{"title":"DEF CON Training Singapore October 2026","description":"\u003cp class=\"p1\"\u003eDEF CON Training is back in Singapore, October 1-2, 2026.\u003c\/p\u003e\n\u003cp class=\"p2\"\u003e\u003cb\u003eCourse Schedule (8:00 am–5:00 pm daily).\u003c\/b\u003e\u003c\/p\u003e","products":[{"product_id":"advanced-cloud-incident-response-in-azure-and-microsoft-365-korstiaan-stam-dctfall26","title":"Advanced Cloud Incident Response in Azure and Microsoft 365 - Korstiaan Stam - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Advanced Cloud Incident Response in Azure and Microsoft 365\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Korstiaan Stam\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eOct 1 -2, 2026\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eTime: \u003c\/strong\u003e8:30 am - 5:30 pm\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eTBD\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e\n\u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3000 (w\/GST)\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3,450 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST) \u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST)\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course equips you with the advanced forensic skills to confidently detect, scope, and investigate sophisticated cyber threats across Azure and Microsoft 365 environments. Through immersive hands-on labs and real-world attack simulations, you will master the analysis of cloud log artifacts to lead effective incident response investigations.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis hands-on two-day training offers a comprehensive guide to incident response in the Microsoft cloud, covering various topics essential for handling threats and attacks. The course starts with an overview of the concepts of the Microsoft cloud that are relevant for incident response. Participants will learn how to scope an incident in the Microsoft cloud and how to leverage it to set up an incident response capability. On the first day you will be immersed in the world of Azure attacks, we cover the different phases of an attack focusing on the evidence an attack leaves and how you can identify attacks based on the available evidence. On the second day we will shift our focus to Microsoft 365. The training covers the different types of evidence available in a Microsoft 365 environment. Participants will gain an understanding of how to acquire data from a Microsoft 365 environment using multiple methods and tools, and how to parse, enrich, and analyze the Microsoft 365 Unified Audit Log (UAL). The best part of the training is that everything you learn you'll apply with hands-on labs in a CTF like environment. Additionally, we have created two full attack scenarios in both Azure \u0026amp; M365 and you're tasked in the CTF to solve as many pieces of the puzzle as you can.\u003cbr\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eDay 1\u003cbr\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eCourse introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure IR introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Terminology \u0026amp; Hierarchy\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEntra ID, Users, Groups \u0026amp; Security Principals\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEntra ID Roles\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEntra ID Hybrid setup\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEntra ID Security (Conditional Access \u0026amp; Identity Protection)\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.1 - Exploring Azure\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure \u0026amp; Entra Audit \u0026amp; Logging\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eKQL for Incident Response\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eKQL Introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eNeed to know KQL commands\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAdvanced KQL\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.2 - KQL Querying\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eGraph API for Incident Response\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eGraph API calls for IR\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack Techniques - Part I\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack Overview\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eReconnaissance: Internal and External\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eInitial Access: Valid accounts, Password Attacks \u0026amp; Malicious apps\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.3 - Investigate Recon \u0026amp; Initial Access\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack Techniques - Part II\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExecution Introduction \u0026amp; Azure RunCommand\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExecution: Virtual Machine Scripting \u0026amp; Automation accounts\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExecution: Function app \u0026amp; Cloud Shell\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePrivilege Escalation: PIM \u0026amp; Elevated Access Toggle\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePrivilege Escalation: Azure AD applications\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence: Account Creation \u0026amp; Network Security Group Modification\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence: Azure Lighthouse \u0026amp; Delegated Administrators\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence: Cross-Tenant Synchronization \u0026amp; Subscription Transfers\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence: Federated options\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.4 - Execution, Persistence \u0026amp; Privilege Escalation\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack Techniques - Part III\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCredential Access: Tokens \u0026amp; Application secrets\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCredential Access: KeyVault dumping\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExfiltration\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack tools\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.5 - Credential Access, Exfiltration\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eResponding to Azure attacks\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eIntroduction \u0026amp; NIST model\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCloud Incident Response: Preparation\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCloud Incident Response: Investigate \u0026amp; Contain\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCloud Incident Response: Remediate \u0026amp; Recover\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eToken \u0026amp; Session Revocation\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Incident Response tools\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cspan\u003e-------------------------- End of day 1---------------------------------------------\u003cbr\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eDay 2\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 IR introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 - Forensic artefacts\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 - Course introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUnified Audit Log: Introduction \u0026amp; Advanced Auditing \u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUnified Audit Log: Structure\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUnified Audit Log: Access \u0026amp; Acquisition\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMailItemsAccessed\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEverything you need to know about the MailItemsAccessed Operation\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 2.1 - Exploration of the UAL\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Email Forwarding Rules\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eForensic analysis of inbox rules\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eForensic analysis of transport rules\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eForensic analysis of the Message Trace Log (MTL)\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attack Techniques - Part I\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attacks Overview\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eInitial Access: Phishing\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eInitial Access: MiTM \u0026amp; AiTM attacks\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attack Techniques - Part II\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExecution: API calls \u0026amp; PowerShell\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence \u0026amp; Privilege Escalation: Account manipulation\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence \u0026amp; Privilege Escalation: Account Creation \u0026amp; MFA registration\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attack Techniques - Part III\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCollection \u0026amp; Exfiltration: eDiscovery \u0026amp; Content search\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCollection \u0026amp; Exfiltration: Power Automate abuse\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 2.2 - Compromise of an email account\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attack tools\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAccess Token abuse \u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAccess Token abuse \u0026amp; Family Of Client IDs (FOCI)\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 2.3 - Extracting \u0026amp; Manipulating tokens (Live Lab)\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Anti-Forensic techniques\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 IR Tools \u0026amp; Techniques\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft Extractor Suite\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eHawk\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUntitled Goose Tool\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft Defender for Cloud Apps\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 2.4- Using the Microsoft Extractor Suite\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eBest practices for remediation and recovery in Microsoft 365\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eRemediation \u0026amp; Recovery - Walkthrough\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\n\u003cstrong\u003eBonus exercises:\u003cbr\u003e\u003c\/strong\u003e\n\u003cul\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigating OAuth apps\u003cbr\u003e\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigation of a malicious Function (Live Lab)\u003cbr\u003e\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cspan\u003e\u003cstrong\u003eInvestigation of a suspicious automation account (Live Lab)\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCTF Time\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure CTF\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft CTF\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\n\u003cstrong\u003eBonus exercise:\u003cbr\u003e\u003c\/strong\u003e\n\u003cul\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigating OAuth applications\u003cbr\u003e\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigation of a malicious Function\u003cbr\u003e\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigation of a suspicious Automation Account\u003c\/strong\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cspan\u003e-------------------------- End of day 2---------------------------------------------\u003cstrong\u003e\u003cbr\u003e\u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIntermediate\/Advanced\u003c\/span\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIntermediate Definition - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eAdvanced Definition - The student is expected to have significant practical experience with the tools and technologies that the training will focus on.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003eExperience in the Microsoft cloud will prove very useful to be able to keep up. Experience with PowerShell and\/or KQL is not required but will help you to gain even more from the training. You must also not be afraid of the command-line interface as this will be a hands-on training and not everything will be in the GUI.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eImportant: You only have to bring your laptop with a browser and we will provide you with access to the cloud tenants and investigation data.\u003cstrong\u003e\u003c\/strong\u003e\u003cspan\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003eDigital training materials\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eCloud Access to a training environment\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eLab Access to a pre-configured Microsoft lab environment for the duration of the class\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eKorstiaan Stam is the Founder and CEO of Invictus Incident Response \u0026amp; former SANS Trainer - FOR509: Cloud Forensics and Incident Response. Korstiaan is a passionate incident responder, preferably in the cloud. He developed and contributed to many open-source tools related to cloud incident response. Korstiaan has gained a lot of knowledge and skills over the years which he is keen to share.  \u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eWay before the cloud became a hot topic, Korstiaan was already researching it from a forensics perspective. “Because I took this approach I have an advantage, because I simply spent more time in the cloud than others. More so, because I have my own IR consultancy company, I spent a lot of time in the cloud investigating malicious behavior, so I don’t just know one cloud platform, but I have knowledge about all of them.” That equips him to help students with the challenge of every cloud working slightly or completely different. “If you understand the main concepts, you can then see that there’s also a similarity among all the clouds. That is why I start with the big picture in my classes and then zoom in on the details. Korstiaan also uses real-life examples from his work to discuss challenges he’s faced with students to relate with their day-to-day work. “To me, teaching not only means sharing my knowledge on a topic, but also applying real-life implications of that knowledge. I always try to combine the theory with the everyday practice so students can see why it’s important to understand certain concepts and how the newly founded knowledge can be applied.”\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course has the option for a proficiency certificate add-on. To earn the proficiency certificate, students will need to participate in the CTF challenge at the end of Day 2 and answer at least 50% of the questions across Microsoft 365 and Azure.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51478377005196,"sku":null,"price":3000.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2","offer_id":51478377037964,"sku":null,"price":3450.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/KorstiaanStam.png?v=1768361711"},{"product_id":"ai-secureops-attacking-defending-ai-applications-agents-abhinav-singh-dctfall26","title":"AI SecureOps: Attacking \u0026 Defending AI Applications \u0026 Agents - Abhinav Singh - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e AI SecureOps: Attacking \u0026amp; Defending AI Applications \u0026amp; Agents\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Abhinav Singh\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Oct 1-2, 2026\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eTime: \u003c\/strong\u003e8:30 am - 5:30 pm\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eTBD\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$2,200 (w\/GST)\u003cbr\u003e\u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$2,650 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST) \u003cbr\u003e\u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST)\u003c\/span\u003e\u003cbr\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eStep into the front lines of securing enterprise AI with an immersive, CTF-style training built around realistic attack-and-defense scenarios for AI applications, agents, and MCP-connected systems. Through hands-on labs, participants will explore how prompt injection, agent abuse, poisoned context, unsafe tool use, and authorization failures can lead to backend compromise, data exposure, and infrastructure impact. The course focuses on the enterprise realities of securing AI apps \u0026amp; agentic systems, covering red and blue teaming, guardrails, monitoring, incident response, and Responsible AI. Designed for security practitioners, builders, and defenders, this training helps attendees understand how modern AI systems fail, how those failures chain into larger enterprise risks, and how to implement practical controls to secure AI deployments at scale.