com\/in\/nalinikanth-m\/\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/www.linkedin.com\/in\/nalinikanth-m\/\u003c\/span\u003e\u003c\/a\u003e\u003cu\u003e\u003cspan style=\"color: #1155cc;\"\u003e\u003c\/span\u003e\u003c\/u\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\n\u003ca name=\"_drb9odb4u636\"\u003e\u003c\/a\u003e\u003cb\u003e\u003cspan style=\"font-size: 13.0pt; line-height: 115%; color: black;\"\u003eFarooq Mohammad\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eFarooq Mohammad is a security researcher and practitioner focused on securing modern applications and emerging AI-powered systems, and co-creator of AIGoat. His work spans application security, threat modelling, DevSecOps, and cloud security, with a sharp and growing focus on identifying and mitigating risk in LLM-based applications and AI-driven platforms. He works closely with engineering teams to embed security into the design and development of modern systems.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eIn recent years, Farooq has researched the attack surfaces introduced by AI systems - prompt injection, model jailbreaks, data exfiltration, RAG pipeline manipulation, and vulnerabilities in AI agents and tool integrations. He is particularly interested in practical AI red teaming and in translating offensive testing insight into defensive engineering patterns teams can actually adopt.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eHe has delivered AI security workshops at the Seasides Conference and talks at XConf, SecConf, OWASP meetups, and null community chapters. Outside security research he enjoys cooking and travelling, bringing the same curiosity to both.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eLinkedIn:\u003c\/b\u003e \u003ca href=\"https:\/\/www.linkedin.com\/in\/farooqmohammad\/\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/www.linkedin.com\/in\/farooqmohammad\/\u003c\/span\u003e\u003c\/a\u003e\u003c\/p\u003e\n\u003ch2\u003e8. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e8.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.8\u003c\/strong\u003e \u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49908106690803,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/Nalinikanth.png?v=1786917638"},{"product_id":"ai-risk-assurance-for-the-gcc-hands-on-red-teaming-risk-quantification-regulator-ready-governance","title":"AI Risk Assurance for the GCC: Hands-On Red-Teaming, Risk Quantification,Regulator-Ready Governance","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e AI Risk Assurance for the GCC Hands-On Red-Teaming, Risk Quantification, Regulator-Ready Governance\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Satinder Sandhu\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-10, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eAI is being deployed across GCC banks, government, and enterprises faster than security and risk teams can keep up. This three-day course teaches both technical practitioners and risk\/governance managers how to test AI systems for real attacks, translate findings into quantified business risk, and produce the regulator-ready evidence packs that SDAIA, SAMA, CBB, CBUAE, DIFC, and the upcoming Bahrain AI Regulation Law expect — working side-by-side on the same live labs.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eMost AI security courses are built for offensive specialists, leaving the people who actually own AI risk inside GCC organizations — CISOs, AI risk officers, GRC managers, internal auditors, and mid-career security practitioners — without a practical entry point. This course closes that gap.\u003c\/p\u003e\n\u003cp\u003eAcross three days, students work in mixed pairs (one technically-leaning, one governance-leaning, by design) on a live, instructor-built lab environment of vulnerable AI applications, including a RAG-based financial advisor, an MCP-connected tool-using agent, and an Arabic-language customer service agent.\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDay 1 teaches the most common AI attack patterns (prompt injection, indirect injection, RAG poisoning, agent tool abuse) using guided, step-by-step labs — no prior offensive security experience required.\u003c\/li\u003e\n\u003cli\u003eDay 2 teaches students how to convert each attack finding into a defensible dollar-value loss estimate using a simplified FAIR-style method, and how to design controls that are actually testable rather than aspirational.\u003c\/li\u003e\n\u003cli\u003eDay 3 maps everything to the GCC regulatory stack — SDAIA AI Ethics Principles and Generative AI Guidelines, UAE AI Charter and PDPL, DIFC Regulation 10, Bahrain's draft AI Regulation Law, Qatar Central Bank AI Guidelines, ISO\/IEC 42001, and NIST AI RMF — and culminates in a capstone where each pair produces a complete regulator-ready evidence pack for a fictional GCC bank deploying an Arabic AI agent. Students leave with the lab access (30 days), all templates, and a methodology they can apply to a real production AI system the Monday after the course.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.1\u003c\/strong\u003e Welcome, lab access setup, partner pairing (technical + governance pairs). Why GCC AI deployments are different: the regulatory landscape, the buyer urgency, and the threat model. No-laptop-needed framing module designed so even the least technical student is grounded before the first lab.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2\u003c\/strong\u003e The AI attack landscape, in plain language. OWASP LLM Top 10 (2026) and OWASP Agentic AI Top 10 walked through with one live demonstration per category. Governance students learn what each attack type means for risk; technical students learn the mechanics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3 Guided Lab 1:\u003c\/strong\u003e Prompt injection and jailbreaks against the lab's financial advisor agent. Step-by-step instructions provided. Pairs work together technical student executes, governance student documents the finding using the standardized template.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.4 Guided Lab 2:\u003c\/strong\u003e System prompt extraction and instruction leakage. Pairs swap roles governance student executes the (very simple) attack, technical student documents.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.5 Guided Lab 3:\u003c\/strong\u003e Indirect prompt injection via documents and emails. This is the most important attack pattern for GCC enterprises adopting Microsoft Copilot, Google Workspace AI, and Claude\/GPT-class agents. Pairs see how a single malicious document can hijack an AI assistant.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.6 Guided Lab 4:\u003c\/strong\u003e Agent tool abuse and confused deputy. Students attack an MCP-connected agent that has access to multiple tools (file read, email send, balance lookup) and chain a low-severity prompt injection into a meaningful business impact.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.7 Guided Lab 5:\u003c\/strong\u003e Arabic and RTL-specific attacks. Cross-lingual jailbreaks, dialect-based safety bypasses, and RTL Unicode tricks against multilingual models. This module reflects original research and is the course's most distinctive regional element.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.8\u003c\/strong\u003e Day 1 debrief. Pairs consolidate findings into a structured inventory.\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.9\u003c\/strong\u003e The assurance gap, in plain language: why most AI red-team reports never lead to action, and what it takes to make findings stick with executives and regulators. Introduction to the AI Decision Receipt pattern.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.10 Guided Lab 6:\u003c\/strong\u003e Simplified FAIR-style loss quantification. Pairs take three findings from Day 1 and produce dollar-value loss exposure ranges using a provided spreadsheet. Governance students lead this module; technical students provide the attack-side detail.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.11 Guided Lab 7:\u003c\/strong\u003e Building a quantified AI risk register. Pairs aggregate their findings into a single board-ready view, including a simple Monte Carlo simulation (provided spreadsheet — no coding required).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.12 Guided Lab 8:\u003c\/strong\u003e Designing testable controls. For each finding category, pairs design a control that is implementable, measurable, and re-testable. Common anti-patterns walked through with examples: aspirational policy language, untestable \"human review\" requirements, one-time assessments.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.13 Guided Lab 9:\u003c\/strong\u003e The AI Decision Firewall pattern, explained for both audiences. Technical students see a simple reference implementation; governance students learn how to specify and audit it. Pairs re-test Day 1 attacks against the hardened agent and see which controls held.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.14 Guided Lab 10:\u003c\/strong\u003e Continuous AI assurance — what \"ongoing testing\" actually means in practice, and how it integrates with the GRC, SOC, and ServiceNow workflows that already exist in most GCC enterprises.\u003c\/p\u003e\n\u003ch3\u003eDay 3\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.15\u003c\/strong\u003e The GCC regulatory landscape walkthrough: SDAIA AI Ethics Principles and Generative AI Guidelines (KSA), UAE AI Charter and PDPL, DIFC Regulation 10, ADGM ( Data Protection Regulations ) , Bahrain Personal Data Protection Law and the draft AI Regulation Law (April 2024), Qatar Central Bank AI Guidelines, ISO\/IEC 42001, and NIST AI RMF. Where they overlap, where they conflict, and what an examiner actually asks for. Designed to be useful for both technical and governance students.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.16 Guided Lab 11:\u003c\/strong\u003e Mapping Day 2 controls to the regulatory stack using a provided cross-walk matrix. Pairs identify gaps where their controls satisfy one framework but leave another exposed.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.17 Guided Lab 12:\u003c\/strong\u003e Building the regulator-ready evidence pack — adversarial test results, quantified risk register, control register, residual risk acceptance memo, and a one-page executive briefing — assembled into a single defensible artifact.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.18 Capstone briefing:\u003c\/strong\u003e Scenario: a fictional GCC bank (\"Bank Al-Khaleej\") is deploying an Arabic-language customer service agent with limited tool access to balance lookup, transaction history, and small transfers. Pairs must deliver a complete assurance package.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.19 Capstone execution:\u003c\/strong\u003e Pairs attack the live capstone agent, quantify findings, design controls, map to the regulatory stack, and produce the evidence pack. Instructor circulates for guidance throughout. Pairs that purchased the proficiency exam add-on submit their evidence packs for graded review.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.20\u003c\/strong\u003e Capstone debrief, instructor walkthrough of the reference solution, course wrap-up, and post-course resource handoff (lab access continues for 30 days, instructor follow-up available for 60 days).\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eThis course is designed for two complementary audiences who will work together in pairs: (a) security practitioners with 2–4 years of general cybersecurity experience (any background — pentest, SOC, GRC, audit, cloud security) and basic comfort with a Linux terminal and reading code; and (b) risk, governance, and management professionals (CISOs, AI risk officers, GRC managers, internal auditors, compliance leads) with foundational security knowledge equivalent to CISM, CRISC, ISO 27001 LA, or 3+ years in a security-adjacent role.\u003c\/p\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLaptop running Windows 10\/11, macOS 12+, or a recent Linux distribution\u003c\/li\u003e\n\u003cli\u003e8 GB RAM minimum (16 GB recommended)\u003c\/li\u003e\n\u003cli\u003e20 GB free disk space\u003c\/li\u003e\n\u003cli\u003eModern web browser (Chrome or Firefox)\u003c\/li\u003e\n\u003cli\u003eThe ability to install a small set of free tools provided in pre-work (a terminal client and a code editor — no Docker or local AI models required, as all heavy compute runs in the instructor-provided cloud lab). Students must be able to reach the cloud lab over standard HTTPS — corporate-locked devices that block outbound web traffic to non-approved domains may not work, and students should plan to bring a personal device if needed.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e30 days of access to the live cloud-hosted lab environment, including all vulnerable AI applications, agents, and the capstone scenario, with the ability to redeploy and re-attack at will\u003c\/li\u003e\n\u003cli\u003eA complete digital course pack including the finding inventory template, FAIR quantification spreadsheet, Monte Carlo notebook, control register template, regulatory cross-walk matrix, and evidence pack template.\u003c\/li\u003e\n\u003cli\u003eThe AI Decision Firewall reference architecture and source code.\u003c\/li\u003e\n\u003cli\u003eThe adversarial test suite as an importable evaluation harness.\u003c\/li\u003e\n\u003cli\u003eA curated reading list and the instructor's contact for follow-up questions for 60 days post-course.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3\u003eSatinder Sandhu\u003c\/h3\u003e\n\u003cp\u003eSatinder Sandhu is a cybersecurity engineer and AI risk practitioner with over 15 years of experience delivering offensive security training, advisory, and consulting engagements across 25+ countries. He holds multiple industry certifications, including CISSP, CISM, CCSP, CEH, CHFI, CND, EC-Council Certified Trainer and ISO 27001 Lead Auditor.\u003c\/p\u003e\n\u003cp\u003eHis work spans offensive security, enterprise risk management, cloud and infrastructure security, and AI assurance, with a focus on translating technical vulnerabilities into quantified business and financial impact for executive leadership and regulators. He has supported regulated organizations across financial services, healthcare, and government, with hands-on experience implementing and assessing control frameworks and regional regulatory expectations relevant to AI systems.\u003c\/p\u003e\n\u003cp\u003eSatinder is the founder of a Toronto-based cybersecurity, privacy, and AI risk firm, Security Assured. The lab environments, risk quantification methods, and regulator-ready evidence templates used in his courses are drawn directly from real-world engagements building AI assurance capabilities for regulated enterprises—grounded in production practice rather than theory.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49908107084019,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/SatinderSandhu.png?v=1786895474"},{"product_id":"a-practical-malware-analysis-threat-hunting-with-memory-forensics-endpoint-telemetry-ai-driven-hunting","title":"A Practical Malware Analysis \u0026 Threat Hunting with Memory Forensics, Endpoint Telemetry, \u0026 AI-Driven Hunting","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e A Practical Malware Analysis \u0026amp; Threat Hunting with Memory Forensics, Endpoint Telemetry, \u0026amp; AI-Driven Hunting\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Monnappa, Sajan Shetty\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-10, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eThis hands-on training covers malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting. It also introduces AI-powered hunting with the Garuda Framework to triage events, extract IOCs, and detect unknown attacks without relying on signatures or patterns.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eThis intensive, hands-on training teaches the concepts, tools, and techniques required to analyze, investigate, and hunt malware by combining four powerful approaches: malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting.\u003c\/p\u003e\n\u003cp\u003eThe course begins with the foundations of malware analysis, Windows internals, and memory forensics, before moving into advanced concepts of malware investigation and hunting adversary techniques.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003e3.1 Introduction to Malware Analysis\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e What is Malware\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e What they do\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Why malware analysis\u003cbr\u003e\u003cstrong\u003e3.1.4\u003c\/strong\u003e Types of malware analysis\u003cbr\u003e\u003cstrong\u003e3.1.5\u003c\/strong\u003e Setting up an isolated lab environment\u003c\/p\u003e\n\u003ch3\u003e3.2 Static Analysis\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e Fingerprinting the malware\u003cbr\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Extracting strings\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Determining File obfuscation\u003cbr\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e Pattern matching using YARA\u003cbr\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Fuzzing hashing \u0026amp; comparison\u003cbr\u003e\u003cstrong\u003e3.2.6\u003c\/strong\u003e Understanding PE File characteristics\u003cbr\u003e\u003cstrong\u003e3.2.7\u003c\/strong\u003e Hands-on lab exercise involves analyzing real malware sample\u003c\/p\u003e\n\u003ch3\u003e3.3 Dynamic Analysis \/ Behavioural Analysis\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e Dynamic Analysis Steps\u003cbr\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e Understanding Dynamic Analysis tools\u003cbr\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Simulating services\u003cbr\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e Performing Dynamic Analysis\u003cbr\u003e\u003cstrong\u003e3.3.5\u003c\/strong\u003e Monitoring process, filesystem, registry, and network activity\u003cbr\u003e\u003cstrong\u003e3.3.6\u003c\/strong\u003e Determining the Indicators of compromise (host and network indicators)\u003cbr\u003e\u003cstrong\u003e3.3.7\u003c\/strong\u003e Demo - Showing the static \u0026amp; dynamic analysis of real malware sample\u003cbr\u003e\u003cstrong\u003e3.3.8\u003c\/strong\u003e Hands-on lab exercise involves analyzing real malware sample\u003c\/p\u003e\n\u003ch3\u003e3.4 Automating Malware Analysis (Sandbox)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e Custom Sandbox Overview\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e Working of Sandbox\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Sandbox Features\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e Demo - Analyzing malware in the custom sandbox\u003c\/p\u003e\n\u003ch3\u003e3.5 Malware Persistence Methods\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e Run registry key\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Scheduled Tasks\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e Startup Folder\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Service\u003cbr\u003e\u003cstrong\u003e3.5.5\u003c\/strong\u003e Winlogon registry entries\u003cbr\u003e\u003cstrong\u003e3.5.6\u003c\/strong\u003e Image File Execution Options (IFEO)\u003cbr\u003e\u003cstrong\u003e3.5.7\u003c\/strong\u003e Accessibility programs\u003cbr\u003e\u003cstrong\u003e3.5.8\u003c\/strong\u003e AppInit_DLLs\u003cbr\u003e\u003cstrong\u003e3.5.9\u003c\/strong\u003e DLL Search order hijacking\u003cbr\u003e\u003cstrong\u003e3.5.10\u003c\/strong\u003e Hands-on lab exercise involves analyzing real malware sample\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003e3.6 Code Analysis\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Code Analysis Overview\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e Disassembler \u0026amp; Debuggers\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e Code Analysis Tools\u003cbr\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Basics of IDA Pro\u003cbr\u003e\u003cstrong\u003e3.6.5\u003c\/strong\u003e Basics of x64dbg\u003cbr\u003e\u003cstrong\u003e3.6.6\u003c\/strong\u003e Understanding API Calls\u003cbr\u003e\u003cstrong\u003e3.6.7\u003c\/strong\u003e Cross References using IDA\u003cbr\u003e\u003cstrong\u003e3.6.8\u003c\/strong\u003e Cross References using x64dbg\u003c\/p\u003e\n\u003ch3\u003e3.7 Reversing Malware Functionalities\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.1\u003c\/strong\u003e Downloader\u003cbr\u003e\u003cstrong\u003e3.7.2\u003c\/strong\u003e Dropper\u003cbr\u003e\u003cstrong\u003e3.7.3\u003c\/strong\u003e Keylogger\u003cbr\u003e\u003cstrong\u003e3.7.4\u003c\/strong\u003e Code injection (Fileless malware)\u003cbr\u003e\u003cstrong\u003e3.7.5\u003c\/strong\u003e Malware replication via removable media\u003cbr\u003e\u003cstrong\u003e3.7.6\u003c\/strong\u003e Malware Command \u0026amp; Control (C2)\u003c\/p\u003e\n\u003ch3\u003e3.8 Introduction to Memory Forensics\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.1\u003c\/strong\u003e What is Memory Forensics\u003cbr\u003e\u003cstrong\u003e3.8.2\u003c\/strong\u003e Why Memory Forensics\u003cbr\u003e\u003cstrong\u003e3.8.3\u003c\/strong\u003e Steps in Memory Forensics\u003cbr\u003e\u003cstrong\u003e3.8.4\u003c\/strong\u003e Memory acquisition and tools\u003cbr\u003e\u003cstrong\u003e3.8.5\u003c\/strong\u003e Acquiring memory From physical machine\u003cbr\u003e\u003cstrong\u003e3.8.6\u003c\/strong\u003e Acquiring memory from virtual machine\u003cbr\u003e\u003cstrong\u003e3.8.7\u003c\/strong\u003e The hands-on exercise involves acquiring the memory\u003c\/p\u003e\n\u003ch3\u003e3.9 Volatility Overview\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.9.1\u003c\/strong\u003e Introduction to Volatility Advanced Memory Forensics Framework\u003cbr\u003e\u003cstrong\u003e3.9.2\u003c\/strong\u003e Volatility Installation\u003cbr\u003e\u003cstrong\u003e3.9.3\u003c\/strong\u003e Volatility basic commands\u003cbr\u003e\u003cstrong\u003e3.9.4\u003c\/strong\u003e Determining the profile\u003cbr\u003e\u003cstrong\u003e3.9.5\u003c\/strong\u003e Volatility help options\u003cbr\u003e\u003cstrong\u003e3.9.6\u003c\/strong\u003e Running the plugin\u003c\/p\u003e\n\u003ch3\u003e3.10 Investigating Process\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.1\u003c\/strong\u003e Understanding Process Internals\u003cbr\u003e\u003cstrong\u003e3.10.2\u003c\/strong\u003e Process (EPROCESS) Structure\u003cbr\u003e\u003cstrong\u003e3.10.3\u003c\/strong\u003e Process organization\u003cbr\u003e\u003cstrong\u003e3.10.4\u003c\/strong\u003e Process Enumeration by walking the double linked list\u003cbr\u003e\u003cstrong\u003e3.10.5\u003c\/strong\u003e Process relationship (parent-child relationship)\u003cbr\u003e\u003cstrong\u003e3.10.6\u003c\/strong\u003e Understanding DKOM attacks\u003cbr\u003e\u003cstrong\u003e3.10.7\u003c\/strong\u003e Process Enumeration using pool tag scanning\u003cbr\u003e\u003cstrong\u003e3.10.8\u003c\/strong\u003e Volatility plugins to enumerate processes\u003cbr\u003e\u003cstrong\u003e3.10.9\u003c\/strong\u003e Identifying malware process\u003cbr\u003e\u003cstrong\u003e3.10.10\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003e3.11 Investigating Process Handles \u0026amp; Registry\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.11.1\u003c\/strong\u003e Objects and handles overview\u003cbr\u003e\u003cstrong\u003e3.11.2\u003c\/strong\u003e Enumerating process handles using Volatility\u003cbr\u003e\u003cstrong\u003e3.11.3\u003c\/strong\u003e Understanding Mutex\u003cbr\u003e\u003cstrong\u003e3.11.4\u003c\/strong\u003e Detecting malware presence using the mutex\u003cbr\u003e\u003cstrong\u003e3.11.5\u003c\/strong\u003e Understanding the Registry\u003cbr\u003e\u003cstrong\u003e3.11.6\u003c\/strong\u003e Investigating common registry keys using Volatility\u003cbr\u003e\u003cstrong\u003e3.11.7\u003c\/strong\u003e Detecting malware persistence\u003cbr\u003e\u003cstrong\u003e3.11.8\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003e3.12 Investigating Network Activities\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.12.1\u003c\/strong\u003e Understanding malware network activities\u003cbr\u003e\u003cstrong\u003e3.12.2\u003c\/strong\u003e Volatility Network Plugins\u003cbr\u003e\u003cstrong\u003e3.12.3\u003c\/strong\u003e Investigating Network connections\u003cbr\u003e\u003cstrong\u003e3.12.4\u003c\/strong\u003e Investigating Sockets\u003cbr\u003e\u003cstrong\u003e3.12.5\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003e3.13 Investigation Process Memory\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.13.1\u003c\/strong\u003e Process memory Internals\u003cbr\u003e\u003cstrong\u003e3.13.2\u003c\/strong\u003e Listing DLLs using Volatility\u003cbr\u003e\u003cstrong\u003e3.13.3\u003c\/strong\u003e Identifying hidden DLLs\u003cbr\u003e\u003cstrong\u003e3.13.4\u003c\/strong\u003e Dumping malicious executable from memory\u003cbr\u003e\u003cstrong\u003e3.13.5\u003c\/strong\u003e Dumping Dll's from memory\u003cbr\u003e\u003cstrong\u003e3.13.6\u003c\/strong\u003e Scanning the memory for patterns (yarascan)\u003cbr\u003e\u003cstrong\u003e3.13.7\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003eDay 3\u003c\/h3\u003e\n\u003ch3\u003e3.14 Investigating User-Mode Rootkits \u0026amp; Fileless Malwares\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.14.1\u003c\/strong\u003e Code Injection\u003cbr\u003e\u003cstrong\u003e3.14.2\u003c\/strong\u003e Types of Code injection\u003cbr\u003e\u003cstrong\u003e3.14.3\u003c\/strong\u003e Remote DLL injection\u003cbr\u003e\u003cstrong\u003e3.14.4\u003c\/strong\u003e Remote Code injection\u003cbr\u003e\u003cstrong\u003e3.14.5\u003c\/strong\u003e Reflective DLL injection\u003cbr\u003e\u003cstrong\u003e3.14.6\u003c\/strong\u003e Hollow process injection\u003cbr\u003e\u003cstrong\u003e3.14.7\u003c\/strong\u003e Demo - Case Study\u003cbr\u003e\u003cstrong\u003e3.14.8\u003c\/strong\u003e Hands-on lab exercise (scenario based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003e3.15 Investigating Kernel-Mode Rootkits\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.15.1\u003c\/strong\u003e Understanding Rootkits\u003cbr\u003e\u003cstrong\u003e3.15.2\u003c\/strong\u003e Understanding Functional call traversal in Windows\u003cbr\u003e\u003cstrong\u003e3.15.3\u003c\/strong\u003e Level of Hooking\/Modification on Windows\u003cbr\u003e\u003cstrong\u003e3.15.4\u003c\/strong\u003e Kernel Volatility plugins\u003cbr\u003e\u003cstrong\u003e3.15.5\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003cbr\u003e\u003cstrong\u003e3.15.6\u003c\/strong\u003e Demo - Rootkit Investigation\u003c\/p\u003e\n\u003ch3\u003e3.16 Threat Hunting Using Endpoint Telemetry\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.1\u003c\/strong\u003e Introduction to Sysmon\u003cbr\u003e\u003cstrong\u003e3.16.2\u003c\/strong\u003e Understanding Sysmon Events\u003cbr\u003e\u003cstrong\u003e3.16.3\u003c\/strong\u003e Introduction to Garuda Threat Hunting Framework\u003cbr\u003e\u003cstrong\u003e3.16.4\u003c\/strong\u003e Filtering Sysmon events using Garuda\u003cbr\u003e\u003cstrong\u003e3.16.5\u003c\/strong\u003e Living off the Land attacks\u003cbr\u003e\u003cstrong\u003e3.16.6\u003c\/strong\u003e Demo: Hunting LoLbins (Living of the land binary) and multi-staged attacks\u003c\/p\u003e\n\u003ch3\u003e3.17 AI-Powered Threat Hunting\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.1\u003c\/strong\u003e Introduction to AI in threat detection \u0026amp; hunting\u003cbr\u003e\u003cstrong\u003e3.17.2\u003c\/strong\u003e Introduction to MCP (Model Context Protocol)\u003cbr\u003e\u003cstrong\u003e3.17.3\u003c\/strong\u003e Exposing Tools to the LLM\u003cbr\u003e\u003cstrong\u003e3.17.4\u003c\/strong\u003e Integrating Garuda Framework with AI application\u003cbr\u003e\u003cstrong\u003e3.17.5\u003c\/strong\u003e How Garuda + AI can triage events, identify IOCs, and Map events to ATT\u0026amp;CK Techniques\u003cbr\u003e\u003cstrong\u003e3.17.6\u003c\/strong\u003e Demo: AI-powered autonomous Threat hunting to hunt for complex attack patterns\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eAdvanced\u003c\/strong\u003e - The student is expected to have significant practical experience with the tools and technologies that the training will focus on.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eExpert or Specialized\u003c\/strong\u003e - The student has a solid understanding of the topic at hand, usually with knowledge of relevant standards, tactics, tools, and years of relevant hands-on experience. Students should expect to use these skills with agility to solve problems in novel ways.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents should be familiar with using Windows\/Linux.\u003c\/li\u003e\n\u003cli\u003eStudents should have an understanding of basic programming concepts, while programming experience is not mandatory.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLaptop with a minimum of 8GB RAM and 60GB free hard disk space\u003c\/li\u003e\n\u003cli\u003eLaptop with USB ports - lab samples and custom Linux VM will be shared via USB sticks\u003c\/li\u003e\n\u003cli\u003eVMware Workstation or VMware Fusion (even trial versions can be used)\u003c\/li\u003e\n\u003cli\u003eWindows Operating system (preferably 64-bit versions of Windows 11 or Windows 10) installed inside the VMware Workstation\/Fusion. Students must have full administrator access to the Windows operating system installed inside the VMware Workstation\/Fusion.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c\/strong\u003e VMware Player or VirtualBox is not suitable for this training. Apple systems using the M1 processor line cannot perform the necessary virtualization functionality; therefore, they are not suitable for this course.\u003c\/p\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e7.1\u003c\/strong\u003e Course material (pdf copy)\u003cbr\u003e\u003cstrong\u003e7.2\u003c\/strong\u003e Lab solution material\u003cbr\u003e\u003cstrong\u003e7.3\u003c\/strong\u003e Videos used in the course\u003cbr\u003e\u003cstrong\u003e7.4\u003c\/strong\u003e Malware samples used in the course\/labs\u003cbr\u003e\u003cstrong\u003e7.5\u003c\/strong\u003e Memory Images used in the course\/labs\u003cbr\u003e\u003cstrong\u003e7.6\u003c\/strong\u003e Linux VM (to be opened with VMware Workstation\/Fusion) containing necessary tools and samples\u003cbr\u003e\u003cstrong\u003e7.7\u003c\/strong\u003e Custom tools\u003c\/p\u003e\n\u003ch2\u003e8. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3\u003eMonnappa K A\u003c\/h3\u003e\n\u003cp\u003eMonnappa K A is a Security Professional with over 17 years of experience in incident response, investigation, and threat hunting. He previously worked for Microsoft and Cisco as a threat hunter, mainly focusing on the investigation and research of advanced cyberattacks. He is the author of the best-selling book Learning Malware Analysis, and serves on the review board for Black Hat Asia, Black Hat USA, and Black Hat Europe.\u003c\/p\u003e\n\u003cp\u003eHe is the creator of the Garuda Threat Hunting Framework, Limon Linux sandbox, and the winner of the Volatility Plugin Contest 2016. He co-founded the cybersecurity research community Cysinfo (\u003ca href=\"https:\/\/www.cysinfo.com\"\u003ehttps:\/\/www.cysinfo.com\u003c\/a\u003e).\u003c\/p\u003e\n\u003cp\u003eMonnappa has trained thousands of security professionals globally through his highly acclaimed hands-on training sessions on malware analysis, reverse engineering, memory forensics, and threat hunting at major conferences such as Black Hat (USA, Europe, Asia, MEA), DEFCON, BruCON, HITB, FIRST (Forum of Incident Response and Security Teams), SEC-T, OPCDE, and 4SICS-SCADA\/ICS cybersecurity summit.\u003c\/p\u003e\n\u003cp\u003eHe has also presented at numerous security conferences, including Black Hat, DEFCON, FIRST, DSCI, National Cyber Defence Summit, Bharat NCX, and Cysinfo meetings, covering topics related to threat hunting, memory forensics, malware analysis, and reverse engineering.\u003c\/p\u003e\n\u003cp\u003eIn addition, he has authored articles for eForensics and Hakin9 magazines. You can find some of his contributions to the community on his YouTube channel (\u003ca href=\"http:\/\/www.youtube.com\/c\/MonnappaKA\"\u003ehttp:\/\/www.youtube.com\/c\/MonnappaKA\u003c\/a\u003e), and you can read his blog posts at \u003ca href=\"https:\/\/cysinfo.com\"\u003ehttps:\/\/cysinfo.com\u003c\/a\u003e.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTwitter:\u003c\/strong\u003e @monnappa22\u003c\/p\u003e\n\u003ch3\u003eSajan Shetty\u003c\/h3\u003e\n\u003cp\u003eSajan Shetty is a Cyber Security enthusiast. He is an active member of Cysinfo, an open Cyber Security Community (\u003ca href=\"https:\/\/www.cysinfo.com\"\u003ehttps:\/\/www.cysinfo.com\u003c\/a\u003e) committed to educating, empowering, inspiring, and equipping cyber security professionals and students to better fight and defend against cyber threats.\u003c\/p\u003e\n\u003cp\u003eHe has conducted training sessions at Black Hat, DEFCON, BRUCON and HITB, and his primary fields of interest include machine learning, malware analysis, and memory forensics. He has various certifications in machine learning and is passionate about applying machine learning techniques to solve cybersecurity problems.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e \u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e \u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942323658995,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/Monnappa_updated_image.webp?v=1786560120"},{"product_id":"cryptocurrency-basics-managing-security","title":"Cryptocurrency Basics: Managing Security","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Cryptocurrency Basics: Managing Security\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Michael Schloh von Bennewitz\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 AM - 5:00 PM\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eWe review most aspects of cryptocurrency systems and identify secure engineering practice while examining the roles of users, consumers, providers, and regulators. This is comprehensive training illustrating the cryptographic primitives of a wallet, the flow of funds across nodes in blocks, to the custodial or regulatory systems managing user transfers.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eManaging Security is a practical, no-nonsense introduction to safely navigating the world of digital assets. Designed for beginners and curious professionals alike, this course demystifies how cryptocurrencies work while focusing on the real risks users face every day where wallet compromise, phishing attacks, exchange failures, and human error are considered. Participants will gain a clear understanding of private keys, seed phrases, wallets, and transaction mechanics, along with why these elements are frequent targets for attackers.\u003c\/p\u003e\n\u003cp\u003eThrough hands-on demonstrations and real-world scenarios, attendees will learn how to set up and secure wallets, evaluate hot and cold storage options, recognize common scams, and build a personal threat model. By the end of the course, students won’t just understand cryptocurrency, they’ll know how to manage it responsibly, protect it effectively, and avoid the costly mistakes that plague even experienced users.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.1\u003c\/strong\u003e Blockchain explorer\u003cbr\u003e\u003cstrong\u003e3.2\u003c\/strong\u003e Privacy management\u003cbr\u003e\u003cstrong\u003e3.3\u003c\/strong\u003e AI and LLM tools\u003cbr\u003e\u003cstrong\u003e3.4 Exercise:\u003c\/strong\u003e Operate a blockchain explorer\u003cbr\u003e\u003cstrong\u003e3.5\u003c\/strong\u003e Custodial operation\u003cbr\u003e\u003cstrong\u003e3.6\u003c\/strong\u003e Exchanges\u003cbr\u003e\u003cstrong\u003e3.7\u003c\/strong\u003e Swap services\u003cbr\u003e\u003cstrong\u003e3.8 Exercise:\u003c\/strong\u003e Create a custodial account\u003cbr\u003e\u003cstrong\u003e3.9\u003c\/strong\u003e Noncustodial operation\u003cbr\u003e\u003cstrong\u003e3.10\u003c\/strong\u003e Wallet security\u003cbr\u003e\u003cstrong\u003e3.11\u003c\/strong\u003e Blockchains\u003cbr\u003e\u003cstrong\u003e3.12\u003c\/strong\u003e Testnets\u003cbr\u003e\u003cstrong\u003e3.13\u003c\/strong\u003e Mainnets\u003cbr\u003e\u003cstrong\u003e3.14\u003c\/strong\u003e Networking\u003cbr\u003e\u003cstrong\u003e3.15\u003c\/strong\u003e Decentral transports\u003cbr\u003e\u003cstrong\u003e3.16\u003c\/strong\u003e Wallets\u003cbr\u003e\u003cstrong\u003e3.17\u003c\/strong\u003e Structural analysis\u003cbr\u003e\u003cstrong\u003e3.18 Exercise:\u003c\/strong\u003e Create a noncustodial wallet\u003cbr\u003e\u003cstrong\u003e3.19\u003c\/strong\u003e Nodes\u003cbr\u003e\u003cstrong\u003e3.20\u003c\/strong\u003e Top services\u003cbr\u003e\u003cstrong\u003e3.21 Exercise:\u003c\/strong\u003e Operate a full node\u003cbr\u003e\u003cstrong\u003e3.22\u003c\/strong\u003e Consensus mechanisms\u003cbr\u003e\u003cstrong\u003e3.23\u003c\/strong\u003e Proof of stake\u003cbr\u003e\u003cstrong\u003e3.24\u003c\/strong\u003e Proof of work\u003cbr\u003e\u003cstrong\u003e3.25\u003c\/strong\u003e Mining operation\u003cbr\u003e\u003cstrong\u003e3.26 Exercise:\u003c\/strong\u003e Create a new cryptocurrency\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.27\u003c\/strong\u003e Initialising wallets\u003cbr\u003e\u003cstrong\u003e3.28\u003c\/strong\u003e Dice tooling\u003cbr\u003e\u003cstrong\u003e3.29\u003c\/strong\u003e Logical storage\u003cbr\u003e\u003cstrong\u003e3.30\u003c\/strong\u003e Portable electronics\u003cbr\u003e\u003cstrong\u003e3.31\u003c\/strong\u003e Datacenter electronics\u003cbr\u003e\u003cstrong\u003e3.32\u003c\/strong\u003e Dedicated hardware\u003cbr\u003e\u003cstrong\u003e3.33\u003c\/strong\u003e Physical storage\u003cbr\u003e\u003cstrong\u003e3.34\u003c\/strong\u003e Brain wallets\u003cbr\u003e\u003cstrong\u003e3.35\u003c\/strong\u003e Paper wallets\u003cbr\u003e\u003cstrong\u003e3.36\u003c\/strong\u003e Sheet wallets\u003cbr\u003e\u003cstrong\u003e3.37\u003c\/strong\u003e Metal wallets\u003cbr\u003e\u003cstrong\u003e3.38\u003c\/strong\u003e Hardware interfaces\u003cbr\u003e\u003cstrong\u003e3.39\u003c\/strong\u003e ATM devices\u003cbr\u003e\u003cstrong\u003e3.40\u003c\/strong\u003e IVI terminals\u003cbr\u003e\u003cstrong\u003e3.41\u003c\/strong\u003e Parking metres\u003cbr\u003e\u003cstrong\u003e3.42\u003c\/strong\u003e Vending machines\u003cbr\u003e\u003cstrong\u003e3.43 Exercise:\u003c\/strong\u003e Secure a new cryptocurrency\u003cbr\u003e\u003cstrong\u003e3.44\u003c\/strong\u003e Team collaboration\u003cbr\u003e\u003cstrong\u003e3.45\u003c\/strong\u003e Design and implementations\u003cbr\u003e\u003cstrong\u003e3.46 Exercise:\u003c\/strong\u003e Red and blue team role playing\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003ch2\u003e5. What Students Should Bring\u003c\/h2\u003e\n\u003cp\u003eLaptop you control from the UEFI to the OS, and a USB cable with a Type-C plug.