• 10:00
  • Persisting with Microsoft Office: Abusing Extensibility Options

    William Knowles
    Sat, 10:00 - 10:20
    101 Track
  • $BIGNUM steps forward, $TRUMPNUM steps back: how can we tell if we're winning?

    Cory Doctorow
    Sat, 10:00 - 10:45
    Track 2
  • Get-$pwnd: Attacking Battle-Hardened Windows Server

    Lee Holmes
    Sat, 10:00 - 10:20
    Track 3
  • The spear to break the security wall of S7CommPlus

    Cheng Lei, Zhang Yunhai
    Sat, 10:00 - 10:20
    Track 4
  • Welcome - Saturday

     
    Sat, 10:00 - 10:30
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 10:20
  • Breaking Wind: Adventures in Hacking Wind Farm Control Networks

    Jason Staggs
    Sat, 10:20 - 10:40
    101 Track
  • WSUSpendu: How to hang WSUS clients

    Romain Coltel, Yves Le Provost
    Sat, 10:20 - 10:40
    Track 3
  • (Un)Fucking Forensics: Active/Passive (i.e. Offensive/Defensive) memory hacking/debugging.

    K2
    Sat, 10:20 - 10:40
    Track 4
  • 10:30
  • The Surveillance Capitalism Will Continue Until Morale Improves

    J0N J4RV1S
    Sat, 10:30 - 11:30
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 11:00
  • Microservices and FaaS for Offensive Security

    Ryan Baxendale
    Sat, 11:00 - 11:20
    101 Track
  • Secure Tokin' and Doobiekeys: How to roll your own counterfeit hardware security devices

    Joe FitzPatrick, Michael Leibowitz
    Sat, 11:00 - 11:45
    Track 2
  • If You Give a Mouse a Microchip... It will execute a payload and cheat at your high-stakes video game tournament

    Rob Stanley, Mark Williams
    Sat, 11:00 - 11:45
    Track 3
  • Evading next-gen AV using artificial intelligence

    Hyrum Anderson
    Sat, 11:00 - 11:20
    Track 4
  • WS: Implementing An Elliptic Curve in Go

    George Tankersley
    Sat, 11:00 - 12:30
    Florentine Ballroom 3 - Crypto and Privacy Village
  • 11:20
  • Abusing Webhooks for Command and Control

    Dimitry Snezhkov
    Sat, 11:20 - 11:40
    101 Track
  • All Your Things Are Belong To Us

    0x00string, CJ_000, Maximus64, Zenofex
    Sat, 11:20 - 12:35
    Track 4
  • 11:30
  • Privacy is Not An Add-On: Designing for Privacy from the Ground Up

    Alisha Kloc
    Sat, 11:30 - 12:00
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 12:00
  • Driving down the rabbit hole

    Oleksandr Bazhaniuk, Jesse Michael, Mickey Shkatov
    Sat, 12:00 - 12:45
    101 Track
  • When Privacy Goes Poof! Why It's Gone and Never Coming Back

    Richard Thieme
    Sat, 12:00 - 12:45
    Track 2
  • DNS - Devious Name Services - Destroying Privacy & Anonymity Without Your Consent

    Jim Nitterauer
    Sat, 12:00 - 12:45
    Track 3
  • Operational Security Lessons from the Dark Web

    Shea Nangle
    Sat, 12:00 - 13:00
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 12:30
  • WS: Secrets Management in the Cloud

    Evan Johnson
    Sat, 12:30 - 13:30
    Florentine Ballroom 3 - Crypto and Privacy Village
  • 13:00
  • Demystifying Windows Kernel Exploitation by Abusing GDI Objects.

    Saif El-Sherei
    Sat, 13:00 - 13:45
    101 Track
  • Koadic C3 - Windows COM Command & Control Framework

    Sean Dillon, Zach Harding
    Sat, 13:00 - 13:45
    Track 2
  • Twenty Years of MMORPG Hacking: Better Graphics, Same Exploits

    Manfred
    Sat, 13:00 - 13:45
    Track 3
  • A Picture is Worth a Thousand Words, Literally: Deep Neural Networks for Social Stego

    Michael Raggo, Philip Tully
    Sat, 13:00 - 13:45
    Track 4
  • The Symantec/Chrome SSL debacle - how to do this better...