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003eTop 3 Takeaways\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLearn how to identify, exploit, and defend against real-world attacks on AI applications, agents, and tool-connected systems, including prompt injection, jailbreaks, agent abuse, and chained compromise paths.\u003c\/li\u003e\n\u003cli\u003eBuild practical defensive capabilities for enterprise AI, including guardrails, security scanners, monitoring, and response patterns for public, private, and MCP-enabled AI services.\u003c\/li\u003e\n\u003cli\u003eGain hands-on experience using modern AI techniques for security testing, validation, and red\/blue teaming, including judge-LLM workflows, attack automation, and securing agentic AI supply chains.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eCan prompt injections lead to complete infrastructure takeovers? Could AI agents, MCP-connected tools, or poisoned external context be abused to compromise backend services? Can data poisoning in AI copilots impact a company’s stock? Can jailbreaks create false crisis alerts in security systems? This immersive, CTF-styled training in GenAI, LLM, agent, and MCP security dives into these pressing questions. Engage in realistic attack-and-defense scenarios focused on real-world threats, from prompt injection and remote code execution to backend compromise, tool abuse, unsafe agent orchestration, and MCP-specific trust and authorization failures. Tackle hands-on challenges with live AI applications to understand vulnerabilities and build robust defenses. Learn how to create a comprehensive security pipeline, master AI red and blue team strategies, secure tool-connected and agentic systems, build resilient guardrails for LLMs, and handle incident response for AI-based threats. You will also explore governance, Responsible AI, and enterprise security patterns for modern AI ecosystems.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy 2027, Gartner, Inc. predicts that over 80% of enterprises will engage with AI applications, up from less than 5% in 2023. This rapid adoption presents a new challenge for security professionals. This training provides essential AI and LLM security skills through an immersive CTF-styled framework, bringing you from an intermediate to an advanced level. Delve into sophisticated techniques for mitigating AI threats and engineer robust defense mechanisms to address the complex security challenges posed by AI's rapid expansion. You will be provided with access to a live playground with custom-built AI applications replicating real-world attack scenarios covering use-cases defined under the OWASP LLM top 10 framework and mapped with stages defined in MITRE ATLAS. This dense training will navigate you through areas like the red and blue team strategies, create robust LLM defenses, incident response in LLM attacks, implement a Responsible AI (RAI) program, and enforce ethical AI standards across enterprise services, with the focus on improving the entire AI supply chain.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eThis training will also cover the completely new segment of Responsible AI (RAI), ethics, and trustworthiness in AI services. Unlike traditional cybersecurity verticals, these unique challenges such as bias detection, managing risky behaviors, and implementing mechanisms for tracking information are going to be the key challenges for enterprise security teams.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy the end of this training, you will be able to:\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\n\u003cspan\u003eExploit vulnerabilities in AI applications to achieve code and command execution, uncovering scenarios such as instruction injection, agent control bypass, remote code execution for infrastructure takeover, and chaining multiple agents for goal hijacking.\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eConduct AI red-teaming using adversary simulation, OWASP LLM Top 10, and MITRE ATLAS frameworks, while applying AI security and ethical principles in real-world scenarios.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eExecute and defend against adversarial attacks, including prompt injection, data poisoning, jailbreaks, agentic attacks, and insecure tool-connected workflows.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003ePerform advanced AI red and blue teaming through multi-agent auto-prompting attacks, implementing a 3-way autonomous system consisting of attack, defend, and judge models.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eBuild and deploy enterprise-grade LLM defenses, including custom guardrails for input\/output protection, security benchmarking, penetration testing of LLM agents, and defensive controls for MCP-enabled integrations.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eUnderstand MCP \u0026amp; agent fundamentals and assess how they expand the attack surface of modern AI systems.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eEstablish a comprehensive LLM SecOps process to secure the supply chain from adversarial attacks. Create a robust threat model for enterprise applications, including AI systems connected to external tools and data sources through MCP-like architectures.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eImplement an incident response and risk management plan for enterprises developing or using GenAI services.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cdiv dir=\"ltr\"\u003e\n\u003cdiv class=\"gmail_quote\"\u003e\n\u003cdiv dir=\"ltr\"\u003e\u003cspan id=\"m_4537920884060312m_4557477349097280137m_-2991987330191836870gmail-docs-internal-guid-81f1794d-7fff-aac0-e0e1-98237d64c6cd\"\u003e\u003c\/span\u003e\u003c\/div\u003e\n\u003c\/div\u003e\n\u003c\/div\u003e\n\u003cp\u003e\u003cspan\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e### Introduction \u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduction to LLM and AI\u003c\/li\u003e\n\u003cli\u003eTerminologies and architecture\u003c\/li\u003e\n\u003cli\u003eTransformers, Attention \u0026amp; their security implications (hallucinations, jailbreaks, etc)\u003c\/li\u003e\n\u003cli\u003eAgents, multi-agents and multi-modal models\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eIntroduction to tool-connected AI systems and MCP as an emerging standard for connecting agents to external tools, data, and workflows\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Elements of AI Security (1 lab)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eUnderstanding AI vulnerabilities with case studies on AI security breaches\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eOWASP LLM Top 10 and MITRE mapping of attacks on AI supply chain  \u003c\/li\u003e\n\u003cli\u003eThreat modeling of AI Applications, tool-connection and MCP-enabled architectures, including trust boundaries across hosts, clients, servers, tools, resources, and external systems  \u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Adversarial LLM Attacks and Defenses (6 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e(What, Why \u0026amp; how’s)Direct and indirect prompt injection attacks and their subtypes \u003c\/li\u003e\n\u003cli\u003eAdvanced prompt injections through obfuscation and cross-model injections\u003c\/li\u003e\n\u003cli\u003eBreaking system prompts and their trust criteria\u003c\/li\u003e\n\u003cli\u003eIndirect prompt injections through external input sources\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Responsible AI \u0026amp; Jailbreaking (6 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eJailbreaking public LLMs covering adversarial AI, offensive security, and CBRN use-cases\u003c\/p\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cp\u003eResponsible use and governance implications of increasingly autonomous, tool-connected AI systems\u003c\/p\u003e\n\u003c\/li\u003e\n\u003cli\u003eModel alignment, system prompt optimization, and defense\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Building Enterprise-grade LLM Defenses (2 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploying LLM security scanner, adding custom rules, prompt block-lists, and guardrails.\u003c\/li\u003e\n\u003cli\u003eWriting custom detection logic, trustworthiness checks, and filters.\u003c\/li\u003e\n\u003cli\u003eBuilding security log monitoring and alerting for models using open-source tools.\u003c\/li\u003e\n\u003cli\u003eLLM security benchmarking and continuous reporting.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Red \u0026amp; Blue Teaming of Enterprise AI applications (4 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBusiness control flow testing for risky responses \u0026amp; misaligned behavior of applications\u003c\/li\u003e\n\u003cli\u003eUsing Colab notebooks for automation of API calls and reporting\u003c\/li\u003e\n\u003cli\u003eVector database and model-weight tracing for root-cause investigation\u003c\/li\u003e\n\u003cli\u003eRainbow teaming through a 3-way LLM implementation: target, attacker, and judge with self-improving attack prompts\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### MCP Security \u0026amp; Defensive Architecture (1 lab)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eMCP fundamentals \u0026amp; security for agentic systems: protocol basics, trust-boundary changes, key risks like malicious servers and over-broad permissions, plus a browser-based exploit-and-defend lab\u003c\/li\u003e\n\u003cli\u003eDefense patterns for MCP-enabled systems with protection architectures\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Attacking \u0026amp; Defending Agentic Systems (5 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eThreat modeling of agentic and multi-agent systems, including planning loops, memory, tool invocation, delegation, trust boundaries, and escalation paths\u003c\/li\u003e\n\u003cli\u003eAttacking LLM agents for task manipulation, risky behavior and PII disclosure in RAG\u003c\/li\u003e\n\u003cli\u003eInjection attacks on AI agents for code and command execution\u003c\/li\u003e\n\u003cli\u003eCompromising backend infrastructure by abusing over-permissioning and tool usage in agentic systems\u003c\/li\u003e\n\u003cli\u003eMulti-agent attacks causing privilege too calls, goal manipulation \u0026amp; chained escalations\u003c\/li\u003e\n\u003cli\u003eDefense patterns for agentic systems, including observability, approval gates, scoped permissions, secure delegation, and runtime tracing for high-risk actions.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Building AI SecOps Process\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSummarizing the learnings into a SecOps workflow\u003c\/li\u003e\n\u003cli\u003eMonitoring trustworthiness, safety and security of enterprise AI applications\u003c\/li\u003e\n\u003cli\u003eImplementing NIST AI Risk Management Framework (RMF) for security monitoring\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eIntermediate - The student has education, some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003eComplete the simple pre-training instructions: create a paid OpenAI API key, set up a Google Colab notebook, and read the Introduction document. No local setup is needed. All the training materials and lab access will be provided during the training.\u003cbr\u003e\u003c\/p\u003e\n\u003cp\u003eWho Should Take This Course\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity professionals who need to understand how modern AI systems fail and how to defend them\u003c\/li\u003e\n\u003cli\u003eRed and blue teamers looking to add AI applications, agents, and tool-connected systems to their offensive and defensive workflows\u003c\/li\u003e\n\u003cli\u003eAI\/LLM developers and engineers who want to build more secure applications, agents, and integrations\u003c\/li\u003e\n\u003cli\u003eSecurity architects, detection engineers, and defenders responsible for securing enterprise AI deployments\u003c\/li\u003e\n\u003cli\u003eAI safety, governance, and risk professionals who need a practical understanding of how technical failures map to real enterprise risk\u003c\/li\u003e\n\u003cli\u003eProduct leaders, founders, and technical decision-makers who want to better understand the attack surface of AI-enabled products and agentic systems\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003e\u003cspan\u003e\u003c\/span\u003eA laptop with browser access is ideal, preferably a personal laptop without network restricting tools.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eComplete the pre-training setup prior to the class which includes setting up:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eAPI key for OpenAI.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eGoogle Colab account.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eComplete the pre-training setup before the first day.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eOne year access to a live interactive playground with various exercises to practice different attack and defense scenarios for GenAI and LLM applications.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003e\"AI SecureOps\" Metal coin for CTF players.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eComplete course guide containing 200+ pages in PDF format. It will contain step-by-step guidelines for all exercises and labs, and a detailed explanation of concepts discussed during the training.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003ePDF versions of the slides that will be used during the training.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eAccess to the Discord server for continued engagement, support, and development in the field of AI Security \u0026amp; Safety.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eAccess to HuggingFace models, datasets, and transformers.\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cspan\u003e\u003cstrong\u003eAbhinav Singh\u003c\/strong\u003e is an esteemed cybersecurity leader \u0026amp; researcher with over 15 years of experience across technology leaders and financial institutions, as well as an independent trainer and consultant. Author of \"Metasploit Penetration Testing Cookbook\" and \"Instant Wireshark Starter,\" his contributions span patents, open-source tools, and numerous publications. Recognized in security portals and digital platforms, Abhinav is a sought-after speaker \u0026amp; trainer at international conferences like Black Hat, RSA, DEFCON, BruCon, and many more, where he shares his deep industry insights and innovative approaches in cybersecurity. He also leads multiple AI security groups at CSA, responsible for coming up with cutting-edge white papers and industry reports on the safety and security of AI.