BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-tallinn-2026//speaker//JJSUWM
BEGIN:VTIMEZONE
TZID:Europe/Helsinki
BEGIN:DAYLIGHT
DTSTART:20250924T000000
TZNAME:EEST
TZOFFSETFROM:+0300
TZOFFSETTO:+0300
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T040000
RDATE:20261025T040000
TZNAME:EET
TZOFFSETFROM:+0300
TZOFFSETTO:+0200
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T040000
RDATE:20270328T040000
TZNAME:EEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0300
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:(FULL) Anti-Forensics (and Anti-Anti-Forensics) Techniques for Inc
 ident Responders (ALL SPOTS FULL) - Stephan Berger
DTSTART;TZID=Europe/Helsinki:20260924T140000
DTEND;TZID=Europe/Helsinki:20260924T180000
DTSTAMP:20260926T112158Z
UID:pretalx-bsides-tallinn-2026-PKPUQY@pretalx.com
DESCRIPTION:Sign-up form: [**Google forms**](https://docs.google.com/forms
 /d/e/1FAIpQLSflrNlvBgEhynGyZiMNxAOgZrIG98CO1ViXK0M9v9ovC-JORQ/viewform?usp
 =sharing&ouid=104367224945762059530)\n\nA full-spectrum dive into anti-for
 ensics across Windows and Linux (with a tad of MacOS\, if time permits)\, 
 centered on real incidents and modern attacker behavior. The course walks 
 through classic log wiping\, deeper filesystem tricks\, PowerShell\, times
 tomping\, sandbox artifacts\, memory-only execution\, endpoint solution bl
 ind spots\, and advanced Linux log manipulation.\n\nEach technique is pair
 ed with detection logic\, weaknesses in attacker tradecraft\, and practica
 l forensic recovery paths. The material emphasizes hands-on analysis\, inc
 luding MFT/MSRUM/USN artifacts\, ETW traces\, VHDX extraction\, /proc-base
 d investigation\, and highlights new research and tooling that shape curre
 nt offensive and defensive strategies.\n\nThis is an excerpt from my full 
 2-3 day training I offer under my brand malmium.com (https://malmium.com/t
 raining-anti-forensics.html)
LOCATION:Office 6
URL:https://pretalx.com/bsides-tallinn-2026/talk/PKPUQY/
END:VEVENT
BEGIN:VEVENT
SUMMARY:Deconstructing Modern macOS Initial Access Vectors - Stephan Berge
 r
DTSTART;TZID=Europe/Helsinki:20260925T140000
DTEND;TZID=Europe/Helsinki:20260925T144500
DTSTAMP:20260926T112158Z
UID:pretalx-bsides-tallinn-2026-A79GBX@pretalx.com
DESCRIPTION:For years\, a persistent myth suggested that macOS was inheren
 tly immune to malware. Today\, threat actors are aggressively shattering t
 hat illusion by deploying sophisticated initial access chains tailored to 
 bypass macOS defenses. This talk provides a deep-dive analysis of how mode
 rn adversaries gain their first foothold on Apple hardware.\n\nWe will dis
 sect the entire initial access pipeline\, starting with Infection Vectors 
 like deceptive Google Ads\, malicious ClickFix campaigns\, and sophisticat
 ed malvertising that trick users into lowering their guard. From there\, w
 e explore the Execution Phase\, analyzing how attackers weaponize scriptin
 g languages\, including traditional Bash and Python\, as well as native Ap
 pleScript\, Compiled AppleScript\, Perl\, and JavaScript for Automation (J
 XA). Finally\, we will examine the delivery mechanisms\, contrasting the a
 buse of native Binaries (Mach-O\, Platypus-packaged apps\, and Electron fr
 ameworks) with the trojanization of Storage and Installer Formats (DMGs an
 d PKGs).\n\nAttendees will walk away with a technical understanding of con
 temporary macOS tradecraft\, real-world attacker methodologies\, and the i
 nsights needed to hunt for and defend against modern Mac-focused threats.
LOCATION:Stage B
URL:https://pretalx.com/bsides-tallinn-2026/talk/A79GBX/
END:VEVENT
END:VCALENDAR