     
    Sat, 13:00 - 14:00
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 14:00
  • Attacking Autonomic Networks

    Omar Eissa
    Sat, 14:00 - 14:45
    101 Track
  • Trojan-tolerant Hardware & Supply Chain Security in Practice

    Dan Cvrcek, Vasilios Mavroudis
    Sat, 14:00 - 14:45
    Track 2
  • Linux-Stack Based V2X Framework: All You Need to Hack Connected Vehicles

    Nicholas Haltmeyer, Duncan Woodbury
    Sat, 14:00 - 14:45
    Track 3
  • XenoScan: Scanning Memory Like a Boss

    Nick Cano
    Sat, 14:00 - 14:45
    Track 4
  • Have you seen my naked selfies? Neither has my snoopy boyfriend. Pr

    Lauren Rucker
    Sat, 14:00 - 15:00
    Florentine Ballroom 4 - Crypto and Privacy Village
  • WS: SECURE COMMUNICATIONS IN ANDROID WITH TLS/SSL

    Miguel Guirao
    Sat, 14:00 - 16:00
    Florentine Ballroom 3 - Crypto and Privacy Village
  • 15:00
  • MS Just Gave the Blue Team Tactical Nukes (And How Red Teams Need To Adapt)

    Chris Thompson
    Sat, 15:00 - 15:45
    101 Track
  • Tracking Spies in the Skies

    Jason Hernandez, Jerod MacDonald-Evoy, Sam Richards
    Sat, 15:00 - 15:45
    Track 2
  • DOOMed Point of Sale Systems

    trixr4skids
    Sat, 15:00 - 15:45
    Track 3
  • Digital Vengeance: Exploiting the Most Notorious C&C Toolkits

    Professor Plum
    Sat, 15:00 - 15:45
    Track 4
  • DC to DEF CON: Q&A with Congressmen James Langevin and Will Hurd

    Joshua Corman, Rep. Will Hurd, Rep. James Langevin (D-RI)
    Sat, 15:00 - 17:00
    Capri Room
  • Yet another password hashing talk

    Evgeny Sidorov
    Sat, 15:00 - 15:30
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 15:30
  • Core Illumination: Traffic Analysis in Cyberspace

    Kenneth Geers
    Sat, 15:30 - 16:00
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 16:00
  • Dealing the perfect hand - Shuffling memory blocks on z/OS

    Ayoul3
    Sat, 16:00 - 16:45
    101 Track
  • From "One Country - One Floppy" to "Startup Nation" - the story of the early days of the Israeli hacking community, and the journey towards today's vibrant startup scene

    Inbar Raz, Eden Shochat
    Sat, 16:00 - 16:45
    Track 2
  • CableTap: Wirelessly Tapping Your Home Network

    Chris Grayson, Logan Lamb, Marc Newlin
    Sat, 16:00 - 16:45
    Track 3
  • Game of Drones: Putting the Emerging "Drone Defense" Market to the Test

    Francis Brown, David Latimer
    Sat, 16:00 - 16:45
    Track 4
  • rustls: modern\, fast\, safer TLS

    Joseph Birr-Pixton
    Sat, 16:00 - 17:00
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 17:00
  • Here to stay: Gaining persistency by abusing advanced authentication mechanisms

    Igal Gofman, Marina Simakov
    Sat, 17:00 - 17:45
    101 Track
  • Taking Windows 10 Kernel Exploitation to the next level - Leveraging write-what-where vulnerabilities in Creators Update

    Morten Schenk
    Sat, 17:00 - 17:45
    Track 2
  • Introducing HUNT: Data Driven Web Hacking & Manual Testing

    Jason Haddix
    Sat, 17:00 - 17:45
    Track 3
  • Popping a Smart Gun

    Plore
    Sat, 17:00 - 17:45
    Track 4
  • Blue Team TLS Hugs

    Lee Brotherston
    Sat, 17:00 - 17:30
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 17:30
  • Automated Testing using Crypto Differential Fuzzing (DO NOT RECORD)

    Yolan Romailler
    Sat, 17:30 - 18:00
    Florentine Ballroom 4 - Crypto and Privacy Village
  • 20:00
  • Panel - Meet the Feds (who care about security research)

    Leonard Bailey, Kimber Dowsett, Allan Friedman, Amélie E. Koran, Nick Leiserson
    Sat, 20:00 - 22:00
    Capri Room
  • D0 No H4RM: A Healthcare Security Conversation

    Joshua Corman, Christian Dameff, Michael McNeil, Jerome Radcliffe, Suzanne Schwartz, MD, Jeff Tully, Beau Woods
    Sat, 20:00 - 22:00
    Modena Room