Program Overview

All times are listed in Central Standard Time – San Mexico City, CDMX, Mexico (GMT-6)

Monday, October 27th

October 27 - Plenary Sessions
09:00 – 09:30

Registration and Welcome Coffee

TLP:CLEAR
09:30 – 10:00
 MX

Opening FIRSTMX25 and Remarks

Autoridades Universidad IBERO y Comitre FIRST (MX)

TLP:CLEAR
10:00 – 11:00
 MX

Incident Response: Making It Everyone’s Business

Juan Pablo Castro (Trend Micro, MX)

TLP:CLEAR
11:00 – 11:50

Advanced Signals: NextGen Threat Hunting using Active and Passive DNS and Internet NetFlow Telemetry

Ed Gibbs (WHOIS); Ernesto Guzmán (Digital Forensics Incident Response and ES Consulting)

TLP:GREEN
12:00 – 12:15

Coffee Break

12:15 – 13:00
 RU

Privacy Digital Identity by Criminal Eyes: Insights From Russian-Speaking Underground

Vladimir Kropotov (Trend Micro, RU)

TLP:GREEN
13:00 – 13:50

How to Cook Hora-bot... The Long and Slow Way.

David Martin (CERT Arteria)

TLP:GREEN
14:00 – 15:00

Lunch

15:00 – 15:50
 MX

Beyond Incident Reponse: Mastering the Art of Cyber Crisis Forecasting

Maricarmen García de Ureña (Secure Information Technologies, MX)

TLP:CLEAR
16:00 – 16:30

Networking Coffee

Tuesday, October 28th

October 28 - Plenary Sessions
09:00 – 10:50
 US

Agentic CTI: Automating Threat Intelligence with MCP-Powered AI Agents

Ensar Şeker (SOCRadar, US)

TLP:GREEN
11:00 – 11:50

How to Become One of Them

Sean Jones (Groupsense, cognyte)

TLP:GREEN
12:00 – 12:15

Coffee Break

12:15 – 13:00
 MX

Are You Talking to Me? Tailoring CTI Communication for Maximum Impact

Demian García (CTI Analyst Sr, MX)

TLP:CLEAR
13:00 – 13:50
 MX

Building a Threat Landscape: The Foundation of an Effective Cybersecurity Strategy

Juan Alberto Muñoz (Infomatec, MX)

TLP:CLEAR
14:00 – 14:45

Lunch

14:45 – 15:35
 MX

Know Your Enemy: Unveiling the Most Prevalent TTPs in Latin America 2025

Arturo Torres (FortiGuard Labs , MX)

TLP:GREEN
15:35 – 16:30
 MX

From Breadcrumbs to Breaches: OSINT in the Heat of Incident Response

Evelyn Hernández (Sr. Cyber Threat Intelligence Analyst, MX)

TLP:GREEN

Wednesday, October 29th

October 29 - Training Day: XDR-Driven Response: Strategies for Modern Threat Environments
09:00 – 11:15

Session: Introduction and Recent Case Example

Marc Lanzerdorfen (Trend Micro)

TLP:GREEN
11:15 – 11:30

Coffee Break

11:30 – 13:00

XDR-Driven Incident Response

Marc Lanzerdorfen (Trend Micro)

TLP:GREEN
13:00 – 13:45

Lunch

13:45 – 15:45

XDR-Driven Incident Response

Marc Lanzerdorfen (Trend Micro)

TLP:GREEN
15:45 – 16:00

Coffee Break

16:00 – 16:45

Communicating and Reporting

Marc Lanzerdorfen (Trend Micro)

TLP:GREEN