\u003c\/p\u003e\n\u003ch2\u003e6. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003eUSB media drive, hardware developer kit, hardware wallet, and printed workbook. These course materials belong to you, to take home for continued study.\u003c\/p\u003e\n\u003ch2\u003e7. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3\u003eMichael Schloh von Bennewitz\u003c\/h3\u003e\n\u003cp\u003eMichael Schloh von Bennewitz (MSvB) is a computer scientist specializing in financial technology and embedded systems. As chairman of Novel Circuits and director of Cryptocurrency Advocate, he produces cryptosecure electronic devices while contributing to Opensource development communities. Michael teaches hardware security to cryptocurrency groups and fosters electronics enthusiasts eager to explore secure hardware devices. Together with a team of hackers, he leads the cryptocurrency areas at DEFCON since 2017.\u003c\/p\u003e\n\u003ch2\u003e8. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e8.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003e8.8 \u003c\/strong\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942327984371,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/rn-image_picker_lib_temp_c5ab6730-a6e6-487d-8789-60f15298a95e.png?v=1786906596"},{"product_id":"applied-ai-security-attacking-and-defending-llms","title":"Applied AI Security: Attacking and Defending LLMs","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Applied AI Security: Attacking and Defending LLMs\u003cbr\u003e\u003cstrong\u003eTrainer(s): \u003c\/strong\u003eDrinor Selmanaj, \u003cspan\u003eIva Amos\u003c\/span\u003e\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 800 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eApplied AI Security: Breaking and Defending LLMs training focuses on how AI systems fail in practice, how those failures can be abused, and how to stop them. Learners exploit LLMs the way attackers do, then flip sides and build defenses that work. All exercises run on a professional cyber range purpose-built for hands-on skill development.\u003c\/p\u003e\n\u003cp\u003eApplied AI Security: Breaking and Defending LLMs is an in-depth, hands-on training that examines the security of systems built on large language models (LLMs) as they are deployed in real-world environments. As organizations increasingly integrate LLMs into applications, services, and operational workflows, these systems introduce new security risks that extend beyond traditional application and infrastructure security models.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eThis course focuses on how LLM-based systems fail in practice, how those failures can be abused, and how they can be mitigated through sound security engineering and operational controls.\u003c\/p\u003e\n\u003cp\u003eParticipants will explore common design patterns used in LLM-enabled applications, including prompt-based interfaces, retrieval-augmented systems, tool-using agents, and automated workflows. Through guided exercises, attendees will analyze how trust boundaries shift in these systems and how misuse, manipulation, or unsafe behavior can lead to data exposure, unauthorized actions, or downstream system impact.\u003c\/p\u003e\n\u003cp\u003eThe training takes a balanced approach between offense and defense. On the offensive side, participants will examine techniques used to manipulate model behavior, influence decision-making, and abuse integrations between LLMs and external systems.\u003c\/p\u003e\n\u003cp\u003eOn the defensive side, the course emphasizes secure design principles, input and output controls, monitoring strategies, and response mechanisms tailored to AI-enabled systems. Rather than focusing on isolated model weaknesses, the course treats AI security as a system-level problem involving architecture, configuration, and operational context.\u003c\/p\u003e\n\u003cp\u003eAll concepts are reinforced through hands-on labs conducted in realistic environments designed to reflect how LLMs are used in production. Participants will practice assessing risk, testing AI-enabled features, and applying mitigations that are practical and maintainable.\u003c\/p\u003e\n\u003cp\u003eThe course also addresses operational considerations, including how to evaluate AI-related security incidents, how to integrate AI security into existing security workflows, and how to reason about risk when deploying or managing LLM-based systems.\u003c\/p\u003e\n\u003cp\u003eBy the end of the training, participants will have a practical understanding of how to evaluate the security posture of LLM-powered systems, how to identify and test meaningful failure modes, and how to design and operate defenses that reduce risk while allowing AI systems to remain useful and effective.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003e3.1 AI Systems Security Foundations\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e How LLM-based systems are built and deployed in practice\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Trust boundaries in AI-enabled workflows\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Why traditional AppSec assumptions fail for LLMs\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.4\u003c\/strong\u003e Exploring an LLM-enabled application\u003cbr\u003e\u003cstrong\u003e3.1.5\u003c\/strong\u003e Identifying components, data flows, and trust boundaries\u003c\/p\u003e\n\u003ch3\u003e3.2 LLM Architecture and Integration Patterns\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e Prompt-driven applications and system prompts\u003cbr\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Retrieval-augmented generation (RAG)\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Tool use, plugins, and agent-based workflows\u003cbr\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e Where attackers gain leverage in real deployments\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Architecture mapping of an LLM-based system\u003cbr\u003e\u003cstrong\u003e3.2.6\u003c\/strong\u003e Identifying attacker-controlled inputs and integration risks\u003c\/p\u003e\n\u003ch3\u003e3.3 AI Red Teaming Concepts and Methodology\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e What AI red teaming is (and what it is not)\u003cbr\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e Red teaming LLM systems vs traditional applications\u003cbr\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Adversarial thinking for language-driven systems\u003cbr\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e Using structured frameworks to guide testing\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eFrameworks discussed\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.5\u003c\/strong\u003e OWASP guidance for AI and LLM risk categorization\u003cbr\u003e\u003cstrong\u003e3.3.6\u003c\/strong\u003e MITRE ATLAS for adversary behavior modeling\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.7\u003c\/strong\u003e Mapping AI system behaviors to structured red-team categories\u003cbr\u003e\u003cstrong\u003e3.3.8\u003c\/strong\u003e Identifying realistic abuse goals and success criteria\u003c\/p\u003e\n\u003ch3\u003e3.4 Threat Modeling for AI Systems\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e Threat modeling LLM systems end-to-end\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e Assets, actors, and abuse paths\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Differentiating misuse, abuse, and unintended behavior\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e Prioritizing attacks based on real-world impact\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.5\u003c\/strong\u003e Threat modeling an AI-enabled workflow\u003cbr\u003e\u003cstrong\u003e3.4.6\u003c\/strong\u003e Selecting high-impact red-team test scenarios\u003c\/p\u003e\n\u003ch3\u003e3.5 Breaking LLM-Based Systems (Red Team Execution)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e Prompt manipulation and behavioral influence\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Indirect input abuse through documents, data sources, or tools\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e Unsafe agent behavior and excessive autonomy\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Chaining weaknesses across system components\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.5\u003c\/strong\u003e Executing controlled red-team scenarios against an LLM system\u003cbr\u003e\u003cstrong\u003e3.5.6\u003c\/strong\u003e Demonstrating unintended actions or data exposure\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003e3.6 Defensive Engineering, and Operations Defensive Design for LLM-Based Systems\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Secure design principles for AI-enabled applications\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e Reducing attack surface in prompts, tools, and agents\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e Managing permissions, autonomy, and scope\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Hardening an LLM system against identified red-team techniques\u003cbr\u003e\u003cstrong\u003e3.6.5\u003c\/strong\u003e Applying guardrails and constraints\u003c\/p\u003e\n\u003ch3\u003e3.7 Monitoring and Detection for AI Abuse\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.1\u003c\/strong\u003e Observability challenges in AI workflows\u003cbr\u003e\u003cstrong\u003e3.7.2\u003c\/strong\u003e Logging, tracing, and behavior monitoring\u003cbr\u003e\u003cstrong\u003e3.7.3\u003c\/strong\u003e Detecting prompt manipulation, misuse, and abnormal behavior\u003cbr\u003e\u003cstrong\u003e3.7.4\u003c\/strong\u003e Turning red-team findings into detection logic\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.5\u003c\/strong\u003e Instrumenting an LLM system for visibility\u003cbr\u003e\u003cstrong\u003e3.7.6\u003c\/strong\u003e Detecting simulated red-team activity\u003c\/p\u003e\n\u003ch3\u003e3.8 AI Blue Teaming and Incident Response\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.1\u003c\/strong\u003e Responding to AI-specific security incidents\u003cbr\u003e\u003cstrong\u003e3.8.2\u003c\/strong\u003e Containment and remediation for AI misuse\u003cbr\u003e\u003cstrong\u003e3.8.3\u003c\/strong\u003e Assessing downstream and organizational impact\u003cbr\u003e\u003cstrong\u003e3.8.4\u003c\/strong\u003e Coordinating technical and non-technical response\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.5\u003c\/strong\u003e Handling a simulated AI security incident\u003cbr\u003e\u003cstrong\u003e3.8.6\u003c\/strong\u003e Analysis, containment, and response decisions\u003c\/p\u003e\n\u003ch3\u003e3.9 Operationalizing AI Security and Red Team Feedback\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.9.1\u003c\/strong\u003e Feeding red-team findings into secure development\u003cbr\u003e\u003cstrong\u003e3.9.2\u003c\/strong\u003e Continuous testing of AI-enabled features\u003cbr\u003e\u003cstrong\u003e3.9.3\u003c\/strong\u003e Aligning AI security with organizational risk management\u003cbr\u003e\u003cstrong\u003e3.9.4\u003c\/strong\u003e Using red teaming to improve system design over time\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.9.5\u003c\/strong\u003e Creating an AI red-team test plan for a real deployment\u003cbr\u003e\u003cstrong\u003e3.9.6\u003c\/strong\u003e Defining testing scope, goals, and reporting outputs\u003c\/p\u003e\n\u003ch3\u003e3.10 Capstone: End-to-End AI Security Assessment\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.1\u003c\/strong\u003e Applying red and blue team concepts together\u003cbr\u003e\u003cstrong\u003e3.10.2\u003c\/strong\u003e Evaluating risk, controls, and residual exposure\u003cbr\u003e\u003cstrong\u003e3.10.3\u003c\/strong\u003e Communicating findings clearly to stakeholders\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs (Capstone \/ Certification)\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.4\u003c\/strong\u003e Full assessment of an LLM-enabled system\u003cbr\u003e\u003cstrong\u003e3.10.5\u003c\/strong\u003e Identify risks, execute red-team tests, and propose defenses\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eStudents should have:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBasic familiarity with using popular AI or chat-based tools\u003c\/li\u003e\n\u003cli\u003eAbility to read and modify basic Python code\u003c\/li\u003e\n\u003cli\u003eComfort using command-line tools and working in a lab environment\u003c\/li\u003e\n\u003cli\u003eBasic understanding of how APIs and modern web applications are structured\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLaptop with Wi-Fi\u003c\/li\u003e\n\u003cli\u003eModern web browser\u003c\/li\u003e\n\u003cli\u003eAbility to follow guided, hands-on lab instructions\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003eDuring the training, students will be provided with:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003ePre-configured adversary and target infrastructure\u003c\/li\u003e\n\u003cli\u003eCustom tooling and scripts\u003c\/li\u003e\n\u003cli\u003eDigital course workbook and reference materials\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer Bio\u003c\/h2\u003e\n\u003ch3\u003eDrinor Selmanaj\u003c\/h3\u003e\n\u003cp\u003eDrinor Selmanaj is a cybersecurity practitioner, researcher, and instructor specializing in adversary emulation, threat-informed defense, and offensive security operations. He is the author of the O’Reilly book Adversary Emulation with MITRE ATT\u0026amp;CK, which provides a structured methodology for translating real-world threat intelligence into realistic, measurable adversary campaigns.\u003c\/p\u003e\n\u003cp\u003eWith over a decade of experience across penetration testing, red teaming, and national-level cybersecurity consulting, Drinor has worked with multinational enterprises, critical infrastructure operators, and government-aligned stakeholders. He is the founder of Cyber Academy, where he designs and delivers advanced cybersecurity training programs and develops cyber ranges focused on realistic offensive and defensive scenarios.\u003c\/p\u003e\n\u003ch3\u003eIva Amos\u003c\/h3\u003e\n\u003cp\u003eIva Amos is a cybersecurity professional and practitioner researcher specializing in AI security, prompt injection, and agentic AI risk. She leads a multimillion CISA federal contract for upskilling government employees and architects training programs for over 70% of the Fortune 500 at Infosec.\u003c\/p\u003e\n\u003cp\u003eThe scope of her work spans a professional cyber range platform with 600+ labs, training 10K+ security professionals annually. She also teaches cybersecurity and AI\/ML at two universities. She presents breakout sessions and workshops at Gartner, EDUCAUSE, ISACA, NICE, Infosec World, and Hack Space Con, and brings 19+ years in technology with deep focus on cybersecurity and AI security training.\u003c\/p\u003e\n\u003cp\u003eIva and Drinor have worked together for over a year, architecting hands-on lab exercises for multiple training programs. Their most recent collaboration produced the labs for Infosec's \"Generative and Agentic AI for Cybersecurity Professionals\" course.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e \u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e \u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942328180979,"sku":null,"price":800.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/Iva_headshot.jpg?v=1786895364"},{"product_id":"certified-cloud-penetration-tester","title":"Certified Cloud Penetration Tester","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Certified Cloud Penetration Tester\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Hackers Academy\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eThis course provides a comprehensive introduction to cloud penetration testing for beginners, covering theoretical concepts, hands-on exercises, and practical strategies to breaching the top 3 cloud vendors: Azure, AWS \u0026amp; GCP.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eAs organizations increasingly adopt cloud services, securing cloud environments becomes paramount. Azure, AWS and GCP cloud platforms, are widely used across industries, making them a prime target for cyber threats. This course provides a comprehensive introduction to cloud penetration testing for beginners, covering theoretical concepts, hands-on exercises, and practical strategies to breaching the top 3 cloud vendors.\u003c\/p\u003e\n\u003cp\u003eWith over 20 immersive labs, learn how real attackers target AWS, Azure, and Google Cloud Platform. Through dynamic labs, guided simulations, and red-team thinking, you'll uncover the techniques adversaries use to breach, move and blend inside modern cloud environments.\u003c\/p\u003e\n\u003cp\u003eYou'll explore how identity, networking, automation, serverless, storage, and logging systems become both the attack surface and the battlefield.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics covered include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnumerating services and usernames\u003c\/li\u003e\n\u003cli\u003eVariety of initial access tailored for Azure, AWS and GCP\u003c\/li\u003e\n\u003cli\u003eBypassing defenses like Conditional Access Policies and MFA\u003c\/li\u003e\n\u003cli\u003eUsing cloud native tools to blend in avoid detection\u003c\/li\u003e\n\u003cli\u003eHacking service like storage in Azure, AWS and GCP\u003c\/li\u003e\n\u003cli\u003eCompromising compute for RCE and tokens\u003c\/li\u003e\n\u003cli\u003ePillaging secrets from key vaults\u003c\/li\u003e\n\u003cli\u003eAbusing serverless for privilege escalation\u003c\/li\u003e\n\u003cli\u003eIdentifying IAM weaknesses to create persistent backdoors\u003c\/li\u003e\n\u003cli\u003eAnd a lot more!\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003e3.1 Azure Pentesting\u003c\/h3\u003e\n\u003ch4\u003eIntroduction \u0026amp; Lab Setup\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e Introduction to Microsoft Azure, AWS and GGP and some of the most used services\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Important concepts and terminology: tenant, subscription, resource groups, resource, IAM, VM, EC2, Storage, S3, etc.