Program Agenda

Agenda is subject to change. Times are reflected in UTC +2 (CEST). Workshops have limited seating and based on the registration admission purchased. Plenary sessions are open to all registered delegates.

Tuesday, April 21st

Workshops
Forum 4
Workshops
Forum 5
Workshops
Forum 6
Workshops
Forum 7
08:30 – 10:00
 NL

Workshop Cyber Scenario Planning for Cybersecurity Decision-Making

Gert-Jan Bruggink (Venation, NL)

TLP:CLEAR
 CH

Cloud Forensics with Open Source: Building Your Own OSDFIR Lab on GCP

Alexander Jäger (Google, CH); Janosch Köpper

TLP:GREEN
 NO US GB

Intelligence Collection Planning Workshop: Maturing your Threat Intelligence Program through Targeted Stakeholder Engagement and Advanced Analytic Techniques

Freddy Murstad (Nordic Financial CERT, NO); Garrett Carstens (Intel471, US); Kevin Williams (Intel471, GB)

TLP:GREEN
 DE

Detection Engineering with Sigma

Thomas Patzke (Evonik Industries AG, DE)

TLP:CLEAR
10:00 – 10:15

Networking Break

10:15 – 12:30
 NL

Workshop Cyber Scenario Planning for Cybersecurity Decision-Making

Gert-Jan Bruggink (Venation, NL)

TLP:CLEAR
 CH

Cloud Forensics with Open Source: Building Your Own OSDFIR Lab on GCP

Alexander Jäger (Google, CH); Janosch Köpper

TLP:GREEN
 NO US GB

Intelligence Collection Planning Workshop: Maturing your Threat Intelligence Program through Targeted Stakeholder Engagement and Advanced Analytic Techniques

Freddy Murstad (Nordic Financial CERT, NO); Garrett Carstens (Intel471, US); Kevin Williams (Intel471, GB)

TLP:GREEN
 DE

Detection Engineering with Sigma

Thomas Patzke (Evonik Industries AG, DE)

TLP:CLEAR
12:30 – 13:30

Lunch

14:00 – 16:00

Structured Analytic Techniques for Cyber Threat Intelligence

Scott Roberts

TLP:CLEAR
 LU

Drone Threat Intelligence Workshop

He/Him Paul Jung (CERT-XLM (Thales/Excellium Services), LU); Sami Mokaddem (CIRCL, LU)

TLP:CLEAR
 NO US GB

Intelligence Collection Planning Workshop: Maturing your Threat Intelligence Program through Targeted Stakeholder Engagement and Advanced Analytic Techniques

Freddy Murstad (Nordic Financial CERT, NO); Garrett Carstens (Intel471, US); Kevin Williams (Intel471, GB)

TLP:GREEN

Collaborative Detection Engineering with Rulezet

Théo Geffe

TLP:CLEAR
16:00 – 16:15

Networking Break

16:15 – 18:00

Structured Analytic Techniques for Cyber Threat Intelligence

Scott Roberts

TLP:CLEAR
 LU

Drone Threat Intelligence Workshop

He/Him Paul Jung (CERT-XLM (Thales/Excellium Services), LU); Sami Mokaddem (CIRCL, LU)

TLP:CLEAR
 NO US GB

Intelligence Collection Planning Workshop: Maturing your Threat Intelligence Program through Targeted Stakeholder Engagement and Advanced Analytic Techniques

Freddy Murstad (Nordic Financial CERT, NO); Garrett Carstens (Intel471, US); Kevin Williams (Intel471, GB)

TLP:GREEN

Wednesday, April 22nd

Plenary Sessions Day 1
09:00 – 09:15
 DE

Welcome Remarks

Prof. Dr. Thomas Schreck (Munich University of Applied Sciences, DE)

09:15 – 09:45
 US

Evaluating Threat Intelligence Through Velocity

Joe Slowik (Paralus, US)

TLP:CLEAR
09:45 – 10:15
 NL

Dealing With Uncertainty: Scenario Planning for Cybersecurity Decision-Making

Gert-Jan Bruggink (Venation, NL)

TLP:CLEAR
10:15 – 10:45

Networking Break

10:45 – 11:15
 AU

Structured CTI - How Hard Could It Be?

