Loading…
arrow_back View All Dates
Saturday, April 26
 

9:00am PDT

Breakfast
Saturday April 26, 2025 9:00am - 10:00am PDT
Breakfast is served in the Embarcadero. Drip
coffee and water are available all day throughout the
Participant Hall.
Saturday April 26, 2025 9:00am - 10:00am PDT
Participation Hall City View at Metreon

9:00am PDT

Espresso & Coffee
Saturday April 26, 2025 9:00am - 4:00pm PDT
Three barista stations are located within the Participant
Hall. Stop by for an espresso drink of your choosing!
Sponsors
avatar for DeepTempo

DeepTempo

Espresso & Coffee
avatar for Meta

Meta

Espresso & Coffee
avatar for Vanta

Vanta

Silver, Espresso & Coffee
Saturday April 26, 2025 9:00am - 4:00pm PDT
Participation Hall City View at Metreon

9:00am PDT

Headshots
Saturday April 26, 2025 9:00am - 5:00pm PDT
TBD
Free headshots, first come first serve.
Sponsors
OS

Opal Security

Headshots
Saturday April 26, 2025 9:00am - 5:00pm PDT
TBD City View at Metreon

9:00am PDT

Sponsors
Saturday April 26, 2025 9:00am - 5:00pm PDT
Visit the sponsor booths that line the walls of the Participant Hall and learn more about the companies that have made this year’s event possible. You’ll be introduced to new products, services, and career opportunities. At each booth you can also obtain one of the stamps you need to complete your Sponsor Passport (which can be found in the bag you received at registration).
Saturday April 26, 2025 9:00am - 5:00pm PDT
Participation Hall City View at Metreon

9:00am PDT

Capture the Flag
Saturday April 26, 2025 9:00am - 5:00pm PDT
TBD
Come play our awesome CTF! Everyone is welcome to participate as the competition features a range of challenges at all difficulty levels. In case you find yourself in need of assistance, we have folks onsite who can provide hints and guidance. All that is needed to participate is a laptop.

The server is available all weekend long, and anyone is welcome to play. Server information is at https://bsidessf.org/ctf

At least one player must be onsite to claim any prizes won.
Sponsors
avatar for Adobe

Adobe

Capture the Flag
Saturday April 26, 2025 9:00am - 5:00pm PDT
TBD City View at Metreon

9:00am PDT

Bar and Chill Out
Saturday April 26, 2025 9:00am - 5:30pm PDT
Take a break from the day’s events with a stop at the Bar and Chill Out Space. Two complimentary drink tickets were provided to you at registration. We already paid for them, so please use them!
Sponsors
avatar for runZero

runZero

Daytime Social (Sat)
Saturday April 26, 2025 9:00am - 5:30pm PDT
Participation Hall City View at Metreon

9:00am PDT

Lounge
Saturday April 26, 2025 9:00am - 5:30pm PDT
Enjoy the SF skyline from the Lounge. Located on the patio next to the tent, the Lounge includes comfortable places to rest and relax, as well as lawn games to play.
Sponsors
avatar for runZero

runZero

Daytime Social (Sat)
Saturday April 26, 2025 9:00am - 5:30pm PDT
City View Terrace City View at Metreon

9:00am PDT

Registration
Saturday April 26, 2025 9:00am - 5:30pm PDT
TBD
Saturday April 26, 2025 9:00am - 5:30pm PDT
TBD City View at Metreon

9:00am PDT

Villages
Saturday April 26, 2025 9:00am - 5:30pm PDT
Our villages are returning! Come engage with multiple different hands-on opportunities to learn new skills, practice skills, or share your knowledge. We have a broad selection of villages planned for this year and will be releasing the line-up soon.
Saturday April 26, 2025 9:00am - 5:30pm PDT
Participation Hall City View at Metreon

9:00am PDT

Info Desk
Saturday April 26, 2025 9:00am - 6:30pm PDT
Have a question or comment about the event that you’d
like to share? Drop by the Info Desk and chat with
members of the BSidesSF staff and volunteer teams.
Saturday April 26, 2025 9:00am - 6:30pm PDT
Lobby City View at Metreon

