Talks
Presentations from 67th TF-CSIRT meeting - Threat modeling with ATT&CK and How quickly do we patch?
· β˜• 1 min read
67th meeting of the TF-CSIRT community took place this week and I've had a chance to contribute to it with two presentations - one discussing the speed with which we apply patches (from a global standpoint), and another one, in which we looked at a basic approach to threat modeling using MITRE ATT&CK. If you would like to take a look at the slides, they are now available for download...

Log4shell Lightning talk - 2022 TF-CSIRT Meeting & FIRST Regional Symposium Europe
· β˜• 1 min read
Few weeks ago, I attended the 2022 TF-CSIRT Meeting & FIRST Regional Symposium Europe and gave a lighting talk there discussing couple of interesting trends seen in Log4shell exploitation attempts and the possibility to create a simple generic defense agains similar attacks in the future. Recordings of all the talks are now available on YouTube...

Interview - ECSC 2021
· β˜• 1 min read
Prague is currently hosting this year’s European Cyber Security Challenge - an international security competition for teams of young talents from different European countries. Since I am the author of one of the practical challenges that make up the competition and ALEF is one of its sponsors, I was asked for a short interview by the competition’s organizers in the run up to the Challenge itself. The resulting video was published on Youtube today.

Presentation from TF-CSIRT meeting - How TLS 1.3 adoption (and disposal of SSL) is going
· β˜• 1 min read
64th meeting of the TF-CSIRT community took place today. I've had the pleasure to contribute to it with a short presentation about the current state of adoption of TLS 1.3 and continued use of SSL protocols. Although I usually don't mention presentations I've prepared for TF-CSIRT meetings here, I've decided to make an exception for this one, since I believe that it might be worth looking at even without the accompanying commentary...

SANS@MIC - Catch and Release: Phishing Techniques for the Good Guys
· β˜• 1 min read
I did a SANS@MIC talk yesterday, in which I discussed interesting phishing techniques (mainly) from the point of view of red teamers. Since the recording was published today, if you didn’t get the chance to join us live, you may take a look at how it went on YouTube.

CrisisCon - Breaking Windows
· β˜• 1 min read
Videos of all presentations from last weeks CrisisCon are now accessible on Youtube. Among them is my own talk on known unpatched vulnerabilities and weaknesses in Windows. If you couldn’t make it to the online conference, I recommend you at least go through some of the recordings as couple of the talks were quite interesting.