{"id":91,"date":"2026-05-23T17:23:10","date_gmt":"2026-05-23T15:23:10","guid":{"rendered":"https:\/\/it-defense.hostpress.me\/it-defense-2027\/?page_id=91"},"modified":"2026-08-19T11:58:00","modified_gmt":"2026-08-19T09:58:00","slug":"presentations","status":"publish","type":"page","link":"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/","title":{"rendered":"Presentations"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Presentations \u2013 IT-DEFENSE 2027<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><br><strong><strong>C2 Evolution From the Past to Tomorrow \u2013 <a href=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/xavier-mertens\/\" data-type=\"link\" data-id=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/xavier-mertens\/\" target=\"_blank\" rel=\"noreferrer noopener\">Xavier Mertens<\/a><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since malware has evolved with time, it has to communicate with a server to work smoothly. Most of it always used the good old \u201cclient &#8211; server\u201d model. That\u2019s the basics of a botnet where we have \u201cbots\u201d waiting for commands from their master. From a malware developer\u2019s perspective, the implementation of this communication channel has always been a key element because it must happen below the radar. I\u2019ll provide a recap of the C2 protocols from the past to today and tomorrow and show you common tactics used by attackers to interact with the infected computers.<br><br><em>This talk will be held in English.<\/em><br>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><strong>The Next Era of Cyber Defense: Clarity, Control and Response at Scale &#8211; <a href=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/paula-januszkiewicz\/\" data-type=\"link\" data-id=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/paula-januszkiewicz\/\" target=\"_blank\" rel=\"noreferrer noopener\">Paula Januszkiewicz<\/a><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this keynote, cybersecurity is reframed as a challenge of clarity and control rather than tooling. Despite significant investments, organizations continue to experience breaches that go unnoticed until it is too late.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers exploit gaps in understanding rather than gaps in technology. Signals exist, often in abundance, yet they are not translated into actionable insight at scale. This creates environments where detection is present, but response is ineffective. Paula presents a strategic approach to achieving clarity across identity, endpoints and cloud environments, along with methods for transforming that clarity into coordinated response.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The session offers a new perspective on how organizations can see, understand and act on attacks as they happen. Attendees can expect practical insights, real-world lessons learned and incident examples drawn directly from Paula&#8217;s field experience.<br><br><em>This talk will be held in English.<\/em><br>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><strong>Trust No Token: Hunting Identity-Based Attacks Beyond the IdP \u2013 <a href=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/nestori-syynimaa\/\" data-type=\"link\" data-id=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/nestori-syynimaa\/\" target=\"_blank\" rel=\"noreferrer noopener\">Nestori Syynimaa<\/a><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Identity has become the primary security perimeter. Modern attackers no longer need to exploit vulnerabilities or bypass network defenses. Instead, they steal authentication tokens and operate as legitimate users. Whether obtained through adversary-in-the-middle (AiTM) phishing kits, infostealer malware or compromised endpoints, bearer tokens provide direct access to cloud services without requiring the attacker to authenticate again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most organizations focus their detection efforts on identity providers (IdPs), treating them as the central control point for identity security. However, token theft fundamentally changes the game. Once a token has been issued, attackers can bypass many IdP-centric detections and interact directly with service providers, where critical activities such as data access, lateral movement and exfiltration occur.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This presentation examines the modern token-based authentication ecosystem from both offensive and defensive perspectives. We will dissect how authentication tokens are issued, used, abused, and replayed across cloud environments. We will explore the limitations of traditional indicators such as IP addresses and HTTP headers and demonstrate how emerging techniques such as JA4 TLS fingerprinting can provide more resilient methods for identifying both human and non-human identities. Attendees will learn why visibility from either the IdP or the service provider alone is insufficient, and how correlating telemetry across both sides of the trust boundary enables detection of advanced token replay attacks that would otherwise remain invisible. Through real-world attack scenarios, detection strategies and practical guidance, this session provides a deep dive into the technologies and signals required to defend the modern identity perimeter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>This talk will be held in English.<\/em><br>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Fighting the Dark Triad: Navigating Toxic Leadership in Cybersecurity &#8211; <a href=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/matthew-webster\/\" data-type=\"link\" data-id=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/matthew-webster\/\">Matthew Webster<\/a><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity professionals often focus on technical growth, governance and risk maturity &#8211; but what happens when the greatest threat isn&#8217;t a vulnerability in code, but in character?<br><br>In this deeply personal and practical session, I share my encounter with individuals who exhibited traits of the Dark Triad &#8211; narcissism, Machiavellianism and psychopathy &#8211; and how those encounters derailed not just security efforts, but entire teams. These personalities are rarely talked about in our field, but they can cause immense harm to cybersecurity programs, organizations and people alike.<br><br>You&#8217;ll learn how to recognize common behaviors, patterns and tactics used by Dark Triad personalities, especially those in positions of influence. More importantly, you&#8217;ll walk away with strategies to detect, manage and protect yourself and your teams from psychological and organizational harm.