9:00am PDT

Prayer & Mother's Room
Saturday April 26, 2025 9:00am - 6:30pm PDT
Need a quiet place for meditation or mothering duties? Ask at the Info Desk, and we can guide you to a private location.
Saturday April 26, 2025 9:00am - 6:30pm PDT
Lobby City View at Metreon

9:00am PDT

Coat Check
Saturday April 26, 2025 9:00am - 10:00pm PDT
Secure storage for your personal belongings is available
for all participants. Please remember to pick up your
items before the end of the event!
Saturday April 26, 2025 9:00am - 10:00pm PDT
Coat Check City View at Metreon

10:00am PDT

Opening Remarks (Saturday)
Saturday April 26, 2025 10:00am - 10:15am PDT
Opening Remarks
Saturday April 26, 2025 10:00am - 10:15am PDT
AMC IMAX AMC at Metreon

10:15am PDT

Keynote (Saturday)
Saturday April 26, 2025 10:15am - 11:00am PDT
TBD
Speakers
Saturday April 26, 2025 10:15am - 11:00am PDT
AMC IMAX AMC at Metreon

11:00am PDT

T-Shirt Sales
Saturday April 26, 2025 11:00am - 9:00pm PDT
Pick up pre-purchased event t-shirts and purchase t-shirts for the current and previous years. Please note, we have limited t-shirt quantities.
Proceeds benefit three charities. You select 1 of the 3 charities we've selected by voting, and we donate to all of the charities based on the vote percentages.
Saturday April 26, 2025 11:00am - 9:00pm PDT
Coat Check City View at Metreon

11:15am PDT

Let's talk about the AI apocalypse.
Saturday April 26, 2025 11:15am - 11:45am PDT
What's it look like when someone spends hours fine-tuning llama 3.1 to be the most destructive hacking robot the world has ever seen, with a pure goal of causing damage, with no safeguards? Are we ready for that? Not a pentesting bot with guardrails; a harbinger of chaos, tasked only with spreading.
Speakers
Saturday April 26, 2025 11:15am - 11:45am PDT
AMC IMAX AMC at Metreon

11:15am PDT

Lex Sleuther - A Novel Approach to Script Language Detection
Saturday April 26, 2025 11:15am - 11:45am PDT
Join us as we go far off the beaten path in search of strange and exciting methods of script language detection.

File signatures? Nope.
Machine learning? Nah.
Here be dragons, but dragons often guard treasure…
Speakers
Saturday April 26, 2025 11:15am - 11:45am PDT
AMC Theatre 09 AMC at Metreon

11:15am PDT

The hidden access paths to Smaugs Caven
Saturday April 26, 2025 11:15am - 11:45am PDT
This talk will explore the hidden access patterns to the crown jewels, including most-common access patterns, hidden paths and popular backdoors left by engineers to get their jobs done. We will discuss practical tips to understand the problem and work on removing the hidden access paths.
Speakers
Saturday April 26, 2025 11:15am - 11:45am PDT
AMC Theatre 07 AMC at Metreon

11:15am PDT

Guardians of AI Safety -Assembling Heroes to Conquer Dragons of the Future
Saturday April 26, 2025 11:15am - 12:00pm PDT
Uncover the hidden risks of AI! Join this BoF session to explore frameworks for identifying system failures, understand new safety harm categories with Gen AI, possible mitigations and practical ways to govern, build and respond to AI Safety threats. Don't let what you don't know hurt you!
Speakers
Saturday April 26, 2025 11:15am - 12:00pm PDT
AMC Theatre 01 AMC at Metreon

11:15am PDT

Slaying Reputation Dragons: A Security Pro's Path to Influence
Saturday April 26, 2025 11:15am - 12:00pm PDT
Every security expert faces three dragons: the voice that whispers 'not expert enough,' the shadow that hides achievements, and the fear of claiming recognition. Ready to step out of the shadows and into your power as a security leader? The dragons await—will you answer the call?
Saturday April 26, 2025 11:15am - 12:00pm PDT
AMC Theatre 02 AMC at Metreon

