BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.balccon.org//balccon2k26-2026//speaker//TBADRU
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-balccon2k26-2026-BJ9BW9@cfp.balccon.org
DTSTART;TZID=CET:20260919T123000
DTEND;TZID=CET:20260919T140000
DESCRIPTION:Have EDRs taken the glory of in-memory investigation? We' ll go
  through a side by-side comparison of  of incident investigation with mode
 rn EDR against traditional memory forensics with volatility3. \n(And by co
 mparing we mean complimenting the knowledge and arsenal of blue teams to p
 ick the right solution for the right problem. It's isn't really a competit
 ion on what is best\, NOR a shameless product selling)\n\nTheory is always
  good but gaining experience is also important! \nWe aim to start from mem
 ory internals 101 and dive into the analysis of a compromised system using
  volatility3 in parallel with KQL from Windows Defender for Endpoint. We s
 howcase why memory forensics remains a solid option in incident response -
 even in the age of telemetry\, and why rightfully considered an art form.\
 n\nThe workshop aims to be more than an RTFM of volatility3/KQL or use-plu
 gin-and-find flags CTF\, but rather equip participants with solid knowledg
 e on linking pieces of evidence to fill the jigsaw puzzle of an incident. 
 \nNewbie or seasoned\, professional or just curious\, this session is for 
 you!
DTSTAMP:20260901T064112Z
LOCATION:Pupin
SUMMARY:Memory Forensics in the age of EDR - November
URL:https://cfp.balccon.org/balccon2k26-2026/talk/BJ9BW9/
END:VEVENT
END:VCALENDAR
