Program Overview

Agenda is subject to change.

Meeting Venue - Training Sessions on December 2 & 3

All TRAINING sessions (December 2 & 3) will be taking place at the Polytechnics Mauritius unless otherwise noted.

Polytechnics Mauritius - Reduit Campus
Reduit Triangle, Moka
80835 Reduit
Mauritius
https://maps.app.goo.gl/gSUQesKbB3mdJXDv7

Meeting Venue - Plenary Sessions on December 4 & 5

All PLENARY sessions (December 4 & 5) will be taking place at the Hennessy Park Hotel unless otherwise noted.

Hennessy Park Hotel
QF4Q+WVH, 65 Cybercity
Ebene, Quatre Bornes
Mauritius
https://maps.app.goo.gl/grqBCC471jsbGGhc7

Tuesday, December 2nd

Training Day 1: Track 1Training Day 1: Track 2Training Day 1: Track 3
09:00 – 10:45
 DJ

Investigating Ransomware Through Windows Artifacts and Event Log Correlation

Chireh Mohamed Abdi, Yacin Djibril Waberi (DJ-CERT, DJ)

TLP:CLEAR
 MU

Setting Up of the National Honeypot

Dr. Kaleem Ahmed Usmani (CERT-MU, MU); Sachindra Reechaye (National CERT of Mauritius, MU)

TLP:CLEAR
 FR US BJ

Hands-On Network Threat Detection Training for Critical Infrastructure using Security Onion

Ezeckiel Dadjo (Iservices CSIRT, FR); Howard Mukanda (Senior Red Team Engineer and AfricaCERT Volunteer, US); Luc Semassa (Iservices CSIRT , BJ)

TLP:CLEAR
10:45 – 11:00

Coffee Break

11:00 – 13:00
 DJ

Investigating Ransomware Through Windows Artifacts and Event Log Correlation

Chireh Mohamed Abdi, Yacin Djibril Waberi (DJ-CERT, DJ)

TLP:CLEAR
 MU

Setting Up of the National Honeypot

Dr. Kaleem Ahmed Usmani (CERT-MU, MU); Sachindra Reechaye (National CERT of Mauritius, MU)

TLP:CLEAR
 FR US BJ

Hands-On Network Threat Detection Training for Critical Infrastructure using Security Onion

Ezeckiel Dadjo (Iservices CSIRT, FR); Howard Mukanda (Senior Red Team Engineer and AfricaCERT Volunteer, US); Luc Semassa (Iservices CSIRT , BJ)

TLP:CLEAR
13:00 – 14:00

Lunch Break

14:00 – 16:00
 PL

Interpreting and Visualizing Shadowserver Threat Data Using IntelMQ + ELK Dashboard

Piotr Kijewski (Shadowserver, PL)

TLP:CLEAR
 FR

Enhancing CSIRT Capability through the SIM3 Maturity Model

Olivier Caleff (FR)

TLP:CLEAR
 FR US BJ

Hands-On Network Threat Detection Training for Critical Infrastructure using Security Onion

Ezeckiel Dadjo (Iservices CSIRT, FR); Howard Mukanda (Senior Red Team Engineer and AfricaCERT Volunteer, US); Luc Semassa (Iservices CSIRT , BJ)

TLP:CLEAR
16:00 – 16:15

Coffee Break

16:15 – 18:00
 PL

Interpreting and Visualizing Shadowserver Threat Data Using IntelMQ + ELK Dashboard

Piotr Kijewski (Shadowserver, PL)

TLP:CLEAR
 FR US BJ

Hands-On Network Threat Detection Training for Critical Infrastructure using Security Onion

Ezeckiel Dadjo (Iservices CSIRT, FR); Howard Mukanda (Senior Red Team Engineer and AfricaCERT Volunteer, US); Luc Semassa (Iservices CSIRT , BJ)

TLP:CLEAR

Wednesday, December 3rd

Training Day 2: Track 1Training Day 2: Track 2Training Day 2: Track 3
09:00 – 10:45
 KE LS

Automating CSIRT Workflows with RTIR, MISP, and Taranis-NG

Amos Mibey (Kifarunix, KE); Luka Mafereka (Lesotho Communications Authority, LS)

TLP:GREEN
 MA

Detecting & Investigating Advanced Adversaries Across the Kill Chain

Jamaleddine Hadini (MA)

TLP:CLEAR
 FR US BJ

Hands-On Network Threat Detection Training for Critical Infrastructure using Security Onion

Ezeckiel Dadjo (Iservices CSIRT, FR); Howard Mukanda (Senior Red Team Engineer and AfricaCERT Volunteer, US); Luc Semassa (Iservices CSIRT , BJ)

TLP:CLEAR
10:45 – 11:00

Coffee Break

11:00 – 13:00
 KE LS

Automating CSIRT Workflows with RTIR, MISP, and Taranis-NG

Amos Mibey (Kifarunix, KE); Luka Mafereka (Lesotho Communications Authority, LS)

TLP:GREEN
 MA

Detecting & Investigating Advanced Adversaries Across the Kill Chain

Jamaleddine Hadini (MA)

TLP:CLEAR
 FR US BJ

Hands-On Network Threat Detection Training for Critical Infrastructure using Security Onion

Ezeckiel Dadjo (Iservices CSIRT, FR); Howard Mukanda (Senior Red Team Engineer and AfricaCERT Volunteer, US); Luc Semassa (Iservices CSIRT , BJ)

TLP:CLEAR
13:00 – 14:00

Lunch Break

14:00 – 16:00
 GH

Practical Digital Forensics in the African Context. Tools, Workflows, and Infrastructure Gaps

Dunstan Guba (Wisconsin International University College, GH); Maxwell Selorm Amuzu (Wisconsin International University College, Ghana (WIUC–Ghana) Digital Forensics & Cybersecurity Lab, GH)

TLP:CLEAR
 MA

Making CTI Useful: Growing an Intelligence-Led SOC Without a Big Budget

Imane Bachane (BLUESEC, MA)

TLP:CLEAR
 FR US BJ

Hands-On Network Threat Detection Training for Critical Infrastructure using Security Onion

Ezeckiel Dadjo (Iservices CSIRT, FR); Howard Mukanda (Senior Red Team Engineer and AfricaCERT Volunteer, US); Luc Semassa (Iservices CSIRT , BJ)

TLP:CLEAR
16:00 – 16:15

Coffee Break

16:15 – 18:00
 GH

Practical Digital Forensics in the African Context. Tools, Workflows, and Infrastructure Gaps

Dunstan Guba (Wisconsin International University College, GH); Maxwell Selorm Amuzu (Wisconsin International University College, Ghana (WIUC–Ghana) Digital Forensics & Cybersecurity Lab, GH)

TLP:CLEAR
 MA

Making CTI Useful: Growing an Intelligence-Led SOC Without a Big Budget

Imane Bachane (BLUESEC, MA)

TLP:CLEAR
 FR US BJ

Hands-On Network Threat Detection Training for Critical Infrastructure using Security Onion

Ezeckiel Dadjo (Iservices CSIRT, FR); Howard Mukanda (Senior Red Team Engineer and AfricaCERT Volunteer, US); Luc Semassa (Iservices CSIRT , BJ)

TLP:CLEAR
19:00 – 22:00

Thursday, December 4th

FIRST Plenary Sessions: Room 1FIRST Plenary Sessions: Room 2
08:00 – 09:00

Registration

09:00 – 10:00

Opening Ceremonies

10:00 – 11:15

Group Photo & Coffee Break Networking

11:15 – 11:45
 NG

Sovereign by Design: Advancing Africa's Data Security Governance and Cyber Resilience

Abdul-Hakeem Ajijola (Individual Contributor, NG)

TLP:CLEAR
11:45 – 12:15
 NG MU

Norms, CBMs and Role of Incident Responders

Abdul-Hakeem Bolade Dirisu Ajijola (African Union Cyber Security Expert Group (AU-CSEG), NG); Dr. Kaleem Ahmed Usmani (CERT-MU, MU)

TLP:CLEAR
 MU

WHOIS for Incident Response Teams (IRTs)

Madhvi Gokool (AFRINIC, MU)

TLP:CLEAR
12:15 – 12:45
 RE

Starting the Local CSIRT on the Island of Réunion

Charli Hoarau (Réunion THD, RE)

TLP:CLEAR
 ZA

Strategic Playbook for Safeguarding the National Critical Infrastructure

Sithembile Songo (Individual Contributor, ZA)

TLP:AMBER
12:45 – 13:45

Lunch

13:45 – 14:15
 TN

From Local Awareness to Global Cooperation: Tunisia's Path toward Cybersecurity Excellence

Hasna Tlili (National Agency for Cybersecurity, TN)

TLP:CLEAR
 ZA

OT Cyber Risks Reduction: What Leaders Need to Know

Michelle Govender (Octarity, ZA)

13:45 – 15:30

14:15 – 14:45
 AL

AI Powered Threat Detection: Opportunities and Risks for National CSIRTS

Olgerta Prendi (National Cyber Security Authority of Albania, AL)

TLP:CLEAR
14:45 – 15:15
 GH

Mastering Incident Handling Metrics: The Goal, Question, Metric (GQM) Framework

Stephen Cudjoe-Seshie (Cyber Security Authority, GH)

15:15 – 15:45

Coffee Break

15:45 – 16:15
 MU

Threat Actor Engagement

Neil Hare-Brown (STORM Guidance, MU)

TLP:GREEN
 NA

Supply Chain Cyber Resilience, Threat Intelligence Sharing Platforms and Tools & Team Updates

Cornelia Shipindo (NAM-CSIRT , NA)

TLP:CLEAR
16:15 – 16:45
 US

The Future of Security Begins with Identity

Kuleni Tamerat (US)

TLP:CLEAR
 JP

Sharing our CVD Journey: Insights and Lessons

Koichiro Komiyama (JPCERT/CC, JP)

TLP:GREEN
16:45 – 17:15
 US

Identity and Sustainable Development: Building Secure National Identity and Access Management Program

Konneh Mamady (Individual Contributor, US)

17:15 – 17:45
 DZ

Conformity Assessment Meets Cybersecurity: Building a Common Language Between Auditors and Analysts

Taher Amine Elhouari (OWASP Algiers / CSA Algeria / CAS Algeria / EKSec Group / AfricaCERT, DZ)

TLP:CLEAR
 US

Let's Speak CVE

Jean-Robert Hountomey (AfricaCERT, US)

TLP:CLEAR
17:45 – 18:15

Closing Remarks

Friday, December 5th

AfricaCERT Closed Meeting
09:00 – 09:30

Welcome Remarks

09:30 – 10:00
 SG

From Response to Leadership: Leveraging INTERPOL and International Conventions for CERT’s Pursuit of Cyber Justice

Dong Uk Kim (INTERPOL, SG)

TLP:GREEN
10:00 – 10:30

Coffee Break

10:30 – 12:15
 US

Ransomware in Progress: What to Do Right Now: Ransomware Active Attack Course of Action

Brian Scriber (M3AAWG, US)

TLP:AMBER
12:15 – 13:15

Lunch

13:15 – 14:45

AfricaCERT Closed Meeting

14:45 – 15:15

Coffee Break

15:15 – 16:45

AfricaCERT Closed Meeting

16:45 – 17:15

Closing Remarks