11:15am PDT

AppSec as Glue: Building Partnerships to Scale Security
Saturday April 26, 2025 11:15am - 12:00pm PDT
Join AppSec leaders from Chime, Twilio, Rippling, (ex)Snowflake, and Datadog to explore how successful security teams act as organizational glue. Learn how to scale security impact by building essential partnerships across platform engineering, compliance, threat detection teams, and more!
Saturday April 26, 2025 11:15am - 12:00pm PDT
AMC Theatre 13 AMC at Metreon

11:15am PDT

How to train your Detection Dragon?
Saturday April 26, 2025 11:15am - 12:00pm PDT
Ever wanted to start fresh and train the "detection and response" dragon? Hear my account of how I did this (and hope to continue building!) from scratch with learnings from my professional experience so far!
Speakers
Saturday April 26, 2025 11:15am - 12:00pm PDT
AMC Theatre 06 AMC at Metreon

11:15am PDT

Inside the Information Stealer Ecosystem: From Compromise to Countermeasure
Saturday April 26, 2025 11:15am - 12:00pm PDT
Information stealer malware is underestimated by our industry. In this deep-dive, we look into what is captured by them – desktop screenshots, password vaults, browser extensions, MFA bypass material, etc. –, cover the Redline takedown, and offer defensive countermeasures including code and samples.
Speakers
Saturday April 26, 2025 11:15am - 12:00pm PDT
AMC Theatre 15 AMC at Metreon

12:00pm PDT

Navigating the Unknowns: Fraud Mitigation for Netflix Live Events
Saturday April 26, 2025 12:00pm - 12:30pm PDT
As Netflix enters live streaming, fraud prevention stakes rise significantly. This talk offers an insider's view of strategies and challenges in tackling fraud during live events, focusing on preparing for the unpredictable and maintaining robust defenses amidst this unpredictability.
Saturday April 26, 2025 12:00pm - 12:30pm PDT
AMC IMAX AMC at Metreon

12:00pm PDT

One SOC, The Whole SOC, and Nothing But The SOC, So Help Me
Saturday April 26, 2025 12:00pm - 12:30pm PDT
I’ve been working in security ops for 20 years. Most SOCs struggle because of one big mistake: don’t let this happen to you. I will step you through how to organize a SOC: what should go in it, what should probably stay out, and what your SOC will look like if you get it right.
Speakers
Saturday April 26, 2025 12:00pm - 12:30pm PDT
AMC Theatre 07 AMC at Metreon

12:00pm PDT

Resiliency in the uncharted AI landscape
Saturday April 26, 2025 12:00pm - 12:30pm PDT
So you've just battled a dragon: how quickly and effectively can you fight the next one?
We dive into Resiliency by Design for an AI search / chat product - based on considerations like uptime, disaster recovery, availability, fault testing etc, while meeting audit/compliance & privacy regulations.
Saturday April 26, 2025 12:00pm - 12:30pm PDT
AMC Theatre 11 AMC at Metreon

12:00pm PDT

The Art of Cybersecurity Mastery: From Entry-Level to Staff+
Saturday April 26, 2025 12:00pm - 12:30pm PDT
Are you aspiring to break into cybersecurity or looking to take your career to the next level but don’t have a mentor to guide you? This talk is for you. We'll dive into practical advice to guide your career journey, based on real-world questions asked by my mentees.
Speakers
Saturday April 26, 2025 12:00pm - 12:30pm PDT
AMC Theatre 09 AMC at Metreon

12:00pm PDT

Lunch
Saturday April 26, 2025 12:00pm - 1:30pm PDT
Lunch is served in the Embarcadero. Drip
coffee and water are available all day throughout the
Participant Hall.
Saturday April 26, 2025 12:00pm - 1:30pm PDT
Participation Hall City View at Metreon

12:30pm PDT

Sponsor Raffle
Saturday April 26, 2025 12:30pm - 1:00pm PDT
TBD
Visit the sponsor booths throughout the Participant Hall and learn more about the many of the companies that have made this year’s event possible. You’ll be introduced to new products, services, and even career opportunities. At
many booths you can also acquire one of the stamps needed to complete the Sponsor Passport, which can be found in the bag you received at registration. Drop your completed card into the Sponsor Passport raffle box located at the
BSidesSF booth to be entered into the raffle. Please note you must be present to win.
Saturday April 26, 2025 12:30pm - 1:00pm PDT
TBD City View at Metreon

