Microsoft Security Response Center’s Post

Many thanks to all our incredible #BlueHatIndia speakers. In addition to the keynotes we previously highlighted, we want to acknowledge the following speakers for their incredible presentations: John Sherchan, Red Team Security Researcher at CyberWarFare Labs , presented "Assembly.Load: Writing One Byte to Evade AMSI Scan." He discussed bypass techniques and implementation. Vishal Mishra, Senior Security Engineer, Microsoft, presented "The Dusky Shark: TDS Downgrade," covering TDS protocol, exploits, mitigations, and CVE-2024-0056. Dinesh Prakash, Senior Technical Manager at Comcast, presented “xGitGuard: The Sentinels of Secrecy,” discussing xGitGuard and other open-source projects from Comcast SPIDER. Omkar Gudhate, Senior Threat Analyst, Microsoft, and Abhishek Pustakala, Security Researcher II, Microsoft, presented "Scam 2023: The Story Behind How Cybercriminals Are Targeting Indian Android Users," focusing on MITRE ATT&CK TTPs and MDE mitigation. Preksha Saxena and Yashvi Shah, Security Researchers at McAfee, presented “Phishing Landscape Evolution: Unveiling Layers of Email-Initiated Malware Delivery,” discussing phishing email tactics and vulnerabilities. Dmitrijs Trizna, Senior Security Researcher at Microsoft, gave a talk titled: “The Impact of Backdoor Poisoning Vulnerabilities on AI-Based Threat Detectors,” covering AI-based defenses and attacks on AI models. Tarun Gudipati and Ritik Bavdekar, Software Engineers at Microsoft presented “Unveiling Quantum Horizons: Decrypting the Future of Cryptography,” covering present-day cryptography, quantum computing challenges, and Crystals Kyber. Venkatachalabathy SR, Senior Security Research Lead, Microsoft, and Shaleen Dev P.K., Security Researcher II, Microsoft, presented "Adversaries Abuse OAuth Applications with Diverse TTPs to Automate Attacks," focusing on OAuth phishing campaigns and TTPs. Dhruva Goyal, Founder & CEO at BugBase, and Sitaraman S., Founder & CIO at BugBase, presented "Pentest Copilot: Redefining Penetration Testing with LLMs," discussing LLM-based penetration testing and AI safety. Rajesh Kumar Natarajan, Senior Security Researcher, Microsoft, presented “CryptoCurrency Harvest: Unraveling the Progression of Linux Coinminers and Strategic MITRE ATT&CK Alignments," covering cryptomining attacks and detection tactics. Shreya Pohekar Agrawal, Product Security Analyst at HackerOne, presented “Wolf in Sheep’s Code: The Lesser-Known Business Logic Flaws,” discussing business logic bugs and mitigation. Kirtikumar Anandrao Ramchandani, Independent Security Researcher, presented "Hacking WebViews for Fun and Profit," discussing intent-based and Tel URL-based vulnerabilities. Jacob T., Head of Labs at ThinkstCanary, presented “Tracking Illicit Phishermen in the Deep Blue Azure,” discussing deception engineering and a new Canarytoken for Azure phishing detection.

  • No alternative text description for this image
  • No alternative text description for this image
  • No alternative text description for this image
  • No alternative text description for this image
  • No alternative text description for this image
    +11
John Sherchan

Red Team Security Researcher at CyberWarFare Labs

1mo

It was a remarkable opportunity to participate alongside such talented speakers at #BlueHatIndia. I'm grateful for the chance to contribute and engage with such a dynamic community. My heartfelt thanks to MSRC for organizing such an exceptional event.

Gamuchirai Blessing M.

SOC Analyst trainee| Front-End Developer | CyberGirl 4.0 | CyberSecurity Analyst | ISC2 CC | OpenSource Contributor| Wireshark | Security+ | Kali linux | Ubuntu | Nmap | Metasploit

1mo

When are you going to have a Bluehat South Africa conference? I will love to attend

Like
Reply
Nirmal Unagar

Security Engineer - SIEM/SOAR at University of Winchester | Security+ | eJPTv2

1mo

Is it recorded?

Like
Reply
See more comments

To view or add a comment, sign in

Explore topics