Presentations
Presentations – IT-DEFENSE 2027
C2 Evolution From the Past to Tomorrow – Xavier Mertens
Since malware has evolved with time, it has to communicate with a server to work smoothly. Most of it always used the good old “client – server” model. That’s the basics of a botnet where we have “bots” waiting for commands from their master. From a malware developer’s perspective, the implementation of this communication channel has always been a key element because it must happen below the radar. I’ll provide a recap of the C2 protocols from the past to today and tomorrow and show you common tactics used by attackers to interact with the infected computers.
This talk will be held in English.
The Next Era of Cyber Defense: Clarity, Control and Response at Scale – Paula Januszkiewicz
In this keynote, cybersecurity is reframed as a challenge of clarity and control rather than tooling. Despite significant investments, organizations continue to experience breaches that go unnoticed until it is too late.
Attackers exploit gaps in understanding rather than gaps in technology. Signals exist, often in abundance, yet they are not translated into actionable insight at scale. This creates environments where detection is present, but response is ineffective. Paula presents a strategic approach to achieving clarity across identity, endpoints and cloud environments, along with methods for transforming that clarity into coordinated response.
The session offers a new perspective on how organizations can see, understand and act on attacks as they happen. Attendees can expect practical insights, real-world lessons learned and incident examples drawn directly from Paula’s field experience.
This talk will be held in English.
Trust No Token: Hunting Identity-Based Attacks Beyond the IdP – Nestori Syynimaa
Identity has become the primary security perimeter. Modern attackers no longer need to exploit vulnerabilities or bypass network defenses. Instead, they steal authentication tokens and operate as legitimate users. Whether obtained through adversary-in-the-middle (AiTM) phishing kits, infostealer malware or compromised endpoints, bearer tokens provide direct access to cloud services without requiring the attacker to authenticate again.
Most organizations focus their detection efforts on identity providers (IdPs), treating them as the central control point for identity security. However, token theft fundamentally changes the game. Once a token has been issued, attackers can bypass many IdP-centric detections and interact directly with service providers, where critical activities such as data access, lateral movement and exfiltration occur.
This presentation examines the modern token-based authentication ecosystem from both offensive and defensive perspectives. We will dissect how authentication tokens are issued, used, abused, and replayed across cloud environments. We will explore the limitations of traditional indicators such as IP addresses and HTTP headers and demonstrate how emerging techniques such as JA4 TLS fingerprinting can provide more resilient methods for identifying both human and non-human identities. Attendees will learn why visibility from either the IdP or the service provider alone is insufficient, and how correlating telemetry across both sides of the trust boundary enables detection of advanced token replay attacks that would otherwise remain invisible. Through real-world attack scenarios, detection strategies and practical guidance, this session provides a deep dive into the technologies and signals required to defend the modern identity perimeter.
This talk will be held in English.