12:30pm PDT

Capture the Flag 101
Saturday April 26, 2025 12:30pm - 2:30pm PDT
See registration to determine current session availability. Event filled in Sched to limit confusion.
YOU ARE REQUIRED TO REGISTER AT https://bsidessf.regfox.com/2025 TO ATTEND THIS WORKSHOP (i.e. this session cannot be reserved with Sched)
-----
Capture the Flag events are exciting and competitive. But, they can be scary to developers and security practitioners who have never participated in them.

In this session, I introduce CTFs, discuss their benefits to developers, and examine an easy and medium-difficulty CTF challenge in depth.
Speakers
Saturday April 26, 2025 12:30pm - 2:30pm PDT
AMC Theatre 02 AMC at Metreon

12:30pm PDT

Shifting Left - a hands on introductory guide to DevSecOps
Saturday April 26, 2025 12:30pm - 2:30pm PDT
See registration to determine current session availability. Event filled in Sched to limit confusion.
YOU ARE REQUIRED TO REGISTER AT https://bsidessf.regfox.com/2025 TO ATTEND THIS WORKSHOP (i.e. this session cannot be reserved with Sched)
-----
This two hour workshop on Shifting Left guides BSides SF participants through integrating security tooling into a GitHub Actions based DevSecOps CI/CD pipeline.

BSides SF attendees will learn about setting up basic CI/CD processes that incorporate security using both open source and commercial tool
Saturday April 26, 2025 12:30pm - 2:30pm PDT
AMC Theatre 01 AMC at Metreon

1:00pm PDT

TBD (Podcast)
Saturday April 26, 2025 1:00pm - 1:45pm PDT
TBD
Saturday April 26, 2025 1:00pm - 1:45pm PDT
AMC Theatre 13 AMC at Metreon

1:00pm PDT

Into The Dragon’s Den
Saturday April 26, 2025 1:00pm - 1:45pm PDT
In this talk, we will take you through our journey of bringing a high stakes SaaS product to the Chinese market while exploring the challenges we faced and sharing what we learned. We will offer insights and practical advice for navigating the unique threats of the Chinese market for global company.
Saturday April 26, 2025 1:00pm - 1:45pm PDT
AMC Theatre 06 AMC at Metreon

1:00pm PDT

Light in the Labyrinth: Attack Path Analysis for Anyone
Saturday April 26, 2025 1:00pm - 1:45pm PDT
Learn to build your own treasure map of how attackers might move laterally through your company’s assets. We’ll provide a conceptual engineering framework for attack path analysis, recommend no- or low-cost tools, share examples, and release an open-source attack graph ontology to learn from.
Speakers
Saturday April 26, 2025 1:00pm - 1:45pm PDT
AMC Theatre 15 AMC at Metreon

1:30pm PDT

Centralizing Egress Access Controls Across a Hybrid Environment at Block
Saturday April 26, 2025 1:30pm - 2:00pm PDT
Hybrid environments complicate network egress. Learn how Block centralized network egress policies and ensured consistent deployment of rules across diverse enforcement endpoints—regardless of type or location—enabling secure, scalable, and streamlined outbound traffic management.
Speakers
Saturday April 26, 2025 1:30pm - 2:00pm PDT
AMC Theatre 07 AMC at Metreon

1:30pm PDT

Threat Modeling Meets Model Training: Web App Security Skills for AI
Saturday April 26, 2025 1:30pm - 2:00pm PDT
New specializations have emerged in this AI-adoring age, but where does that leave security practitioners? Good news: if you know web application security, you can secure AI uses too. This talk examines normal web app security issues relevant to any LLM-based app—and the handful unique to AI.
Speakers
Saturday April 26, 2025 1:30pm - 2:00pm PDT
AMC Theatre 11 AMC at Metreon

1:30pm PDT

WHOIS Your Daddy: Tracking Iranian-backed cyber operations with Passive DNS
Saturday April 26, 2025 1:30pm - 2:00pm PDT
A unique name server linked to Iran-nexus cyber activity reveals a broader set of malicious name servers with potential nation-state tires. Learn how passive DNS data connects a single typosquatting domain to multiple name servers being used to for malware distribution.
Speakers
Saturday April 26, 2025 1:30pm - 2:00pm PDT
AMC Theatre 09 AMC at Metreon

2:00pm PDT

Future-Proof Your Career: Evolving in the Age of AI
Saturday April 26, 2025 2:00pm - 2:45pm PDT
Discover how AI is reshaping cybersecurity careers in this dynamic panel discussion. Join industry experts as they tackle pressing questions about AI-driven skills, job evolution, and adapting to an ever-changing landscape. Gain actionable insights to future-proof your career!
Saturday April 26, 2025 2:00pm - 2:45pm PDT
AMC Theatre 13 AMC at Metreon

2:00pm PDT

Hack, Patch, Repeat: Insider Tales from Android’s Bug Bounty
Saturday April 26, 2025 2:00pm - 2:45pm PDT
What does it take to secure 3 billion users on the world’s leading mobile platform? This session dives into Android security from a holistic perspective.
Saturday April 26, 2025 2:00pm - 2:45pm PDT
AMC Theatre 15 AMC at Metreon

2:15pm PDT

Adventures & Findings in ISP Hacking
Saturday April 26, 2025 2:15pm - 2:45pm PDT
Network security is important, but what about the networks that serve your network?

In this talk I go over my methodology and findings performing a security audit of some local ISPs. I’ll outline how simple vulnerabilities and configuration mistakes are still making it to these production networks,
Speakers
Saturday April 26, 2025 2:15pm - 2:45pm PDT
AMC Theatre 09 AMC at Metreon

2:15pm PDT

Log In Through the Front Door: Automating Defense Against Credential Leaks
Saturday April 26, 2025 2:15pm - 2:45pm PDT
Imagine a cybercriminal accessing your network with credentials bought on the dark web—they walk in unnoticed. Attackers aren't breaking in—they're logging in. With 80% of attacks involving stolen credentials, discover how Automated Credential Threat Monitoring (ACT) keeps you ahead of threats
Saturday April 26, 2025 2:15pm - 2:45pm PDT
AMC Theatre 07 AMC at Metreon

2:15pm PDT

One Search To Rule Them All: Threat Modelling AI Search
Saturday April 26, 2025 2:15pm - 2:45pm PDT
Enterprise AI search tools like Glean and Guru aggregate all your company’s data into a single, easy-to-navigate interface. Think of it as Google, but for juicy, sensitive corporate information. In this session, we’ll explore effective threat modeling and controls when deploying these tools.
Speakers
Saturday April 26, 2025 2:15pm - 2:45pm PDT
AMC Theatre 11 AMC at Metreon

2:15pm PDT

Versus Killnet
Saturday April 26, 2025 2:15pm - 2:45pm PDT
The Russian hacktivist group Killnet was a cyber army directed by a few to cause harm. With a checkered history and inconsistent behaviors, deciphering who is behind this group was challenging, but we’ll lift this veil and share a personal story of disrupting and unbalancing Killnet into chaos.
Speakers
Saturday April 26, 2025 2:15pm - 2:45pm PDT
AMC IMAX AMC at Metreon

2:45pm PDT

How to Build Security Products that People Actually Buy
Saturday April 26, 2025 2:45pm - 4:45pm PDT
See registration to determine current session availability. Event filled in Sched to limit confusion.
YOU ARE REQUIRED TO REGISTER AT https://bsidessf.regfox.com/2025 TO ATTEND THIS WORKSHOP (i.e. this session cannot be reserved with Sched)
-----
Frustrated with your current security toolset and ready to build a better solution? You can—but it's harder than it looks! Join us to learn how to scope and design cybersecurity MVPs that attract customers, solve security problems, and draw VC interest.
Speakers
Saturday April 26, 2025 2:45pm - 4:45pm PDT
AMC Theatre 01 AMC at Metreon