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eReview a few examples of Abhinav's previous courses at the links below:\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cspan\u003e \u003c\/span\u003e\u003cspan\u003e2026:\u003ca href=\"https:\/\/sg.shop.defcon.org\/collections\/singapore-2026\/products\/ai-secureops-defending-ai-applications-and-services-abhinav-singh-dcsg2026\" target=\"_blank\"\u003e DEF CON Singapore,\u003c\/a\u003e\u003ca href=\"https:\/\/training.defcon.org\/collections\/def-con-training-las-vegas-2026\/products\/ai-secureops-attacking-defending-ai-applications-agents-abhinav-singh-dclv2026\" target=\"_blank\"\u003e \u003c\/a\u003e\u003ca href=\"https:\/\/insomnihack.ch\/workshops\/ai-secureops-attacking-defending-ai-applications-agents\/\" target=\"_blank\"\u003eInsomni’hack\u003c\/a\u003e,\u003ca href=\"https:\/\/hackmiami.com\/training-ai-secureops-attacking-defending-genai-applications-and-services.html\" target=\"_blank\"\u003e HackMiami\u003c\/a\u003e,\u003ca href=\"https:\/\/www.x33fcon.com\/#!t\/AbhinavSingh.md\" target=\"_blank\"\u003e x33fcon\u003c\/a\u003e,\u003ca href=\"https:\/\/owasp.glueup.com\/event\/owasp-global-appsec-eu-2026-vienna-austria-162243\/training.html\" target=\"_blank\"\u003e OWASP Global AppSec EU\u003c\/a\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli role=\"presentation\"\u003e\n\u003cspan\u003e2025:\u003ca href=\"https:\/\/insomnihack.ch\/workshops\/ai-secureops-attacking-defending-genai-applications-and-services\/\" target=\"_blank\"\u003e Insomni’hack\u003c\/a\u003e, BruCon, Hack Miami, \u003ca href=\"https:\/\/www.rsaconference.com\/experts\/abhinav-singh\" target=\"_blank\"\u003eRSA Conference\u003c\/a\u003e,\u003ca href=\"https:\/\/training.defcon.org\/collections\/def-con-training-las-vegas-2025\/products\/abhinav-singh-ai-attacks-defense-las-vegas-2025\" target=\"_blank\"\u003e DEF CON Vegas\u003c\/a\u003e, Nsec\u003c\/span\u003e\u003cu\u003e\u003cspan\u003e, Lacson, \u003ca href=\"https:\/\/events.humanitix.com\/owaspnz2025-training\"\u003eOWASP Auckland\u003c\/a\u003e\u003c\/span\u003e\u003c\/u\u003e\u003cspan\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli role=\"presentation\"\u003e\u003cspan\u003e2024:\u003ca href=\"https:\/\/blackhatmea.com\/trainings-list\/2024\/ai-secureops-genai-and-llm-security-enterprises\" target=\"_blank\"\u003e Black Hat MEA\u003c\/a\u003e,\u003ca href=\"https:\/\/www.rsaconference.com\/Library\/presentation\/USA\/2024\/Blueprint%20for%20Data%20Defense%20in%20the%20Public%20Cloud%20Strategies%20and%20Playbooks\" target=\"_blank\"\u003e RSA San Francisco Workshop\u003c\/a\u003e, Hack Miami, Florida,\u003ca href=\"https:\/\/appsec.org.nz\/conference-2024\/training-ai_secure_ops\" target=\"_blank\"\u003e OWASP New Zealand\u003c\/a\u003e, LASCON 2024,\u003ca href=\"https:\/\/deepsec.net\/archive\/2024.deepsec.net\/speaker.html#WSLOT693\" target=\"_blank\"\u003e DeepSec Austria\u003c\/a\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli role=\"presentation\"\u003e\u003cspan\u003e2023:\u003ca href=\"https:\/\/blackhatmea.com\/trainings-list\/2023\/cloud-security-masterclass-defenders-guide-securing-aws-azure-infrastructure\" target=\"_blank\"\u003e Black Hat\u003c\/a\u003e, DEF CON Las Vegas, OWASP AppSec Days New Zealand,\u003ca href=\"https:\/\/www.rsaconference.com\/Library\/presentation\/USA\/2023\/Defender%20Guide%20to%20Securing%20Data%20in%20Public%20Cloud%20Infrastructures\" target=\"_blank\"\u003e RSA Conference\u003c\/a\u003e, Insomni’hack Geneva,\u003ca href=\"https:\/\/www.infosecworldusa.com\/isw23\/workshops\/\" target=\"_blank\"\u003e InfoSec World\u003c\/a\u003e, BruCon (virtual), BruCon 2023, OWASP LASCON\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course has the option for a proficiency certificate add-on. To earn the proficiency certificate, students will have to score at least 1400 out of 2200 on the course capture the flag (CTF). Only students who purchase the proficiency certificate will have their work evaluated by the instructor to certify mastery of the course material.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51478533734540,"sku":null,"price":2200.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2","offer_id":51478533767308,"sku":null,"price":2650.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/Abhinav_image_2.png?v=1768361707"},{"product_id":"red-team-sigint-practical-sdr-hacking-for-mission-critical-automotive-aviation-and-marine-targets-jos-wetzels-wouter-bokslag-midnight-blue-dcsgfall26","title":"Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets - INCL HARDWARE - Jos Wetzels \u0026 Wouter Bokslag (Midnight Blue) - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e: Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets - INCL HARDWARE \u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e: Jos Wetzels \u0026amp; Wouter Bokslag (Midnight Blue)\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eDates\u003c\/strong\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eOct 1-2, 2026\u003cbr\u003e\u003cstrong\u003eTime: \u003c\/strong\u003e8:30 am - 5:30 pm\u003cbr\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eTBD\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cmeta charset=\"UTF-8\"\u003e \u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$4,250 (w\/GST) - includes SDR and attack targets\u003cbr\u003e\u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$4,700 SGD (w\/GST) - includes SDR and attack targets\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD (w\/GST)\u003cbr\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis practically-oriented course, taught by the Midnight Blue team known for their TETRA research, aims to equip security practitioners with field-relevant RF security knowledge enabling them to assess and target important but rarely addressed RF technologies such as automotive, aviation, marine, physical access control RF protocols and mission-critical radio (e.g. TETRA, DMR, P25) used by police, military, private security, and critical infrastructure.\u003c\/p\u003e\n\u003cp\u003eHands-on exercises such as intercepting and decrypting handheld radio comms and breaking automotive security systems are alternated with thorough overviews of relevant RF protocols and their security posture as well as case studies of real-world RF attacks on railways, water utilities, drones, and police\/military radios.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eHave you ever had to deal with attacking an RF signal and Youtube tutorials on the Flipper Zero didn't get you anywhere? Have you ever wanted to listen in to a security team's radio communications during a physical red team engagement? Did you ever think covertly breaking into corporate vehicle fleets or garages should be in-scope, but didn't know how to approach this?\u003c\/p\u003e\n\u003cp\u003eThen this is the course for you.\u003c\/p\u003e\n\u003cp\u003eIn an increasingly wireless world, we are surrounded by readily exploitable signals everywhere. Yet too often Red Team operations and pentests leave the RF spectrum unaddressed due to a lack of specialist knowledge and experience, especially when it comes to sensitive RF protocols not typically encountered in conventional enterprise and IoT contexts.\u003c\/p\u003e\n\u003cp\u003eThis practically-oriented course, taught by the Midnight Blue team known for their TETRA research, aims to equip security practitioners with field-relevant RF security knowledge and experience. While it thoroughly covers the fundamentals of RF, SDR, and SIGINT, it avoids math-heavy RF engineering with limited relevance to day-to-day operational reality.\u003c\/p\u003e\n\u003cp\u003eInstead, this course will provide attendees with a structured, step-by-step approach to the Signals Intelligence (SIGINT) cycle of targeting, identifying, collecting, processing, and analyzing Signals of Interest (SOIs). This includes the often cumbersome task of getting various special-purpose SDR tools to work on current systems. Attendees will learn how to exploit such signals with commonly available tooling through awareness of common risks and pitfalls in RF security.\u003c\/p\u003e\n\u003cp\u003eWhere other SDR trainings tend to focus on enterprise and IoT RF protocols such as 4G\/5G, WiFi, RFID, and BT, this training focuses on important but rarely addressed RF technologies such as automotive, aviation, marine, physical access control RF protocols and mission-critical radio (e.g. TETRA, DMR, P25) used by police, military, private security, and critical infrastructure. Hands-on exercises such as intercepting and decrypting handheld radio comms and breaking automotive security systems are alternated with thorough overviews of relevant RF protocols and their security posture as well as case studies of real-world RF attacks on railways, water utilities, drones, and police\/military radios.\u003cbr\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cem\u003eCourse outline is preliminary and subject to minor changes and improvements.\u003c\/em\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"text-decoration: underline;\"\u003eDAY 1 - BLOCK 1: Basics of SDR and SIGINT\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e- Introduction to Radio Frequency (RF), Software Defined Radio (SDR), Digital Signal Processors (DSPs)\u003cbr\u003e- SDR theory of operation\u003cbr\u003e- Overview of SDR hardware \u0026amp; software\u003cbr\u003e- Modulation and signal types\u003cbr\u003e- Antenna selection, tuning, and positioning\u003cbr\u003e- Building and working with SDR software stacks: SDRangel, Gqrx, GNU Radio, Universal Radio Hacker (URH),DragonOS, Flipper Zero\u003cbr\u003e- Signals Intelligence (SIGINT) cycle\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"text-decoration: underline;\"\u003eDAY 1 - BLOCK 2: Fundamentals of RF Security\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e- Security requirements in RF protocols\u003cbr\u003e- Common risks and pitfalls: Jamming, replay, relay, cryptanalysis, etc.\u003cbr\u003e- Case studies: railways, water utilities, emergency broadcasts\u003c\/p\u003e\n\u003cp\u003e- Physical access control RF systems: automatic doors, gates, barriers, bollards, alarms, etc.\u003cbr\u003e- Automotive access control RF systems: Remote Keyless Entry (RKE), Passive Keyless Entry (PKE)\u003cbr\u003e- Automotive case study: professional car theft rings\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"text-decoration: underline;\"\u003eDAY 2 - BLOCK 1: Professional Mobile Radio (PMR) \/ Land Mobile Radio (LMR) Security\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e- Introduction to PMR \/ LMR\u003c\/p\u003e\n\u003cp\u003e- Terrestrial Trunked Radio (TETRA): Overview, security, vulnerabilities, and available tooling\u003cbr\u003e- TETRA SIGINT tooling discussion\u003cbr\u003e- TETRA case study: Real-world TETRA interception incidents\u003c\/p\u003e\n\u003cp\u003e- APCO-25 (P25): Overview, security, vulnerabilities, and available tooling\u003cbr\u003e- dPMR\/NXDN: Overview, security, vulnerabilities, and available tooling\u003cbr\u003e- TETRAPOL: Overview, security, vulnerabilities, and available tooling\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"text-decoration: underline;\"\u003eDAY 2 - BLOCK 2: PMR continued, Marine \u0026amp; Aviation\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e- Digital Mobile Radio (DMR): Overview, security, vulnerabilities, and available tooling\u003cbr\u003e- DMR SIGINT tooling discussion\u003cbr\u003e- DMR case study: DMR usage and targeting in Russia-Ukraine war, Middle-Eastern conflicts, and Mexican cartels\u003c\/p\u003e\n\u003cp\u003e- Marine RF systems: AIS\/VDES, GMDSS, etc.\u003cbr\u003e- Marine case study: tracking \u0026amp; spoofing in conflict zones, piracy, and sanctions evasions\u003c\/p\u003e\n\u003cp\u003e- Aviation RF systems: ADS-B, ACARS\/VDL, etc.\u003cbr\u003e- Drones \/ Unmanned Aircraft Systems (UAS): telecontrol, analog \u0026amp; digital video (VTX) downlink, scrambling and encryption\u003cbr\u003e- Aviation case study: Counter-UAS\/drone examples from the Russia-Ukraine war and Middle-Eastern conflicts\u003cbr\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003eBeginner to Intermediate\u003c\/p\u003e\n\u003cp\u003eBeginner Definition - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIntermediate Definition - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e- Basic familiarity with Linux\u003cbr\u003e- Basic familiarity with Python\u003cbr\u003e- Some understanding of pentesting and red teaming fundamentals\u003c\/p\u003e\n\u003cp\u003eThis will be a tech-forward course less suited for executives, project managers, compliance auditors, etc. Ideally, students have some basic general cybersecurity experience (or equivalent education). That being said, we've had some quick learners with different backgrounds, that benefited greatly from the hands-on nature of the course.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e- Modern laptop with Core i7 CPU or equivalent\/better and preferably 32GB+ RAM (absolute minimum 16GB)\u003cbr\u003e- Laptop should run DragonOS Noble (24.04) or newer (see \u003ca class=\"moz-txt-link-freetext\" href=\"https:\/\/cemaxecuter.com\/\"\u003ehttps:\/\/cemaxecuter.com\/\u003c\/a\u003e). A VM is fine, but preferably native installation to reduce risk of spending time on setup problems\u003cbr\u003e- Laptop should *not* be a locked-down corporate laptop, administrator privileges are a must-have\u003cbr\u003e- Laptop should have USB type A (or Type C + converter) for SDR hardware\u003cbr\u003e- Bring a charger\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e- HackRF based SDR hardware (platform + antenna)\u003cbr\u003e- Several exercise targets including: Fixed-code alarm system, rolling-code RKE\/door control system\u003cbr\u003e- Syllabus, exercises, exercise solutions, and tooling\u003cbr\u003e- Certificate of attendance\u003c\/p\u003e\n\u003cp\u003eAll students will receive a hardware kit to keep as part of their registration, including:\u003cbr\u003e- The versatile HackRF based SDR platform\u003cbr\u003e- All the covered exercise targets\u003cbr\u003e- Bonus target: a motion-based alarm system, together with an exercise sheet and solution. \u003cbr\u003e\u003cbr\u003eThis will allow you to hone your skills in the field with familiar tools, and to continue and reproduce training exercises at home.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eJos Wetzels\u003c\/strong\u003e is a co-founding partner at Midnight Blue. His research has involved reverse-engineering, vulnerability research and exploit development across various domains ranging from industrial and automotive systems to IoT, networking equipment and deeply embedded SoCs. He has discovered zero-day vulnerabilities across tech stacks ranging from bootloaders and RTOSes to proprietary protocol implementations. At Midnight Blue, he has consulted to government agencies, grid operators, and Fortune 500 companies worldwide and has been involved in the first ever public analysis of the TETRA radio standard used by police and critical infrastructure globally - uncovering several critical vulnerabilities. Prior to founding Midnight Blue, he worked as a security researcher and reverse engineer at Forescout where he developed state-of-the-art intrusion detection capabilities for Operational Technology (OT) environments. Jos is a member of the Black Hat USA Review Board and a regular conference speaker who has presented at events such as Black Hat, DEF CON, CCC, USENIX, HITB, OffensiveCon, ReCon, EkoParty, and others.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eWouter Bokslag \u003c\/strong\u003eis a co-founding partner and security researcher at Midnight Blue. He is known for the reverse-engineering and cryptanalysis of the previously secret cryptographic algorithms used in the TETRA radio standard. He has performed specialist security assessments on RF networks of law enforcement agencies, critical infrastructure, and some of the largest companies in the world. In addition, his prior research includes reverse-engineering and cryptanalysis of several proprietary in-vehicle immobilizer authentication ciphers used by major automotive manufacturers as well as co-developing the world's fastest public attack against the Hitag2 cipher. He holds a Master's Degree in Computer Science \u0026amp; Engineering from Eindhoven University of Technology (TU\/e) and designed and assisted in teaching hands-on offensive security classes for graduate students at the Dutch Kerckhoffs Institute for several years. He presented research at venues like Black Hat, DEF CON, USENIX, CCC, hardwear.io and many others.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course has the option for a proficiency certificate add-on.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThe proficiency exam will consist of a CTF-style challenge which incorporates major learnings from the training and evaluates the student's proficiency with the taught methodologies and tooling. In the unlikely event the challenge cannot be completed, a re-take opportunity is provided.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51479944364172,"sku":null,"price":4250.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2","offer_id":51479944396940,"sku":null,"price":4600.