Agenda

8:45 am
Center Room
Opening Remarks
9:00 am
North Room
Lawrence Kincheloe & Julio Tirado
Captain’s Log: We Tried to Build a Combadge. It Got Complicated. But we made a cool AR Hacking the Holodeck mini-game!
Lawrence & Julio talk through this year’s efforts to build an engaging conference badge with the supply chain challenges in the current economic circumstances. They’ll explore the original goal, what happened, and how we ended up with an awesome AI augmented reality game.
Center Room
Andrew Lemon
How to steal a network
What happens when the biggest threat to your network isn’t an APT, ransomware crew, or zero-day but your own administrators? What do you do when a ransomware group embeds themselves in your network.
In this talk we’ll cover real world engagements where we were tasked with surreptitiously obtaining the keys to the kingdom without alerting authorized and unauthorized admins. We’ll discuss the pitfalls you may run into and how Microsoft or Cisco can completely blow your cover.
Speaker Bio
Andrew Lemon is the founder of Red Threat Security where he serves as the lead over Penetration Testing and Red Teaming. Lemon honed his Red Teaming skills through years of incident response against APT groups that target the Hospitality, Legal, Oil and Gas, and Critical national infrastructure industries. Lemon used the Tools, Techniques and Procedures he learned from adversaries as a spring board to develop his Companies Methodology for adversarial emulation. This methodology has enabled his team to compromise a variety of targets, such as airports, utilities companies, oil tankers and drilling rigs, and gain physical access to hardened targets like ISP data centers, Chemical Production facilities, and Cash Depositories.
South Room
Andre Piazza
Acts of God: How Cybercriminals Leverage AI to Exploit Breaking News
The ubiquitous “detect and respond” approach to cybersecurity is particularly vulnerable when cybercriminals exploit unexpected, unanticipated, or “acts of God” events—ranging from natural disasters and geopolitical shifts to viral disinformation campaigns and economic turbulence—to launch sophisticated scams. These events create unique windows of opportunity for adversaries to manipulate public trust, urgent needs, or prevailing narratives, targeting individuals, charities, aid agencies, and other stakeholders through phishing, impersonation, and online fraud.
The presentation includes cases taken from several threat advisories and reports focusing on scam and fraud activity catalyzed by real-world events like the Los Angeles wildfires, the Texas floods, the Trump/Musk feud, and more.
Using real-world examples, the session demonstrates how malicious actors use clever tactics and AI to quickly spin up scam campaigns on the web that manipulate public sentiment. These campaigns seek to elicit an emotional response and subsequent reaction by preying on stakeholders at every level of involvement in a newsworthy event. By inspiring empathy, asking for help, requesting donations, inciting rage, or sparking an argument, internet users are driven to click to their detriment.
The discussion also covers how internet-scale behavioral predictive analytics can identify and disrupt the types of malicious infrastructure used in these scams before they can be activated. This foresight enables preemptive blocking and takedowns of threat actor assets, effectively neutralizing attacks before any victim is made and significantly increasing the cost and reducing the ROI for criminal enterprises. The combination of contextual visibility of the exploitation of large-scale disinformation campaigns and economic volatility with the method of predicting attacker infrastructure offers a unique and highly effective defense against criminal opportunism in an unpredictable world.
Speaker Bio
Andre Piazza is a cybersecurity strategist with over two decades of experience translating complex technical trends into practical strategies for enterprises. Specializing in predictive security frameworks, fraud prevention, and analyst relations, he helps organizations anticipate and mitigate emerging threats.
His background spans product strategy, engineering, and market influence, including pioneering five cybersecurity categories and generating more than 40 mentions from Gartner analysts. Andre speaks regularly at industry events on cybersecurity strategy, fostering collaboration between practitioners, analysts, and vendors to grow awareness and build a more resilient security community.
