Loading…
ChiBrrCon 2027
Type: Incident Response clear filter
Friday, October 9
 

10:15am PDT

Cyber Extortion: Breach, Response, and After Effects
LIMITED
Friday October 9, 2026 10:15am - 11:00am PDT
Limited Capacity seats available
  1. Cyber-extortion breach tactics and techniques
    1. Gaining access through social engineering
    2. Gaining access through zero-day
    3. Bypassing EDR
    4. Elevating privileges on internal systems
    5. Finding and exfiltrating data
    6. Covering tracks
  2. First hour of a network breach
    1. Locking down accounts and killing sessions
    2. Preserving artifacts
    3. Collecting logs
    4. Terminating access
    5. Blocking C2 channels
    6. Determining scope and source of compromise
    7. Other common pitfalls
  3. Breach extortion negotiations
    1. Common threat actor techniques
    2. Threat actor offerings and payments
    3. Negotiaion goals, strategies and best practices
Speakers
avatar for Kevin Bong

Kevin Bong

Director, Ghostscale
Biography: Kevin is a Director at Ghostscale, responsible for overseeing penetration testing, risk assessments, compliance audits, incident response, and cybersecurity advisory services. Kevin has 25+ years working in a variety of cybersecurity leadership roles, including application... Read More →
Friday October 9, 2026 10:15am - 11:00am PDT
➡️ 8. Empathy (Expo)

11:15am PDT

Modernizing Security Operations in a World of AI Threats
LIMITED
Friday October 9, 2026 11:15am - 12:00pm PDT
Limited Capacity seats available
We are currently at an inflection point. The traditional SOC model—relying on manually correlated alerts and fragmented SIEM, EDR, and SOAR tools is failing. Why? Because the adversary has industrialized the attack chain using Generative AI.

Threat actors no longer operate at human speed. They can generate complex phishing campaigns, discover vulnerabilities, and execute sophisticated attacks in hours, not months. This isn’t a future risk; it’s happening today, with AI-powered worms accelerating the speed and scale of breaches.

Our challenge is simple: We cannot fight machine speed with human effort.

The core architectural flaw in legacy environments is the "human correlation engine." You pay massive fees to ingest data into a SIEM, then you pay highly skilled analysts to manually pivot through disjointed consoles to stitch together a single attack story. This results in overwhelming alert fatigue, long Mean Time to Resolution (MTTR), and high analyst burnout.

To survive and compete in the AI era, you must adopt an Autonomous SOC model.

This means replacing fragmented tools with a single, unified platform—one that fuses XDR, SIEM, and SOAR onto a single data lake. The goal is to move the human out of the repetitive decision-making process. The AI should automatically ingest all telemetry, synthesize it into a single, comprehensive Incident (the full story), and orchestrate the response before your team even sees the alert.

This shift isn't about incremental improvement; it's about architectural transformation. It’s the only way to solve the most common problems that we face in the SOC today

Speakers
avatar for Paul Hill

Paul Hill

Sales Manager, Palo Alto Networks


Friday October 9, 2026 11:15am - 12:00pm PDT
⏪️ 3. Despair (Ballroom)

11:15am PDT

Stop Drowning in Logs: AI Accelerated Incident Response
LIMITED
Friday October 9, 2026 11:15am - 12:00pm PDT
Limited Capacity seats available
DFIR today involves millions of artifacts, hundreds of thousands of logs with a hundred different sources. An analyst would spend more time collecting, normalizing and then searching for data rather than reasoning about what happened. An average incident resulting in large timelines as APTs and ransomware gangs today, equipped with AI to help them on their quest for world encryption.

So why not look at the problem? The analysts spending hours analyzing and looking at logs, a hundred different tools and then normalizing the mess... phew! This makes DFIR the path with the highest burnout rates withing the cybersecurity domain. The solution to this is relatively simple, or is it? Let's dive into employing the OSDFIR framework to automate investigations and as a plus, leveraging the ability of LLMs to work with opensource tools like OpenRelik and Tmesketch (both would be explained to the audience) to make this workflow applicable in your day to day forensics and incident response scenarios.

I would demonstrate how a practical, end-to-end workflow using the above can be set and show the audience a demo where I prompt an LLM to identify malicious activity within a defined time frame. We will walk through a realistic muti-stage timeline where forensic artifacts are standardized and is used to build an enriched timeline for the the LLM to work with. The process to do the same would be explained followed by a short demo on the final product: a solution where you can ask the LLM using prompts in natural language to identify malicious activity!
Speakers
avatar for Joel John

Joel John

Forensic Analyst, Charles River Associates
Cybersecurity professional with over 5 years in the industry, currently working in incident response and digital forensics. Initially, I specialized in a red team role as a Security Consultant at Synopsys, where I was heavily involved in Offensive Security and Penetration testing... Read More →
Friday October 9, 2026 11:15am - 12:00pm PDT
➡️ 8. Empathy (Expo)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.