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/MidnightBluelogofulllinescentered.svg?v=1784218507"},{"product_id":"car-hacking-masterclass-attacking-defending-automotive-systems-and-infrastructure-kamel-ghali-dctlv2026","title":"Car Hacking Masterclass - Attacking \u0026 Defending Autonomous Driving Systems and Infrastructure - Kamel Ghali  - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e: Car Hacking Masterclass - Attacking \u0026amp; Defending Autonomous Driving Systems and Infrastructure\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e: Kamel Ghali\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e: Oct 1-2, 2026\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eTime\u003c\/strong\u003e: \u003c\/span\u003e\u003cspan\u003e8:30 am to 5:30 pm\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e\u003cspan\u003e: TBD\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$2,200 (w\/GST)\u003cbr\u003e\u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$2,650 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST) \u003cbr\u003e\u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST)\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003cstrong\u003eHardware:\u003c\/strong\u003e $650 (optional, if you choose to retain after the course)\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"UTF-8\"\u003e\u003cspan\u003eThis intermediate Automotive Cybersecurity and Car Hacking Masterclass delivers hands-on experience attacking and defending real vehicle systems, from in-vehicle networks and infotainment to electric vehicles, autonomous vehicles, and charging infrastructure. Participants gain practical, risk-focused insight into how modern autonomous transportation systems are compromised and secured, making the course valuable for both technical security engineers and decision-makers responsible for connected transportation systems.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eThis Automotive Cybersecurity and Car Hacking Masterclass provides an in-depth, practitioner-focused exploration of how modern vehicles are designed, attacked, and defended in today’s connected transportation ecosystem. Participants begin with a strategic, bird’s-eye view of automotive cybersecurity, grounding technical topics in real-world car-hacking case studies, regulatory drivers, and lifecycle security practices such as ISO\/SAE 21434 and threat analysis and risk assessment (TARA). By connecting observed attacks to industry standards and evolving global regulations, the course equips attendees with a clear understanding of why vehicle cybersecurity matters—not only for automobiles, but for autonomous transportation systems and other cyber-physical products operating at scale.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eA defining feature of this masterclass is its emphasis on immersive, hands-on labs that allow participants to directly apply concepts across in-vehicle networks, infotainment systems, electric vehicle charging infrastructure, and autonomous-driving technologies. Learners actively interact with CAN-based systems, diagnostic protocols, and modern vehicle defenses, progressing from protocol analysis and reverse engineering to realistic attack and mitigation scenarios. Additional labs use autonomous-vehicle simulation to examine data flows between perception, planning, control, and vehicle components, demonstrating how tampering, spoofing, and message manipulation can affect vehicle behavior and create wider operational and economic risks. Designed for an intermediate technical audience, the course delivers deep, actionable knowledge for security engineers while remaining highly valuable for architects, product managers, decision-makers, and executives seeking a practical, first-hand understanding of automotive cybersecurity risks, controls, and trade-offs.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eDay 1:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBirds-eye View of Automotive Cybersecurity \n\u003cul\u003e\n\u003cli\u003eIntroduction to Car Hacking \u0026amp; Automotive Cybersecurity\n\u003cul\u003e\n\u003cli\u003eThis section introduces participants to car hacking and automotive cybersecurity, looking at the short history of the industry and establishing the cybersecurity priorities for the automotive industry and the scope of impact car hackers have had on its evolution\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e Car Hacking Case Studies\n\u003cul\u003e\n\u003cli\u003eThis section explores real instances of vehicle security research and automotive cybercrime observed \"in the wild.\" driving home that car hacking is a reality in the age of connected transportation.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e Lifecycle Cybersecurity for Cars and Other Products\n\u003cul\u003e\n\u003cli\u003eThis section explores modern automotive cybersecurity management systems and how they have evolved to ensure vehicles are protected from threats throughout their entire operational lifecycle.\u003c\/li\u003e\n\u003cli\u003eThis section provides an in-depth analysis of the risks posed by vulnerabilities in autonomous driving systems, including autonomous logistics and transportation vehicles. It also examines the potential economic and operational impact of these vulnerabilities if exploited.\u003c\/li\u003e\n\u003cli\u003eThis content applies to more than just automobiles, and is being adopted by other industries to meet regulatory requirements for the EU Cyber Resilience Act and other global cybersecurity regulations\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003eHands-on Automotive Cybersecurity \u0026amp; Car Hacking \n\u003cul\u003e\n\u003cli\u003eHands-on Automotive Threat Analysis and Risk Assessment (TARA) and ISO 21434\n\u003cul\u003e\n\u003cli\u003eIn this section participants implement TARA hands-on, seeing first-hand how cyber risk is evaluated in vehicles and evaluating the vulnerabilities presented in the case studies shared prior to this sections.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e In-Vehicle Networks \u0026amp; CAN Bus Hands-on I\n\u003cul\u003e\n\u003cli\u003eThis section covers the technical details of CAN, a networking technology found in nearly every vehicle in the world as well as maritime systems, ICS systems, and even washing machines.\u003c\/li\u003e\n\u003cli\u003eParticipants will learn advanced technical details of the CAN protocol as well as how to transmit, receive, and reverse engineer CAN data using open-source software and industry grade CAN tools. They will complete labs to put this knowledge to use, solving CTF problems by sending and receiving CAN data, as well as reverse-engineering CAN signals.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDay 2:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBeyond the CAN Bus \n\u003cul\u003e\n\u003cli\u003eCAN Bus Hands-on II\n\u003cul\u003e\n\u003cli\u003eThis section covers more advanced applications of CAN, from diagnostic protocols implemented on top of the CAN standard to security systems implemented in CAN to protect CAN networks from eavesdropping, traffic injection attacks, and more.\u003c\/li\u003e\n\u003cli\u003eStudents will complete labs in which they must use what they learn to attack CAN systems and implement the defenses covered in the lecture content. Labs based on CAN network diagnostic protocols will also be included.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e In-Vehicle Infotainment System Security\n\u003cul\u003e\n\u003cli\u003eThis section will introduce students to the attack surfaces of in-vehicle infotainment systems - often the most vulnerable part of an automobile's architecture.\u003c\/li\u003e\n\u003cli\u003eParticipants will see demonstrations of exploits being performed against IVI systems taken from commercial vehicles and complete labs to create their own exploits for the same systems, targeting USB, Bluetooth, and other interfaces.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e Electric Vehicle \u0026amp; EV Charging Infrastructure Security\n\u003cul\u003e\n\u003cli\u003eIn this section participants will learn about the unique attack surfaces electric vehicles contain and how vulnerabilities in their charging systems and associated infrastructure can have consequences that spread much farther into society, impacting the power grids of cities and bringing logistic networks to a grinding halt.\u003c\/li\u003e\n\u003cli\u003eHands-on labs covering CAN, OCPP, PLC, and other EV charging infrastructure technology will be included in this section.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cspan\u003eAutonomous Vehicle Simulation Lab\u003c\/span\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eThis section introduces attendees to tools and resources for simulating autonomous vehicles and developing secure autonomous-driving capabilities.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\n\u003cspan\u003eAttendees will analyze data flows between autonomous-driving components and observe how communication tampering and spoofing can affect vehicle behavior.\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e Final Assessment \u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIntermediate - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eNecessary Skills\/Knowledge:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLinux Command Line Experience\u003c\/li\u003e\n\u003cli\u003eBash Scripting Experience\u003c\/li\u003e\n\u003cli\u003eDigital Signaling Understanding\u003c\/li\u003e\n\u003cli\u003eBinary Algebra\/Operations Understanding\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eSuggested Prerequisite Reading:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eJeep Hack News Video: https:\/\/www.youtube.com\/watch?v=MK0SrxBC1xs\u0026amp;pp=ygUJamVlcCBoYWNr\u003c\/li\u003e\n\u003cli\u003eJeep Hack Whitepaper: https:\/\/illmatics.com\/Remote%20Car%20Hacking.pdf\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eStudents should bring a laptop computer with at minimum the following features:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eVirtualization Enabled\u003c\/li\u003e\n\u003cli\u003eVMWare or Oracle VirtualBox Installed\u003c\/li\u003e\n\u003cli\u003eAt least one USB-A port available\n\u003cul\u003e\n\u003cli\u003eA USB hub is a optional, but can be useful for labs requiring multiple USB devices\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eAll vehicle network hardware will be lent by the instructor. The instructor will also share reference documents and pre- configured virtual machine images for use during the course ahead of time. Uniquely, this Car Hacking Training utilizes both virtualized vehicle network environments AND real vehicle hardware. This includes hardware purchased on the aftermarket as well as vehicle parts retrieved directly from real vehicles, giving students the opportunity to interact with vehicle networks as they are used in real vehicle hardware. In addition,several of the hardware modules incorporated into the course have been featured in the Automotive Pwn2Own competition from 2024, 2025, and 2026.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eThe trainer will provide all necessary equipment to complete the course. The hardware used in the course exercises and will be loaned to the students, but they have the option of purchasing the hardware to keep for $450.00 USD. The hardware platform provided is a hands-on vehicle networking and cybersecurity educational platform developed and manufactured by the instructor.\u003c\/p\u003e\n\u003cp\u003eSeveral labs in this course make use of larger industry-grade systems taken from real automobiles - allowing students to interact with real vehicular systems and develop exploits for vulnerable targets found on the market. As these systems are rather heavy, a limited number will be available for the students to use during the course but they may not be taken home by the participants.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eA seasoned expert with over eight years of experience in automotive and IoT cybersecurity, Kamel has worked across the U.S. and Japan as a vehicle penetration tester, security consultant, and car hacking trainer. He currently serves as Vice President of International Affairs for the DEF CON Car Hacking Village, where he leads global outreach and awareness efforts focused on vehicle security.\u003c\/p\u003e\n\u003cp\u003eKamel brings deep expertise in cyber-physical systems security and is fluent in English, Arabic, and Japanese. Passionate about transportation cybersecurity, he actively engages with communities worldwide to promote education and awareness in this critical domain. His community contributions include organizing major Japanese cybersecurity conferences such as CODE BLUE, TenguCon, and BSides Tokyo, and he regularly seizes opportunities to advocate for cybersecurity and privacy in connected transportation systems.\u003c\/p\u003e\n\u003cp\u003eKamel has spoken at numerous cybersecurity events around the world and is a frequent contributor to online journals and other publications, where he speaks about cyber-physical security.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course has the option for a proficiency certificate add-on. \u003c\/p\u003e\n\u003cp\u003eThe proficiency exam for this training covers both the theoretical\/high-level aspects of automotive cybersecurity taught in the course as well as proficiency in the hands-on technical aspects of the hacking of vehicle networks and other technologies taught in this course. Students are given a quiz (delivered via Google Forms or a similar platform) with questions answered either through data analysis, recollection of the course content, or solving of CTF challenges implemented on the hardware platform used in the training labs.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2 \/ Borrow","offer_id":51480135893132,"sku":null,"price":2200.0,"currency_code":"SGD","in_stock":true},{"title":"Course only - Oct 1-2 \/ Keep","offer_id":51480135925900,"sku":null,"price":2850.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2 \/ Borrow","offer_id":51480135958668,"sku":null,"price":2650.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2 \/ Keep","offer_id":51480135991436,"sku":null,"price":3300.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/Kamel2.jpg?v=1784219143"},{"product_id":"ai-soc-101-bootcamp-building-modern-security-operation-skills-with-ai-integration-rod-soto-dctlv2026","title":"AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration - Rod Soto - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e AI + SOC 101 Bootcamp: Building Modern Security Operations Skills with AI Integration\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Rod Soto\u003cbr\u003e\u003c\/span\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eOct 1-2, 2026\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eTime: \u003c\/strong\u003e8:30 am - 5:30 pm\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eTBD\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3,100 (w\/GST)\u003cbr\u003e\u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3,550 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST) \u003cbr\u003e\u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST)\u003c\/span\u003e\u003cbr\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eLearn core Security Operations Center (SOC) skills enhanced with AI-powered tooling in an intensive, lab-driven bootcamp. Students will work through realistic SOC analyst workflows—log analysis, detection, investigation, and response—while integrating modern AI\/LLM tools into their processes. This course is designed to bridge traditional SOC fundamentals with AI-driven detection, analysis, and automation, preparing participants for today’s rapidly evolving security landscape\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eThis two-day bootcamp delivers practical, hands-on training in SOC fundamentals with a strong focus on real-world workflows and AI augmentation. Students will work directly with logs, packets, SIEMs, EDR platforms, and AI tools that mirror what’s used in modern security operations.\u003c\/p\u003e\n\u003cp\u003eParticipants will start with foundational concepts—SOC roles, access controls, logging, and incident triage—then progressively move into network analysis, SIEM workflows, detection engineering, and adversarial simulation. Throughout the course, AI and LLMs are positioned as force multipliers: enhancing detection, supporting triage, summarizing evidence, and accelerating investigation.\u003c\/p\u003e\n\u003cp\u003eBy the end of the bootcamp, students will be able to:\u003cbr\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eUnderstand how a SOC operates and where a Level 1 analyst fits.\u003c\/li\u003e\n\u003cli\u003eCollect, parse, and analyze security logs from Windows, Linux, and network sensors.\u003c\/li\u003e\n\u003cli\u003eUse tools like Sysmon, Zeek, Arkime, Suricata, Elasticsearch, Splunk, and Wazuh in realistic scenarios.\u003c\/li\u003e\n\u003cli\u003eApply frameworks such as MITRE ATT\u0026amp;CK, ATT\u0026amp;CK-based kill chains, and OWASP Top 10 to detection and incident analysis.\u003c\/li\u003e\n\u003cli\u003eIntegrate AI\/LLMs into SOC workflows for triage, summarization, and threat hunting.\u003c\/li\u003e\n\u003cli\u003eRecognize and mitigate security risks introduced by AI and LLM usage (including Shadow AI and MCP-based agents).\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp style=\"text-align: left;\"\u003eThe course emphasizes practical, baseline SOC analyst competencies that are enhanced—but never replaced—by AI. Graduates will leave with a well-rounded skill set suitable for SOC Analyst 1 roles in AI-enabled environments.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eDay 1 – SOC Fundamentals \u0026amp; Core Tooling\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003c\/strong\u003eFundamentals of a SOC\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eIntroduction and instructor background\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eWhat is a Security Operations Center (SOC)?\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eRoles and responsibilities of a SOC analyst\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eSecurity posture, SecOps, and the pillars of information security (Confidentiality, Integrity, Availability)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAccess Controls \u0026amp; Operating Systems\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAccess control concepts: Authentication, Authorization, Principle of Least Privilege (PoLP), Separation of Duties (SoD)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAccess control models: MAC, DAC, RBAC, ABAC, risk-based access\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eDefense in Depth and Endpoint Detection \u0026amp; Response (EDR)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eHands-on Exercises (Access Controls)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eLinux: Mandatory and discretionary access controls (AppArmor, file permissions)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eWindows: Access controls in Active Directory, NTFS permissions, and local\/system accounts\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eWindows: Processes, integrity levels, and permissions\u003c\/li\u003e\n\u003cli\u003eSecurity Events \u0026amp; Logging\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eSecurity events vs. incidents; triage fundamentals (true\/false positives, CISA severity)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eLog structure and common formats: JSON, XML, YAML, CSV\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eText manipulation and regular expressions (regex) for log parsing\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eWindows and Linux log sources: EVTX, Syslog\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eSysmon overview and configuration\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eHands-on exercise: Installing Sysmon and detecting malicious activity in logs\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eNetwork Basics \u0026amp; Intrusion Detection\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eNetwork fundamentals for SOC analysts: packet capture, TCPDump, Wireshark\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eCore protocols: TCP\/IP, DNS, HTTP\/HTTPS\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eCommon network attacks and artifacts\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eNetwork analysis tools: Zeek, Arkime, and Suricata in SOC workflows\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eStandards \u0026amp; Frameworks\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eCVE, CWE, CAPEC\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eMITRE ATT\u0026amp;CK, ATLAS\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eOWASP Top 10\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eKey compliance frameworks and why they matter to SOCs\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eHands-on exercise: Replicating an OWASP Top 10 attack and observing\/analyzing the resulting logs\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDay 2 – SIEM, EDR, and AI-\/Agentic-Enhanced SOC Workflows\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eCentralized Logging \u0026amp; SIEM\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eCIS Critical Security Controls for log management\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eRemote log collection (WEC\/WEF, SIEM agents)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eSIEM fundamentals and core use cases\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eHands-on Exercises (Elastic Stack)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eElasticsearch setup\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eThreat discovery using search, filters, and dashboards\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eIntegrating Zeek and Windows logs (Winlogbeat)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eHands-on Exercises (Splunk)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eIntroduction to Splunk: architecture, apps, and add-ons\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eRunning Splunk in Docker and exploring the UI\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eData onboarding, basic searches, and threat discovery\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAnalyzing Suricata IDS logs in Splunk\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eEndpoint Detection \u0026amp; Response (EDR)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eEDR concepts and the role of EDR in SOC operations\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eWazuh as an open-source EDR platform\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAdversarial Simulation \u0026amp; Detection Engineering\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eIaC and modern SOC infrastructure (ephemeral\/immutable)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eDetection engineering fundamentals\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eCryptography touchpoints and SOC-adjacent teams \u0026amp; Legal considerations\u003cbr\u003e(IR, CIRT\/SERT, Legal)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAI\/LLMs, MCP, and the Agentic SOC\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAI + SOC foundations (LLMs, multimodal models, core concepts)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003ePractical SOC applications (enrichment, summarization, anomaly\u003cbr\u003edetection, agentic workflows)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eLLM\/agent usage examples and prompt best practices\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eFree and open-source LLMs (e.g., GPT4All, Ollama) and local deployment\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAgentic workflow basics(LangChain ecosystem, CrewAI, A2A)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAgentic SOC applications\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAI\/LLM\/MCP\/Agent Risks \u0026amp; Frameworks (OWASP, MITRE ATLAS)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eRisks of LLMs\/MCP\/Agents\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eShadow AI and unapproved model\/agent usage\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eMonitoring and logging requirements for LLM and agent orchestration visibility\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eOWASP Top 10 for LLMs and agentic applications\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAgentic security: monitoring and threat surface\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAI SOC Exercises\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eSetting up Ollama Web UI and describing a synthetic firewall dataset\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eAgentic security workflow: from log → detection → incident\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eDetecting LLM\/MCP abuse using log telemetry (Splunk MCP LLM SIEMulator)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eOptional: agentic workflow security analysis\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eCTF-style SOC challenges\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eBeginner to Intermediate.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eStudents should have foundational IT knowledge and basic networking familiarity. The course builds on this baseline to develop practical SOC analyst skills with integrated AI tooling. No prior SOC or AI experience is required.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBeginner Definition - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIntermediate Definition - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003eBasic understanding of networking concepts (TCP\/IP, DNS, HTTP\/HTTPS)\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eFamiliarity with Linux command-line operations\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eGeneral awareness of cybersecurity threats and terminology\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eComfort with technical content and hands-on labs\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003eLaptop with at least 16 GB RAM (32 GB recommended)\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eAbility to run virtual machines (VMware Workstation, VirtualBox, or similar)\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eMinimum 50 GB of free disk space\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eAdministrative privileges on the laptop\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003ePlease do not bring laptops with USB ports blocked. Course materials\u003cbr\u003eare provided via SSD. Corporate laptops not recommended.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003eNote: Apple M-series laptops are not compatible with the course VMs; Intel\/AMD x86-64 architecture is required.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003cspan style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003ePre-configured virtual machine images with all required tools and lab environments\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eComprehensive course workbook with exercises and reference materials\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eAccess to lab scenarios and synthetic datasets\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eDetection rule templates and practical examples\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eResource guides for continued self-study after the course\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRod Soto\u003c\/strong\u003e has over 15 years of experience in information technology and cybersecurity, with deep expertise in Security Operations Centers. He has served as a SOC support engineer, SOC engineer, security emergency response analyst, and incident responder, and currently works as a detection engineer and researcher on Splunk’s Cisco Threat Research Team. His previous roles include positions at Prolexic\/Akamai, Splunk UBA, and JASK (SOC automation).\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eRod is an accomplished cybersecurity competitor and educator. He won the Black Hat Las Vegas CTF in 2012 and the Red Alert ICS CTF at DEF CON 2022. He has presented at DEF CON, Black Hat, RSA Conference, Splunk .CONF, DerbyCon, BSides events, HackMiami, and numerous ISSA, ISC2, and OWASP chapters. His work and commentary have appeared in major media outlets including Rolling Stone, Pentest Magazine, Forbes, VICE, BBC, Univision, Fox News, and CNN.\u003c\/p\u003e\n\u003cp\u003eRod’s current research at Splunk–Cisco focuses on securing AI and LLM ecosystems, including:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeveloping the Splunk Technology Add-on for Ollama to monitor Shadow AI deployments.\u003c\/li\u003e\n\u003cli\u003eCreating detection frameworks for Microsoft 365 Copilot security threats.\u003c\/li\u003e\n\u003cli\u003eAnalyzing LLM-based attack vectors such as the PromptLock ransomware proof-of-concept.\u003c\/li\u003e\n\u003cli\u003ePublishing on monitoring MCP servers (open-source LLM MCP Security Monitoring Tool).\u003c\/li\u003e\n\u003cli\u003eUsing RAG with Splunk ESCU and MLTK to build AI-enhanced security detections aligned with the MITRE ATLAS framework.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eHe combines frontline SOC experience, active research, and a strong teaching background to deliver training that is both practical and current.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course has the option for a proficiency certificate add-on. \u003c\/p\u003e\n\u003cp\u003eStudents who purchase the proficiency exam add-on will complete a capstone challenge simulating a real-world SOC investigation (CTF-style).\u003c\/p\u003e\n\u003cp\u003eThe exam covers:\u003cbr\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eAlert triage\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eThreat detection\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eIncident analysis\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eResponse documentation\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eStudents must score at least 75% to pass.\u003c\/p\u003e\n\u003cp\u003eThose who opt in will receive:\u003cbr\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDetailed performance feedback\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eIndividualized coaching on areas for improvement\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eA verified certificate of proficiency suitable for professional portfolios and employment verification\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51489743995020,"sku":null,"price":3100.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2","offer_id":51489744027788,"sku":null,"price":3550.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/rodsoto.jpg?v=1784252534"},{"product_id":"breaking-physical-access-control-electrical-fundamentals-rfid-credentials-and-hands-on-offense-red-team-alliance-dctlv2026","title":"Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense - Red Team Alliance - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Red Team Alliance\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eDates\u003c\/strong\u003e: Oct 1-2, 2026\u003cbr\u003e\u003cstrong\u003eTime\u003c\/strong\u003e: 8:30 am to 5:30 pm\u003cbr\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e: TBD\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3,500 (w\/GST)\u003cbr\u003e\u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3,950 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST) \u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eHardware:\u003c\/strong\u003e $870 \u003cmeta charset=\"utf-8\"\u003e(optional) - All students in class will be issued and make use of a Proxmark3 RDV4.01 with an array of test RFID credentials and re-writable RFID credentials, an ESPkey and service tools, and our custom RFID Door Simulator and workbench analysis unit.  If you wish to retain this equipment at the end of class, students may opt to pay this additional equipment fee during registration.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eMost security professionals have never received formal training on the physical access control systems they're paid to test. This two-day course fixes that with hands-on labs using real commercial hardware, covering everything from electrical fundamentals and sensor technologies to RFID credential attacks and Wiegand interception.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis two-day intensive combines Red Team Alliance's IDAC 101 (Access Control and Intrusion Detection: Common Concepts and Foundation) and PACS 201 (Physical Access Control Systems: Commercial Platforms and Designs) into a single, hands-on training package. Over two full days of instruction, students will build a comprehensive understanding of how physical security systems work from the ground up, then learn to identify and exploit weaknesses in commercial access control installations. This is the same curriculum used in RTA's professional training program, delivered at DEF CON for the first time as a combined package.\u003c\/p\u003e\n\u003cp\u003ePhysical access control is one of the most overlooked and misunderstood areas in security. Organizations spend millions on electronic locks, credentials, and alarm systems, yet the professionals tasked with testing these systems rarely receive formal training on how they actually work. This course changes that. Students will work with real commercial hardware, build circuits on trainer boards, intercept credential data, and clone RFID badges using industry-standard tools including the Proxmark3 RDV4, which is provided to every student during class.\u003c\/p\u003e\n\u003cp\u003eWhether you are a penetration tester looking to expand into physical security, a red team operator building foundational skills, or a security consultant who needs to understand what you are assessing, this two-day program delivers the hands-on experience and conceptual depth that sets RTA training apart from conference talks and YouTube videos.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003eCourse Outline:\u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e#### Day 1: Intrusion Detection and Access Control Foundations (IDAC 101)\u003c\/p\u003e\n\u003cp\u003e#### Low-Voltage Electrical Fundamentals\u003c\/p\u003e\n\u003cp\u003e- Key Electricity Concepts for Physical Security Applications\u003cbr\u003e- Voltage, Current, and Resistance in Low-Voltage Installations\u003cbr\u003e- Power Supplies, Circuits, and Common Wiring Configurations\u003c\/p\u003e\n\u003cp\u003e#### System Architecture: The Shared DNA of PACS and PIDS\u003c\/p\u003e\n\u003cp\u003e- Both Platforms as Embedded Systems: Central Controller Boards Connected to Remote Low-Voltage Devices\u003cbr\u003e- Input Devices, Output Devices, and Programmed Logic\u003cbr\u003e- How Modern PACS Often Functions as a Superset of PIDS Capabilities\u003c\/p\u003e\n\u003cp\u003e#### Sensor Technologies Common to Both Platforms\u003c\/p\u003e\n\u003cp\u003e- Passive Infrared (PIR) Motion Sensors\u003cbr\u003e- Magnetic Reed Switches and Door\/Window Contacts\u003cbr\u003e- Hands-On: Working with Common Sensor Components\u003c\/p\u003e\n\u003cp\u003e#### Wiring, Terminations, and Field Installation\u003c\/p\u003e\n\u003cp\u003e- Common Termination Types Encountered in the Field\u003cbr\u003e- How Systems Are Designed, Wired, and Installed\u003cbr\u003e- What Red Teamers Need to Recognize During Reconnaissance\u003c\/p\u003e\n\u003cp\u003e#### Current-Sensing Loops and Supervision\u003c\/p\u003e\n\u003cp\u003e- How Input Devices Use Current-Sensing Loops\u003cbr\u003e- End-of-Line Resistors (EOLR): What They Are, How They Work, How to Identify Them, and Their Limitations\u003cbr\u003e- Supervised vs. Unsupervised Circuits\u003c\/p\u003e\n\u003cp\u003e#### Identifying PACS and PIDS in the Field\u003c\/p\u003e\n\u003cp\u003e- Visual Hallmarks and Characteristics of Installed Systems\u003cbr\u003e- Recognizing System Presence During Physical Assessments\u003c\/p\u003e\n\u003cp\u003e#### Business Drivers and Design Constraints\u003c\/p\u003e\n\u003cp\u003e- Why Physical Security Controls Are Designed the Way They Are\u003cbr\u003e- Cost, Compliance, and Operational Factors That Shape Implementations\u003c\/p\u003e\n\u003cp\u003e---\u003c\/p\u003e\n\u003cp\u003e#### Day 2: Physical Access Control Systems (PACS 201)\u003c\/p\u003e\n\u003cp\u003e#### PACS Architecture and Design Principles\u003c\/p\u003e\n\u003cp\u003e- System Components: Credentials, Readers, Input Devices, Output Devices, Controllers, and Management Software\u003cbr\u003e- Standalone vs. Non-Standalone Readers\u003cbr\u003e- Centralized vs. Decentralized Authentication Architectures\u003cbr\u003e- Review of Commercial Platforms Commonly Found Worldwide\u003c\/p\u003e\n\u003cp\u003e#### Reader-to-Controller Communication\u003c\/p\u003e\n\u003cp\u003e- The Wiegand Protocol: History, How It Works, Modern Usage, and Why It Is Vulnerable\u003cbr\u003e- Wiegand Data Formats\u003cbr\u003e- The Fundamental \"Wiegand Problem\" in Modern Installations\u003cbr\u003e- Forward-Looking Protocols Such as OSDP, SSCP, and Others\u003c\/p\u003e\n\u003cp\u003e#### Credential Technologies as a Concept\u003c\/p\u003e\n\u003cp\u003e- How RFID Credentials Work: Power Harvesting, Data Transmission, and Reader Interaction\u003cbr\u003e- Card and Technology Data Models\u003cbr\u003e- Low-Frequency vs. High-Frequency Technologies\u003c\/p\u003e\n\u003cp\u003e#### Introduction to the Proxmark3\u003c\/p\u003e\n\u003cp\u003e- Hardware Overview and Setup\u003cbr\u003e- Reading and Identifying Unknown Credentials\u003cbr\u003e- Cloning and Emulation Fundamentals\u003cbr\u003e- Building Your Credential Analysis Workflow\u003c\/p\u003e\n\u003cp\u003e#### Commercial RFID Credential Technologies In-Depth\u003c\/p\u003e\n\u003cp\u003e- Common Commercial Credential Formats and How They Differ\u003cbr\u003e- Reading, Cloning, and Emulation Techniques\u003cbr\u003e- Working with Writable Credentials\u003c\/p\u003e\n\u003cp\u003e#### Wiegand Interception with ESPKey\u003c\/p\u003e\n\u003cp\u003e- How the ESPKey Works\u003cbr\u003e- Installation Points and Techniques\u003cbr\u003e- Capturing and Replaying Credentials\u003c\/p\u003e\n\u003cp\u003e#### Hands-On Labs Throughout\u003c\/p\u003e\n\u003cp\u003e- Building and Testing Circuits on the Trainer Board\u003cbr\u003e- Access Control Wiring and Component Installation\u003cbr\u003e- Working with the RFID Door Simulator\u003cbr\u003e- Credential Reading, Cloning, and Emulation Exercises\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eBeginner to Intermediate \u003c\/p\u003e\n\u003cp\u003eBeginner Definition - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003cp\u003eIntermediate Definition - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eAlthough this course provides necessary material and context for physical security professionals of all levels, no prior experience with physical security systems is required.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cmeta charset=\"utf-8\"\u003eComputer with administrative access and permission to install software. Windows 11 is the official platform used in class. Virtual Machines and other operating systems have historically performed inconsistently with the software being used. Laptop should not be running in restricted \"S Mode\" for Windows.  Other operating systems are permitted, but students should understand that live technical support may not be available for OS-specific issues. Students may install the software on a Linux or MacOS system, as well, but those doing so should ensure that they have ready access to a native Windows 11 machine if it becomes needed.\u003c\/p\u003e\n\u003cp\u003eIf a student has their own Proxmark or FlipperZero that is fine, and we're happy to get these devices updated with the latest firmware and modifications, but classroom units of these and other tools and hardware will be available to all students.  If students have RFID credentials which they are particularly interested in exploring, they may also bring those for analysis at the end of class.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eThe course price includes several components used throughout both days of instruction. All items are yours to keep for continued practice after class:\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e- Intrusion Detection and Access Control Trainer Board\u003cbr\u003e- USB-C Power Supply with USB-PD Trigger Cable\u003cbr\u003e- Commercial ANSI Electric Strike\u003cbr\u003e- Commercial Door Position Indicators\u003cbr\u003e- Hook-Up Wire and Field Terminators\u003cbr\u003e- End-of-Line Resistor Variety Pack\u003cbr\u003e- Magnetic Reed Switch with Trigger Magnet\u003cbr\u003e- Mini Breadboard\u003c\/p\u003e\n\u003cp\u003eFor an optional hardware fee ($670), students can keep a kit that provides a complete RFID testing platform for continued practice after class. Students will receive access to this equipment during Day 2 of instruction, regardless of purchase:\u003c\/p\u003e\n\u003cp\u003e- Standalone RFID Reader\u003cbr\u003e- RFID Door Simulator\u003cbr\u003e- RFID Testing Credential Pack\u003cbr\u003e- ESPKey Wiegand Field Interception Tool\u003c\/p\u003e\n\u003cp\u003eA Proxmark3 RDV4 will be provided to every student for use during class. Students who wish to purchase a Proxmark3 to keep will have the opportunity to do so.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eBabak Javadi \u003c\/strong\u003eis the President and Founder of The CORE Group, and one of the original co-founding Directors of TOOOL, The Open Organisation of Lockpickers. As a keystone member of the security industry, he is well-recognized expert in professional circles hacker community. Babak's expertise extends to a wide range of security disciplines ranging from high security mechanical cylinders to alarm systems \u0026amp; physical access control systems. Over the past fifteen years Babak has presented and provided trainings a wide range of commercial and government agencies, including Black Hat, The SANS Institute, the USMA at West Point, and more.\u003c\/p\u003e\n\u003cp\u003e\u003cmeta charset=\"UTF-8\"\u003e\u003cspan\u003e\u003cstrong\u003eJames Matlock\u003c\/strong\u003e\u003c\/span\u003e\u003cspan\u003e is a former U.S. Army unmanned aerial vehicle (UAV) operator and combat veteran.  Upon his departure from the Army, James applied his military experience insecurity to enhancing security services in the enterprise space.  Building upon his information technology and physical security experience, James joined Red Team Alliance and Red Team Tools in 2022, where he supports security evaluation services and hands-on professional training.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003eWhile paying the bills as a physical penetration specialist with The CORE Group and the Director of Education for Red Team Alliance, \u003cstrong\u003eDeviant Ollam\u003c\/strong\u003e also sat on the Board of Directors of the US division of TOOOL --The Open Organisation Of Lockpickers -- for 14 years... acting as the the nonprofit's longest-serving Board Member. His books Practical Lock Picking and Keys to the Kingdom are among Syngress Publishing's best-selling pen testing titles. In addition to being a lockpicker, Deviant is also a SAVTA certified safe technician, a GSA certified safe and vault inspector, member of the International Association of Investigative Locksmiths, a Life Safety and ADA Consultant, and an NFPA Fire Door Inspector. At multiple annual security conferences Deviant started Lockpick Village workshop areas, and he has conducted physical security training sessions for Black Hat, the SANS Institute, DeepSec, ToorCon, HackCon, ShakaCon, HackInTheBox, ekoparty, AusCERT, GovCERT, CONFidence, the FBI, the NSA, DARPA, the National Defense University, Los Alamos National Lab, the United States Naval Academy at Annapolis, and the United States Military Academy at West Point.\u003cstrong\u003e\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eCourse Progression\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eCompleting this two-day training fulfills both the IDAC 101 and PACS 201 prerequisites for Red Team Alliance's in-depth PACS program. After this course, students are prepared to advance to any PACS 21x Regional Course:\u003c\/p\u003e\n\u003cp\u003e- \u003cstrong\u003ePACS 212\u003c\/strong\u003e: North American Platforms and Credential Technologies\u003cbr\u003e- \u003cstrong\u003ePACS 213\u003c\/strong\u003e: European Platforms and Credential Technologies\u003cbr\u003e- \u003cstrong\u003ePACS 214\u003c\/strong\u003e: Australian Platforms and Credential Technologies\u003c\/p\u003e\n\u003cp\u003eOnly one regional course is required to progress to the PACS 22x series and beyond. Students interested in the Physical Intrusion Detection Systems (PIDS) track are also prepared to advance to PIDS 200-level coursework.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2 \/ Borrow","offer_id":51489895350412,"sku":null,"price":3500.0,"currency_code":"SGD","in_stock":true},{"title":"Course only - Oct 1-2 \/ Keep","offer_id":51489895383180,"sku":null,"price":4370.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/DEFCONLinkedInAdImage.jpg?v=1784256247"},{"product_id":"vs-s-rad-satellite-radio-analysis-disruption-milenko-starcik-andrzej-olchawa-ricardo-fradique-dctlv2026","title":"VS: S-RAD (Satellite-Radio Analysis \u0026 Disruption) - Andrzej Olchawa, Ricardo Fradique \u0026 André Cirne - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e VS: S-RAD (Satellite-Radio Analysis \u0026amp; Disruption)\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Andrzej Olchawa, Ricardo Fradique \u0026amp; André Cirne\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eDates\u003c\/strong\u003e: Oct 1-2, 2026\u003cbr\u003e\u003cstrong\u003eTime\u003c\/strong\u003e: 8:30 am to 5:30 pm\u003cbr\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e: TBD\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3,100 (w\/GST)\u003cbr\u003e\u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3,550 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST) \u003cbr\u003e\u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST)\u003cbr\u003e\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eIf you always wondered how it would be to talk with the stars, this is the right place for you. This hands-on course will teach you how to understand some of the satellite communications that surround us every day, as well as how to use that knowledge to target space missions.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eAs space systems become increasingly critical to communications, navigation, and national infrastructure, understanding their unique protocols, RF characteristics, and operational dependencies is vital for identifying risks before adversaries do.\u003c\/p\u003e\n\u003cp\u003eThis 2-day course will teach you how to analyse and exploit satellite and groundstation systems using software only in a safe lab environment. We will go over satellite architecture and common link protocols, as well as SDR fundamentals. The hands-on labs cover protocol analysis and exploitation, simulated attacks, and how they can be combined with more traditional vulnerabilities to compromise space missions.\u003c\/p\u003e\n\u003cp\u003eBy the end of the course participants will be able to demonstrate a full, nondestructive red team chain of compromise in a controlled environment and produce actionable remediation and detection recommendations.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eDay 1 - Foundations, Recon, SDR \u0026amp; RF \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eMorning\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIntro, rules of engagement, legal \u0026amp; lab safety\u003c\/li\u003e\n\u003cli\u003eSatellite systems architecture\u003c\/li\u003e\n\u003cli\u003eThreat model \u0026amp; attack surface mapping\u003c\/li\u003e\n\u003cli\u003eProtocols and data links: lecture + guided packet lab\u003cbr\u003e\n\u003cul\u003e\n\u003cli\u003eDecode CCSDS captures\u003c\/li\u003e\n\u003cli\u003eIdentify TM\/TC fields and payloads\u003c\/li\u003e\n\u003cli\u003eUse Wireshark for analysis and Scapy to parse, craft, and modify frames.\u003c\/li\u003e\n\u003cli\u003eProduce a brief report describing a found issue (e.g., replayable TC, plaintext\u003cbr\u003epayload).\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eAfternoon\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSDR fundamentals (software-only): lecture + guided labs with prerecorded IQs\u003cbr\u003e\n\u003cul\u003e\n\u003cli\u003eLearn IQ basics, sampling, waterfalls, and constellation plots using prerecorded IQ files.\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eBuild and run GNU Radio flowgraphs\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eDemodulate a simulated BPSK\/CCSDS capture, extract packets, and visualize signal manipulations (frequency shift, filtering, SNR changes).\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eProduce short notes with screenshots and a short checklist of what parameter changes did.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003eRF attacks (simulated): replay\/spoofing\/manipulation labs\u003cbr\u003e\n\u003cul\u003e\n\u003cli\u003eDemonstrate practical replay and basic spoofing attacks using prerecorded IQ files and purely software tools.\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eSimple replay: repeat a segment containing a TC so it is received twice by the demodulator (demonstrates replay vulnerability).\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eTime-shift replay: extract a TC segment and insert it later to simulate delayed\/replayed command (shows timing effects).\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eSegment injection\/splice: insert a synthesized TC (crafted payload) into the IQ stream (spoof).\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003eDay 1 wrap \u0026amp; prep for Day 2\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDay 2 - Recon, Ground-Station Attacks, TM\/TC, Post-Compromise \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eMorning\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eRecap \u0026amp; objectives\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eOSINT \u0026amp; reconnaissance: guided build of target profile\u003cbr\u003e\n\u003cul\u003e\n\u003cli\u003eBuild a comprehensive target profile for a smallsat operator including orbital data, infrastructure components, personnel, software stack, and likely attack surfaces.\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eProduce an asset\/attack-surface map and prioritized reconnaissance plan.\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003eGround-station network attack surfaces + small hands-on exploit lab\u003cbr\u003e\n\u003cul\u003e\n\u003cli\u003eSimulate exploiting a vulnerable ground-station web console, escalate to operator workstation\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eAfternoon\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eTM\/TC deep-dive: message structures, Scapy toolkits, and full hands-on lab\u003cbr\u003e\n\u003cul\u003e\n\u003cli\u003eReview CCSDS TM\/TC message structure, authenticated vs unauthenticated flows, and safe crafting\/injection of simulated telecommands into a controlled receiver\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eDemonstrate replay, modification, and detection techniques using Scapy-based toolkits.\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003eSimulated red-team exercise\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eIntermediate - \u003cspan\u003eThe student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e• Basic Linux command-line proficiency (shell, file editing, package install).\u003cbr\u003e• Fundamental networking knowledge (TCP\/IP, DNS, HTTP, basic routing).\u003cbr\u003e• Familiarity with Python (reading\/writing simple scripts; using pip).\u003cbr\u003e• Experience with packet analysis tools (Wireshark\/tshark).\u003cbr\u003e• Introductory radio concepts (IQ samples, sampling, basic modulation) - helpful but not mandatory.\u003cbr\u003e• Ability to run a VM on a laptop (VirtualBox\/VMware; 8+ GB RAM recommended).\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eTrainees only need to bring a laptop capable of running a VM (VirtualBox\/VMware; 8+ GB RAM recommended).\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eSlides, lab workbooks, prebuilt VM with all required tools and exercise files\u003cstrong\u003e\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eAndrzej Olchawa \u003c\/strong\u003eis an offensive security researcher with over 15 years of experience in the space industry. In recent years, Andrzej has specialized in vulnerability research, exploit development, and the exploitation of space systems and protocols. He has published numerous research papers on space systems security and has presented at prominent security conferences, including Black Hat USA, DEF CON, multiple BSides, and others. He holds several industry-standard certifications and has been credited with numerous CVEs.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eRicardo Fradique\u003c\/strong\u003e is a cybersecurity engineer at Visionspace, where he focuses on vulnerability research and training content development targeting space systems and protocols. His research has produced several CVEs and contributed to technical briefings at leading security conferences including Black Hat and DEF CON, and he holds multiple industry certifications.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eAndré Cirne \u003c\/strong\u003eis a Cybersecurity Engineer at VisionSpace, where he develops solutions for space, conducts vulnerability research, and develops cybersecurity training. Previously, he worked as a research assistant, co-authoring several academic publications in the field of embedded and hardware security. He holds a master's degree in information security and a Ph.D. in computer science. In his free time, he's also an amateur radio enthusiast.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cmeta charset=\"utf-8\"\u003eThis course has the option for a proficiency certificate add-on. \u003c\/p\u003e\n\u003cp\u003eStudents have the option to obtain a proficiency certificate based on their performance in the final activity. This constitutes a CTF-based red team engagement including most of the content delivered during the training. While the activity itself will be available to all students, those opting for the certification must obtain over 80% of the flags in the environment and provide a written report detailing all findings and exploits, as well as recommended fixes for the issues found. The report is then graded by the trainers, with detailed feedback, and the final passing grade is dependent on both scores.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51489896497292,"sku":null,"price":3100.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2","offer_id":51489896530060,"sku":null,"price":3550.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/VS-S-Rad_logo.png?v=1784256317"},{"product_id":"modern-agentic-ai-engineering-and-security-joseph-mlodzianowski-dctfall26","title":"Modern Agentic AI Engineering and Security - Joseph Mlodzianowski  - DCTFall26","description":"\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eName of Training: \u003c\/b\u003eModern Agentic AI Engineering and Security\u003cbr\u003e\u003cb\u003e\u003c\/b\u003e\u003cb\u003eTrainer(s): \u003c\/b\u003eJoseph Mlodzianowski\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Oct 1-2, 2026\u003c\/span\u003e\u003cbr\u003e\u003cb\u003eVenue:\u003c\/b\u003e TBD\u003cbr\u003e\u003cb\u003eEarly Bird Cost:\u003c\/b\u003e $2500 SGD (w\/GST)\u003cbr\u003e\u003cb\u003eRegular Cost:\u003c\/b\u003e $2,950 SGD (w\/GST)\u003cbr\u003e\u003cspan style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003e\u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD (w\/GST)\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eShort Summary:\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eThis two-day intensive bootcamp delivers practical, hands-on training tooling in an lab-driven bootcamp that will take a student from beginner to intermediate, with some advanced capabilities.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eCourse Description:\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eThe course is designed to \u003cspan style=\"mso-spacerun: yes;\"\u003e \u003c\/span\u003estarts with an overview of the main two AI coding agents, with a heavy emphasis on OpenAI Codex, and secondary on Claude Code. On the first day you will be immersed in to moving from coding to code to using coding agents to plan, build, verify, troubleshoot and fix simple to more complex issues. Modern AI coding agents can do more than write code: they can remember project context, read instructions, call tools, use app integrations, consult MCP servers, and coordinate specialized sub-agents. This course shows how to put those pieces together without creating an ungoverned automation mess.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003e\u003cspan style=\"font-size: 14.0pt; line-height: 115%;\"\u003eCourse Outline:\u003c\/span\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 1 — The Modern AI Software Engineering Stack\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eHow AI-assisted development has evolved beyond autocomplete\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eThe model–agent–tool–workflow architecture\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCodex interfaces and repository-aware development\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRepository instructions and external tool integrations\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity, Sandboxing, approvals, least privilege, and human review\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eHow to analyze and safely approach an unfamiliar repository\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eAnalyze, bound, and validate a repository change\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 2 — Installing and Configuring Codex\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eInstallation and runtime considerations\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAuthentication and credential boundaries\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eUser-level, project-levels and security configuration\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eConfiguration precedence and repository trust\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAdvanced Sandbox and approval settings\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDiagnosing an effective Codex configuration without exposing secrets\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eVerify and explain a safe Codex setup\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 3 — Context Engineering\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eWhy incomplete or excessive context causes failures\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSources of repository and task context\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSelecting relevant files, tests, errors, and documentation\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining assumptions, constraints, and exclusions\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eConstructing a structured context packet\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eBalancing completeness with context discipline\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eBuild and validate a bounded context packet\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 4 — Mastering AGENTS.md\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eHow durable repository guidance works\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eInstructions, discovery and precedence\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRepository-level and directory-level guidance\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eWriting concise and actionable engineering instructions\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity controls for Agents\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eHandling conflicting, outdated, or oversized guidance\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSeparating behavioral instructions from enforcement controls\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eAuthor and verify repository and subtree guidance\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 5 — Steering Codex\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEngineering task postures such as Explore, Plan, Implement, Test, and Review\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining deliverables, constraints, validation, and stopping conditions\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003ePlanning before complex or ambiguous implementation\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity Considerations and Moving safely between task postures\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEscalation and retry boundaries\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEvidence-based completion decisions\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eBuild and validate an evidence-gated steering plan\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 6 — Cost-Effective Models and Modes\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEvaluating work by complexity, ambiguity, and risk\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSelecting appropriate reasoning and execution approaches\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMeasuring latency, retries, context, and review effort\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eConsidering total engineering cost instead of model cost alone\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining escalation thresholds and budgets\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAvoiding unsupported cost-saving claims\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity models and secure approaches\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eBuild a measurable model-role decision\u003c\/b\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 7 — Advanced Codex Development\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eBreaking complex work into dependency-aware tasks\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003ePlanning repository changes before implementation\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eUsing branches and isolated checkouts appropriately\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eImplementing changes within bounded scope\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity and Layered testing and validation\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eReviewing diffs, addressing findings, and preparing handoffs\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003ePlan, implement, test, review, and hand off a bounded change\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 8 — MCP Servers and Tool Integration\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMCP host, client, server, and tool architecture\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCapability discovery and tool contracts\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTransport, lifecycle, schema, and result handling\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIdentity, data, side effects, and authorization boundaries\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eConfiguring and operating MCP integrations\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMonitoring, disabling, and safely retiring integrations\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eCore lab: \u003cb\u003eInspect, invoke, constrain, validate, and retire a local MCP tool\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eOptional Lab 8.1 — Five Engineering MCP Servers\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents explore:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eOpenAI documentation integration\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eVersion-aware library documentation\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eGitHub repository workflows\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eBrowser-based engineering workflows\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDesign-system and Figma workflows\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCanaries, monitoring, disablement, and removal\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eDeploy and monitor five engineering MCP servers\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eRecommended Lab 8.2 — Supply-Chain Security\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l0 level1 lfo10; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eServer admission and ownership checks\u003c\/li\u003e\n\u003cli style=\"mso-list: l0 level1 lfo10; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSource and dependency verification\u003c\/li\u003e\n\u003cli style=\"mso-list: l0 level1 lfo10; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eVersion and artifact integrity\u003c\/li\u003e\n\u003cli style=\"mso-list: l0 level1 lfo10; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eThreat modeling before installation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eThreat-model and evaluate an MCP server before admission\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eSupplemental Lab 8.3 — Identity and Authorization\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l7 level1 lfo11; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAuthentication versus authorization\u003c\/li\u003e\n\u003cli style=\"mso-list: l7 level1 lfo11; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eLeast-privilege scopes\u003c\/li\u003e\n\u003cli style=\"mso-list: l7 level1 lfo11; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eToken audience and identity separation\u003c\/li\u003e\n\u003cli style=\"mso-list: l7 level1 lfo11; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTesting permitted and denied behavior\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eDesign and verify MCP identity and authorization boundaries\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eSupplemental Lab 8.4 — Runtime and Secret Boundaries\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l13 level1 lfo12; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTransport and process isolation\u003c\/li\u003e\n\u003cli style=\"mso-list: l13 level1 lfo12; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEnvironment and secret handling\u003c\/li\u003e\n\u003cli style=\"mso-list: l13 level1 lfo12; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eFilesystem and network restrictions\u003c\/li\u003e\n\u003cli style=\"mso-list: l13 level1 lfo12; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecure runtime configuration\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eHarden MCP transport, runtime, and secret boundaries\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eSupplemental Lab 8.5 — Tool and Side-Effect Safety\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l14 level1 lfo13; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTool schema and contract review\u003c\/li\u003e\n\u003cli style=\"mso-list: l14 level1 lfo13; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eInput and output validation\u003c\/li\u003e\n\u003cli style=\"mso-list: l14 level1 lfo13; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRead versus write operations\u003c\/li\u003e\n\u003cli style=\"mso-list: l14 level1 lfo13; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eApproval boundaries and dangerous side effects\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eEvaluate tool contracts, content, and side effects\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eSupplemental Lab 8.6 — Monitoring and Incident Response\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMCP health and security monitoring\u003c\/li\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDetecting unexpected tools or behavior\u003c\/li\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity Controls and Best Practices\u003c\/li\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAlerting and audit evidence\u003c\/li\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eContainment, recovery, and credential rotation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eMonitor and respond to an MCP security incident\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 9 — Claude Code as a Complementary Tool\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eComparing engineering tools using evidence\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSelecting the appropriate tool for a task\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eClaude Code context and control concepts\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003ePortable repository instructions\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAvoiding conflicting simultaneous writers\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCreating governed handoffs between tools\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eSelect and govern a complementary-tool workflow\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 10 — AI Development Workflow Engineering\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDesigning an end-to-end AI-assisted development lifecycle\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining states, owners, inputs, outputs, and gates\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCreating executable validation and evidence chains\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eManaging permissions, failures, and escalation\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRollback and release controls\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eWorkflow monitoring, economics, and improvement\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eDesign and validate a governed AI delivery workflow\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 11 — Multi-Agent and Review Workflows\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eWhen parallel agents are beneficial\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTask independence and dependency graphs\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining agent roles, context, authority, and budgets\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIsolating parallel changes\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIdentifying textual and semantic conflicts\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIndependent review and finding adjudication\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSafe integration and stopping\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eDesign and validate a safe parallel task and review workflow\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 12 —\u003cspan style=\"mso-spacerun: yes;\"\u003e  \u003c\/span\u003eAI Agentic \u0026amp; Platform Engineering Rollup\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents apply the entire course through:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eA bounded enterprise change request\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eInstruction and context analysis\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSurface, execution, cost, and tool decisions\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMinimal implementation\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eLayered validation\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity and least-authority controls\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIndependent review and remediation\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRelease, rollback, and residual-risk decisions\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eA short technical defense\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eAgentic lab:\u003c\/b\u003e Implement, validate, review, and defend an enterprise change\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eOptional Chapter 12.5 — AI Code Engineering Best Practices\u003c\/b\u003e\u003cb\u003e\u003c\/b\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eWhat Students Should Bring: \u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eLaptop with at least 16 GB RAM (32 GB recommended) \u0026amp; 60gb free disk space\u003c\/li\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eOperating system with support and ability to run virtual machines (VMware Workstation, VirtualBox, or similar virtualization platform)\u003c\/li\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eA ChatGPT (Codex)\u003cspan style=\"mso-spacerun: yes;\"\u003e  \u003c\/span\u003e$20\/Month plan and a separate free account plan and\/or Claude Code $20 a month\u003cspan style=\"mso-spacerun: yes;\"\u003e  \u003c\/span\u003eand a separate free limited account plan.\u003c\/li\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAdministrative privileges on the laptop\u003c\/li\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eA Virtual Machine with Ubuntu 26.04 or newer installed and updated.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eIntermediate - The student has education, some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli class=\"MsoNormal\"\u003eStudents should have foundational Coding\/Programing knowledge and beginner exposure to intermediate Codex and Claude Code familiarity.\u003c\/li\u003e\n\u003cli class=\"MsoNormal\"\u003eUnderstanding of Defense in Depth, Security Frameworks like NIST CSF 2.0\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003e\u003cspan\u003e\u003c\/span\u003eA laptop with browser access is ideal, preferably a personal laptop without network restricting tools.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eDetails coming soon.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003e\u003cstrong\u003eJoseph Mlodzianowski\u003c\/strong\u003e \u003c\/span\u003eis an information security aficionado, author, keynote speaker and adventurer; he started multiple villages at RSA Conference, DEF CON, and BLACK HAT, among others, including founding the original Red Team Village at RSAC and Def Con. Joseph has extensive expertise in cybersecurity infrastructure and architecture with over 25 years leading large teams of Cybersecurity and Network engineers, project managers, and architects in the design, deployment, and monitoring of various ranges of technologies in highly complex and rigorous environments. He designed and deployed a number of multi-million dollar datacenters from inception to completion for the Department of Defense in support of cybersecurity program deployments and critical infrastructure. Joseph is a AI Datacenter Cybersecurity Architect for OpenAI. Previously a Secure Network Data-center Architect at the Department of Defense, and before that a Lead Cybersecurity Data Center Architect at Cisco Systems Federal, for thirteen years building very large datacenters for ML and AI systems, for the Department of Defense. His experience extends beyond Designing, architecting, and deploying nearly two hundred data centers in commercial, private and public sector as highly restrictive environments.  Follow him on X @cedoxx , Facebook and Linkedin.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003eTwo-hour combination of hands-on project build and multiple questions with evidence.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51494589825164,"sku":null,"price":2500.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2","offer_id":51494589857932,"sku":null,"price":2950.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/joseph_716e153b-fc6e-4a7a-ab4c-ecdb319a50f5.png?v=1784676533"},{"product_id":"aws-real-world-attack-analysis-threat-detection-in-the-cloud-in-ming-loh-wei-chea-ang-dcsgfall26","title":"AWS Real-World Attack Analysis: AI-Assisted Threat Detection in the Cloud - In Ming Loh \u0026 Wei Chea Ang - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e AWS Real-World Attack Analysis: AI-Assisted Threat Detection in the Cloud\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e In Ming LOH \u0026amp; Wei Chea ANG\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eOct 1-2, 2026\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eTime: \u003c\/strong\u003e8.30am - 5.30pm\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e TBD\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e: \u003c\/strong\u003e\u003c\/span\u003e\u003cspan\u003e$2,250 (w\/GST)\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$2,700 (w\/GST)\u003cbr\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003eThis comprehensive, hands-on course equips security teams with the practical skills to master AWS security services and CloudTrail analysis, moving beyond theory to effectively detect and respond to modern attack techniques like privilege escalation and data exfiltration. Attendees will leave with a robust security foundation and the proven ability to investigate and defend their AWS infrastructure, directly strengthening their organization's cloud security posture.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cmeta charset=\"utf-8\"\u003eThis course is designed to equip security teams with the essential knowledge and practical skills needed to safeguard their AWS environments from modern threats. Participants will gain a deep understanding of core AWS security services, common attack vectors, and the capabilities of AWS CloudTrail for effective threat detection and response. Through hands-on labs, students will begin by configuring fundamental AWS services like Identity and Access Management (IAM), Amazon Elastic Compute Cloud (EC2), and AWS CloudTrail, establishing a robust foundation for security monitoring.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eBuilding upon this foundation, participants will engage in various investigation scenarios, analyzing CloudTrail data to identify and investigate various attack techniques demonstrated by the instructor. This practical approach allows students to master the analysis of CloudTrail logs and uncover suspicious activity. They will learn to identify prevalent attack techniques, such as privilege escalation and data exfiltration.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course empowers security professionals to build a robust security posture and effectively defend their AWS infrastructure against evolving threats.\u003cbr\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cmeta charset=\"utf-8\"\u003eTopic 1: AWS Fundamentals (Day 1)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eAWS Overview: Introducing the AWS core concept.\u003c\/li\u003e\n\u003cli\u003e\n\u003cmeta charset=\"utf-8\"\u003eHands on Configuration of AWS services such as IAM, EC2, Lambda, S3. This will provide the fundamental knowledge for the attendees before we cover how these services are abused by the threat actor.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cmeta charset=\"utf-8\"\u003eTopic 2: Introduction to AWS CloudTrail (Day 1)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eCloudTrail Fundamentals: Learn the core concepts and functionalities of AWS CloudTrail.\u003c\/li\u003e\n\u003cli\u003eConfiguring CloudTrail: Master the process of setting up CloudTrail trails to capture relevant events and activities.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eTopic 3: CloudTrail Log Analysis (Day 1\/Day 2)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLog Interpretation: Develop the ability to decipher CloudTrail logs to identify user activities, API calls, and resource changes.\u003c\/li\u003e\n\u003cli\u003eThreat Detection: Learn to recognize indicators of compromise (IoCs), indicators of attack (IoA) and anomalies within CloudTrail logs.\u003c\/li\u003e\n\u003cli\u003eAdvanced Analysis Techniques: Explore methods for extracting actionable intelligence from CloudTrail data.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eTopic 4: Understanding the AWS Threat Landscape (Day 2)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eCommon AWS Attack Vectors: Explore real-world attack scenarios, including unauthorized access and data exfiltration.\u003c\/li\u003e\n\u003cli\u003eThreat Actor Tactics: Analyze the techniques employed by malicious actors to target AWS environments, aligning them with the industry-standard MITRE ATT\u0026amp;CK Framework.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eTopics 5: AWS Attack Detection (Day 2)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdvanced Threat Hunting with CloudTrail: Analyze attacker methodologies and tactics as captured in CloudTrail logs to understand the techniques used by adversaries, enabling you to proactively identify and counteract potential threats.\u003c\/li\u003e\n\u003cli\u003ePractical Tips for Effective CloudTrail-Based Threat Hunting: Learn proven best practices and actionable strategies to perform robust threat hunting with CloudTrail, ensuring you can efficiently monitor, detect, and respond to evolving cyber risks.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIntermediate - \u003c\/span\u003e\u003cspan\u003eThe student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003e\u003cmeta charset=\"utf-8\"\u003eParticipants are not required to have prior AWS knowledge. The training curriculum includes comprehensive coverage of AWS fundamentals, though any existing AWS and SOC experience will be beneficial.\u003cbr\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\n\u003cmeta charset=\"utf-8\"\u003eLaptop\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\n\u003cmeta charset=\"utf-8\"\u003eOnline lab + Slides\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eIn Ming LOH\u003c\/strong\u003e is a principal consultant at a prominent cybersecurity firm, specializing in incident response and technical assessment engagements with a strong emphasis on cloud environments. He has been instrumental in numerous high-profile investigations, involving both nation-state and e-crime threat actors across a wide array of industries.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWei Chea ANG \u003c\/strong\u003ecurrently works at a leading SaaS company, empowering enterprises to secure and manage their digital assets. For the past 7 years, he has specialized in cloud security, working with a diverse range of organizations from startups to Fortune 100 companies. His expertise has been shared at prestigious conferences, including HITCon, ISC2 APAC Congress, and FIRST APAC Symposium.\u003cstrong\u003e\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51499658412172,"sku":null,"price":2250.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/InMing.jpg?v=1768361718"}],"url":"https:\/\/sg.shop.defcon.org\/collections\/def-con-training-singapore-october-2026.oembed","provider":"DEF CON SG","version":"1.0","type":"link"}