10:00 am
North Room
Michael Oglesby
Hardening the OS: Fighting 0-Days with Modern Exploit Defenses
As advanced threats evolve, defending against zero-day exploits has become increasingly challenging. Old-school mitigations like DEP and ASLR are largely ineffective against today’s sophisticated attacks. To raise the bar, OS vendors and hardware manufacturers have introduced new features such as Control-flow Enforcement Technology (CET) and Memory Integrity, designed to make code execution attacks significantly harder. In this session, we’ll unpack how these protections work, when you should enable them, and demo how to verify your systems are protected.
Speaker Bio
Michael is a cybersecurity consulting industry veteran with 15+ years of experience guiding security programs to become more resilient and defensible. He has worked with numerous companies, from small startups to large Fortune 100 enterprises, maturing their security programs against modern threats. Michael has a broad range of technical expertise, including penetration testing, red/blue teaming, threat intelligence, DFIR, and secure application development. Michael has a Master’s degree from the University of Tulsa and is an adjunct instructor teaching penetration testing in the School of Cyber Studies. In addition to his security testing experiences, Michael has worked roles in product development, compliance, auditing, and risk analysis. Michael focuses on the cutting edge of security research and how new technologies like data science, AI, and automation will impact the future security landscape.
Center Room
Ian Anderson
The Adversary Doesn't Care About Your Compliance Score
Cybersecurity standards exist for good reason; they establish a floor. But floors aren’t ceilings, and adversaries like Volt Typhoon are playing a game our frameworks weren’t designed for. This session breaks down Cyber Persistence Theory (CPT), the idea that cyberspace is a domain of constant contact where nation-states compete below the threshold of armed conflict, and measures how well our most relied-upon standards actually align with that reality. The gap isn’t technical; it’s philosophical. Attendees will leave with a reusable scoring methodology you can apply to your own environment and a short list of high-impact actions that work regardless of which standard your industry lives under.
Speaker Bio
Ian Anderson is the Director of Enterprise Security, Network, and Monitoring for Oklahoma Gas & Electric, headquartered in Oklahoma City, Oklahoma. Ian has experience in government, energy, financial, and manufacturing industries. Ian has a bachelor’s degree in management of information systems and a master’s in public administration, with a concentration in public policy, both from the University of Oklahoma. Ian also serves on the faculty of Arizona State University in the school of Politics and Global Studies teaching within the Master of Arts in Global Security program.
South Room
Sharrone Berry-Davis
Offensive Engineering: Applying DevOps Principles to Offensive Security
Most offensive security programs start off with a small, one-person team, a few created or borrowed scripts and tools, and operate largely on trust and muscle memory. In teams I’ve been part of, that tribal knowledge approach worked… until it didn’t. Manual infrastructure stuck around longer than it should have, tools behaved differently depending on who built them, and more than once I caught myself thinking, “I really hope nothing breaks at the wrong time… or worse.”
This talk is built around lessons learned from those moments. I’ll share the problems I ran into as offensive security work became more complex, the ideas I borrowed from DevOps and platform engineering, and the small changes that made a big difference. Along the way, we’ll discuss practical approaches you can apply immediately, even if you never build a full platform to manage everything. I’ll wrap up with a brief demo showing how I eventually put these ideas into practice.
Speaker Bio
Sharrone Berry-Davis is an offensive security practitioner who has spent time building and operating within offensive security programs in a variety of environments. His work focuses on applying engineering and DevOps principles to offensive security operations in order to make them safer, more consistent, and less dependent on tribal knowledge.
He enjoys breaking things responsibly, automating and building structure around the hard parts, and learning from the times when things didn’t go quite as planned.
https://www.linkedin.com/in/sharrone-b-39996957/
11:00 am
North Room
Steven Lykins
“I’m in Danger”: From Alert Chaos to CTEM
As the digital attack surface expands beyond traditional endpoints and into the realms of identity, cloud misconfigurations, and shadow IT, the standard “patch-all-critical” approach has become unsustainable. This presentation explores Continuous Threat Exposure Management (CTEM), a systemic framework designed to prioritize security efforts based on actual business risk rather than just vulnerability severity scores. We will deconstruct the five essential stages of CTEM- Scoping, Discovery, Prioritization, Validation, and Mobilization- to demonstrate how organizations can move from a reactive, siloed posture to a proactive, attacker-centric defense. Attendees will leave with a roadmap for reducing remediation noise, bridging the gap between Security and IT operations, and communicating measurable risk reduction to executive stakeholders.
Speaker Bio
Steven Lykins is a Senior Security Solution Architect at Qualys with over 20 years of experience in cybersecurity across enterprise, cloud, and hybrid environments. He specializes in helping organizations simplify risk, reduce tool sprawl, and operationalize vulnerability and exposure management. Steven is known for translating complex security challenges into practical, actionable strategies that drive measurable risk reduction and business alignment.
Center Room
Camron Borders
Operation Moonlander: Dismantling the Anyproxy/5socks Botnet
Hear about how in 2025, the FBI and Dutch National Police conducted a coordinated takedown of a decades-old botnet that enabled millions of dollars of criminal activity by foreign cyber threat actors.
Speaker Bio
Camron has a degree in Computer Science with previous experience as a software engineer and software engineering manager. Currently he works as a Special Agent with the FBI in Oklahoma City on the Cyber Task Force.
South Room
Stephen Engler
Burned-Out Admins: Your Most Exploitable Vulnerability
Your organization has invested in EDR, SIEM, zero-trust architecture, and a SOC—yet your most critical security vulnerability might be sitting in the next room, responding to their fourth incident this week on three hours of sleep. Burned-out system and security administrators don’t just suffer individually; they create exploitable weaknesses in your security posture that no amount of tooling can compensate for.
This talk reframes administrator burnout as a security architecture problem, examining how exhausted teams create cascading vulnerabilities: delayed patches, misconfigured security controls, degraded incident response, and dangerous shortcuts under pressure. We’ll explore measurable security risks, demonstrate how burnout undermines defense-in-depth, and provide engineering-focused mitigation strategies that improve both security posture and team resilience.
Speaker Bio
Stephen’s been deep in the trenches of IT for over two decades — from coaxing life out of tape backups to engineering modern hybrid infrastructures. He brings an old-school sense of grit and humor to a field that’s constantly reinventing itself, challenging technologists to evolve without losing their edge.
12:00 pm
Center Room
Lunch
1:00 pm
North Room
J Fridley
Extending Shared Threat Models with the Application Attack Matrix
Shared threat frameworks have transformed how defenders describe adversary behavior and coordinate response. As attackers increasingly target software supply chains, application runtimes, and AI-enabled systems, defenders face new challenges applying existing models consistently. This session shares lessons from the Application Attack Matrix, a community-driven effort involving contributors from organizations such as Mandiant (Google Cloud), Microsoft, AWS, Meta, and others, exploring how application-layer attack techniques can be systematically described and operationalized.
Speaker Bio
J. Fridley is a Senior Solutions Engineer at Oligo Security, helping teams secure modern cloud environments through deep runtime visibility. He previously led and supported Solutions Engineering teams at Snyk and has a background as a software engineer and technical project lead. J also brings over 18 years of military service with the U.S. Navy and Army National Guard.
Center Room
Kris Wall
The Mentor's Roadmap to Your Cyber Career
The job market is tough and there are numerous paths shrouded in mystery one can take in their cyber security career. Join us as a veteran of the industry demistifies the field and provides the must know, nice to know, and optional to know information so you can strategically prepare yourself for your next big jump in cyber.
Speaker Bio
Kris Wall is a senior penetration tester for the 48th Cyber Test Squadron out of Eglin AFB. Kris supports the US Air Force and Space Force in providing Development and Operational Testing and Evaluation (DOT&E) to discovery vulnerabilities and maximize cyber resiliency from foreign adversaries. Before working for the USAF, Kris founded Critical Fault, a penetration testing and digital forensics company based in Edmond. Kris has spoken at several security conferences include BSides, Information Warfare Summit, RVASEC, Nolacon, GrrCon, and more.