\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Running the lab scripts to build up the attack scenarios\u003c\/p\u003e\n\u003ch3\u003e3.2 Azure Recon\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e Tenant availability and gather tenant information\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Validating tenant availability\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Azure subdomains recon as outsider\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Identifying Azure services in use\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Enumerating subdomains\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e User enumeration in Azure\u003cbr\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Understanding error codes\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Enumerating usernames\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.3 Azure Initial Access\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e Password Spraying\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Password spraying\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e Consent Phishing\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Consent grant\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Device Code Phishing\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Device Code Phishing\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e Adversary-in-The-Middle\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: AiTM\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.4 Conditional Access Policies\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e Understanding CAPs\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e What CAPs can and cannot do\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Understanding CAP gaps\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e CAP bypass strategies: membership, location, device, application …\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Bypass CAP\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.5\u003c\/strong\u003e Lab: Bypassing CAP with stolen tokens\u003c\/p\u003e\n\u003ch3\u003e3.5 Azure IAM (RBAC)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e IAM vs. Entra roles\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Primary resource roles\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e Separation of IAM and Entra roles\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Global admin elevation to RBAC – Case Study: Dev-1084 APT\u003c\/p\u003e\n\u003ch3\u003e3.6 Azure Storage Attacks\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Storage types\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e Storage accounts\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e Storage endpoints\u003cbr\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Storage Access Levels\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Enumerate and access public storage\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.5\u003c\/strong\u003e Storage Account Access\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSAS\u003c\/li\u003e\n\u003cli\u003eEntra ID authorization\u003c\/li\u003e\n\u003cli\u003eShared Keys\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.6\u003c\/strong\u003e Lab: Storage access with SAS\u003cbr\u003e\u003cstrong\u003e3.6.7\u003c\/strong\u003e Lab: Storage access with shared key\u003c\/p\u003e\n\u003ch3\u003e3.7 Azure Virtual Machines \u0026amp; IMDS\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.1\u003c\/strong\u003e Azure VMs\u003cbr\u003e\u003cstrong\u003e3.7.2\u003c\/strong\u003e Managed identities\u003cbr\u003e\u003cstrong\u003e3.7.3\u003c\/strong\u003e IMDS\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: requesting tokens from IMDS\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.8 Azure Key Vaults\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.1\u003c\/strong\u003e Understanding key vaults\u003cbr\u003e\u003cstrong\u003e3.8.2\u003c\/strong\u003e Key vault access policies\u003cbr\u003e\u003cstrong\u003e3.8.3\u003c\/strong\u003e Key vault IAM\u003cbr\u003e\u003cstrong\u003e3.8.4\u003c\/strong\u003e Managed IDs and Key Vaults\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Retrieving secrets from key vaults\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.5\u003c\/strong\u003e Key vault tampering for persistence\u003c\/p\u003e\n\u003ch3\u003e3.9 AWS Pentesting\u003c\/h3\u003e\n\u003ch3\u003e3.10 AWS Introduction\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.1\u003c\/strong\u003e Intro to AWS\u003cbr\u003e\u003cstrong\u003e3.10.2\u003c\/strong\u003e Attacker’s view and AWS APIs\u003cbr\u003e\u003cstrong\u003e3.10.3\u003c\/strong\u003e Understanding ARNs\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eCommon Services\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eS3\u003c\/li\u003e\n\u003cli\u003eEC2\u003c\/li\u003e\n\u003cli\u003eLambda\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.11 AWS Storage\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.11.1\u003c\/strong\u003e Understanding S3 common usages\u003cbr\u003e\u003cstrong\u003e3.11.2\u003c\/strong\u003e Where to look for S3 information\u003cbr\u003e\u003cstrong\u003e3.11.3\u003c\/strong\u003e Lab: S3 enumeration\u003c\/p\u003e\n\u003ch3\u003e3.12 AWS Initial Access\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.12.1\u003c\/strong\u003e Cloud attack lifecycle\u003cbr\u003e\u003cstrong\u003e3.12.2\u003c\/strong\u003e AWS access keys\u003cbr\u003e\u003cstrong\u003e3.12.3\u003c\/strong\u003e Searching for leaked keys\u003cbr\u003e\u003cstrong\u003e3.12.4\u003c\/strong\u003e Lab: Finding leaked keys\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003e3.13 AWS Pentesting (Cont.)\u003c\/h3\u003e\n\u003ch3\u003e3.14 AWS IAM\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.14.1\u003c\/strong\u003e What is IAM and what does it do?\u003cbr\u003e\u003cstrong\u003e3.14.2\u003c\/strong\u003e Policies, actions in policies and reading JSON\u003cbr\u003e\u003cstrong\u003e3.14.3\u003c\/strong\u003e AWS Roles\u003cbr\u003e\u003cstrong\u003e3.14.4\u003c\/strong\u003e AWS permissions\u003cbr\u003e\u003cstrong\u003e3.14.5\u003c\/strong\u003e Roles vs. Users\u003cbr\u003e\u003cstrong\u003e3.14.6\u003c\/strong\u003e Lab: Compromised user IAM user and role\u003c\/p\u003e\n\u003ch3\u003e3.15 Insider Recon\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.15.1\u003c\/strong\u003e Understanding cloud attacker mindset\u003cbr\u003e\u003cstrong\u003e3.15.2\u003c\/strong\u003e Important questions for post initial access\u003cbr\u003e\u003cstrong\u003e3.15.3\u003c\/strong\u003e Important AWS cli commands to know for situational awareness\u003cbr\u003e\u003cstrong\u003e3.15.4\u003c\/strong\u003e Lab: Post initial access, determine users, roles, policies and resources\u003c\/p\u003e\n\u003ch3\u003e3.16 EC2 \u0026amp; IMDS\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.1\u003c\/strong\u003e What is EC2\u003cbr\u003e\u003cstrong\u003e3.16.2\u003c\/strong\u003e Enumerating role assignments to EC2\u003cbr\u003e\u003cstrong\u003e3.16.3\u003c\/strong\u003e Understanding IMDS\u003cbr\u003e\u003cstrong\u003e3.16.4\u003c\/strong\u003e IMDS v1 vs. IMDS v2\u003cbr\u003e\u003cstrong\u003e3.16.5\u003c\/strong\u003e Lab: Hacking an EC2 with IMDS v1 to retrieve tokens\u003cbr\u003e\u003cstrong\u003e3.16.6\u003c\/strong\u003e Lab: Trying to hack an EC2 with MDS v2\u003c\/p\u003e\n\u003ch3\u003e3.17 AWS Lambda\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.1\u003c\/strong\u003e Understanding serverless and Lambda\u003cbr\u003e\u003cstrong\u003e3.17.2\u003c\/strong\u003e Examples of Lambda usage\u003cbr\u003e\u003cstrong\u003e3.17.3\u003c\/strong\u003e Enumerating role assignments to Lambda\u003cbr\u003e\u003cstrong\u003e3.17.4\u003c\/strong\u003e Lambda misconfigurations and exploitation\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSecrets\u003c\/li\u003e\n\u003cli\u003eCommand injection\u003c\/li\u003e\n\u003cli\u003eOverly permissive roles\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.5\u003c\/strong\u003e RCE example abusing Lambda function\u003cbr\u003e\u003cstrong\u003e3.17.6\u003c\/strong\u003e Lab: Pillaging Lamda functions for secrets\u003c\/p\u003e\n\u003ch3\u003e3.18 AWS Privilege Escalation\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.18.1\u003c\/strong\u003e What to look for in AWS\u003cbr\u003e\u003cstrong\u003e3.18.2\u003c\/strong\u003e Common paths to root\u003cbr\u003e\u003cstrong\u003e3.18.3\u003c\/strong\u003e Hunting for interesting permissions\u003cbr\u003e\u003cstrong\u003e3.18.4\u003c\/strong\u003e Finding admin\/root users\u003cbr\u003e\u003cstrong\u003e3.18.5\u003c\/strong\u003e Lab: hunting for privileged users\u003cbr\u003e\u003cstrong\u003e3.18.6\u003c\/strong\u003e Lab: Identifying exploitable permissions for privesc\u003c\/p\u003e\n\u003ch3\u003e3.19 AWS Persistence\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.19.1\u003c\/strong\u003e Paths to persistence in AWS\u003cbr\u003e\u003cstrong\u003e3.19.2\u003c\/strong\u003e Backdooring users\u003cbr\u003e\u003cstrong\u003e3.19.3\u003c\/strong\u003e Backdooring access keys\u003cbr\u003e\u003cstrong\u003e3.19.4\u003c\/strong\u003e Backdooring IAM Role trust\u003cbr\u003e\u003cstrong\u003e3.19.5\u003c\/strong\u003e Lab: assign admin permissions to user and create backdoored access key\u003c\/p\u003e\n\u003ch3\u003e3.20 GCP Introduction\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.20.1\u003c\/strong\u003e GCP intro and attacker setup\u003cbr\u003e\u003cstrong\u003e3.20.2\u003c\/strong\u003e What is GCP and how is it different than AWS and Azure\u003cbr\u003e\u003cstrong\u003e3.20.3\u003c\/strong\u003e The attacker’s view of GCP\u003cbr\u003e\u003cstrong\u003e3.20.4\u003c\/strong\u003e GCP hierarchy and why it matters\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eGCP Common Services\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eGCE\u003c\/li\u003e\n\u003cli\u003eStroage\u003c\/li\u003e\n\u003cli\u003eSQL\u003c\/li\u003e\n\u003cli\u003eBigQuery\u003c\/li\u003e\n\u003cli\u003eGatekeeper\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.21 GCP IAM\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.21.1\u003c\/strong\u003e What IAM in GCP looks like\u003cbr\u003e\u003cstrong\u003e3.21.2\u003c\/strong\u003e Understanding Principals\u003cbr\u003e\u003cstrong\u003e3.21.3\u003c\/strong\u003e IAM Roles\u003cbr\u003e\u003cstrong\u003e3.21.4\u003c\/strong\u003e IAM Resources and some examples\u003cbr\u003e\u003cstrong\u003e3.21.5\u003c\/strong\u003e IAM Policies and Policy Binding\u003cbr\u003e\u003cstrong\u003e3.21.6\u003c\/strong\u003e Service Accounts\u003cbr\u003e\u003cstrong\u003e3.21.7\u003c\/strong\u003e Service Account Keys\u003cbr\u003e\u003cstrong\u003e3.21.8\u003c\/strong\u003e Tokens\u003cbr\u003e\u003cstrong\u003e3.21.9\u003c\/strong\u003e Dangerous default accounts\u003c\/p\u003e\n\u003ch3\u003e3.22 GCP Initial Access\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eGCP Attack LifeCycle\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.22.1\u003c\/strong\u003e GCP Attack Playbook\u003cbr\u003e\u003cstrong\u003e3.22.2\u003c\/strong\u003e Evading detection\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eInitial Access\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.22.3\u003c\/strong\u003e The reality of most breaches\u003cbr\u003e\u003cstrong\u003e3.22.4\u003c\/strong\u003e Leaked service account keys\u003cbr\u003e\u003cstrong\u003e3.22.5\u003c\/strong\u003e Where to find keys\u003cbr\u003e\u003cstrong\u003e3.22.6\u003c\/strong\u003e Most exploited misconfigurations\u003cbr\u003e\u003cstrong\u003e3.22.7\u003c\/strong\u003e Default Compute Service Account example\u003cbr\u003e\u003cstrong\u003e3.22.8\u003c\/strong\u003e RCE to short-lived tokens\u003c\/p\u003e\n\u003ch3\u003e3.23 Enumeration\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.23.1\u003c\/strong\u003e Tools for post-breach recon\u003cbr\u003e\u003cstrong\u003e3.23.2\u003c\/strong\u003e How to blend it when the dev team\u003cbr\u003e\u003cstrong\u003e3.23.3\u003c\/strong\u003e What to avoid\u003cbr\u003e\u003cstrong\u003e3.23.4\u003c\/strong\u003e Key questions for situation awareness\u003cbr\u003e\u003cstrong\u003e3.23.5\u003c\/strong\u003e Key commands for gcloud cli\u003cbr\u003e\u003cstrong\u003e3.23.6\u003c\/strong\u003e Hunting for valuable data\u003cbr\u003e\u003cstrong\u003e3.23.7\u003c\/strong\u003e Lab: Insider enum\u003c\/p\u003e\n\u003ch3\u003e3.24 Cloud Storage\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.24.1\u003c\/strong\u003e What is Google cloud storage?\u003cbr\u003e\u003cstrong\u003e3.24.2\u003c\/strong\u003e What are high value targets in cloud storage?\u003cbr\u003e\u003cstrong\u003e3.24.3\u003c\/strong\u003e Abusing common misconfigurations\u003cbr\u003e\u003cstrong\u003e3.24.4\u003c\/strong\u003e Lab: list storage buckets, identify permission gaps and exfil sensitive data\u003c\/p\u003e\n\u003ch3\u003e3.25 Compute Engine \u0026amp; Metadata Exploitation\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.25.1\u003c\/strong\u003e What is GCP compute engine\u003cbr\u003e\u003cstrong\u003e3.25.2\u003c\/strong\u003e What is it a valuable target\u003cbr\u003e\u003cstrong\u003e3.25.3\u003c\/strong\u003e What is the Metadata Service\u003cbr\u003e\u003cstrong\u003e3.25.4\u003c\/strong\u003e Why target the Metadata Service\u003cbr\u003e\u003cstrong\u003e3.25.5\u003c\/strong\u003e Legacy v0.1 endpoints and how Google fixed it\u003cbr\u003e\u003cstrong\u003e3.25.6\u003c\/strong\u003e Modern attack vectors\u003cbr\u003e\u003cstrong\u003e3.25.7\u003c\/strong\u003e RCE to steal tokens\u003cbr\u003e\u003cstrong\u003e3.25.8\u003c\/strong\u003e How to use stolen tokens\u003cbr\u003e\u003cstrong\u003e3.25.9\u003c\/strong\u003e Lab: exploit a vulnerable app to steal tokens\u003c\/p\u003e\n\u003ch3\u003e3.26 Secret Manager\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.26.1\u003c\/strong\u003e What is Google Secret Manager\u003cbr\u003e\u003cstrong\u003e3.26.2\u003c\/strong\u003e What to expect if it’s exploited\u003cbr\u003e\u003cstrong\u003e3.26.3\u003c\/strong\u003e Secret Manager common misconfigurations\u003cbr\u003e\u003cstrong\u003e3.26.4\u003c\/strong\u003e Lab: Listing secrets and retrieving their values\u003c\/p\u003e\n\u003ch3\u003e3.27 Privilege Escalation in GCP\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.27.1\u003c\/strong\u003e GCP’s unique model\u003cbr\u003e\u003cstrong\u003e3.27.2\u003c\/strong\u003e The concept of chained impersonations\u003cbr\u003e\u003cstrong\u003e3.27.3\u003c\/strong\u003e Service account impersonation and how it works\u003cbr\u003e\u003cstrong\u003e3.27.4\u003c\/strong\u003e Impersonation attack flow\u003cbr\u003e\u003cstrong\u003e3.27.5\u003c\/strong\u003e Other privesc path\u003cbr\u003e\u003cstrong\u003e3.27.6\u003c\/strong\u003e Lab: from low priv user to generating tokens to privesc\u003c\/p\u003e\n\u003ch3\u003e3.28 Persistence in GCP\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.28.1\u003c\/strong\u003e GCP persistence TTPs: Backdooring keys, users and hijacking accounts\u003cbr\u003e\u003cstrong\u003e3.28.2\u003c\/strong\u003e Techniques for org level persistence\u003cbr\u003e\u003cstrong\u003e3.28.3\u003c\/strong\u003e Lab: Backdooring org with service account and new keys\u003c\/p\u003e\n\u003ch3\u003e3.29 BigQuery – Bonus Section if Time Allows\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.29.1\u003c\/strong\u003e What is BigQuery\u003cbr\u003e\u003cstrong\u003e3.29.2\u003c\/strong\u003e Why is it a valuable target\u003cbr\u003e\u003cstrong\u003e3.29.3\u003c\/strong\u003e BigQuery common misconfigurations: permissions, datasets, service accounts\u003cbr\u003e\u003cstrong\u003e3.29.4\u003c\/strong\u003e BigQuery enumeration\u003cbr\u003e\u003cstrong\u003e3.29.5\u003c\/strong\u003e BigQuery exfil\u003cbr\u003e\u003cstrong\u003e3.29.6\u003c\/strong\u003e Lab: Finding PII in BigQue\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eStudents should have:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eStudents are not expected to have knowledge of cloud services. However, it would help to have a basic level understanding of cyber security concepts, networking and operating systems.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents should bring a laptop with RDP client.\u003c\/li\u003e\n\u003cli\u003eAll labs are cloud based.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents will be provided with all course material. This includes over 300 slides and over 70 pages of lab manuals.\u003c\/li\u003e\n\u003cli\u003eCloud labs will be available for each student for 90 hours usage (within 15 days from the start of the training).\u003c\/li\u003e\n\u003cli\u003eThe instructors will share their own lab guides and scripts so students can replicate the setup in their private labs.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer Bio\u003c\/h2\u003e\n\u003ch3\u003eTarek Naja\u003c\/h3\u003e\n\u003cp\u003eTarek Naja is the founder of AstraSec.io and HackersAcademy.com. Tarek holds an MSc. in Information Security, is an international trainer who teaches at Blackhat, HiTB and other major conferences. He is also the technical advisor for GISEC, the largest security conference in the Middle East and is a previous OWASP Dubai Chapter Leader.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003eDEF CON Training Code of Conduct\u003c\/a\u003e and the registration terms and conditions listed above.\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942335914227,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/default_DCT_photo.webp?v=1786559556"},{"product_id":"certified-azure-purple-teamer","title":"Certified Azure Purple Teamer","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Certified Azure Purple Teamer\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Hackers Academy\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-10, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eLearn exactly what groups like LAPSUS, Star Blizzard, Storm-2373, Storm-0485, Storm-0501 and many others do and how you can lock down your Azure tenant to defend against them.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eFollow along with famous APTs, understand and replicate their TTPs in the live lab, then work hard on fortifying your Azure castle.\u003c\/p\u003e\n\u003cp\u003eDesigned for cloud engineers, administrators, architects, penetration testers and defenders, this training gives you a solid understanding of the day-to-day operations and resulting misconfigurations, different attacks path and multiple ways for initial access, persistence and privilege escalation. Followed by how you can enforce, audit, monitor and secure your Azure services.\u003c\/p\u003e\n\u003cp\u003eWith a great balance between practice and theory, you will quickly get your hands dirty with Azure services and multiple attack tools and techniques.\u003c\/p\u003e\n\u003cp\u003eWith 25 Red Labs and 22 Blue Lab, some of the topics covered will include:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSetting up for successful defense\u003c\/li\u003e\n\u003cli\u003eFoundations of Azure security: logs, network security, defender, etc.\u003c\/li\u003e\n\u003cli\u003eRecon and enumeration\u003c\/li\u003e\n\u003cli\u003e5 different ways to compromise identities\u003c\/li\u003e\n\u003cli\u003eIdentity protection and defense\u003c\/li\u003e\n\u003cli\u003eFinding gaps in Conditional Access\u003c\/li\u003e\n\u003cli\u003eFull Storage attack chain including persistence, C2 and exfil\u003c\/li\u003e\n\u003cli\u003eAbusing and securing Automation Accounts\u003c\/li\u003e\n\u003cli\u003eNetwork Services to lock down your resources\u003c\/li\u003e\n\u003cli\u003eKey Vaults pillaging, persistence and defense\u003c\/li\u003e\n\u003cli\u003eLocking down your secrets\u003c\/li\u003e\n\u003cli\u003eAzure Container Registries misconfigurations and security\u003c\/li\u003e\n\u003cli\u003eAbusing VMs for tokens, secrets and shell\u003c\/li\u003e\n\u003cli\u003eMonitoring and detecting VM abuse\u003c\/li\u003e\n\u003cli\u003eAnd a lot more!\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch4\u003e3.1 Introduction \u0026amp; Lab Setup\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e Introduction to Microsoft Azure and some of the most used services\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Important Azure concepts and terminology: tenant, subscription, resource groups, resource, etc.\u003c\/p\u003e\n\u003ch4\u003e3.2 Defender Essentials\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e Control and data planes\u003cbr\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Roles (IAM and Entra roles)\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Different types of logs in Azure\u003cbr\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e Where to store logs\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: Create Log Analytics\u003c\/li\u003e\n\u003cli\u003eBlue Lab: Analyze Entra ID Activity Logs\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.3 Network Security\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e Virtual networks\u003cbr\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e VNet Service Endpoints\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab (optional): Create a VNet \u0026amp; Service Endpoint\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Private Endpoints\u003c\/p\u003e\n\u003ch4\u003e3.4 Recon\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e Tenant availability and gather tenant information\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Validating tenant availability\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e Azure subdomains recon as outsider\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Identifying Azure services in use\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Enumerating subdomains\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e User enumeration in Azure\u003cbr\u003e\u003cstrong\u003e3.4.5\u003c\/strong\u003e Understanding error codes\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Enumerating usernames\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.5 Identity Attacks for Initial Access\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e Entra Connect – Case Study: Mercury \u0026amp; Dev\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Retrieving passwords for on-prem and on-cloud users\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Obtaining Valid Credentials – Case Study: LAPSUS$\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e Credential Stuffing – Case Study: Multiple APTs\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Password Spraying – Case Study: Multiple APTs\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Password spraying\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.5\u003c\/strong\u003e Consent Phishing – Case Study: Multiple APTs\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Consent grant\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.6\u003c\/strong\u003e Device Code Phishing – Case Study: Storm-2373\u003cbr\u003e\u003cstrong\u003e3.5.7\u003c\/strong\u003e Adversary-in-The-Middle – Case Study: Star Blizzard, Storm-0485\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: AiTM\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.8\u003c\/strong\u003e NEW: Device join phishing\u003cbr\u003e\u003cstrong\u003e3.5.9\u003c\/strong\u003e NEW: Teams phishing – Case Study: Storm-1674\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Teams calls phishing\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.10\u003c\/strong\u003e NEW: Using AI for phishing lures\u003c\/p\u003e\n\u003ch4\u003e3.6 Identity Attacks Defense \u0026amp; Detection\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Password spraying\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDefenses, playbooks, triggers and investigation\u003c\/li\u003e\n\u003cli\u003eBlue Lab: Investigate password spraying\u003c\/li\u003e\n\u003cli\u003eBlue Lab: Investigate password spraying with IP rotation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e Consent Phishing\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDefenses, playbooks, triggers and investigations\u003c\/li\u003e\n\u003cli\u003eAuditing app permissions\u003c\/li\u003e\n\u003cli\u003eUnderstanding consent types\u003c\/li\u003e\n\u003cli\u003eBlue Lab: Investigate app consent\u003c\/li\u003e\n\u003cli\u003eBlue Lab: Create and review app consent workbook\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e AiTM\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDefense best practices\u003c\/li\u003e\n\u003cli\u003eUnderstanding different types of tokens\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Device Code Phishing\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBest practices for protection\u003c\/li\u003e\n\u003cli\u003eConditional Access Policies\u003c\/li\u003e\n\u003cli\u003eInvestigating device code phishing\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.5\u003c\/strong\u003e General Identity Security\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSecure Score for Identity\u003c\/li\u003e\n\u003cli\u003eSecure Score top actions (password protection, SSPR, MFA, CAPs, PIM etc.)\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch4\u003e3.7 Conditional Access Policies\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.1\u003c\/strong\u003e Understanding CAPs\u003cbr\u003e\u003cstrong\u003e3.7.2\u003c\/strong\u003e What CAPs can and cannot do – Case Study: APT29\u003cbr\u003e\u003cstrong\u003e3.7.3\u003c\/strong\u003e Understanding CAP gaps\u003cbr\u003e\u003cstrong\u003e3.7.4\u003c\/strong\u003e CAP bypass strategies: membership, location, device, application …\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Bypass CAP\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.5\u003c\/strong\u003e Token types and FOCI\u003cbr\u003e\u003cstrong\u003e3.7.6\u003c\/strong\u003e Bypassing CAP with stolen tokens\u003c\/p\u003e\n\u003ch4\u003e3.8 Conditional Access Policies – Closing The Gaps\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.1\u003c\/strong\u003e Recommendations and best practices when planning CAPs\u003cbr\u003e\u003cstrong\u003e3.8.2\u003c\/strong\u003e What-if tool\u003cbr\u003e\u003cstrong\u003e3.8.3\u003c\/strong\u003e Analyzing insights and reporting and understanding CAP impacts\u003cbr\u003e\u003cstrong\u003e3.8.4\u003c\/strong\u003e Using Microsoft templates\u003cbr\u003e\u003cstrong\u003e3.8.5\u003c\/strong\u003e Gap Analyzer\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: CAP insights and reporting\u003c\/li\u003e\n\u003cli\u003eBlue Lab: CAP Gap Analyzer\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.9 Entra ID Roles \u0026amp; External Collaboration\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.9.1\u003c\/strong\u003e Entra ID resources\u003cbr\u003e\u003cstrong\u003e3.9.2\u003c\/strong\u003e Deep dive in Azure Entra ID roles and permissions\u003cbr\u003e\u003cstrong\u003e3.9.3\u003c\/strong\u003e Understanding users, groups and service principals\u003cbr\u003e\u003cstrong\u003e3.9.4\u003c\/strong\u003e Dynamic group membership\u003cbr\u003e\u003cstrong\u003e3.9.5\u003c\/strong\u003e Guest invites\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Abusing guest access for persistence\u003c\/li\u003e\n\u003cli\u003eRed Lab: Abusing dynamic groups for privilege escalation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.10 External Collaboration Security Strategies\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.1\u003c\/strong\u003e Entra ID risky default settings \u0026amp; their implications\u003cbr\u003e\u003cstrong\u003e3.10.2\u003c\/strong\u003e Entitlement Management\u003cbr\u003e\u003cstrong\u003e3.10.3\u003c\/strong\u003e Access Packages\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: External Collaboration Identity Governance\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.11 Entra ID App Registrations\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.11.1\u003c\/strong\u003e Understanding app registration\u003cbr\u003e\u003cstrong\u003e3.11.2\u003c\/strong\u003e What are service principals?\u003cbr\u003e\u003cstrong\u003e3.11.3\u003c\/strong\u003e Entra ID risky default settings \u0026amp; their implications\u003cbr\u003e\u003cstrong\u003e3.11.4\u003c\/strong\u003e App secrets and certificates\u003cbr\u003e\u003cstrong\u003e3.11.5\u003c\/strong\u003e Case Study: Nobelium APT\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: App registrations for persistence and privilege escalation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.12 Entra ID App Registrations Security Strategies\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.12.1\u003c\/strong\u003e Understanding app API permissions\u003cbr\u003e\u003cstrong\u003e3.12.2\u003c\/strong\u003e Delegated vs. App permissions\u003cbr\u003e\u003cstrong\u003e3.12.3\u003c\/strong\u003e Best practices when using service principals\u003cbr\u003e\u003cstrong\u003e3.12.4\u003c\/strong\u003e Reviewing service principal permission assignments\u003cbr\u003e\u003cstrong\u003e3.12.5\u003c\/strong\u003e Investigating service principal logins\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: investigate service principal logins\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.12.6\u003c\/strong\u003e PIM notifications on permissions changes\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: review SP role assignment changes\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.13 Managed Identities\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.13.1\u003c\/strong\u003e Understanding managed IDs\u003cbr\u003e\u003cstrong\u003e3.13.2\u003c\/strong\u003e Where can managed ID be used\u003cbr\u003e\u003cstrong\u003e3.13.3\u003c\/strong\u003e Types of managed IDs\u003cbr\u003e\u003cstrong\u003e3.13.4\u003c\/strong\u003e Managed ID tokens\u003cbr\u003e\u003cstrong\u003e3.13.5\u003c\/strong\u003e IMDS with virtual machines\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Retrieving managed ID token from IMDS\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.14 Managed Identities Security Strategies\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.14.1\u003c\/strong\u003e Finding and reviewing managed IDs: portal vs. PowerShell vs. Graph Explorer\u003cbr\u003e\u003cstrong\u003e3.14.2\u003c\/strong\u003e Reviewing role assignments\u003c\/p\u003e\n\u003ch4\u003e3.15 Azure IAM (RBAC)\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.15.1\u003c\/strong\u003e IAM vs. Entra roles\u003cbr\u003e\u003cstrong\u003e3.15.2\u003c\/strong\u003e Primary resource roles\u003cbr\u003e\u003cstrong\u003e3.15.3\u003c\/strong\u003e Separation of IAM and Entra roles\u003cbr\u003e\u003cstrong\u003e3.15.4\u003c\/strong\u003e Global admin elevation to RBAC – Case Study: Dev-1084 APT\u003c\/p\u003e\n\u003ch4\u003e3.16 Storage Attack Chain\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.1\u003c\/strong\u003e Storage types\u003cbr\u003e\u003cstrong\u003e3.16.2\u003c\/strong\u003e Storage accounts\u003cbr\u003e\u003cstrong\u003e3.16.3\u003c\/strong\u003e Storage endpoints\u003cbr\u003e\u003cstrong\u003e3.16.4\u003c\/strong\u003e Storage Access Levels\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Enumerate and access public storage\u003c\/li\u003e\n\u003cli\u003eRed Lab: Storage enumeration with custom wordlist\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.5\u003c\/strong\u003e 3 Types of Shared Access Signatures\u003cbr\u003e\u003cstrong\u003e3.16.6\u003c\/strong\u003e Accessing storage with Entra ID credentials\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Storage access with credentials\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.7\u003c\/strong\u003e Storage Account Access – Case Study: Storm-0501\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSAS\u003c\/li\u003e\n\u003cli\u003eEntra ID authorization\u003c\/li\u003e\n\u003cli\u003eShared Keys\u003c\/li\u003e\n\u003cli\u003eRed Lab: Access account with shared key\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.8\u003c\/strong\u003e NEW: Storage Attack Chain – Case Study: Multiple APTs\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRecon\u003c\/li\u003e\n\u003cli\u003eResource development: Storage for phishing infrastructure\u003c\/li\u003e\n\u003cli\u003eInitial access\u003c\/li\u003e\n\u003cli\u003ePersistence: IAM manipulation, SAS generation\u003c\/li\u003e\n\u003cli\u003eDefense Evasion: log tampering and deletion\u003c\/li\u003e\n\u003cli\u003eCredential Access: token and key extraction, cloud shell\u003c\/li\u003e\n\u003cli\u003eDiscovery: querying for valuable information\u003c\/li\u003e\n\u003cli\u003eLateral Movement: targeting functions or automation that uses storage\u003c\/li\u003e\n\u003cli\u003eCollection: copying and moving data to storage, pre-exfil\u003c\/li\u003e\n\u003cli\u003eExfiltration: exfil using web containers, automation accounts, etc.\u003c\/li\u003e\n\u003cli\u003eC2 using blob storage\u003c\/li\u003e\n\u003cli\u003eImpact: mass deletion, overwriting or encryption\u003c\/li\u003e\n\u003cli\u003eRed Lab: Lateral movement using automation accounts and storage\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eDay 3\u003c\/h3\u003e\n\u003ch4\u003e3.17 Storage Security\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.1\u003c\/strong\u003e Disabling anonymous access – planning phase\u003cbr\u003e\u003cstrong\u003e3.17.2\u003c\/strong\u003e D.R.A.G before disabling anonymous access\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: Investigate storage logs\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.3\u003c\/strong\u003e SAS tracking challenges\u003cbr\u003e\u003cstrong\u003e3.17.4\u003c\/strong\u003e SAS best practices: disallow, least privilege, revocation plan\u003cbr\u003e\u003cstrong\u003e3.17.5\u003c\/strong\u003e SAS policies\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: Find accounts with SAS\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.6\u003c\/strong\u003e Network security: firewall, private endpoint, secure transfer\u003cbr\u003e\u003cstrong\u003e3.17.7\u003c\/strong\u003e Logging \u0026amp; monitoring\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: Monitor for storage authorization\u003c\/li\u003e\n\u003cli\u003eBlue Lab: Storage Diagnostic Settings\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.18 Automation Accounts PrivEsc and Persistence\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.18.1\u003c\/strong\u003e Understanding Automation Accounts\u003cbr\u003e\u003cstrong\u003e3.18.2\u003c\/strong\u003e Run As vs. Managed Identity\u003cbr\u003e\u003cstrong\u003e3.18.3\u003c\/strong\u003e Finding secrets in variables\u003cbr\u003e\u003cstrong\u003e3.18.4\u003c\/strong\u003e Runbooks and runbooks’ modules\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Abusing runbook for privilege escalation\u003c\/li\u003e\n\u003cli\u003eNEW Red Lab: Abusing runbook for reverse shell\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.18.5\u003c\/strong\u003e Webhooks\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Creating webhook for persistence\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.19 Automation Accounts Security\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.19.1\u003c\/strong\u003e Job output precautions\u003cbr\u003e\u003cstrong\u003e3.19.2\u003c\/strong\u003e Precautions with variables\u003cbr\u003e\u003cstrong\u003e3.19.3\u003c\/strong\u003e Using service\/private endpoints\u003cbr\u003e\u003cstrong\u003e3.19.4\u003c\/strong\u003e Using managed IDs\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eNEW Blue Lab: Encrypted variables in Automation Accounts\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.20 Virtual Machines\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.20.1\u003c\/strong\u003e VM extensions\u003cbr\u003e\u003cstrong\u003e3.20.2\u003c\/strong\u003e VM disk snapshots Encrypted vs. Unencrypted\u003cbr\u003e\u003cstrong\u003e3.20.3\u003c\/strong\u003e VM run command\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Run command for privilege escalation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.20.4\u003c\/strong\u003e NEW: NSGs\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Manipulating NSGs to allow remote access\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.20.5\u003c\/strong\u003e NEW: Quota manipulation for attack infrastructure – Case Study: Unknown APT\u003c\/p\u003e\n\u003ch4\u003e3.21 Virtual Machines Security Strategies\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.21.1\u003c\/strong\u003e NSG vs. Firewall vs. WAF\u003cbr\u003e\u003cstrong\u003e3.21.2\u003c\/strong\u003e Restricting management ports\u003cbr\u003e\u003cstrong\u003e3.21.3\u003c\/strong\u003e Understanding Bastion Hosts\u003cbr\u003e\u003cstrong\u003e3.21.4\u003c\/strong\u003e PIM access\u003cbr\u003e\u003cstrong\u003e3.21.5\u003c\/strong\u003e Azure Update Manager\u003cbr\u003e\u003cstrong\u003e3.21.6\u003c\/strong\u003e Disk encryption\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: Retrieving hashes from snapshots – encrypted vs. unencrypted\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.21.7\u003c\/strong\u003e NEW: Quota alerts expected and unexpected quota consumption\u003c\/p\u003e\n\u003ch4\u003e3.22 Key Vaults\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.22.1\u003c\/strong\u003e Understanding key vaults\u003cbr\u003e\u003cstrong\u003e3.22.2\u003c\/strong\u003e Key vault access policies\u003cbr\u003e\u003cstrong\u003e3.22.3\u003c\/strong\u003e Key vault IAM\u003cbr\u003e\u003cstrong\u003e3.22.4\u003c\/strong\u003e Managed IDs and Key Vaults\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Retrieving secrets from key vaults\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.22.5\u003c\/strong\u003e Key vault tampering for persistence – Case Study: Unknown APT\u003c\/p\u003e\n\u003ch4\u003e3.23 Key Vaults Security Strategies\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.23.1\u003c\/strong\u003e Key vault RBAC vs. Access Policies\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: Different built-in roles for different jobs\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.23.2\u003c\/strong\u003e Firewalling key vaults\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlue Lab: Firewall your key vault\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.23.3\u003c\/strong\u003e Key vaults on private endpoints\u003cbr\u003e\u003cstrong\u003e3.23.4\u003c\/strong\u003e CAPs for key vaults\u003cbr\u003e\u003cstrong\u003e3.23.5\u003c\/strong\u003e Purge protection\u003cbr\u003e\u003cstrong\u003e3.23.6\u003c\/strong\u003e Monitoring key vaults\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eWho’s listing and retrieving secrets\u003c\/li\u003e\n\u003cli\u003eWho’s accessing the key vaults\u003c\/li\u003e\n\u003cli\u003eBlue Lab: Queries to monitor retrieving secrets and accessing key vaults\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.24 Azure Container Registries (ACRs)\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.24.1\u003c\/strong\u003e Container lifecycle\u003cbr\u003e\u003cstrong\u003e3.24.2\u003c\/strong\u003e ACR anonymous access\u003cbr\u003e\u003cstrong\u003e3.24.3\u003c\/strong\u003e ACR reader access\u003cbr\u003e\u003cstrong\u003e3.24.4\u003c\/strong\u003e ACR admin access\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRed Lab: Pulling and inspecting images for secrets\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.25 ACR Security Strategies\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.25.1\u003c\/strong\u003e ACR authentication best practices\u003cbr\u003e\u003cstrong\u003e3.25.2\u003c\/strong\u003e Securing ACR pull\u003cbr\u003e\u003cstrong\u003e3.25.3\u003c\/strong\u003e Service endpoints for ACR\u003cbr\u003e\u003cstrong\u003e3.25.4\u003c\/strong\u003e Container image vulnerability management\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eNEW Blue Lab: Restricting network access to ACRs\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003e3.26 Final Exam\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eA CTF style mimicking parts of a breach by Storm-0501.