BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-tallinn-2026//talk//PKPUQY
BEGIN:VTIMEZONE
TZID:Europe/Helsinki
BEGIN:DAYLIGHT
DTSTART:20250924T000000
TZNAME:EEST
TZOFFSETFROM:+0300
TZOFFSETTO:+0300
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T040000
RDATE:20261025T040000
TZNAME:EET
TZOFFSETFROM:+0300
TZOFFSETTO:+0200
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T040000
RDATE:20270328T040000
TZNAME:EEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0300
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:(FULL) Anti-Forensics (and Anti-Anti-Forensics) Techniques for Inc
 ident Responders (ALL SPOTS FULL) - Stephan Berger
DTSTART;TZID=Europe/Helsinki:20260924T140000
DTEND;TZID=Europe/Helsinki:20260924T180000
DTSTAMP:20260926T112157Z
UID:pretalx-bsides-tallinn-2026-PKPUQY@pretalx.com
DESCRIPTION:Sign-up form: [**Google forms**](https://docs.google.com/forms
 /d/e/1FAIpQLSflrNlvBgEhynGyZiMNxAOgZrIG98CO1ViXK0M9v9ovC-JORQ/viewform?usp
 =sharing&ouid=104367224945762059530)\n\nA full-spectrum dive into anti-for
 ensics across Windows and Linux (with a tad of MacOS\, if time permits)\, 
 centered on real incidents and modern attacker behavior. The course walks 
 through classic log wiping\, deeper filesystem tricks\, PowerShell\, times
 tomping\, sandbox artifacts\, memory-only execution\, endpoint solution bl
 ind spots\, and advanced Linux log manipulation.\n\nEach technique is pair
 ed with detection logic\, weaknesses in attacker tradecraft\, and practica
 l forensic recovery paths. The material emphasizes hands-on analysis\, inc
 luding MFT/MSRUM/USN artifacts\, ETW traces\, VHDX extraction\, /proc-base
 d investigation\, and highlights new research and tooling that shape curre
 nt offensive and defensive strategies.\n\nThis is an excerpt from my full 
 2-3 day training I offer under my brand malmium.com (https://malmium.com/t
 raining-anti-forensics.html)
LOCATION:Office 6
URL:https://pretalx.com/bsides-tallinn-2026/talk/PKPUQY/
END:VEVENT
END:VCALENDAR