Chris Horsley (Cosive, AU)

TLP:CLEAR
11:15 – 11:45

Billions of Indicators, Zero Action: How We Fixed That

Daniel Lima, Gabriel Testoni

TLP:CLEAR
11:45 – 12:15

Filtering the Noise: Crafting an Actionable Threat Feed from Community-Shared Standards

JJ Josing

TLP:CLEAR
12:15 – 13:30

Lunch

12:35 – 13:15

CTI SIG Meeting (12:35-13:15) - Room Forum 8

13:30 – 14:00

Keep Calm and ETL On: CTI 101

Jamila Boutemeur

TLP:AMBER
14:00 – 14:30
 LU

Building Intelligence with What You Have: Lessons from the Field

Jean-Louis Huynen (CIRCL, LU)

TLP:AMBER
14:30 – 15:00

From Grassroots to Governance: A Case Study on Formalizing a CTI Function Against All Odds

Yu Hirata

TLP:GREEN
15:00 – 15:30

Networking Break

15:30 – 16:00

Big Game Hunting: Tracking APT's Within Covert Networks

Jonathan Andersen

TLP:RED
16:00 – 16:30

Hunting Cyber Threat Intelligence on Telegram

Emmanuele Zambon, Luca Allodi, Roy Ricaldi, Victor Asanache

TLP:CLEAR
16:30 – 17:00

Lightning Talks

17:00 – 17:10

Day 1 Wrap Up

17:30 – 19:30

Thursday, April 23rd

Plenary Sessions Day 2
08:50 – 09:00

Opening Remarks: Day 2

09:00 – 09:30
 TW

One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?

Cheng-Lin Yang (CyCraft Technology, TW); Sian-Yao Huang, Yen-Shan Chen

TLP:CLEAR
09:30 – 10:00

Operational Efficiency in CTI: A Blueprint for SME's Using Open-Source AI and Cognitive Automation

Omar Saenz, Raquel Guzman

TLP:CLEAR
10:00 – 10:30

Beyond Human Scale: AI and Automation as Force Multipliers in Cyber Threat Intelligence

Cydney Stude, Steve de Vera

TLP:CLEAR
10:30 – 11:00

Networking Break

11:00 – 11:30

Forecasting to stay clear of Blizzards, Typhoons, Sandstorms, Tempests and more.

Clara Bayón González, Elena Casado González

TLP:GREEN
11:30 – 12:00
 LU FR

Forecasting Vulnerability Sightings Under Data Scarcity: Modeling Sparse and Bursty Cyber Threat Signals

Alexandre Dulaunoy (CIRCL, LU); Cédric Bonhomme (CIRCL, FR)

TLP:CLEAR
12:00 – 13:15

Lunch

13:15 – 13:45
 CA US

How NOT to be Your Adversary's Best Friend - Doing What Matters...

Brian Hein (Silobreaker, CA); James Shank (SpyCloud, US)

TLP:CLEAR
13:45 – 14:15

The Integrated CERT Communication Framework (ICCF): A Behavioral Model for Effective CERT Communication, CTI Sharing, and Advisory Dissemination

Rakesh Kumar Singh, Sanjeev Kumar, Yudhishthira Sapru

TLP:CLEAR
14:15 – 14:45

Networking Break

14:45 – 15:15
 NL LU

OpenTide: From Raw Intelligence to Structured Threat-Informed Detections

Amine Besson (Behemoth Cyberdefence, NL); Remi Seguy (European Commission, LU)

TLP:CLEAR
15:15 – 15:45

Who Did It? Getting Started with Threat Actor Profiling

Marthe Raaheim Rogndokken

TLP:CLEAR
15:45 – 16:15
 CZ

Signals in the Noise: Real-world Fingerprinting Stories

Vlad Iliushin (ELLIO / AMTSO , CZ)

TLP:CLEAR
16:15 – 16:30

Closing Remarks