
BSidesOK
Training: April 2-3
Conference: April 4, 2025
About BSidesOK
Hosted in Tulsa, OK – BSides Oklahoma is a free information security conference focused on practical, hands-on training for improving security. Each BSides is a community-driven framework for building events for and by information security community members.
This is the premier security conference for the state of Oklahoma, pulling speakers from around the country and attendees from several surrounding states. BSidesOK is completely non-profit and volunteer-driven.
Venue
BSidesOK will be held at the Glenpool Conference Center in Glenpool, OK – just southwest of Tulsa. View the location details here.
Code of Conduct
Everyone deserves to attend a learning event, community or professional, with a reasonable expectation of good behavior. Learn more about our code of conduct here.

Pre-Con Happy Hour
Join us for a networking happy hour before the BSidesOK conference on Friday!
Thursday, April 3
5-7:30pm CDT
Main Event Tulsa
7830 South Santa Fe Avenue Tulsa, OK 74132
Badge Intel
8:45 am
Center Room
Opening Remarks
9:00 am
North Room
Peyton Smith
AI Agents: Augmenting Vulnerability Analysis and Remediation
Are AI agents worth the hype? In this talk, we’ll explore the tangible impact of AI agents in cybersecurity, focusing on how they can be used to automate proactive security workflows at scale. We’ll also discuss the technical challenges of implementing agentic security solutions, from managing hallucinations, building human-in-the-loop workflows, to integrating agents with existing security datasets for improved performance. We’ll also discuss the broader implications for security teams — how AI-driven automation is shifting the role of human analysts and changing the way organizations approach cyber resilience.
Center Room
Chris Ogles
Creating Fun and Engaging Tabletops
Walk through elements of a table top and how to make them fun and engaging.
South Room
Vivek Ponnada
No Place to Hide - OT Security's Shining Moment
Unlike a decade ago, there are a variety of tools available now for OT asset discovery, Vulnerability management and Threat Hunting. Most of them require a combination of OT knowledge and IT expertise to both establish a baseline, identify anomalies or perform forensics. This talk touches on the challenges (executive buy-in, aligning stake holders, upskilling relevant technical personnel etc.) and focuses on best practices to leverage the various tools (passive detection, threat monitoring and hunting) for defenders to be efficient and productive.
10:00 am
North Room
Brian Contos
Malicious Actors Depend on Your Unknowns. Disappoint Them!
This presentation will explore real-life stories from the trenches, representing how unknowns have allowed malicious actors to thrive. We’ll dive into specialized tools and techniques attackers use, especially cybercriminals and nation-states. We’ll demonstrate hacking techniques that illustrate the ease of compromise against multiple target types, from cloud applications to industrial robots. Finally, we’ll share vendor-agnostic mitigation strategies to help you discover, secure, monitor, and respond more efficiently and effectively by converting your unknowns to knowns. Malicious actors count on you being passive regarding unknowns and want you to fail. Disappoint them!
Center Room
George Jiang, Scott Kibbey
Ask the Feds: Inside Cybercrime Investigations and Prosecutions
How do cybercrime cases move from an initial investigation to a courtroom conviction? In this panel discussion, a federal cyber investigator and a federal prosecutor will provide insight into the investigative and legal processes behind cybercrime cases. From evidence collection to prosecution, gain a deeper understanding of how cybercriminals are identified, tracked, and brought to justice. We’ll also dive into the challenges involved in prosecuting cyber threats, offering valuable insight for cybersecurity professionals who interact with law enforcement.
South Room
Tanner Shinn
Winging It Like a Pro: The Art of Last-Minute Conference Talks
You are asked to help out a conference and fill a speaking slot last minute, you have nothing prepared. Do you know where to start? In this interactive session, we’ll build a complete, professional-looking presentation from scratch—right in front of you. We’ll outline the key points, structure the talk, and use some nifty tools to generate slides, refine content, and polish the final product. Whether you’re a first-time speaker or a seasoned pro looking to streamline your process, you’ll walk away with practical strategies for efficiently creating a compelling security talk. By the end of the session, you’ll see firsthand the secret sauce behind quickly turning an idea into a full-fledged presentation—without the last-minute panic. Well at least with less panic.
11:00 am
North Room
Geoff Wilson
Securing Your Microsoft Cloud
In this talk, Geoff Wilson of Go Security Pro will discuss the best approaches for hardening your Microsoft cloud configuration including Microsoft 365, Entra ID (Azure AD), and Intune. This talk will include an overview of notable Microsoft 365 data breaches, top recommendations for any Microsoft cloud implementation, how to use conditional access policies to thwart specific attack vectors, Intune policies, and a detailed walkthrough of how you can assess your own Microsoft cloud configuration using CIS Benchmarks. This talk will also have applicability to on-prem Active Directory.
Center Room
Aaron Moss
Red Vs. Blue - Whoever Wins, You Win
This talk is an introduction to Red Teaming, Blue Teaming, and the ever elusive Purple Team. It covers basic concepts around the red and blue teams, how simulating attackers can help both sides, and how working together produces better results for all parties involved.
South Room
Travis Lowe
Kubernetes For Incident Responders
Over the years, Kubernetes has grown massively in popularity with developers and IT teams. Has your security team grown with them? When a security incident happens within a Kubernetes environment do you know how to unpack the events in order to gain insight into the scope and impact of a security incident? In this session we will walk through a Kubernetes investigation from runtime alert to root cause. Throughout the presentation we will be uncovering the attacker’s behavior and the resulting impact from that behavior. Along the way we will discuss some unique features of Kubernetes that can be very powerful when conducting an investigation.
12:00 pm
Center Room
Jonathan Kimmitt + Chad Kliewer
CISO Showdown
Jonathan Kimmitt attempts to win the Oklahoma CISO championship a second time, but challenging the current champ Chad Kliewer to the Oklahoma CISO Showdown!
1:00 pm
North Room
Vanessa Toves
Be Ready: Protecting Microsoft 365 Data from Cyber Attacks
Your company has made significant investments in Microsoft 365—through licenses, solutions, and dedicated staff. With growing threats to the Microsoft ecosystem, it’s crucial that you understand your role in responding to cyber attacks. Every Microsoft 365 professional needs to be aware of the NIST 2.0 framework and the expectations of your role to ensure a swift, effective defense.
In this session, you will deepen your knowledge in these critical areas, empowering you to protect your organization and contribute to a more effective, coordinated response to cyber attacks.
Center Room
Andrew Lemon
Give Cyberwar a Chance
“Nothing exposes security theater like a real attack.”
When Russian hackers took down Ukraine’s power grid in 2015 and 2016, compliance didn’t save them—adaptation did. The attacks forced a rapid evolution in how infrastructure defends itself, pushing organizations to rethink network segmentation, attack surface management, and backup strategies in ways no regulation ever has.
This talk dives into how cyberwarfare forces real security progress, not through paperwork and audits, but through fire and failure. We’ll break down how nation-state threats have shaped better defenses for power grids, industrial control systems, and other critical infrastructure, and why fear of real-world consequences drives stronger security than any compliance framework ever could.
South Room
Carrie Randolph
AI Readiness & Data Governance
1:30 pm
South Room
Laurence Kincheloe
Badge Life
2:00 pm
North Room
Michael Oglesby
Hacks Done Quick
The Algorithm has won the future. Short-form content like Reels and TikTok has destroyed humanity’s attention span. In this dark future knowledge can only be delivered in quick bursts. As hackers we must adapt, the future of cybersecurity is at stake.
Center Room
Gordon Rudd
THE CISO’s Guide to Cultivating Board Support
Attendees will learn how to develop professional relationships with senior executives, the board, and the communications skills required to be an effective executive and world class CISO.
South Room
Samantha St-Louis
Cloud Solutions for Healthcare: Bringing Tech and Care
Healthcare is one of the most complex and data-rich industries, yet it often struggles with outdated systems, fragmented data, and scalability challenges. In this insightful session, Samantha will demonstrate how cloud-first AI solutions are revolutionizing healthcare by enabling secure, scalable, and intelligent workflows.
Drawing on her healthcare background and expertise as a Cloud and AI Solutions Architect, Samantha will showcase real-world case studies, including AI-driven patient care workflows, dynamic decision trees for treatment plans, and secure data-sharing architectures.
This session goes beyond theory—it’s about practical, actionable strategies for implementing cloud and AI solutions that improve patient outcomes, reduce inefficiencies, and bridge the gap between technology and care.
3:00 pm
North Room
Len Noe
The Future Threat Today
Transhumans—individuals with advanced tech enhancements—have moved from sci-fi into reality, challenging traditional cybersecurity. With embedded tech, they can execute complex cyber attacks, pushing the need for innovative defenses. This presentation underscores the urgency for layered security solutions to address these unique, emerging risks.
Center Room
Jonah White
The Dark Side of Browser Extensions: Detection and Defense Strategies
Learn how to analyze and protect your organization against browser extensions that are used by many unsuspecting users each day.
South Room
Mika Ayenson
Supercharging Detection Engineering: How GenAI is Transforming Threat Research and Automation
Threat research and detection engineering are evolving, and so are adversaries. At Elastic, we’ve embedded Generative AI (GenAI) into our security workflows to enhance efficiency, automate routine tasks, and provide high-value insights. This talk explores real-world applications where GenAI is accelerating our TRADEcraft—highlighting its strengths, limitations, and future potential.
Attendees will gain practical insights into integrating AI into security workflows, lessons learned from our journey, and the impact of data-driven security operations. This session will demonstrate how GenAI serves as a force multiplier, enabling teams to scale detection engineering and streamline internal processes.
4:00 pm
Center Room
Final Remarks and Raffle
2025 Training Sessions
Risk Management and Assessments: Proven Strategies for Managing and Assessing Cybersecurity Risk
Geoff Wilson, Daisha Darnaby and Caleb McCray with Go Security Pro will walk us through tried and true Cybersecurity Risk Management and Assessment processes, including some of the wicked problems we’ve faced. This course is for IT and business professionals who play a role in risk management.
Responding to an Incident and Beyond: IR Training
Don’t get caught by surprise – join the Alias IR team and learn how to respond to a cyber-attack. Understand how to walk through an incident response situation and become familiar with the various tools our team utilizes during an engagement. You’ll learn the best ways to respond to different types of IR situations (ransomware, business email compromise, data breach, etc.) in the event your business is compromised. Bring your laptop as this will be a hands-on-keyboard, interactive learning environment.
Pentest 101: Breaking in Without Going to Jail
This one-day intensive course introduces participants to the fundamentals of penetration testing. Designed for beginners, this hands-on workshop covers core concepts, methodologies, and essential tools used by security professionals to assess and exploit vulnerabilities in real-world environments. By the end of the day, attendees should have a foundational understanding of ethical hacking and be able to demonstrate basic penetration testing techniques.
Compliance and Vendor Management
With evolving regulations like HIPAA, GLBA, CMMC, and others, cybersecurity professionals must not only secure their own organizations but also ensure their vendors meet compliance requirements. This session will provide a direct, hands-on approach to both compliance and vendor management, helping cyber professionals understand how to evaluate, monitor, and enforce compliance both internally and externally.
Offensive SCADA : Intro to attacking Critical Infrastructure
Control systems are the lifeblood of Americas Critical Infrastructure, from the water in your pipes to the stoplights on your commute and the electricity that powers your building, all of these things are controlled by a SCADA system somewhere. In this training we’ll be learning how to view Operation Technology through an offensive lens as a Penetration Tester and as a Nation State Actor. This starts with a base understanding of how control systems are architected, the components that make up the systems, and the underlying protocols. After you’ve learned how the systems work, we’ll teach you how to break them. We’ll analyze real world attacks and then recreate them in the lab, including disrupting a municipal water supply and crippling a power grid. No OT or SCADA experience is required for this course, despite having advanced concepts, the material is structured in a way even someone with basic IT experience can follow along and understand.
Thank You to Our 2025 Sponsors!
Diamond Sponsors
Platinum Sponsors
Gold Sponsors
Silver Sponsors
Thank You to Our Community Partners
Oklahoma Chapter @issaok
Oklahoma City Chapter @issaokc