<br><br>This talk blends behavioral science, leadership resilience and cyber governance for professionals operating at the intersection of risk, trust and people.<br><br>Key takeaways:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>How to recognize signs of narcissism, manipulation and psychopathy in the workplace.<\/li>\n\n\n\n<li>Behavioral and structural indicators that you or your team are under social attack.<\/li>\n\n\n\n<li>Practical strategies to reduce your exposure, set boundaries and protect decision-making processes.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u00a0<em>This talk will be held in English.<\/em><br><br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Internet is too fast: From Local to Remote Side-Channel Attacks \u2013 <a href=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/daniel-gruss\/\" data-type=\"link\" data-id=\"https:\/\/it-defense.de\/it-defense-2027\/en\/presentators\/daniel-gruss\/\" target=\"_blank\" rel=\"noreferrer noopener\">Daniel Gruss<\/a><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Modern systems are built on mechanisms designed for a particular context and threat model. But what happens when the context changes while the mechanisms stay the same? Side-channel attacks were traditionally local: an attacker runs code on the same machine and observes subtle effects of shared hardware. Today, these boundaries are disappearing. Trusted execution changes the threat model, browsers expose local hardware to remote code, and fast, stable networks turn latency into a surprisingly precise measurement interface. In this talk, I will show how side channels have evolved from local microarchitectural attacks to attacks crossing increasingly large isolation boundaries &#8211; ultimately reaching victims remotely over the Internet. Across CPUs, caches, storage, and networks, a common theme emerges: mechanisms designed for one context can become security problems in another. Finally, I will discuss how security and efficiency interact in both directions: optimizations can introduce new attack surfaces, while carefully co-designed mechanisms can improve security without sacrificing, and sometimes even improving, efficiency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Presentations \u2013 IT-DEFENSE 2027 C2 Evolution From the Past to Tomorrow \u2013 Xavier Mertens Since malware has evolved with time, it has to communicate with a server to work smoothly. Most of it always used the good old \u201cclient &#8211; server\u201d model. That\u2019s the basics of a botnet where we have \u201cbots\u201d waiting for commands [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"parent":87,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-91","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Presentations - IT Defense 2027<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Presentations - IT Defense 2027\" \/>\n<meta property=\"og:description\" content=\"Presentations \u2013 IT-DEFENSE 2027 C2 Evolution From the Past to Tomorrow \u2013 Xavier Mertens Since malware has evolved with time, it has to communicate with a server to work smoothly. Most of it always used the good old \u201cclient &#8211; server\u201d model. That\u2019s the basics of a botnet where we have \u201cbots\u201d waiting for commands [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/\" \/>\n<meta property=\"og:site_name\" content=\"IT Defense 2027\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T09:58:00+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/program\\\/presentations\\\/\",\"url\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/program\\\/presentations\\\/\",\"name\":\"Presentations - IT Defense 2027\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/#website\"},\"datePublished\":\"2026-05-23T15:23:10+00:00\",\"dateModified\":\"2026-08-19T09:58:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/program\\\/presentations\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/program\\\/presentations\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/program\\\/presentations\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Start\",\"item\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Program\",\"item\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/program\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Presentations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/#website\",\"url\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/\",\"name\":\"IT Defense 2027\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Presentations - IT Defense 2027","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/","og_locale":"en_US","og_type":"article","og_title":"Presentations - IT Defense 2027","og_description":"Presentations \u2013 IT-DEFENSE 2027 C2 Evolution From the Past to Tomorrow \u2013 Xavier Mertens Since malware has evolved with time, it has to communicate with a server to work smoothly. Most of it always used the good old \u201cclient &#8211; server\u201d model. That\u2019s the basics of a botnet where we have \u201cbots\u201d waiting for commands [&hellip;]","og_url":"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/","og_site_name":"IT Defense 2027","article_modified_time":"2026-08-19T09:58:00+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/","url":"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/","name":"Presentations - IT Defense 2027","isPartOf":{"@id":"https:\/\/it-defense.de\/it-defense-2027\/#website"},"datePublished":"2026-05-23T15:23:10+00:00","dateModified":"2026-08-19T09:58:00+00:00","breadcrumb":{"@id":"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/presentations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Start","item":"https:\/\/it-defense.de\/it-defense-2027\/"},{"@type":"ListItem","position":2,"name":"Program","item":"https:\/\/it-defense.de\/it-defense-2027\/en\/program\/"},{"@type":"ListItem","position":3,"name":"Presentations"}]},{"@type":"WebSite","@id":"https:\/\/it-defense.de\/it-defense-2027\/#website","url":"https:\/\/it-defense.de\/it-defense-2027\/","name":"IT Defense 2027","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/it-defense.de\/it-defense-2027\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages\/91","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/comments?post=91"}],"version-history":[{"count":11,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages\/91\/revisions"}],"predecessor-version":[{"id":425,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages\/91\/revisions\/425"}],"up":[{"embeddable":true,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages\/87"}],"wp:attachment":[{"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/media?parent=91"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}