VENDREDI 3 NOVEMBRE 2023
Les ateliers Unlock
IMPROVING ONE'S SECURITY BY LEVERAGING THE CROWD
Anglais
Intermédiaire
11H45 – 13H15
Manuel SABBAN
As of today information security is known to be a main concern for many decision-makers. We will demonstrate how CrowdSec Security Engine could help security teams. CrowdSec Security Engine defends against intrusions by analyzing logs to identify and block offending IPs. Flagged IPs are then sent to the community blocklist to protect the Crowd.
Crowdsec is an open-source tool suite built upon the Security Engine and specialized remediation tools we call bouncer. We will cover the following topics:
- install and configure CrowdSec ;
- crowdsec can perform on cold logs ;
- notifications on specific alerting ;
- demonstrate remediation ;
- analyze metrics with the provided saas tool.
découvrez votre surface d'attaque avec onyphe
Français
Intermédiaire
9H30 – 11H30
Patrice AUFFRET
Dans ce workshop, nous vous proposons de découvrir une méthodologie répétable pour identifier votre surface d’attaque en partant d’un simple nom de domaine. Nous verrons qu’il est possible de pivoter sur d’autres sources d’information afin de détricoter les liens entres ces sources pour créer un inventaire de votre surface d’attaque qui soit le plus complet possible.
Ensuite, nous pourrons analyser votre surface d’attaque pour identifier les faiblesses des actifs exposés à Internet, et nous verrons aussi comment créer des visualisations et des tableaux de bords avec Kibana afin de garder une vue à jour de votre exposition sur Internet.
À propos de l'intervenant :
- Plus de 20 ans d’expérience en cybersécurité tant dans les domaines de l’offensif que du défensif.
- Fondateur, CEO et CTO de la société ONYPHE spécialisée en gestion de la surface d’attaque.
NATURAL LANGUAGE PROCESSING (NLP) FOR THREAT INTELLIGENCE
Anglais
Débutant
9H30 – 11H30
Pauline BOURMEAU
Natural language processing is a subfield of AI. It is at the core of large language models. In this workshop you learn how to break AI into tools and build your first NLP program. You learn to use natural language processing to extract knowledge and uncover patterns in text data. This workshop provides you with practical knowledge and skills that you can apply in your daily practice as a security professional. It is designed for beginners, you will be introduced to the foundations of NLP and gain practical experience in text pre-processing, representation, and classification.
Goals:
- Learn how to leverage natural language processing for Threat Intelligence and investigation in cybersecurity.
- Acquire practical skills to allow you to build your own pipelines.
- Guide you to an intuitive path for learning NLP and integrate it progressively to your daily tasks.
Program:
Building a sentiment analysis pipeline using pre-trained models and industry-standard libraries.
- Learn the essential steps of text pre-processing by practicing on a real dataset.
- Explore different methods of representing text data.
- Build a simple text classifier using popular techniques.
- Learn to measure accuracy of your model.
- Discussions and resources to go further.
Conclusion:
We quickly discuss diverse ranges of applications of NLP, including Open-Source Intelligence (OSINT), Security research and Incident Response.
And finally, we highlight the significance of working with structured and unstructured data.
Requirements: Knowledge in Python, no prior experience in AI is required.
_______________
About the speaker: Cookie has spent a long-time fixing languages and bikes with very little money and great ingenuity, squatting university benches and corrupting teachers for beer. Working for the past four years as a Threat Analyst, she is also a trained linguist and former teacher who brings a unique perspective to her work by exploring and exploiting threats through criminology, social anthropology, philosophy, and psychology. She actively participates in the open-source community and promotes defensive security practices by training industry practitioners.
CRÉEZ VOTRE COMMAND & CONTROL SUR MESURE
Anglais
Avancé
9H30 – 13H00
Guillaume PRIGENT et Adrien BARCHAPT-PERROT
Command & Control is a cornerstone of any attacker’s infrastructure, whether affiliated state actors (APTs), cybercriminals or legitimate Red Team operators.
“Custom your own C&C” is a 4 hours workshop for those interested in getting a quick start into the world of Command & Control design & architecture and who aim to develop their own implant in a famous open source framework.
In this bring-your-own-laptop workshop, participants will get to learn the architecture & the design of a well known open source framework, as an example and get a full hands-on introduction to designing a simple custom implant, working with 2 already prepared virtual machines and concluding with writing their own integrated x64 implant (C++/Python wrapper).
________
About the speakers
Guillaume Prigent (@g0ul4g)
Guillaume is a digital freethinker and an expert in cyber security. Co-founder of DIATEAM, Guillaume started out as an engineer in information systems security, and has been working in the digital security for 25 years now. He has developed many "proofs of concept" and some tools like netglub, ipmorph, hynesim and also gives talks and classes in many engineering schools (ENIB, ENSIETA, ESM Saint-Cyr, ...). Guillaume is the author of several papers on security, and is a frequent speaker and/or attendee at security and testing conferences such as SSTIC, HITB, HACK.LU, FRHACK, ...
Adrien Barchapt-Perrot
Adrien is the RedTeam leader at DIATEAM. Working in the field of offensive cybersecurity for 10 years, he is particularly interested and involved in the development of customized implants and the bypassing of defense systems.
cOMMENT LA CRYPTOMONNAIE MONERO PROTèGE LA VIE PRIVée
Français
Débutant
14H30 – 18H00
Mathias HERBERTS
Monero est la principale cryptomonnaie qui se distingue par son engagement envers la préservation de la vie privée. Lors de ce workshop, Mathias Herberts en détaillera les caractéristiques, les aspects pratiques de sa mise en œuvre et de son utilisation quotidienne, tout en abordant ses perspectives futures.
Ce workshop comprend une partie pratique visant à familiariser les participants avec l’usage de Monero. Un téléphone mobile sous Android ou iOS ou un ordinateur sous Linux/MacOS/Windows sera nécessaire pour recevoir un peu de Monero et participer aux aspects pratiques.
________
À propos de l'intervenant : protège sa vie privée depuis le 20e siècle.
La directive NIS V2 SANS Péridurale
Français
Débutant
14H30 – 16H30
Marc-Antoine LEDIEU et Jean-Philippe GAULIER
La directive NISv2 est une évolution majeure dans le paysage de la cybersécurité européenne. Elle vise à renforcer la sécurité des réseaux et des systèmes d’information à travers l’Union Européenne, élargissant le champ d’application par rapport à la directive NIS originelle, en incluant un plus grand nombre d’entités et en renforçant les exigences en matière de sécurité.
Nous passons ainsi de 300 structures à plus de 10 000 impactées. Ainsi, nous parlerons ensemble de comment établir une roadmap de manière sereine en éclaircissant les buzzwords les plus marquants du texte : état de l’art, hygiène, analyse de risque, chartes, plan d’assurance sécurité, journalisation.
Dans la joie et la bonne humeur, armés de quelques vannes bien préparées, nous passerons ensemble les moments les plus délectables autour d’un texte immanquable !
________
À propos des intervenants
Marc-Antoine Ledieu
Après une expérience de cinq ans comme avocat plaidant en droit des affaires, Marc-Antoine Ledieu s’est spécialisé en droit du numérique et en ingénierie contractuelle BtoB.
Ses domaines d’intervention couvrent le droit du logiciel et du service SaaS, des bases de données, des données personnelles , du web, des communications électroniques et du chiffrement.
Depuis 1999, Marc-Antoine Ledieu enseigne le droit des contrats numériques dans le Master 2 PRO « droit du numérique » de l’Université Paris II Panthéon-Assas.
Jean-Philippe Gaulier