BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.balccon.org//balccon2k26-2026//talk//SXYD3W
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-balccon2k26-2026-SXYD3W@cfp.balccon.org
DTSTART;TZID=CET:20260920T151500
DTEND;TZID=CET:20260920T160000
DESCRIPTION:Your bug bounty / pentest scope is a list of ASN and domains. *
 *Your attack surface isn't.**\n\nModern cloud architectures expand beyond 
 those horizons - Lambda function URLs\, API Gateway endpoints\, S3 buckets
 \, CloudFront distributions\, container registries\, and CI artifacts depl
 oy outside the visible domain space\, weakly monitored and missing from of
 ficial scope.\n\nSo: `whoarethey`? This talk provides the answers to that 
 key question - how to map a target company's cloud-heavy infrastructure wi
 th a pure black-box approach\, beyond standard methods. Alongside a brief 
 recap of the regular recon (acquisitions\, subdomain enumeration) for comp
 leteness\, the focus will be on **cloud-asset recon**. You will learn how 
 to find all the APIs of any given cloud and almost all the cloud domains w
 ith user workloads or content - and how to attribute them to a specific co
 mpany.\n\n*For hunters and pentesters tired of running the same methods ag
 ainst the same scope with the same results and wondering where the bugs we
 nt.*
DTSTAMP:20260901T064452Z
LOCATION:Tesla
SUMMARY:awerqo@balccon:~$ ./whoarethey > 'Cloud Recon for Bughunting.md' - 
 Andrei
URL:https://cfp.balccon.org/balccon2k26-2026/talk/SXYD3W/
END:VEVENT
END:VCALENDAR