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eStudents are not expected to have knowledge of cloud services. However, it would help to have a basic level understanding of cyber security concepts, networking and operating systems.\u003c\/p\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents should bring a laptop with RDP client.\u003c\/li\u003e\n\u003cli\u003eAll labs are cloud based.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents will be provided with all course material. This includes over 300 slides and over 70 pages of lab manuals.\u003c\/li\u003e\n\u003cli\u003eCloud labs will be available for each student for 90 hours usage (within 15 days from the start of the training).\u003c\/li\u003e\n\u003cli\u003eThe instructors will share their own lab guides and scripts so students can replicate the setup in their private labs.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer Bio\u003c\/h2\u003e\n\u003ch3\u003eTim Katsapas\u003c\/h3\u003e\n\u003cp\u003eTim Katsapas is the Founder of Turing Cyber and a senior trainer at Hackers Academy. He is a seasoned security professional with deep expertise in Azure, M365, and hybrid cloud security.\u003c\/p\u003e\n\u003cp\u003eWith a strong background in both cloud and on-premises environments, Tim previously worked at Microsoft as a Premier Field Engineer and Cloud Solution Architect specializing in identity and security. His focus included Active Directory and Entra ID security assessments, helping enterprises maximize the value of Entra ID P2 and Microsoft 365 E5 security features.\u003c\/p\u003e\n\u003cp\u003eAn MCT since 2008, Tim has delivered technical training globally, including at Microsoft and Black Hat Europe and US. He holds numerous certifications, including OSCP and over 30 Microsoft credentials.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003eDEF CON Training Code of Conduct\u003c\/a\u003e and the registration terms and conditions listed above.\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942336372979,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/default_DCT_photo.webp?v=1786559556"},{"product_id":"defending-kubernetes-cloud-native-infrastructure-in-the-age-of-ai","title":"Defending Kubernetes \u0026 Cloud-Native Infrastructure in the Age of AI","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Defending Kubernetes \u0026amp; Cloud-Native Infrastructure in the Age of AI\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Madhu Akula\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1000 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eDefending containerized workloads and cloud-native infrastructure is more critical than ever. Recent security reports indicate that 42% of respondents cite security as a top concern with container and Kubernetes strategies, while attackers start probing new clusters in as little as 18 minutes.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eThis hands-on, real-world training is designed to equip Blue Teamers, Cloud Security Engineers, Security Architects, and DevSecOps professionals with the skills needed to understand and defend Kubernetes clusters across the supply chain, infrastructure, and runtime layers.\u003c\/p\u003e\n\u003cp\u003eThe course addresses current threat landscapes including AI\/ML workload security, supply chain attacks, and emerging attack vectors identified in recent days.\u003c\/p\u003e\n\u003cp\u003eThrough simulated attack scenarios, practical labs, and real-world case studies, participants will learn to detect modern TTPs, implement effective security controls, and improve observability and incident response capabilities.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003eSection 1: Foundation \u0026amp; Threat Landscape\u003c\/h3\u003e\n\u003ch4\u003e3.1 Fast-Track Kubernetes 101 for Defenders\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e Architecture deep-dive from a security perspective\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Attack surface analysis and entry points\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Understanding AI\/ML workload orchestration patterns\u003c\/p\u003e\n\u003ch4\u003e3.2 Threat Modeling \u0026amp; Intelligence\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e MITRE ATT\u0026amp;CK for Containers framework (latest tactics)\u003cbr\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Analysis of latest recent Kubernetes incident trends\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Anonymous authentication exploitation patterns\u003cbr\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e STRIDE methodology adapted for cloud-native environments\u003cbr\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Behavioral threat detection using IOCs\u003c\/p\u003e\n\u003ch4\u003e3.3 Defensive kubectl Kung-Fu: Advanced API Auditing\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e API server security hardening beyond basics\u003cbr\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e Detecting lateral movement through API abuse\u003cbr\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Advanced RBAC audit techniques\u003cbr\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e API server attack path analysis\u003c\/p\u003e\n\u003ch4\u003e3.4 Supply Chain Security Revolution\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e Container image signing with Sigstore\/Cosign\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e Software Bill of Materials (SBOM) enforcement\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Provenance verification and attestation\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e Private registry threat modeling\u003cbr\u003e\u003cstrong\u003e3.4.5\u003c\/strong\u003e Third-party dependency risk assessment\u003c\/p\u003e\n\u003ch3\u003eSection 2: Advanced Hardening \u0026amp; Attack Path Mitigation\u003c\/h3\u003e\n\u003ch4\u003e3.5 Next-Gen Container Isolation\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e Container escape prevention with gVisor\/Kata\/etc.\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Advanced security profiles like KuberArmor or AppArmor \u0026amp; seccomp-bpf\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e User namespace security considerations\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Privileged container detection strategies\u003c\/p\u003e\n\u003ch4\u003e3.6 Zero-Trust Network Security\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Service mesh security (Istio\/Linkerd security policies)\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e eBPF-based network monitoring and enforcement\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e East-west traffic encryption patterns\u003cbr\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Network policy testing and validation\u003c\/p\u003e\n\u003ch4\u003e3.7 Identity \u0026amp; Access Management Revolution\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.1\u003c\/strong\u003e RBAC security assessment methodology\u003cbr\u003e\u003cstrong\u003e3.7.2\u003c\/strong\u003e ServiceAccount token security\u003cbr\u003e\u003cstrong\u003e3.7.3\u003c\/strong\u003e Workload identity \u0026amp; federation\u003cbr\u003e\u003cstrong\u003e3.7.4\u003c\/strong\u003e Pod Security Standards (PSS) enforcement\u003c\/p\u003e\n\u003ch4\u003e3.8 Modern Application Delivery Security\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.1\u003c\/strong\u003e GitOps security patterns and threat modeling\u003cbr\u003e\u003cstrong\u003e3.8.2\u003c\/strong\u003e Helm security beyond basics (OCI registries)\u003cbr\u003e\u003cstrong\u003e3.8.3\u003c\/strong\u003e Kustomize security considerations\u003cbr\u003e\u003cstrong\u003e3.8.4\u003c\/strong\u003e ArgoCD\/Flux security hardening\u003c\/p\u003e\n\u003ch4\u003e3.9 Secrets \u0026amp; Data Protection\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.9.1\u003c\/strong\u003e External Secrets Operator patterns\u003cbr\u003e\u003cstrong\u003e3.9.2\u003c\/strong\u003e HashiCorp Vault integration security\u003cbr\u003e\u003cstrong\u003e3.9.3\u003c\/strong\u003e CSI driver security considerations\u003cbr\u003e\u003cstrong\u003e3.9.4\u003c\/strong\u003e Encryption at rest with cloud KMS integration\u003c\/p\u003e\n\u003ch4\u003e3.10 Cloud-Native Defense Integration\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.1\u003c\/strong\u003e Cloud provider security service integration\u003cbr\u003e\u003cstrong\u003e3.10.2\u003c\/strong\u003e Workload identity and IRSA security patterns\u003cbr\u003e\u003cstrong\u003e3.10.3\u003c\/strong\u003e Cloud metadata API protection strategies\u003cbr\u003e\u003cstrong\u003e3.10.4\u003c\/strong\u003e Multi-cloud security considerations\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003eSection 3: Detection, Monitoring \u0026amp; AI-Enhanced Response\u003c\/h3\u003e\n\u003ch4\u003e3.11 Runtime Security Revolution\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.11.1\u003c\/strong\u003e Falco rule customization and tuning\u003cbr\u003e\u003cstrong\u003e3.11.2\u003c\/strong\u003e eBPF-based monitoring with Tetragon\/Tracee\u003cbr\u003e\u003cstrong\u003e3.11.3\u003c\/strong\u003e Cilium Hubble for network observability\u003cbr\u003e\u003cstrong\u003e3.11.4\u003c\/strong\u003e Container runtime security (containerd\/CRI-O)\u003c\/p\u003e\n\u003ch4\u003e3.12 AI\/ML Workload Security Specialization\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.12.1\u003c\/strong\u003e GPU resource abuse detection\u003cbr\u003e\u003cstrong\u003e3.12.2\u003c\/strong\u003e Model poisoning prevention strategies\u003cbr\u003e\u003cstrong\u003e3.12.3\u003c\/strong\u003e ML pipeline security monitoring\u003cbr\u003e\u003cstrong\u003e3.12.4\u003c\/strong\u003e Jupyter\/MLflow security considerations\u003c\/p\u003e\n\u003ch4\u003e3.13 Advanced Threat Detection\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.13.1\u003c\/strong\u003e Behavioral anomaly detection with ML\u003cbr\u003e\u003cstrong\u003e3.13.2\u003c\/strong\u003e Cryptomining detection patterns\u003cbr\u003e\u003cstrong\u003e3.13.3\u003c\/strong\u003e Advanced persistent threat (APT) indicators\u003cbr\u003e\u003cstrong\u003e3.13.4\u003c\/strong\u003e Secrets scanning in runtime environments\u003c\/p\u003e\n\u003ch4\u003e3.14 Policy-as-Code \u0026amp; Governance\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.14.1\u003c\/strong\u003e Kyverno policy \u0026amp; OPA Gatekeeper engine comparison\u003cbr\u003e\u003cstrong\u003e3.14.2\u003c\/strong\u003e Spotter universal security policy engine\u003cbr\u003e\u003cstrong\u003e3.14.3\u003c\/strong\u003e Policy testing and CI\/CD integration\u003c\/p\u003e\n\u003ch4\u003e3.15 Persistence \u0026amp; Evasion Hunting\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.15.1\u003c\/strong\u003e Sidecar injection attack detection\u003cbr\u003e\u003cstrong\u003e3.15.2\u003c\/strong\u003e Init container abuse patterns\u003cbr\u003e\u003cstrong\u003e3.15.3\u003c\/strong\u003e DaemonSet privilege escalation hunting\u003cbr\u003e\u003cstrong\u003e3.15.4\u003c\/strong\u003e Node-level persistence techniques\u003c\/p\u003e\n\u003ch4\u003e3.16 Incident Response Playbooks\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.1\u003c\/strong\u003e Automated response orchestration\u003cbr\u003e\u003cstrong\u003e3.16.2\u003c\/strong\u003e Container forensics techniques\u003cbr\u003e\u003cstrong\u003e3.16.3\u003c\/strong\u003e Kubernetes-native incident response tools\u003c\/p\u003e\n\u003ch3\u003eSection 4: Auditing, Automation \u0026amp; Future-Ready Defense\u003c\/h3\u003e\n\u003ch4\u003e3.17 Comprehensive Security Posture Assessment\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.1\u003c\/strong\u003e Multi-tool audit orchestration\u003cbr\u003e\u003cstrong\u003e3.17.2\u003c\/strong\u003e KubeAudit, Trivy, Kubescape, Kube-score, Spotter comparison\u003cbr\u003e\u003cstrong\u003e3.17.3\u003c\/strong\u003e Popeye resource optimization auditing\u003cbr\u003e\u003cstrong\u003e3.17.4\u003c\/strong\u003e Custom policy development\u003c\/p\u003e\n\u003ch4\u003e3.18 Compliance \u0026amp; Benchmarking Excellence\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.18.1\u003c\/strong\u003e CIS Kubernetes Benchmark implementation\u003cbr\u003e\u003cstrong\u003e3.18.2\u003c\/strong\u003e NIST Cybersecurity Framework mapping\u003cbr\u003e\u003cstrong\u003e3.18.3\u003c\/strong\u003e SOC 2 compliance for Kubernetes\u003cbr\u003e\u003cstrong\u003e3.18.4\u003c\/strong\u003e PCI-DSS container security requirements\u003c\/p\u003e\n\u003ch4\u003e3.19 DevSecOps Integration Mastery\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.19.1\u003c\/strong\u003e Security scanning in GitOps workflows\u003cbr\u003e\u003cstrong\u003e3.19.2\u003c\/strong\u003e Admission controller testing in CI\/CD\u003cbr\u003e\u003cstrong\u003e3.19.3\u003c\/strong\u003e Infrastructure as Code security scanning\u003cbr\u003e\u003cstrong\u003e3.19.4\u003c\/strong\u003e Progressive delivery security gates\u003c\/p\u003e\n\u003ch4\u003e3.20 Real-World Case Study Deep Dives\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.20.1\u003c\/strong\u003e Kubernetes cryptojacking incident analysis\u003cbr\u003e\u003cstrong\u003e3.20.2\u003c\/strong\u003e Misconfigured API server exploitation case studies\u003cbr\u003e\u003cstrong\u003e3.20.3\u003c\/strong\u003e Supply chain attack post-mortems\u003cbr\u003e\u003cstrong\u003e3.20.4\u003c\/strong\u003e AI\/ML infrastructure compromise scenarios\u003c\/p\u003e\n\u003ch4\u003e3.21 Security Maturity \u0026amp; Future Direction\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.21.1\u003c\/strong\u003e Kubernetes Security Maturity Model (KSMM)\u003cbr\u003e\u003cstrong\u003e3.21.2\u003c\/strong\u003e Emerging security tools landscape\u003cbr\u003e\u003cstrong\u003e3.21.3\u003c\/strong\u003e Cloud-native security platform integration\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eAdvanced\u003c\/strong\u003e - The student is expected to have significant practical experience with the tools and technologies that the training will focus on.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBasic Kubernetes knowledge (kubectl, YAML manifests)\u003c\/li\u003e\n\u003cli\u003eContainer security fundamentals\u003c\/li\u003e\n\u003cli\u003eLinux system administration experience\u003c\/li\u003e\n\u003cli\u003eFamiliarity with cloud provider security services\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents should bring a laptop with a browser and we will provide you with access to the browser-based labs.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e00+ page digital workbook with step-by-step labs and references\u003c\/li\u003e\n\u003cli\u003eCustom lab environment for continued practice\u003c\/li\u003e\n\u003cli\u003eSecurity policy templates and implementation guides\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer Bio\u003c\/h2\u003e\n\u003ch3\u003eMadhu Akula\u003c\/h3\u003e\n\u003cp\u003eMadhu Akula is a pragmatic security leader and creator of Kubernetes Goat, an intentionally vulnerable by-design Kubernetes Cluster to learn and practice Kubernetes Security. Also published author and cloud-native security architect with extensive experience.\u003c\/p\u003e\n\u003cp\u003eAlso, he is an active member of the international security, DevOps, and cloud-native communities (null, DevSecOps, AllDayDevOps, AWS, CNCF, USENIX, OWASP, etc). Holds industry certifications like OSCP (Offensive Security Certified Professional), CKA (Certified Kubernetes Administrator), CKS (Certified Kubernetes Security Specialist), etc.\u003c\/p\u003e\n\u003cp\u003eMadhu frequently speaks and runs training sessions at security events and conferences around the world including DEFCON (24, 26, 27, 28, 29, 30, 31, 32, 33 \u0026amp; 34), BlackHat USA, EU, ASIA (2018, 19, 21, 22, 23, 24, 25 \u0026amp; 26), USENIX LISA (2018, 19 \u0026amp; 21), SANS Cloud Security Summit 2021 \u0026amp; 2022, O'Reilly Velocity EU, GitHub Satellite, Appsec EU (2018, 19 \u0026amp; 22), All Day DevOps (2016, 17, 18, 19, 20, 21, 22, 23 \u0026amp; 24), DevSecCon (London, Singapore, Boston), DevOpsDays India, c0c0n (2017, 18 \u0026amp; 20), Nullcon (2018, 19, 21 \u0026amp; 22), SACON, WeAreDevelopers, null and multiple others.\u003c\/p\u003e\n\u003cp\u003eHis research has identified vulnerabilities in over 200+ companies and organisations including; Google, Microsoft, LinkedIn, eBay, AT\u0026amp;T, WordPress, NTOP Adobe, etc, and is credited with multiple CVEs, Acknowledgements, and rewards.\u003c\/p\u003e\n\u003cp\u003eHe is co-author of Security Automation with Ansible2 (ISBN-13: 978-1788394512), which is listed as a technical resource by Red Hat Ansible. He is the technical reviewer for Learn Kubernetes Security, and Practical Ansible2 books by Packt Pub.\u003c\/p\u003e\n\u003cp\u003eAlso won 1st prize for building an Infrastructure Security Monitoring solution at InMobi flagship hackathon among 100+ engineering teams. In addition to his technical expertise, Madhu advises startups on building exceptional products and communities, helping them add significant value along the way.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003eDEF CON Training Code of Conduct\u003c\/a\u003e and the registration terms and conditions listed above.\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942336504051,"sku":null,"price":1000.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/MadhuAkula.avif?v=1786559982"},{"product_id":"hands-on-hacking-fundamentals","title":"Hands-On Hacking Fundamentals","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Hands-On Hacking Fundamentals\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Orange Cyberdefense Trainers\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eThis introductory hacking course is focused on the fundamentals of the security landscape, how hackers think and the tools, tactics and techniques they use. By the end of the course, you will have a good grasp of how vulnerabilities and exploits work, how attackers think about networks and systems and have compromised several of them from an infrastructure, web application and Wi-Fi perspective.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eStart your journey into information security with a hands-on course that will expose you to the technical fundamentals of penetration testing and security practises in the realms of networking, infrastructure, web applications and wireless technologies.\u003c\/p\u003e\n\u003ch3\u003eKey Points\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHow to think like a hacker\u003c\/li\u003e\n\u003cli\u003eAI as a tool in cybersecurity\u003c\/li\u003e\n\u003cli\u003eFinding vulnerabilities and exploiting them\u003c\/li\u003e\n\u003cli\u003eHow to approach a pentesting methodology in real world scenarios\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eThis is an introductory course for those starting the journey into penetration testing or those working in environments where understanding how hackers think and the tools, tactics and techniques they use are of essence. Learn how to attack and utilise the concepts to enhance your defensive understandings.\u003c\/p\u003e\n\u003cp\u003eThe course presents the background information, technical skills and basic concepts required to those desiring a foundation in the world of information security.