Program Agenda

Agenda is subject to change. Times are reflected in UTC +1 (CET). Workshop sessions have limited seating and based on the registration admission purchased. Plenary sessions are open to all registered delegates.

Virtual Attendance: All TLP:CLEAR plenary presentations will be streamed live. Workshops will not be streamed. Virtual registration is available within the registration form. Streaming will be delivered over Zoom.

Registration Hours

Monday, November 6 - Registration Located on Level 2, Atrium
07:00-10:00 | Registration for Workshop Participants ONLY
11:00-18:00 | Registration for Plenary Participants

Tuesday, November 7 - Registration Located on Level 1, Near Stairway from 2 and Mall Entrance
08:00-16:00 | Registration

Wednesday, November 8 - Registration Located on Level 1, Near Stairway from 2 and Mall Entrance
08:00-15:00 | Registration

Monday, November 6th

Training: Track 1
Level 2 - MOA 16
Training: Track 2
Level 2 - MOA 14
Training: Track 3
Level 2 - MOA 15
08:30 – 09:00
 US

Threat Quantification & Prioritization 101: A Practical Guide to Building (& Maintaining) Your Cyber Threat Profile (08:30-11:00)

Scott Small (Tidal Cyber, US); Simone Kraus

TLP:CLEAR
09:00 – 10:00
 US NO

Intelligence Planning Workshop - How to Create and Employ an Intelligence Plan that Synchronizes with your Stakeholders Needs (09:00-13:00)

Michael DeBolt (Intel 471, US); Freddy Murstad (Nordic Financial CERT, NO)

TLP:CLEAR
 US

Threat Quantification & Prioritization 101: A Practical Guide to Building (& Maintaining) Your Cyber Threat Profile (08:30-11:00)

Scott Small (Tidal Cyber, US); Simone Kraus

TLP:CLEAR
 PL

Hunting and Tracking Adversaries (09:00-13:00)

Bartek Jerzman (Standard Chartered, PL)

TLP:AMBER
10:00 – 10:15

Coffee Break | Level 2 Atrium

10:15 – 11:00
 US NO

Intelligence Planning Workshop - How to Create and Employ an Intelligence Plan that Synchronizes with your Stakeholders Needs (09:00-13:00)

Michael DeBolt (Intel 471, US); Freddy Murstad (Nordic Financial CERT, NO)

TLP:CLEAR

10:15 – 13:00

 US

Threat Quantification & Prioritization 101: A Practical Guide to Building (& Maintaining) Your Cyber Threat Profile (08:30-11:00)

Scott Small (Tidal Cyber, US); Simone Kraus

TLP:CLEAR
 PL

Hunting and Tracking Adversaries (09:00-13:00)

Bartek Jerzman (Standard Chartered, PL)

TLP:AMBER

10:15 – 13:00

11:00 – 13:00
 US

How to Align CTI and Risk Management: Successfully Connecting Two Related Practices (11:00-15:45)

Grace Chi (Pulsedive, US); Jamie Collier, John Doyle (US)

TLP:CLEAR
13:00 – 14:00

Lunch Break | Level 2 Atrium

14:00 – 15:45
 LU

MISP CTI Analyst Threat Information Creator Workshop (14:00-18:00)

Alexandre Dulaunoy, Andras Iklody (CIRCL, LU)

TLP:CLEAR
 US

How to Align CTI and Risk Management: Successfully Connecting Two Related Practices (11:00-15:45)

Grace Chi (Pulsedive, US); Jamie Collier, John Doyle (US)

TLP:CLEAR
 US

‘Build Your Own Threat Landscape’ Workshop (14:00-18:00)

Brian Mohr (Reqfast, US); Roman Sannikov (Constellation Cyber LLC, US)

TLP:GREEN
15:45 – 16:00

Coffee Break | Level 2 Atrium

16:00 – 18:00
 LU

MISP CTI Analyst Threat Information Creator Workshop (14:00-18:00)

Alexandre Dulaunoy, Andras Iklody (CIRCL, LU)

TLP:CLEAR
 CZ

Priority Intelligence Requirements Workshop - How to Set the Directions of Your CTI Program

Ondra Rojcik, Vladimir Janout (Red Hat, CZ)

TLP:CLEAR
 US

‘Build Your Own Threat Landscape’ Workshop (14:00-18:00)

Brian Mohr (Reqfast, US); Roman Sannikov (Constellation Cyber LLC, US)

TLP:GREEN

Tuesday, November 7th

Plenary Sessions Day 1
Level 1, Rm MOA 6-9
09:00 – 09:15

Welcome Remarks

09:15 – 09:45

Helping Organizations Anticipate and Approach Emerging Technology Threats

Natalie Kilber (Harman International)

TLP:CLEAR
09:45 – 10:15
 US

Solving CISO Headaches: How to Align CTI and Risk Management

Jamie Collier (US); John Doyle (Mandiant, US)

TLP:CLEAR
10:15 – 10:45

Networking Break with Exhibits | MOA 3-5

10:45 – 11:15
 US

Will the Real Attribution Please Stand Up?