2:45pm PDT

Practical Threat Modeling
Saturday April 26, 2025 2:45pm - 4:45pm PDT
See registration to determine current session availability. Event filled in Sched to limit confusion.
YOU ARE REQUIRED TO REGISTER AT https://bsidessf.regfox.com/2025 TO ATTEND THIS WORKSHOP (i.e. this session cannot be reserved with Sched)
-----
Threat modeling is vital for secure systems but often seems daunting. In Practical Threat Modeling, you'll explore core concepts, frameworks, and tools, adopt an attacker's mindset, and tackle real-world scenarios. Learn to integrate threat modeling into Agile workflows and apply skills to enhance
Saturday April 26, 2025 2:45pm - 4:45pm PDT
AMC Theatre 02 AMC at Metreon

3:00pm PDT

Decoding GraphQL: How to Map Hidden Vulnerabilities
Saturday April 26, 2025 3:00pm - 3:30pm PDT
GraphQL APIs offer flexibility and efficiency but often introduce security risks that remain hidden in the shadows. In this session, we’ll share findings from scanning GraphQL APIs, revealing vulnerabilities like schema leaks, brute-force risks, and GraphQL-specific "bomb" attacks.
Saturday April 26, 2025 3:00pm - 3:30pm PDT
AMC Theatre 09 AMC at Metreon

3:00pm PDT

Everyday AI: Leveraging LLMs for simple, effective security automation
Saturday April 26, 2025 3:00pm - 3:30pm PDT
Anyone can build simple LLM–based tools that streamline security tasks. Join us to learn how, with short prompts and very little code, you can do more with less by automating IAM, threat detection, and vuln management workflows. Get tips and prebuilt used-in-prod examples to play with on your own.
Saturday April 26, 2025 3:00pm - 3:30pm PDT
AMC Theatre 11 AMC at Metreon

3:00pm PDT

From LOL to LOC: LOLBins are No Laughing Matter
Saturday April 26, 2025 3:00pm - 3:30pm PDT
LOL - a lot less funny than it sounds - (living off the land) attacks have been around for several years, now it is time for LOC (living off the cloud) attacks. With cloud services becoming a core part of engineering today, it is no wonder attackers see this as a high-value attack vector.
Speakers
Saturday April 26, 2025 3:00pm - 3:30pm PDT
AMC Theatre 07 AMC at Metreon

3:00pm PDT

Tracking the Worlds Dumbest Cyber-Mercenaries
Saturday April 26, 2025 3:00pm - 3:30pm PDT
For the last 6 years we have been tracking the activities of the cyber-mercenaries Dark Caracal. In this time we have observed them make a number of hilarious mistakes which have allowed us to gain insights into their activities and targets and see just how effective they actually are despite it all
Saturday April 26, 2025 3:00pm - 3:30pm PDT
AMC IMAX AMC at Metreon

3:00pm PDT

Uncharted Minds: Exploring Neuroscience, Burnout and Cognitive Strengths
Saturday April 26, 2025 3:00pm - 3:45pm PDT
The human mind is both a strength and a vulnerability in cybersecurity. This panel explores the neuroscientific roots of burnout and examines how cognitive load, stress and mental resilience impact cybersecurity professionals, offering fresh strategies to tackle the complexities of cyber threats
Saturday April 26, 2025 3:00pm - 3:45pm PDT
AMC Theatre 13 AMC at Metreon

3:00pm PDT

0.0.0.0 Day: Exploiting Localhost APIs From The Browser
Saturday April 26, 2025 3:00pm - 3:45pm PDT
While seemingly local, services running on localhost are accessible to the browser using a flaw we found, exposing the ports on the localhost network interface, and leaving the floodgates ajar to remote network attacks. This session will dive into the 0.0.0.0 exploit research conducted by the team.
Speakers
Saturday April 26, 2025 3:00pm - 3:45pm PDT
AMC Theatre 15 AMC at Metreon