\u003c\/p\u003e\n\u003cp\u003eBy the end of the course, you will have a good grasp of how vulnerabilities and exploits work, how attackers think about networks and systems, and have compromised several of them, from infrastructure, web applications to Wi-Fi.\u003c\/p\u003e\n\u003cp\u003eEnjoy complementary extended access to our lab environment after completion of the course to revisit and practice the skills you acquired during training.\u003c\/p\u003e\n\u003cp\u003eThis course aims to expose you to the methodologies used by active penetration testers on their day-to-day journey with clients and assessments.\u003c\/p\u003e\n\u003cp\u003eJoin us and hack hard!\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eModule 1: Introduction To Hacking\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.1\u003c\/strong\u003e Think like a hacker. Changing the mindset of students into that of an attacker.\u003cbr\u003e\u003cstrong\u003e3.2\u003c\/strong\u003e What is Kali Linux.\u003cbr\u003e\u003cstrong\u003e3.3\u003c\/strong\u003e Introduction to Linux terminal and common commands\u003cbr\u003e\u003cstrong\u003e3.4\u003c\/strong\u003e Common tools and what you will be exposed to.\u003cbr\u003e\u003cstrong\u003e3.5\u003c\/strong\u003e Making use of AI as a tool in cybersecurity\u003cbr\u003e\u003cstrong\u003e3.6\u003c\/strong\u003e Information Security from a hacker’s perspective.\u003cbr\u003e\u003cstrong\u003e3.7\u003c\/strong\u003e Types of threat actors\u003cbr\u003e\u003cstrong\u003e3.8\u003c\/strong\u003e Risk and business-related security\u003cbr\u003e\u003cstrong\u003e3.9\u003c\/strong\u003e Hacking of history and methodologies.\u003c\/p\u003e\n\u003ch3\u003ePractical 1 – Engage the Brain\u003c\/h3\u003e\n\u003cp\u003eThis practical engages out of the box thinking and picking up on patterns. This allows a student to get into the right mindset to start the hacking journey.\u003c\/p\u003e\n\u003ch3\u003eModule 2: Understanding Finding Targets\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.10\u003c\/strong\u003e Linux 101 – Intro to a terminal.\u003cbr\u003e\u003cstrong\u003e3.11\u003c\/strong\u003e What is a target, a vulnerability, and an exploit.\u003cbr\u003e\u003cstrong\u003e3.12\u003c\/strong\u003e Introduction to finding targets through OSINT by using public information (Google Dorks\/Shodan etc.)\u003cbr\u003e\u003cstrong\u003e3.13\u003c\/strong\u003e Understanding the basics of DNS and target identification.\u003cbr\u003e\u003cstrong\u003e3.14\u003c\/strong\u003e Footprint techniques and the methodology.\u003cbr\u003e\u003cstrong\u003e3.15\u003c\/strong\u003e Tools used to identify and enumerate targets.\u003cbr\u003e\u003cstrong\u003e3.16\u003c\/strong\u003e Domain squatting\u003c\/p\u003e\n\u003ch3\u003ePractical 2 – Recon \u0026amp; Footprint\u003c\/h3\u003e\n\u003cp\u003eUse passive means of gathering information about the target and associated targets. Utilizing AI as a tool to streamline the process of gathering information.\u003c\/p\u003e\n\u003ch3\u003eModule 3: Understanding Scanning\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.17\u003c\/strong\u003e Understanding network communications and the network stack.\u003cbr\u003e\u003cstrong\u003e3.18\u003c\/strong\u003e Fingerprinting a target\u003cbr\u003e\u003cstrong\u003e3.19\u003c\/strong\u003e Using Nmap as a fingerprinting tool.\u003cbr\u003e\u003cstrong\u003e3.20\u003c\/strong\u003e Understanding vulnerability discovery.\u003c\/p\u003e\n\u003ch3\u003ePractical 3 – Scanning\u003c\/h3\u003e\n\u003cp\u003eUse active means of gathering information through fingerprinting and scanning tools about the identified target. Employing AI as a means to quickly research tool usage and for assistance with unknown command line tools.\u003c\/p\u003e\n\u003ch3\u003eModule 4: Understanding Vulnerabilities\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.21\u003c\/strong\u003e Understanding what a vulnerability is and how it differs from an exploit.\u003cbr\u003e\u003cstrong\u003e3.22\u003c\/strong\u003e Automated scanners \u0026amp; the dangers of automation.\u003cbr\u003e\u003cstrong\u003e3.23\u003c\/strong\u003e Common mistakes with automated scanner reports.\u003cbr\u003e\u003cstrong\u003e3.24\u003c\/strong\u003e Known vulnerabilities and their prevalence.\u003cbr\u003e\u003cstrong\u003e3.25\u003c\/strong\u003e Intro to a known vulnerability.\u003c\/p\u003e\n\u003ch3\u003ePractical 4 – Identifying a Known Vulnerability\u003c\/h3\u003e\n\u003cp\u003eThis practical and its objectives allows a student to discover an infamous vulnerability.\u003c\/p\u003e\n\u003ch3\u003eModule 5: Understanding Exploits\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.26\u003c\/strong\u003e What are exploits and where to find them.\u003cbr\u003e\u003cstrong\u003e3.27\u003c\/strong\u003e Public exploits (ExploitDB)\u003cbr\u003e\u003cstrong\u003e3.28\u003c\/strong\u003e Understanding shells (what is a reverse and what is a bind shell)\u003cbr\u003e\u003cstrong\u003e3.29\u003c\/strong\u003e Introduction to the Metasploit Framework.\u003cbr\u003e\u003cstrong\u003e3.30\u003c\/strong\u003e Using Metasploit as a place to find public exploits.\u003cbr\u003e\u003cstrong\u003e3.31\u003c\/strong\u003e Exploits vs payloads.\u003cbr\u003e\u003cstrong\u003e3.32\u003c\/strong\u003e Understanding exploits.\u003cbr\u003e\u003cstrong\u003e3.33\u003c\/strong\u003e Understanding the basic hacking methodology.\u003c\/p\u003e\n\u003ch3\u003ePractical 5 – Exploiting Known Vulnerabilities\u003c\/h3\u003e\n\u003cp\u003eThis practical and its objectives allow a student to exploit an infamous vulnerability and transition from simple remote command execution to complete remote control over a target host.\u003c\/p\u003e\n\u003ch3\u003ePractical 6 – Exploitation Using Metasploit\u003c\/h3\u003e\n\u003cp\u003eAs an introduction in using attack frameworks, students get the chance to play with one of the industry's most well-known tools. After learning how to manually identify a vulnerability and exploit it, students are taught how to expedite that process using an exploitation framework.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.34\u003c\/strong\u003e Understanding Log4j, what happened and why when this vulnerability was released.\u003cbr\u003e\u003cstrong\u003e3.35\u003c\/strong\u003e Diving into how the Log4j vulnerability works.\u003cbr\u003e\u003cstrong\u003e3.36\u003c\/strong\u003e An overview of how the exploit takes advantage of the vulnerability.\u003c\/p\u003e\n\u003ch3\u003ePractical 7 – Exploiting Log4j\u003c\/h3\u003e\n\u003cp\u003eThrough knowledge gained thus far, the student will need to identify the vulnerable service and attempt to exploit it using a publicly available exploit to gain complete control over the affected host.\u003c\/p\u003e\n\u003ch3\u003eModule 6 – Hacking Web Technologies\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.37\u003c\/strong\u003e Understanding web applications, Architecture and HTTP protocol.\u003cbr\u003e\u003cstrong\u003e3.38\u003c\/strong\u003e Deep understanding of the HTTP Request and Response messages.\u003cbr\u003e\u003cstrong\u003e3.39\u003c\/strong\u003e Understanding the risk of web applications.\u003cbr\u003e\u003cstrong\u003e3.40\u003c\/strong\u003e Understanding the core functionality of protocols like HTTP and how an attacker would use this.\u003cbr\u003e\u003cstrong\u003e3.41\u003c\/strong\u003e What are cookies \/ encodings.\u003cbr\u003e\u003cstrong\u003e3.42\u003c\/strong\u003e Learn about PitM proxies and information gathering. Including the use of Burp to view raw request and response messages.\u003cbr\u003e\u003cstrong\u003e3.43\u003c\/strong\u003e OWASP’s Top 10 vulnerability list.\u003cbr\u003e\u003cstrong\u003e3.44\u003c\/strong\u003e Finding more information on a specific target - underlying technologies etc.\u003cbr\u003e\u003cstrong\u003e3.45\u003c\/strong\u003e What is enumeration and how to use it (WFUZZ, google hacking database)\u003cbr\u003e\u003cstrong\u003e3.46\u003c\/strong\u003e Input validation flaws and other common web vulnerabilities.\u003cbr\u003e\u003cstrong\u003e3.47\u003c\/strong\u003e Understanding three of the most common web vulnerabilities; how they work, how to find them and how to exploit them.\u003c\/p\u003e\n\u003ch3\u003ePractical 8 – Proxies\u003c\/h3\u003e\n\u003cp\u003eAn introduction into using Person-in-the-Middle (PitM) Proxies. Allows students to explore under the hood of web requests and response.\u003c\/p\u003e\n\u003ch3\u003ePracticals 9 \u0026amp; 10 – Finding and Attacking Web Related Vulnerabilities\u003c\/h3\u003e\n\u003cp\u003eThis hands-on practical session guides students through the discovery and exploitation of web vulnerabilities, with a focus on varying difficulty levels to accommodate both beginners and advanced learners. The aim is to uncover and exploit weaknesses that lead to system compromises and the exfiltration of sensitive information. Among the key vulnerabilities we cover are Insecure Direct Object References (IDOR) and Cross-Site Scripting (XSS).\u003c\/p\u003e\n\u003ch3\u003eModule 7 – Wi-Fi Hacking\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.48\u003c\/strong\u003e What is Wi-Fi, how does it work.\u003cbr\u003e\u003cstrong\u003e3.49\u003c\/strong\u003e Understanding Wi-Fi concepts.\u003cbr\u003e\u003cstrong\u003e3.50\u003c\/strong\u003e How to monitor traffic and selectively watch for information.\u003cbr\u003e\u003cstrong\u003e3.51\u003c\/strong\u003e Capturing someone else's HTTP traffic, and gathering sensitive information.\u003cbr\u003e\u003cstrong\u003e3.52\u003c\/strong\u003e Capturing and cracking a Wi-Fi password.\u003c\/p\u003e\n\u003ch3\u003ePracticals 11 \u0026amp; 12 – Wi-Fi Exploitation\u003c\/h3\u003e\n\u003cp\u003eThese practicals are about discovering, intercepting and exploiting wireless networks. Giving students the chance to capture traffic and exploit networks using industry standard toolsets.\u003c\/p\u003e\n\u003ch3\u003eModule 8 – Closing Notes and Further Learning\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.53\u003c\/strong\u003e Continued learning.\u003cbr\u003e\u003cstrong\u003e3.54\u003c\/strong\u003e Continued practice.\u003cbr\u003e\u003cstrong\u003e3.55\u003c\/strong\u003e The next steps in the career paths for ethical hacking and penetration testing.\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eNo hacking experience is required for this course; this is a beginner's course. But enthusiasm is a must! It's not necessary, but ideally, some technical background will help, in particular experience with the Windows or Linux command line. However, we're used to meeting students at their level.\u003c\/p\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cp\u003eTo fully engage in our courses, students need a computer with a web browser they are comfortable using. All practical exercises are hosted in the cloud, and our class portal delivers course content. This minimal requirement ensures a seamless and effective learning experience.\u003c\/p\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003eDuring the training, students will be provided with:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eParticipants in our training courses will get access to a comprehensive set of resources through our user-friendly web class portal, offering educational materials like slides, practical exercises, walkthroughs, tools, and detailed course notes.\u003c\/li\u003e\n\u003cli\u003eThe portal remains accessible beyond training sessions, allowing learners to revisit content at their own pace. Additionally, each student receives an individualized lab environment, designed for hands-on practical exercises, enhancing their practical skills and proficiency in the subject matter during the training course.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer(s) Bio\u003c\/h2\u003e\n\u003cp\u003eSensePost, an elite ethical hacking team of Orange Cyberdefense have been training at BlackHat since 2002. We pride ourselves on ensuring our content, our training environment and trainers are all epic in every way possible. The trainers you will meet are working penetration testers, responsible for numerous tools, talks and 0day releases. This provides you with real experiences from the field along with actual practitioners who will be able to support you in a wide range of real-world security discussions. We have years of experience building environments and labs tailored for learning, after all education is at the core of SensePost and Orange Cyberdefense.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942347153651,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/SensePost-Training-Logo-White.png?v=1786560356"},{"product_id":"ai-augmented-operator","title":"AI Augmented Operator","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e AI Augmented Operator\u003cbr\u003e\u003cstrong\u003eTrainer(s):\u003c\/strong\u003e Robert Shala, Armend Gashi, Redon Gashi\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-10, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eAI Augmented Operator teaches security practitioners how to build and deploy reliable AI agents for real cybersecurity operations. Students leave with hands-on experience using AI to augment offensive, defensive, and intelligence operations.\u003c\/p\u003e\n\u003ch2\u003e2. Full Course Description\u003c\/h2\u003e\n\u003cp\u003eAI Augmented Operator is a hands-on course for security practitioners who want to move beyond AI hype and use these systems as a real force multiplier in operator workflows. You will learn how to design, build, and evaluate AI agents that can assist with offense, defense, and intelligence!\u003c\/p\u003e\n\u003cp\u003eAI is changing security operations, but turning it into something useful, reliable, and safe is still hard. AI Augmented Operator gives you a clear path: first, you will learn how modern AI systems and agent architectures actually work, including tools, retrieval, memory, alloys, evaluation, and failure modes. Across two days of guided training and one capstone project day, you will build and harden your own high-performance AI-augmented system for offense, defense, or intelligence operations, so you leave with practical skills and a project you can adapt to real security work.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003e3.1 Morning: AI and Agent Foundations\u003c\/h3\u003e\n\u003cp\u003eStudents begin with the core mechanics needed to build AI-augmented security systems: how language models work, what next-token prediction means in practice, why models hallucinate, and where AI is reliable or unreliable in operator workflows.\u003c\/p\u003e\n\u003cp\u003eThe session covers tokenization, context windows, embeddings, retrieval, prompt structure, and model\/tool boundaries.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 35 minutes on model fundamentals, 35 minutes on tokenization and context design, 35 minutes on embeddings\/RAG, 35 minutes on reliability and hallucination controls, 50 minutes for a guided lab, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e How language models actually work\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Next-token prediction and the mechanics behind AI behavior\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Where models are strong, where they fail, and how to design around it\u003cbr\u003e\u003cstrong\u003e3.1.4\u003c\/strong\u003e Hallucinations, uncertainty, and reliability controls\u003cbr\u003e\u003cstrong\u003e3.1.5\u003c\/strong\u003e Tokenization, context windows, and prompt structure\u003cbr\u003e\u003cstrong\u003e3.1.6\u003c\/strong\u003e Embeddings, semantic search, and retrieval-augmented generation\u003cbr\u003e\u003cstrong\u003e3.1.7\u003c\/strong\u003e Model\/tool boundaries: when to ask the model and when to call a tool\u003cbr\u003e\u003cstrong\u003e3.1.8 Guided lab:\u003c\/strong\u003e build a first working security assistant\u003c\/p\u003e\n\u003ch3\u003e3.2 Agent Architecture and Hardening\u003c\/h3\u003e\n\u003cp\u003eStudents move from “using a model” to designing an agent. This block covers agent loops, tool use\/function calling, memory, retrieval pipelines, planning patterns, structured outputs, and human-in-the-loop checkpoints. Students then learn how to harden agents against prompt injection, unsafe tool use, bad outputs, and trust-boundary failures.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 40 minutes on agent architecture, 35 minutes on tool use and function calling, 35 minutes on RAG\/memory design, 40 minutes on agent security and guardrails, 40 minutes for a hardening lab, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e How agent loops work\u003cbr\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Tool use, function calling, and structured outputs\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Memory, retrieval pipelines, and context management\u003cbr\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e Planning patterns for multi-step security tasks\u003cbr\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Human-in-the-loop checkpoints and approval gates\u003cbr\u003e\u003cstrong\u003e3.2.6\u003c\/strong\u003e Prompt injection and indirect prompt injection\u003cbr\u003e\u003cstrong\u003e3.2.7\u003c\/strong\u003e Trust boundaries between model, tools, data, and user input\u003cbr\u003e\u003cstrong\u003e3.2.8\u003c\/strong\u003e Output validation, guardrails, and safe execution patterns\u003cbr\u003e\u003cstrong\u003e3.2.9 Guided lab:\u003c\/strong\u003e harden a working security agent\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003e3.3 Applied Security Workflows\u003c\/h3\u003e\n\u003cp\u003eStudents apply agent patterns to real security workflows across intelligence and defense. Topics include OSINT collection, IOC extraction and correlation, threat intelligence summarization, alert triage, log analysis, investigation workflows, and SIEM\/detection stack integration. The flavor is defensive in the morning.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 40 minutes on threat intelligence agents, 35 minutes on IOC extraction\/correlation, 40 minutes on SOC triage and log analysis, 30 minutes on SIEM\/detection integration patterns, 45 minutes for a guided applied lab, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e AI agents for threat intelligence workflows\u003cbr\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e OSINT collection and enrichment\u003cbr\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e IOC extraction, normalization, and correlation\u003cbr\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e Threat report summarization and analyst-ready outputs\u003cbr\u003e\u003cstrong\u003e3.3.5\u003c\/strong\u003e SOC alert triage and prioritization\u003cbr\u003e\u003cstrong\u003e3.3.6\u003c\/strong\u003e Log analysis and investigation workflows\u003cbr\u003e\u003cstrong\u003e3.3.7\u003c\/strong\u003e SIEM and detection stack integration patterns\u003cbr\u003e\u003cstrong\u003e3.3.8\u003c\/strong\u003e Keeping analysts in control of defensive automation\u003cbr\u003e\u003cstrong\u003e3.3.9 Guided lab:\u003c\/strong\u003e build an applied intelligence or triage workflow\u003c\/p\u003e\n\u003ch3\u003e3.4 Offensive, Research, and Operations\u003c\/h3\u003e\n\u003cp\u003eStudents examine AI augmentation for offensive security and vulnerability research in a controlled lab context. Topics include recon automation, vulnerability research support, exploit-chain reasoning, code review agents, patch diffing, and responsible boundaries for offensive agent use. The day closes with operational concerns: evaluation, observability, cost, drift, governance, and preparing for the capstone.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 40 minutes on offensive workflow augmentation, 35 minutes on vulnerability research\/code review agents, 35 minutes on evaluation and observability, 30 minutes on governance and human-in-the-loop design, 50 minutes for capstone planning\/project scoping, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e AI agents for offensive security workflows\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e Recon automation and target understanding\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Vulnerability research support\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e Exploit-chain reasoning in controlled lab environments\u003cbr\u003e\u003cstrong\u003e3.4.5\u003c\/strong\u003e Code review agents for security findings\u003cbr\u003e\u003cstrong\u003e3.4.6\u003c\/strong\u003e Patch diffing and CVE research workflows\u003cbr\u003e\u003cstrong\u003e3.4.7\u003c\/strong\u003e Responsible boundaries for offensive agent use\u003cbr\u003e\u003cstrong\u003e3.4.8\u003c\/strong\u003e Evaluation, observability, and failure analysis\u003cbr\u003e\u003cstrong\u003e3.4.9\u003c\/strong\u003e Cost, latency, drift, and operational readiness\u003cbr\u003e\u003cstrong\u003e3.4.10\u003c\/strong\u003e Capstone planning: choose offense, defense, or intelligence track\u003c\/p\u003e\n\u003ch3\u003eDay 3\u003c\/h3\u003e\n\u003ch3\u003e3.5 Capstone Project Build\u003c\/h3\u003e\n\u003cp\u003eStudents choose a capstone track: defense, offense, or intelligence. Working with instructors, they define a realistic security problem, scope a buildable agent system, identify required tools\/data, set success criteria, and begin implementation. Each project must include a working agent loop, tool use or retrieval, structured output, and basic safety controls.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 35 minutes for project selection and scoping, 35 minutes for architecture review with instructors, 120 minutes for the first build sprint, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e Choose a capstone track: defense, offense, or intelligence\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Define a realistic security problem to solve\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e Scope an agent system that can be built and demonstrated\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Identify required tools, data sources, and APIs\u003cbr\u003e\u003cstrong\u003e3.5.5\u003c\/strong\u003e Set clear success criteria and evaluation goals\u003cbr\u003e\u003cstrong\u003e3.5.6\u003c\/strong\u003e Design the agent loop and system architecture\u003cbr\u003e\u003cstrong\u003e3.5.7\u003c\/strong\u003e Add tool use, retrieval, or structured data processing\u003cbr\u003e\u003cstrong\u003e3.5.8\u003c\/strong\u003e Build safety controls and human approval points\u003cbr\u003e\u003cstrong\u003e3.5.9\u003c\/strong\u003e Begin implementation with instructor support\u003c\/p\u003e\n\u003ch3\u003e3.6 Capstone Completion and Review\u003c\/h3\u003e\n\u003cp\u003eStudents continue building their capstone systems with instructor support, then test, evaluate, and prepare a short operational brief. Each student or team demonstrates a working AI-augmented security system and explains what it does, how it was tested, where human review is required, and how it could be adapted to a real environment.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 120 minutes for final build sprint, 20 minutes for preparing the operational brief\/demo, 50 minutes for demonstrations and peer review, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Continue capstone implementation with instructor support\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e Test the agent against realistic security inputs\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e Evaluate accuracy, reliability, and failure modes\u003cbr\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Verify tool use, retrieval, structured output, and safety controls\u003cbr\u003e\u003cstrong\u003e3.6.5\u003c\/strong\u003e Prepare a short operational brief and demo narrative\u003cbr\u003e\u003cstrong\u003e3.6.6\u003c\/strong\u003e Explain what the system does and where human review is required\u003cbr\u003e\u003cstrong\u003e3.6.7\u003c\/strong\u003e Demonstrate a working AI-augmented security system\u003cbr\u003e\u003cstrong\u003e3.6.8\u003c\/strong\u003e Receive peer review and instructor feedback\u003cbr\u003e\u003cstrong\u003e3.6.9\u003c\/strong\u003e Discuss how the system could be adapted to real-world operations\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eStudents should be comfortable with basic cybersecurity concepts and workflows. They do not need prior AI or machine learning experience. The course starts by explaining how LLMs and agents work and provides a strong foundation with which to work on.\u003c\/p\u003e\n\u003cp\u003eStudents should be able to read and write basic Python scripts, use the command line, install packages, work with JSON\/CSV\/text data, and make HTTP\/API requests. The course will use Python for agent logic, tool calling, data parsing, retrieval, and automation. Students should be comfortable using a code editor, terminal, Git, and Python virtual environments.\u003c\/p\u003e\n\u003cp\u003eStudents should be comfortable with basic cybersecurity concepts and workflows. They do not need prior AI or machine learning experience. The course starts by explaining how LLMs and agents work and provides a strong foundation with which to work on.\u003c\/p\u003e\n\u003cp\u003eStudents should be able to read and write basic Python scripts, use the command line, install packages, work with JSON\/CSV\/text data, and make HTTP\/API requests. The course will use Python for agent logic, tool calling, data parsing, retrieval, and automation. Students should be comfortable using a code editor, terminal, Git, and Python virtual environments.\u003c\/p\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cp\u003eStudents should arrive with a laptop capable of running Python 3, Git, Docker or a similar local lab environment, and a modern code editor such as VS Code.\u003c\/p\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003eDuring the training, students will be provided with:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLLM API access will be provided by the instructors. Students will have access to an LLM API key before class.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3\u003eRobert Shala\u003c\/h3\u003e\n\u003cp\u003eRobert Shala is co-founder of Sentry, where he leads 50 security consultants and has delivered 3000-plus security engagements for some of the world largest organizatons. He was also part of OpenAI's External AI Red Team probing frontier models for safety and security flaws. He has presented at DEF CON AI Village and AppSec Village on novel attack classes targeting AI inference infrastructure. Robert holds an M.S. in Security Studies from Georgetown University, a B.S. from Rochester Institute of Technology, and has a passion for wargaming.\u003c\/p\u003e\n\u003ch3\u003eArmend Gashi\u003c\/h3\u003e\n\u003cp\u003eArmend Gashi is a Managing Security Consultant at Sentry. He specializes in AI and multi-agent systems engineering. Armend has built multi-agent systems to perform security-focused operations in vulnerability research and exploit development as well as model steering and technical alignment. Armend was part of of Anthropic’s external AI Red Team through HackerOne. He has presented at DEF CON AI Village and AppSec Village on Special Token Injection.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e \u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cbr\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942347776243,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/default_DCT_photo.webp?v=1786559556"},{"product_id":"mastering-breach-and-adversarial-attack-simulation-engagements","title":"Mastering breach and adversarial attack simulation engagements","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Mastering Breach and Adversarial Attack Simulation Engagements\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e ABX\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eParticipants learn to safely emulate real-world threat actors and unknown adversaries in controlled enterprise environments, selecting from a wide range of offensive tradecraft and TTPs to plan and execute realistic attack simulation engagements. The course also covers AI-assisted attack simulation and modern offensive cyber security techniques, equipping defenders to rigorously assess and strengthen their organization’s cyber defense posture.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eThe hands-on training provides participants with a deeper understanding of advanced offensive cyber security operations, breach simulation, and adversary emulation engagements. Participants learn to safely emulate real-world threat actors and unknown adversaries in controlled enterprise environments, selecting from a wide range of offensive tradecraft and TTPs to plan and execute realistic attack simulation engagements.\u003c\/p\u003e\n\u003cp\u003eA significant portion of the course is dedicated to Cobalt Strike, the de facto enterprise C2 framework, Malleable C2 profiles, Beacon operations, lateral movement, and enterprise AD compromise simulation exercises against modern detection stacks.\u003c\/p\u003e\n\u003cp\u003eParticipants will also work with AI-assisted adversary simulation, including the use of locally hosted uncensored open-source models for tasks where commercial frontier models refuse or sanitize the output, supporting workflows such as malware variant generation, evasion refactoring, pretext crafting, and on-the-fly TTP recommendation during live engagements.\u003c\/p\u003e\n\u003cp\u003eBuilding on this, the course introduces agentic breach simulation, where autonomous agents drive multi-stage attack chains and adapt to defensive responses, alongside supply chain attack simulations that mimic one of the fastest-growing categories of real-world breaches.\u003c\/p\u003e\n\u003cp\u003eThe training benefits both offensive and defensive professionals: red teamers sharpen their tradecraft and C2 operations, while SOC analysts, detection engineers, and blue teamers gain visibility into modern attacker behaviors, including AI-assisted evasion, so they can harden their environments against the threat actor playbooks actually being used today.\u003c\/p\u003e\n\u003cp\u003eParticipants who opt to take the proficiency exam at the end of the program will receive the CBAS certification, formally recognizing their capability to plan, lead, and execute enterprise-grade breach and adversary simulation engagements.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003ePART I - Foundations and Adversary Emulation\u003c\/h3\u003e\n\u003ch3\u003eModule 1: Taking the First Step - Understanding the Fundamentals\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e Introduction to offensive cyber security operations\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Adversary emulation vs adversary simulation\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Assessing return on investment (ROI)\u003cbr\u003e\u003cstrong\u003e3.1.4\u003c\/strong\u003e Breach and attack simulation (BAS)\u003cbr\u003e\u003cstrong\u003e3.1.5\u003c\/strong\u003e Cyber threat intelligence and threat-informed defense\u003cbr\u003e\u003cstrong\u003e3.1.6\u003c\/strong\u003e Cyber defense systems, blue teams, and the importance of purple teaming\u003cbr\u003e\u003cstrong\u003e3.1.7\u003c\/strong\u003e Frameworks and standards: MITRE ATT\u0026amp;CK matrix, Cyber Kill Chain\u003cbr\u003e\u003cstrong\u003e3.1.8\u003c\/strong\u003e Evolution of threat actors\u003cbr\u003e\u003cstrong\u003e3.1.9\u003c\/strong\u003e Red teaming\u003cbr\u003e\u003cstrong\u003e3.1.10\u003c\/strong\u003e Adversarial Exposure Validation\u003cbr\u003e\u003cstrong\u003e3.1.11\u003c\/strong\u003e Introduction to AI-assisted offensive operations and agentic adversary simulation\u003cbr\u003e\u003cstrong\u003e3.1.12\u003c\/strong\u003e Supply chain compromise as a dominant breach category\u003c\/p\u003e\n\u003ch3\u003eModule 2: Introduction to Adversary Emulation Engagements\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e Adversary emulation kickoff in your organization\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdversary emulation exercises\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Collecting actionable cyber threat intelligence from public sources\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eThreat Report ATT\u0026amp;CK Mapper (TRAM)\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Identifying and selecting TTPs to emulate, building an emulation plan\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e Performing and executing adversary emulation engagements to test cyber defenses\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Testing endpoint security controls with adversary emulation techniques\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.6\u003c\/strong\u003e Open-source projects for effective emulation of threats\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.7\u003c\/strong\u003e Adversary emulation - Atomic Red Team\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eExecuting Atomic Red Team\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.8\u003c\/strong\u003e Adversary emulation - MITRE Caldera project\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eGetting started with the Caldera project\u003c\/li\u003e\n\u003cli\u003eDeploying Caldera in your organization's environment\u003c\/li\u003e\n\u003cli\u003eEmulating threat actors with Caldera\u003c\/li\u003e\n\u003cli\u003eEmulating known threat actors with Caldera ATT\u0026amp;CK Navigator\u003c\/li\u003e\n\u003cli\u003eUsing VECTR for generating reports and documentation\u003c\/li\u003e\n\u003cli\u003eUsing AI\/GPT systems for practical threat-intel-powered adversarial attack emulation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.9\u003c\/strong\u003e AI-assisted adversary simulation in practice\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLocally hosted uncensored open-source models for tasks where commercial frontier models refuse or sanitise output\u003c\/li\u003e\n\u003cli\u003eAI-driven workflows: malware variant generation, evasion refactoring, pretext crafting, on-the-fly TTP recommendation during live engagements\u003c\/li\u003e\n\u003cli\u003eOperational security considerations for AI in red team workflows\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003ePART II - Offensive Tradecraft, Loaders, and Cobalt Strike\u003c\/h3\u003e\n\u003ch3\u003eModule 3: Breach and Adversary Simulation - Infrastructure and Tradecraft\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e Introducing the breach and adversary simulation range lab environment\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e Adversary and red team infrastructure\u003c\/p\u003e\n\u003cp\u003eBuilding efficient adversary infrastructure: this module gives an overview of building production-ready red team infrastructure to bypass and validate the defenses of your organization.\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRedirector design and traffic shaping\u003c\/li\u003e\n\u003cli\u003eDomain fronting, categorisation, and reputation building\u003c\/li\u003e\n\u003cli\u003ePhishing infrastructure and mail relays\u003c\/li\u003e\n\u003cli\u003eOPSEC considerations for long-running engagements\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Breach simulation lab infrastructure - guided walkthrough\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. What Students Should Bring\u003c\/h2\u003e\n\u003cp\u003eLaptop\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eMinimum requirements:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eCPU cores: 4 (8 recommended)\u003c\/li\u003e\n\u003cli\u003eRAM: 16 GB (32 GB recommended)\u003c\/li\u003e\n\u003cli\u003eDisk: 500 GB (1 TB recommended)\u003c\/li\u003e\n\u003cli\u003e6. What the Trainer Will Provide\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eDuring the training, students will be provided with:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eAll labs are hosted in AWS.\u003c\/li\u003e\n\u003cli\u003eStudnets will have access to LMS.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3\u003eAbhijith B R (ABX)\u003c\/h3\u003e\n\u003cp\u003eAbhijith B R, also known by the pseudonym Abx, has more than a decade of experience in the offensive cyber security industry. He is a professional hacker, offensive cyber security specialist, red team consultant, security researcher, trainer and public speaker.\u003c\/p\u003e\n\u003cp\u003eCurrently, he is building BreachSimRange.io as a founder, director and involved with multiple organizations as a consulting specialist, to help them build offensive security operations programs, improve their current security posture, assess cyber defense systems, bridge the gap between business leadership and security professionals.\u003c\/p\u003e\n\u003cp\u003eAbhijith was responsible for building and managing offensive security operations and adversary simulation for a prominent FinTech company called Envestnet, Inc. In the past, he held the position of Deputy Manager - Cyber Security at Nissan Motor Corporation, and prior to that, he worked as a Senior Security Analyst at EY.\u003c\/p\u003e\n\u003cp\u003eAs the founder of Adversary Village (\u003ca href=\"https:\/\/adversaryvillage.org\/\"\u003ehttps:\/\/adversaryvillage.org\/\u003c\/a\u003e), Abhijith spearheads a community initiative focused on adversary simulation, adversary-tactics, purple teaming, threat actor\/ransomware research-emulation, and offensive cyber security. Adversary Village is part of DEF CON Villages and organizes hacking villages at prominent events such as the DEF CON Hacking Conference, RSA Conference etc.\u003c\/p\u003e\n\u003cp\u003eAbx also acts as the Lead of an official DEF CON Group named DC0471. He is actively involved in leading the Tactical Adversary project (\u003ca href=\"https:\/\/tacticaladversary.io\/\"\u003ehttps:\/\/tacticaladversary.io\/\u003c\/a\u003e) a personal initiative that centers around offensive cyber security, adversary attack simulation and red teaming tradecraft.\u003c\/p\u003e\n\u003cp\u003eAbhijith has spoken at various hacking and cyber security conferences such as, DEF CON hacker convention - Las Vegas, RSA Conference - San Francisco, The Diana Initiative - Las Vegas, DEF CON 28 safemode - DCG Village, Opensource India, Security BSides Las Vegas, BSides San Francisco, BSides Tampa, Hack Space Con - Kennedy space center Florida, Nullcon - Goa, c0c0n - Kerala, BSides Delhi etc.\u003c\/p\u003e\n\u003ch2\u003e8. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e8.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the DEF CON Training Code of Conduct and the registration terms and conditions listed above.\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942347874547,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/abx.webp?v=1786806703"}],"url":"https:\/\/me.shop.defcon.org\/collections\/trainings.oembed","provider":"DEF CON MIDDLE EAST","version":"1.0","type":"link"}