Alexis Dorais-Joncas; Joshua Miller (US)

TLP:AMBER
11:15 – 11:45
 CH

What is a Threat Actor? Tracking Sandworm's Transformation

Lennart Maschmeyer (ETH Zürich, CH)

TLP:CLEAR
11:45 – 12:15
 US

If You Want to Build Good Intelligence Requirements, You Do Not Start with Intelligence Requirements.

Brian Mohr (Reqfast, US)

TLP:CLEAR
12:15 – 13:30

Lunch Break with Exhibits | MOA 3-5

13:30 – 14:00
 DE

PXF-X - A Modular Python Framework to Hunt, Extract and Enrich Post-Exploitation Framework Artifacts

Joel Doenne (ATRUVIA AG, DE)

TLP:AMBER
14:00 – 14:30
 LU

MISP 3 - Teaching an Old Dog New Tricks

Andras Iklody, Sami Mokaddem (CIRCL, LU)

TLP:CLEAR
14:30 – 15:00
 NO

How to Tango with MISP

Ingrid Grimstad (NO)

TLP:GREEN
15:00 – 15:30

Networking Break with Exhibits | MOA 3-5

15:30 – 16:00
 GB

ThreatIntelGPT: STIX from Chaos

David Greenwood (EclecticIQ & Signals Corp, GB)

TLP:CLEAR
16:00 – 16:30
 NL

Automating the Junior Analyst: Cyber Security Report Generation with Classic AI

Sergey Polzunov (BlackStork.io, NL)

TLP:CLEAR
16:30 – 17:00
 GB

Why AI Will Not Take Our CTI Analyst Jobs (But We Should Befriend the Machines, Anyway)

Stewart Bertram (Elemendar, GB)

TLP:CLEAR
17:00 – 17:10

Closing Remarks

17:30 – 18:30

Networking Reception with Exhibits - Sponsored by Silent Push | Level 1, Rm MOA 3-5

Wednesday, November 8th

Plenary Sessions Day 2
Level 1, Rm MOA 6-9
08:50 – 09:00

Opening Remarks

09:00 – 09:30
 DE

How Much Alert Fatigue Actually is Threat Intel Fatigue?

Markus Ludwig (ticura, DE)

TLP:CLEAR
09:30 – 10:00
 AT DE

Insights on the Spread and Use of Threat Intelligence Sharing Platforms

Clemens Sauerwein ( University of Innsbruck, Department of Computer Science, AT); Daniel Fischer (Technische Universität Ilmenau, DE)

TLP:GREEN
10:00 – 10:30
 US

The Blueprint for Enduring Actionable CTI

Ross Rustici (US)

TLP:CLEAR
10:30 – 11:00

Networking Break with Exhibits | MOA 3-5

11:00 – 11:30
 PL

OSINT The Hard Way: Navigating Hard Targets In Open-Source Intelligence

Kamil Bojarski (Standard Chartered Bank, PL)

TLP:GREEN
11:30 – 12:00
 US

VERIS Mappings to ATT&CK - Bridging Risk-based and Ops-focused Incident Classification (Virtual)

David Hylender, Philippe Langlois (US)

TLP:CLEAR
12:00 – 13:15

Lunch Break with Exhibits | MOA 3-5

13:15 – 13:45
 LU

How to Improve Your Threat Intelligence Process with AIL Project

Alexandre Dulaunoy (CIRCL, LU)

TLP:CLEAR
13:45 – 14:15
 NO

Foresight Analysis: The Magic Eight Ball of Intelligence Analysis

Freddy Murstad (Nordic Financial CERT, NO)

TLP:CLEAR
14:15 – 14:45

Networking Break with Exhibits | MOA 3-5

14:45 – 15:15

CTI, a Key Component into the M&A Process

Catalin Curelaru, Espen Johansen

TLP:GREEN
15:15 – 15:45
 GR

Spin Your CTI Process Round

Andreas Sfakianakis (SAP, GR)

TLP:CLEAR
15:45 – 16:15
 FR

A Collective CTI Doctrine

David Bizeul, Fabien Gainier (FR)

TLP:CLEAR
16:15 – 16:30

Closing Remarks