3:00pm PDT

Data Splicing Attacks: Breaking Enterprise DLP from the Inside Out
Saturday April 26, 2025 3:00pm - 3:45pm PDT
We uncovered a data exfiltration technique, capable of bypassing all major DLP vendors listed by Gartner. We will dissect the architectural flaws in endpoint and proxy-based DLP, showcase live bypass demos, and launch Angry Magpie, an open-source toolkit for red teams to replicate these attacks.
Saturday April 26, 2025 3:00pm - 3:45pm PDT
AMC Theatre 06 AMC at Metreon

3:45pm PDT

Fake Hires, Real Threats: When Background Checks Aren’t Enough
Saturday April 26, 2025 3:45pm - 4:15pm PDT
When an outside threat becomes an insider threat, are your hiring practices prepared to catch it? In this session, you’ll learn how to examine the tactics of fraudulent job seekers and how to collaborate with talent teams to secure your hiring pipeline *and* protect your organization.
Speakers
Saturday April 26, 2025 3:45pm - 4:15pm PDT
AMC Theatre 09 AMC at Metreon

3:45pm PDT

Something’s Phishy: See the Hook Before the Bait
Saturday April 26, 2025 3:45pm - 4:15pm PDT
If you see a phishing email or domain that’s a public IoC, it’s already too late. Our research team’s approach to threat detection finds more DNS artifacts and adversary infrastructure as they are created and maps intent before it can be weaponized. This session will show how you can do the same.
Speakers
Saturday April 26, 2025 3:45pm - 4:15pm PDT
AMC Theatre 07 AMC at Metreon

3:45pm PDT

Trawling for IOCs: Catching C2 in a sea of data
Saturday April 26, 2025 3:45pm - 4:15pm PDT
In the vast sea of security data, how do we efficiently find malicious activity and turn it into actionable intelligence? This presentation introduces data-driven detection engineering, showcasing a data-first approach to building detection rules and threat feeds.
Speakers
Saturday April 26, 2025 3:45pm - 4:15pm PDT
AMC IMAX AMC at Metreon

3:45pm PDT

Using AI to discover silently patch vulnerabilities in open-source
Saturday April 26, 2025 3:45pm - 4:15pm PDT
We monitored public changelogs of popular open-source projects to detect unreported security fixes. We found 600+ vulnerabilities, 25% high or critical, with most never being reported. We achieved this by using dual LLM models to monitor change logs and verify the result with our security engineers.
Saturday April 26, 2025 3:45pm - 4:15pm PDT
AMC Theatre 11 AMC at Metreon

4:00pm PDT

TBD (Podcast)
Saturday April 26, 2025 4:00pm - 4:45pm PDT
TBD
Saturday April 26, 2025 4:00pm - 4:45pm PDT
AMC Theatre 13 AMC at Metreon

4:00pm PDT

Decentralized Communications: Deep-Dive into APRS and Meshtastic
Saturday April 26, 2025 4:00pm - 4:45pm PDT
This talk compares APRS and Meshtastic protocols for decentralized communications, examining their security models, vulnerabilities, and real-world applications. We will explore how these systems handle encryption, authentication and their attack surface with live demonstrations.
Saturday April 26, 2025 4:00pm - 4:45pm PDT
AMC Theatre 06 AMC at Metreon

4:00pm PDT

Service Mesh Security: Shifting Focus to the Application Layer
Saturday April 26, 2025 4:00pm - 4:45pm PDT
Discover how Yelp's Infrastructure Security team transformed past challenges and failures into success by shifting authentication and authorization from the infrastructure to the application layer. Learn how this pragmatic approach met all security requirements applicable to Yelp's threat model.
Speakers
Saturday April 26, 2025 4:00pm - 4:45pm PDT
AMC Theatre 15 AMC at Metreon

4:30pm PDT

Blank Space: Filling the Gaps in Atomic and Behavioral Cloud-Specific IoCs
Saturday April 26, 2025 4:30pm - 5:00pm PDT
As cloud adoption grows, attackers exploit its unique attack surface. This talk explores atomic IOCs (e.g., IAM metadata, container IDs) and behavioral IOCs (e.g., API activity), featuring real-world examples like threat actor "Bapak" and insights to enhance cloud detection, hunting, and response.
Saturday April 26, 2025 4:30pm - 5:00pm PDT
AMC Theatre 07 AMC at Metreon

4:30pm PDT

BSidesSF plays incident response
Saturday April 26, 2025 4:30pm - 5:00pm PDT
INCIDENT DECLARED! As Incident Commander, team up with your product and privacy leads to navigate the response. Will you launch a forensics investigation? Draft a customer notice? You decide in this choose-your-adventure talk.
Saturday April 26, 2025 4:30pm - 5:00pm PDT
AMC IMAX AMC at Metreon

4:30pm PDT

Dragging out Dragons: Slaying Hidden Threats in Residential Proxies
Saturday April 26, 2025 4:30pm - 5:00pm PDT
Residential proxies are the weapon of choice for bots bypassing defenses by mimicking legit traffic. This talk unpacks how machine learning can expose and mitigate these threats at scale. Expect actionable insights for improving detections while minimizing false positives.
Speakers
Saturday April 26, 2025 4:30pm - 5:00pm PDT
AMC Theatre 09 AMC at Metreon

4:30pm PDT

Enhancing Secret Detection in Cybersecurity with Lean LLMs
Saturday April 26, 2025 4:30pm - 5:00pm PDT
Dive into the challenges of LLMs in cybersecurity as we explore the process of fine tuning an LLM to handle the task of secret detection in code and be efficient enough to run on any laptop.
Can LLMs with low inference times pave the way for new detection methods that were previously overlooked?
Saturday April 26, 2025 4:30pm - 5:00pm PDT
AMC Theatre 11 AMC at Metreon

5:00pm PDT

Can Cyber Mercenaries and Human Rights Coexist?
Saturday April 26, 2025 5:00pm - 5:45pm PDT
Cyber Mercenaries have become a favorite tactic of nation states around the world in the past decade. They spy on activists, civil society, and journalists. They work with countries that have no regard for human rights. This panel of infosec leaders will discuss the problem and potential solutions.
Saturday April 26, 2025 5:00pm - 5:45pm PDT
AMC Theatre 13 AMC at Metreon

5:00pm PDT

Netsec is dead(?): Modern Network Fingerprinting for Real-World Defense
Saturday April 26, 2025 5:00pm - 5:45pm PDT
From p0f to MuonFP and JA4+, learn how network fingerprinting evolved. See how each step helps security teams spot malicious traffic, detect scanners, and more. Attendees gain real-world use cases and practical tips to deploy fingerprinting for monitoring and threat hunting.
Speakers
Saturday April 26, 2025 5:00pm - 5:45pm PDT
AMC Theatre 15 AMC at Metreon

5:15pm PDT

Mind vs Machine: Role of Human Psychology and AI in Security Culture
Saturday April 26, 2025 5:15pm - 5:45pm PDT
Security policies must consider human psychological traits for effectiveness. We'll contrast this with security needs for Non-Human Identities and argue that AI has its own "psychological traits" requiring tailored approaches to secure systems against AI-specific threats.
Saturday April 26, 2025 5:15pm - 5:45pm PDT
AMC Theatre 11 AMC at Metreon

5:30pm PDT

Happy Hour
Saturday April 26, 2025 5:30pm - 6:30pm PDT
Once the last of the Saturday talks are done, join us in the Bar and Chill Out Space to celebrate a successful day one of the event!
Sponsors
avatar for Wiz

Wiz

Gold, Saturday Evening Social
Saturday April 26, 2025 5:30pm - 6:30pm PDT
Participation Hall City View at Metreon

6:30pm PDT

Party
Saturday April 26, 2025 6:30pm - 9:30pm PDT
Welcome to the neon-lit abyss of BSidesSF's dystopian bash, where the boundary between man and machine blurs. Amidst the techno-frenzy, Balinese dancers weave an interpretive tale of technology's ethical struggles. Each movement is a haunting reminder of the delicate balance between promise and peril in our digital age. Welcome to a party where the future is both thrilling and terrifying, welcome to AI.
Sponsors
avatar for Wiz

Wiz

Gold, Saturday Evening Social
Saturday April 26, 2025 6:30pm - 9:30pm PDT
Participation Hall City View at Metreon
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -