BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.balccon.org//balccon2k26-2026//speaker//MMXLC3
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-balccon2k26-2026-LRA3MW@cfp.balccon.org
DTSTART;TZID=CET:20260919T140000
DTEND;TZID=CET:20260919T160000
DESCRIPTION:Type: Intermediate–Advanced\nFocus: Adversary emulation\, det
 ection engineering\, IR workflows\nStyle: Fast\, offensive-defensive\, “
 learn by attacking and defending”\n\nCloud platforms like Amazon Web Ser
 vices (AWS) are foundational to many critical infrastructures and enterpri
 se applications\, making them prime targets for attackers. In this session
 \, we will not only explore the most relevant attack vectors cybercriminal
 s use to compromise AWS infrastructures but will also simulate these attac
 ks using known threat actor techniques in an adversary emulation context. 
 From initial access to hardcore persistence\, this talk will provide a com
 prehensive look at how attackers operate in AWS environments.\n\nWe will t
 ake a technical journey through the tactics\, techniques\, and procedures 
 (TTPs) employed by attackers at every stage of the threat lifecycle\, alig
 ned with the MITRE ATT&CK framework. We’ll start by reviewing common met
 hods of initial access\, such as exploiting exposed credentials or vulnera
 bilities in services like IAM\, Lambda\, and EC2. From there\, we’ll det
 ail how attackers escalate privileges\, move laterally\, and evade detecti
 on from tools like CloudTrail.\n\nThe session will conclude with an in-dep
 th look at advanced persistence techniques in AWS\, including the manipula
 tion of IAM policies\, backdooring Lambda functions or Docker containers\,
  and tampering with logs. Along the way\, we’ll demonstrate how security
  teams can implement defensive and detection strategies to mitigate these 
 risks. By leveraging AWS-native services and third-party tools\, attendees
  will learn how to enhance their incident response capabilities.\n\nThis h
 ands-on workshop will give attendees practical\, technical insights into A
 WS security\, adversary behavior\, and how to better defend against sophis
 ticated\, persistent attacks. A full hands-on experience\, this presentati
 on ensures deep technical immersion.
DTSTAMP:20260901T063732Z
LOCATION:Pupin
SUMMARY:AWS Security - The Purple Team Way - Santiago Abastante
URL:https://cfp.balccon.org/balccon2k26-2026/talk/LRA3MW/
END:VEVENT
END:VCALENDAR
