RVAsec 13 Speaker Feature: Ali Ahmad

With over 5 years of experience in the information security industry, Ali has performed a wide variety of security assessments including network penetration testing, application security assessments, full-scope red team engagements, adversarial simulation, and physical penetration testing. Prior to joining Atredis Partners, Ali performed network penetration tests as a Security Consultant on Optiv’s Attack and Penetration team.

Outside of work, Ali enjoys researching software vulnerabilities and malware techniques on Windows Systems. Ali has created open source tooling and authored blog posts focused on evasive Command and Control (C2) techniques and implant development to give back to the information security community. Ali also holds the Offensive Security Certified Professional (OSCP) certification. X (Twitter): @aahmad097

Hacking Exchange from the Outside In (<– add to your schedule)

Microsoft Exchange 2019 uses the Oracle Outside-In libraries to parse specific file types when attached to emails. This talk covers the process of discovering memory corruption vulnerabilities within the technology using AFL and Jackalope and the results of the fuzzing process. Outside-In was deprecated as a result of this research.

Come see Ali Ahmad at RVAsec 13!


RVAsec 13 Speaker Feature: Ell Marquez

Ell Marquez is a proud Hacking Is Not and Crime and Operation Safe escape advocate. She has traveled the world for five years, educating security practitioners on subjects from on-prem infrastructure to the cloud and everything in between. As part of her journey in 2023, Ell transitioned to Neuvik, focusing on researching and training organizations to strengthen their defenses against the latest cyber threats.

I’ve traveled the world educating security practitioners on subjects from on-prem infrastructure to the cloud and everything in between. X (Twitter): @ell_o_punk

Once Upon a Cyber Threat: The Brothers Grimms Teachings on APT Awareness (<– add to your schedule)

Two hundred years ago, the first volume of fairy tales was published by the Brothers Grimm, introducing to the world a realm of magic, dark forests, and powerful villains to haunt everyone’s dreams.

We never imagined this realm would exist in the digital age. “”Once Upon A Cyber Threat”” delves into the realm of advanced persistent Threat Groups (APTs), drawing parallels between the world of poisoned apples, breadcrumb trails, and magic mirrors and today’s modern cyber threats. Serving not a tale of caution but a call to action and a lesson in storytelling, creating an outline that can help every security professional impart the caution, wisdom, and resilience we need to become the narrators that transformed Brother Grimm’s tales into the happy ever after stories we know today.

Come see Ell Marquez at RVAsec 13!


RVAsec Speaker Feature: Corey Overstreet

Corey has been engaged with Fortune 500 organizations across a variety of industries, including financial services, government services, and healthcare and is widely recognized for his in-depth OSINT talks and workshops. Additionally, he is a Black Hat trainer and has spoken at conferences such as Wild West Hackin’ Fest, Texas Cyber Summit, and CarolinaCon. He has over five years of systems administration and extensive VMWare administration experience. Corey was a member of the SECCDC Red Team and is one of the top Red Team Operators at Red Siege. X (Twitter): @retronaut7

That Shouldn’t Have Worked – Payload Development 101 (<– add to your schedule)

The game of bypassing defenses and detection continues to be a cat and mouse game. Attackers often find clever ways to use common tools and techniques to execute their code and the defenders continue to create detections and mitigations for these methods. As a red teamer, it is becoming increasingly difficult to get around these defenses and emulate those attackers. In this talk, I will cover some of the methods we use during engagements to thread the needle and bypass those defenses.

Come see Corey Overstreet at RVAsec 13!


RVAsec 13 Speaker Announcements

We are pleased to announce the first batch of speakers for RVAsec 13!  Secure your ticket as prices increase on May 1.

While there are still more speakers to announce and the exact schedule is still coming, head over to https://rvasec13.sched.com/directory/speakers to read more about each speaker and talk abstracts!

  • Kymberlee Price – Keynote
  • Caleb Sima – Keynote
  • Darryl MacLeod – Strategic Alliances: How GRC Teams Can Empower Offensive Security Efforts
  • Ariyan Suroosh – Its Coming From Inside the House: A Guide to Physical Facility Penetration Testing
  • Chris Tillett – The Human Experience of Security Operations
  • Jennifer Shannon – API-ocalypse
  • Kevin Johnson – Orion’s Quest: Navigating the Cyber Wilderness – Tales of Modern Penetration Testing
  • Aqeel Yaseen – Mindfulness, Meditation, and Cybersecurity
  • Corey Brennan – Embracing my inner cyber wizard to defeat Impostor Syndrome
  • Corey Overstreet – That Shouldn’t Have Worked – Payload Development
  • Ross Merritt – Improv Comedy for Social Engineering
  • David J. Bianco – My Way is Not Very Sportsman-Like: Shaping Adversary Behavior to Strengthen Defenses
  • Nick Copi – Some Assembly Required: Weaponizing Chrome CVE-2023-2033 for RCE in Electron
  • Oren Koren – Verified for Business Continuity: How to Remediate Risk Safely Across the Enterprise
  • Luke McOmie (Pyr0) – Apples to Apples
  • Sam Panicker – Quickstart to building your own Private AI Chat
  • Jimi Sebree / Evan Grant – Consumer Routers Still Suck
  • Micah Parks – Reverse Engineering for Dummies: The “what if?” user
  • Tucker Mahan – Defending Against the Deep: Is your workforce ready for Generative AI Adversaries?
  • Ben Haynes – Prioritization Myths Busted with Better Vulnerability Data
  • Ali Ahmad – Hacking Exchange from the Outside In

Stay tuned for additional speaker announcements coming soon! We will have a new layout this year with multiple tracks.

And if you haven’t purchased your ticket yet, the time to do so is now as prices go up on May 1st!

Get your tickets here: https://www.eventbrite.com/e/rvasec-13-security-conference-tickets-776407274057


Red Canary – RVAsec 13 Silver Sponsor

RVAsec is pleased to present Red Canary as an RVAsec 13 Silver sponsor!

Red Canary

Get actionable threat intelligence across cloud, identity and endpoint. Anywhere you run your business, we got you.

https://redcanary.com/
X (Twitter): @redcanary

RVAsec 13 tickets are available now!


UR School of Continuing and Professional Studies – RVAsec 13 Silver Sponsor

RVAsec is pleased to present University of Richmond School of Continuing and Professional Studies (URSCPS) as an RVAsec 13 Silver sponsor!

University of Richmond SPCS

The School of Professional & Continuing Studies (SPCS) is 1 of the 5 schools at the University of Richmond. SPCS focuses on the Richmond community by providing academic degrees and certificates along with professional certificates, professional development and lifelong learning opportunities for adult and non-traditional learners.

https://spcs.richmond.edu/
X (Twitter): @urspcs

RVAsec 13 tickets are available now!


Gem Security – RVAsec 13 Gold Sponsor

RVAsec is pleased to present Gem Security as an RVAsec 13 Gold sponsor!

Gem Security

Respond to cloud threats with context. And fast. Empower your security operations teams with built-in expertise and automatic response capabilities fit for the cloud era.

https://www.gem.security/
X (Twitter): @GemSecurity

RVAsec 13 tickets are available now!


Varonis – RVAsec 13 Silver Sponsor

RVAsec is pleased to present Varonis as an RVAsec 13 Silver sponsor!

Varonis

STOP DATA BREACHES AUTOMATICALLY.
Continuously discover and classify critical data, remove exposures, and stop threats in real-time with AI-powered automation

https://www.varonis.com/
X (Twitter): @varonis

RVAsec 13 tickets are available now!


Corelight – RVAsec 13 CTF Sponsor

RVAsec is pleased to present Corelight, Inc. as an RVAsec 13 CTF sponsor!

Corelight

At Corelight, we believe the best approach to cybersecurity risk starts with network evidence. This evidence helps elite defenders increase visibility, unlock powerful analytics, accelerate investigations, and level up threat hunting. Our Open Network Detection and Response Platform is the fastest-growing in the industry, and the only one powered by open source and GenAI. We protect some of the most sensitive, mission-critical enterprises and government agencies in the world. Corelighters are proud of our diversity of background and thought, and we’re united by our strong shared culture and the values we live by every day (just meet us, and you’ll see).

https://corelight.com/
X (Twitter): @corelight_inc

RVAsec 13 tickets are available now!


InterVision – RVAsec 13 Silver Sponsor

RVAsec is pleased to present InterVision as an RVAsec 13 Silver sponsor!

The Power of More: With InterVision® as your technology partner, you can focus on what you do best, while we take care of the rest.

https://intervision.com/
X (Twitter): @InterVision_Sys

RVAsec 13 tickets are available now!