South Room
James Honeycutt
Hunting Smarter, Not Harder: Building Threat Hunting Pipelines with Python (Featuring ESXi Hunting)
Blue teams are swimming in logs, alerts, and noise—but not always the right visibility. Especially when it comes to ESXi and virtualization, most detection tools stop at the OS layer. This talk shows how to build lightweight, Python-driven threat hunting pipelines that bring automation and clarity to ESXi investigations.
We’ll walk through real examples of parsing hypervisor logs, spotting suspicious VM deployments, and visualizing activity patterns with a few dozen lines of Python. The goal isn’t another “AI solves everything” story—it’s about making the hunts we already do faster, repeatable, and more scalable.
Attendees will leave with a working model for building their own hunt pipelines, code samples they can adapt immediately, and a new perspective on how open-source scripting can level up blue team operations.
Speaker Bio
James (Jay) Honeycutt is a cybersecurity professional with over a two decades of experience in Information Security and IT/Signal Operations within the U.S. Army. His work focuses on bridging intel-driven analysis with blue team operations through automation, scripting, and data-driven detection design. He’s passionate about empowering defenders to hunt smarter, not harder, using open-source tools and repeatable workflows.
He holds a Master of Science in Information Security Engineering (MSISE) and numerous industry certifications.
2:00 pm
North Room
Cary Hooper
A Fistful of Headers: Taming the Wild Web at Scale
I built a distributed scanner because I got tired of waiting on bad networks and flaky prototypes. The result: an open, Python-first framework that spins up workers wired together with async gRPC choreography and a humble SQLite DB to collate data. To show it off we scanned the top 1,000,000 sites for HSTS and preload behavior. Expect a live MitM demo, weird header case studies, and a toolkit that makes large-scale, high-latency network research embarrassingly parallel.
Speaker Bio
Cary Hooper is an offensive security engineer working for a Fortune 500 institution. Cary is a combat veteran, graduate of the United States Military Academy at West Point (Math), and graduate of Georgia Tech (Computer Science). He led technical and non-technical teams within the Army Engineer Corps and Cyber Command. Cary’s certifications include CISSP, OSCE, OSCP, and OSWE. He loves teaching almost as much as he does learning new things from others. Come say hello if you see him at the con!
Center Room
Geoff Wilson
Hacking Unpacked: This Year’s Most Interesting Breaches, Mapped to Real Controls
Every year, the cybersecurity landscape is shaped not just by headline-grabbing breaches, but by the repeatable tactics and overlooked vulnerabilities that enable them. In this insight-rich session, Geoff Wilson will unpack the year’s most compelling hacks—revealing how identity misuse, SaaS exploits, third-party blast radius, ransomware operations, and AI-assisted social engineering continue to challenge organizations of all sizes. But this isn’t just a recap. Each incident will be mapped to real-world controls and practical mitigations, translating public failures into a prioritized checklist your team can act on. Whether you lead a blue team, own risk and compliance, or set security strategy, you’ll leave with actionable insights and a roadmap for building durable defenses—turning a year of breaches into a foundation for lasting security.
Speaker Bio
Geoff Wilson is CEO and Co-Founder of Go Security Pro and is an innovative cybersecurity thought leader with deep experience in defensive cybersecurity strategies. Having studied at Carnegie Mellon University and worked at the National Security Agency, Geoff brings over 20 years of cybersecurity experience to your organization. In his many cybersecurity roles, Geoff has been a Federal Auditor, Chief Information Security Officer, Penetration Tester, Author, University Professor, and Consultant. Geoff is a business leader having founded Go Security Pro in 2019 with his co-founder Susan Wilson.
South Room
Andrew Peters
Hide, Obfuscate, Destroy: Techniques and Implications of Anti-Forensics
This talk breaks down how attackers use anti-forensic techniques like stenography, encryption, time stomping, and more to hide their tracks and mislead investigators, and what the implications are for digital forensics and incident response.
-Introduction-
What anti-frorensics is and why it matters
-Core Anti-Forensic techniques-
Methods of hiding data
methods of obscuring data
Methods of destroying data
-Real World Examples-
-Impact on Digital forensics and incident response-
-Conclusion-
Speaker Bio
Andrew Peters is currently a Security Engineer at Alias Cybersecurity where he focuses on digital forensics investigations. His job involves conducting various investigations and assisting in incident response situations among other tasks like conducting pen testing, risk assessments, and other cybersecurity tasks. He is Certified Forensic Computer Examiner through the International Associate of Computer Investigative Specialists, and an expert witness in digital forensics in the state of Oklahoma.
3:00 pm
North Room
Gregg Robbins
Why Disaster Recovery Is NOT Cyber Recovery
Disaster Recovery + Immutable storage is not Cyber Recovery. This talk discusses what real attacks Incident Response teams have had to deal with, and walks through tips and tricks that are needed to prepare ahead of time to successfully recover quickly from these types of devastating attacks both for on-prem and cloud systems.
Speaker Bio
Gregg Robbins is the AVP of IT Security Services and head of the cyber security program at Watco Companies. He is responsible for the security, system monitoring and altering, and security governance teams at Watco. He has over 40 years of IT experience working for such companies as Diebold, JB Hunt, Transplace, BNSF Logistics, and Watco Companies.
Watco started their security operations team under Gregg’s leadership six years ago. In addition to supporting over 4500 team members at more than 450 locations in 4 countries, Watco also operates multiple locations that have been deemed part of the United States’ national critical infrastructure. Gregg is passionate about developing cyber security talent and growing a flexible and effective team to protect Watco from malicious actors. The cybersecurity program at Watco has a cyber security focused team that emphasizes quick detection and response to threats and multi-layered and tested cyber recovery solutions.
Center Room
Jonathan Kimmitt
The CISO as Diplomat: Surviving the Political Battlefield of IT
In today’s organizations, the greatest vulnerability isn’t always in the network — it’s in communication. Security and IT professionals routinely identify serious risks that leadership ignores, minimizes, or delays. This talk explores how technical experts can navigate the political landscape of their organizations to turn warnings into action. Drawing from real-world experience in incident response and executive leadership, Jonathan shares practical strategies for building influence, framing messages that leadership actually hears, and surviving the frustrating gap between technical truth and executive decision-making.
Speaker Bio
Jonathan Kimmitt currently serves as Chief Information Security Officer for Alias Cybersecurity. Jonathan has supported Security and Privacy initiatives for organizations for over 20 years. He supports clients in incident response and program development for IT, cybersecurity and privacy departments and AI governance. An active member of the community, he currently the CISO Showdown Champion of Oklahoma, presented on cyber & privacy topics at over 300 events and helps lead community support as a past ISSA President, InfraGard board member, and an adjunct cybersecurity instructor for local small business and entrepreneur training programs. In his professional role, his focus is for industries, professionals, and leaders to grow and develop their security and privacy postures for organizations, employees, and communities.
South Room
Andy Lewis
Death By (Python) Pickle: "Betrayal ML"
In the original Matrix movie, Neo learned Kung Fu through an upload. Imagine if your ML could learn the same way. That’s what a pickle file does for ML – “I KNOW KUNG FU” or whatever was in the file that was supposed to be “learned” by your ML model.
What if there was a plot twist where Agent Smith tampered with the Kung Fu module so that it included a fun “bonus” lesson that “taught” Neo to call Agent Smith every time he was trying to find an exit?
That’s what’s happening in Pickle Files, and that’s the setup for ML and AI.
This talk will explain the threat, provide some examples, and discuss emerging detection capabilities. When it’s over, you will know kung fu.
Speaker Bio
Andy is a former Marine and veteran of The Worm Wars who’s currently a Technical Marketing Manager at ReversingLabs, a company tackling secure software acquisition head-on. He is the founder of Denver OWASP, Boulder OWASP, Denver Cloud Security Alliance, and co-founder of the SnowFROC AppSec conference. He is a honeybee wrangler in his spare time.
4:00 pm
Center Room
Final Remarks and Raffle























