
Program International Cyber Security Conference 2023
Agenda
10:00-12:00: Pre-Conference Deep Dives (Only for People Who Registered)
Technical Deep Dive
Northwave performs research (reverse engineering & analysis) on (nation-state) malware to complement red teaming engagements, improve blue team monitoring & detection and aid in CERT investigations. In this presentation we will show you two research projects that we have been working on, a deep dive into nation-state malware of two groups, and a deep dive into a prominent ransomware familiy.
We will show the methodology of two state actors and take you back in time, to the execution of two of their attacks. We will deep-dive in various aspects of our research: how these adversaries operate, how our research supports innovative ways of redteaming and how cyber threat intelligence increasingly shapes the way Northwave's services operate.
We will also show a technical analysis of LockBit Black ransomware. We will deep-dive into various subjects of malware analysis: how we deal with "anti-analysis" techniques (e.g., packing, string obfuscation and dynamic API loading), as well as how a vulnerability in the LockBit ransomware can be abused to recover data without paying for a decryption tool.
Behaviour Deep Dive
In this interactive deep dive session you will experience and discuss with others what is needed to make the human sensor around cyber security work. An e-learning or phishing campaign is a good starting point to make employees aware of risks, but this does not sufficiently lead to cybersafe behaviour within your organisation. In this deep dive session, you will learn what else is needed for cybersafe behaviour within your organisation. You will take away new insights on the role of leadership, landscape and learning in relation to cybersafe behaviour and you will leave with practical tools which you can use immediately.