โก Fresh Talk Alert for BSides Luxembourg 2026!
๐ฌ๐ข๐จ๐ฅ ๐๐ง๐ ๐ฅ๐๐ฃ๐ข๐ฅ๐ง๐ฆ ๐๐ฅ๐ ๐จ๐ฆ๐๐๐๐ฆ๐ฆ ๐ช๐๐ง๐๐ข๐จ๐ง ๐ฆ๐ง๐ฅ๐จ๐๐ง๐จ๐ฅ๐: ๐๐ฅ๐ข๐ ๐จ๐ก๐ฆ๐ง๐ฅ๐จ๐๐ง๐จ๐ฅ๐๐ ๐ง๐๐ฅ๐๐๐ง ๐๐ก๐ง๐๐ ๐ง๐ข ๐ฆ๐ง๐๐ซ ๐๐ก๐ข๐ช๐๐๐๐๐ ๐๐ฅ๐๐ฃ๐๐ฆ ๐ช๐๐ง๐ ๐๐๐ ๐ฆ ๐๐ก๐ ๐ ๐๐ฃ ๐ฆ๐๐ฅ๐ฉ๐๐ฅ โ Antonio Formato
Turn unstructured threat intelligence into actionable, machine-readable defense logic in this deep dive from the Actionable CTI & Detection Engineering Village. Every week, critical threat reports are published in PDFs and blog posts โ rich in insight but unusable for SIEMs, SOARs, or AI agents. This talk shows how to bridge that gap using a hybrid architecture that combines deterministic extraction and LLM-based semantic inference to generate STIX 2.1 knowledge graphs.
Youโll explore how threat reports can be transformed into structured intelligence objects, mapped to MITRE ATT&CK, and visualized as interactive knowledge graphs. The session also introduces TI Mindmap HUB, an independent research platform that converts real-world reports into multi-layered CTI views including ATT&CK heatmaps, Diamond Model structures, and CVE prioritization.
A key focus is the Model Context Protocol (MCP), which exposes structured CTI as tool calls for AI agentsโmaking intelligence directly usable in automated workflows, SOC tooling, and AI copilots. The talk concludes with emerging research into LLM-inferred threat intelligence knowledge graphs and cross-report correlation at scale.
Antonio Formato is a Senior Cybersecurity Solution Engineer at Microsoft and an independent researcher focused on Generative AI for Cyber Threat Intelligence. He is the creator of TI Mindmap HUB and co-author of academic research on automated STIX 2.1 generation currently under peer review.
๐
Conference Dates: 6โ8 May 2026 | 09:00โ18:00
๐ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐๏ธ Tickets: https://2026.bsides.lu/tickets/
๐
Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #CTI #ThreatIntelligence #STIX #MITREATTACK #AISecurity #DetectionEngineering
๐ฎ The Return of Malware & Monsters: Collaborative IR Gaming (2h Workshop) on May 6th!
๐๐ข๐ง๐ง๐ ๐๐ข๐ก๐ง๐๐๐ก '๐๐ ๐๐๐: ๐๐ข๐๐๐๐๐ข๐ฅ๐๐ง๐๐ฉ๐ ๐๐ก๐๐๐๐๐ก๐ง ๐ฅ๐๐ฆ๐ฃ๐ข๐ก๐ฆ๐ ๐ง๐ฅ๐๐๐ก๐๐ก๐ ๐ง๐๐ฅ๐ข๐จ๐๐ ๐๐๐ ๐๐ก๐ with Klaus Agnoletti (@klausagnoletti) & ๐๐๐๐ก ๐ฆ๐ข๐ฅ๐๐ก๐ฆ๐๐ก - 6 May, 9AM - 11AM
Back by popular demand after last year's hit! Ditch dull tabletops for Malware & Monsters โ tabletop RPG meets creature-collecting where teams hunt/contain digital threats in story-driven scenarios with MITRE ATT&CK-mapped malware "malmons." Experience real IR chaos: coordination under pressure, incomplete intel, stakeholder drama. Take roles like Hunter, Analyst, Forensicator, Communicator to see how teams actually collaborate. Learn mechanics, build custom scenarios from real malware history, run live sims with "type effectiveness" for defenses and evolution for escalating attacks. Walk away with free, ready-to-use materials for fun, effective IR training.
Led by Klaus Agnoletti https://pretalx.com/orga/event/bsidesluxembourg-2026/speakers/SQVVHK/ (infosec pro since 2004, BSides Kรธbenhavn co-founder, storytelling cyber advisor, neurodiversity advocate) & Glen Sorensen https://pretalx.com/orga/event/bsidesluxembourg-2026/speakers/J3PRCC/ (Recovering CISO, DeleteMe Solutions Engineer, OSINT/AI expert, HackBack Gaming Incident Master).
๐
Conference dates and time: 6โ8 May 2026 | 9AM - 6PM
๐ Venue: 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐๏ธ Tickets: https://2026.bsides.lu/tickets/
๐
Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
Game your way to better IR skills โ popular return engagement! ๐ฒ
#BSidesLuxembourg2026 #IncidentResponse #CyberSecurityTraining #BlueTeam #GameBasedLearning #MITREATTACK #BSides #DnD #DFIR
If the Kardashians launched their own framework it would be Kommand and Kontrol (K2).
The Momager (Kris.exe or Kris.sh): The primary C2 listener.
The Glow Up: Privesc
Keeping Up: Lateral movement
#C2Framework #RedTeaming #PostExploitation #MalwareDevelopment #Infosec #CyberSecurity #EDRBypass #ActiveDirectory #PenTesting #ThreatHunting #MITREATTACK #APTHunting #Shellcode #ZeroDay #Persistence #Exfiltration #BlueTeam #PurpleTeaming #kardashians
Why the MITRE ATT&CK Framework Actually Works: https://levelup.gitconnected.com/why-the-mitre-att-ck-framework-actually-works-29ac26d2d20c
Learn How Malware Survives Reboots and Cleanup Using Cron Persistence Technique in Linux Systems.
Full Details Here: https://ostechnix.com/cron-persistence-linux-malware/
#CronPersistence #Malware #Cronjob #Cron #LinuxSecurity #MitreAttack #Linux
A red-team wiper emulating Sandworm (GRU Unit 74455) has been published - a 90-line Go binary demonstrating LotL execution across 121 MITRE ATT&CK techniques including T1490, T1561.001, and T1070.001.
Full report:
https://www.technadu.com/sandworm-gru-unit-74455-red-team-wiper-released-as-training-sample/614498/
Follow @technadu for more threat intel updates.
#Sandworm #GRU74455 #MITREATTACK #RedTeam #BlueTeam #Infosec #WiperMalware
Red and blue teams breaking down their silos and working in real timeโimagine a cybersecurity defense that evolves with every simulated threat. Curious how continuous purple teaming is rewriting the playbook?
#purpleteaming
#cyberdefense
#breachandattacksimulation
#mitreattack
#redteam
#blueteam
#securityautomation
#continuousvalidation
#cybersecuritystrategy
๐ MITRE ATT&CK v18 = a major leap in detection depth.
The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.
Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile โlinked devicesโ exploits, and ICS asset updates.
MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.
๐ฌ What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
Follow @technadu for more #ThreatIntel insights.
#CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity
New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via โLoginโ flows that appear genuine.
Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
๐ก๏ธ Detection ideas:
- Monitor consent grants in Entra ID logs.
- Restrict unverified app registrations.
- Disable user app creation.
- Flag Copilot bots using trial tenants or untrusted domains.
How are you tuning detections for AI-driven OAuth phishing?
๐ฌ Share your strategies & follow @technadu for more technical threat intel.
#OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu