DistrictCon Junkyard 2025

Presented the research behind CVE-2025-6031, including reconstructing the end-of-life Amazon Cloud Cam backend and bypassing SSL pinning during device pairing to intercept and modify network traffic.
OWASP Global AppSec USA 2025

Presented a threat-model-informed workflow for dynamically testing indirect prompt injection, covering target profiling, guardrail analysis, tool enumeration, and automated testing.
OWASP Global AppSec 2024

Examined secondary-context and business-logic vulnerabilities found in real-world GraphQL assessments, including unauthorized data access, account modification, cross-tenant access, and SSRF.
Defcon Recon Village 2024

Demonstrated using whoiswatcher with serverless infrastructure or IPv6 proxying to build WHOIS datasets, review historical records, and alert on newly registered enterprise domains.
Las Vegas BSides 2024

Demonstrated using whoiswatcher with serverless infrastructure or IPv6 proxying to build WHOIS datasets, review historical records, and alert on newly registered enterprise domains.
Black Hat USA Trainings 2019 (Accepted)

Unfortunately we couldn't fill the class in Las Vegas. It was delivered in Buenos Aires instead with the help of Include Security. Thank you!
OWASP Maine
Pluralsight Training 2017

Covered structuring penetration-testing reports, documenting technical findings, writing executive summaries and attack walkthroughs, building proofs of concept, and reviewing the final draft.
Pluralsight Training 2016

Taught passive and active reconnaissance techniques for identifying, mapping, and prioritizing an organization's external targets.
Black Hat USA Arsenal 2016
Demonstrated the Serpico penetration-test report generation and collaboration tool, including data imports, bundled reporting, and findings trending.
Black Hat USA 2015

Showed how XML external entity attacks could be embedded in XML-based upload formats such as DOCX, XLSX, and PPTX, using examples from products and bug-bounty findings.
Black Hat Webcast November, 2015
Extended the file-parsing XXE material to additional formats, including PDF and image metadata in JPG and GIF files.
BeaCon 2015
Black Hat USA Arsenal 2015
Demonstrated Serpico's customizable penetration-test report generation workflow, including Nessus imports and automated presentation generation.
Black Hat Europe 2014
Examined SAP HANA attack paths that combined web and database behavior, including access to deleted data, server-side JavaScript through SQL, and insecure analytics integrations.
I couldn't make the talk unfortunately.
Troopers 2014
Presented techniques attackers could use to evade SAP logging and post-attack forensic analysis, along with mitigations.
Troopers 2014
Demonstrated techniques for compromising SAP BusinessObjects deployments, including risks to the confidentiality and integrity of business-intelligence data, and discussed mitigations.
BlackHat Arsenal 2014
Introduced Serpico, a collaboration and report-generation tool designed to reduce the time needed to produce customizable penetration-test reports.
Rapid7 Whiteboard Wednesday
Reported research that identified 12,328 Amazon S3 buckets, including 1,951 that were publicly readable and exposed a wide range of data.
Defcon Skytalks 20 (2012)
Focused on fingerprinting web applications and brute-forcing credentials.
Defcon 19 (2011)

Presented with Marcus Carey and David Rude, this talk demonstrated Metasploit auxiliary modules that emulated network attacks to test firewalls, IDS, IPS, and DLP controls.
Defcon Skytalks Las Vegas 2011
Focused on testing DoS mitigations in place from vendors. Unfortunately, I couldn't find the slides or video.
BSides Las Vegas 2011
Focused on testing DoS mitigations provided by vendors. Unfortunately, I couldn't find the slides or video.
OWASP AppSec USA 2010

Covered a penetration-testing methodology for SAP BusinessObjects, including reconnaissance, exposed SOAP services, and attacks against the platform.
SOURCE Barcelona 2010

Covered a penetration-testing methodology for SAP BusinessObjects, including reconnaissance, exposed SOAP services, and attacks against the platform.