Presentations + Trainings

DistrictCon Junkyard 2025

PackageWatch thumbnail
Video: "PackageWatch"

Presented the research behind CVE-2025-6031, including reconstructing the end-of-life Amazon Cloud Cam backend and bypassing SSL pinning during device pairing to intercept and modify network traffic.

OWASP Global AppSec USA 2025

Indirect Prompt Injection thumbnail
Video: "Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems" (conference listing)

Presented a threat-model-informed workflow for dynamically testing indirect prompt injection, covering target profiling, guardrail analysis, tool enumeration, and automated testing.

OWASP Global AppSec 2024

GraphQL Exploitation thumbnail
GraphQL Exploitation: Secondary Context Attacks and Business Logic Vulnerabilities

Examined secondary-context and business-logic vulnerabilities found in real-world GraphQL assessments, including unauthorized data access, account modification, cross-tenant access, and SSRF.

Defcon Recon Village 2024

Bypassing WHOIS Rate Limiting thumbnail
Bypassing WHOIS Rate Limiting & Tracking Fresh Domains

Demonstrated using whoiswatcher with serverless infrastructure or IPv6 proxying to build WHOIS datasets, review historical records, and alert on newly registered enterprise domains.

Las Vegas BSides 2024

Bypassing WHOIS Rate Limiting thumbnail
Bypassing WHOIS Rate Limiting & Tracking Fresh Domains

Demonstrated using whoiswatcher with serverless infrastructure or IPv6 proxying to build WHOIS datasets, review historical records, and alert on newly registered enterprise domains.

Black Hat USA Trainings 2019 (Accepted)

Black Hat Events
"The Web Application Hacker Level-Up Lab"

Unfortunately we couldn't fill the class in Las Vegas. It was delivered in Buenos Aires instead with the help of Include Security. Thank you!

OWASP Maine

Pluralsight Training 2017

Writing Penetration Testing Reports
Video: "Writing Penetration Testing Reports"

Covered structuring penetration-testing reports, documenting technical findings, writing executive summaries and attack walkthroughs, building proofs of concept, and reviewing the final draft.

Pluralsight Training 2016

External Footprinting
Video: "External Footprinting: Reconnaissance and Mapping"

Taught passive and active reconnaissance techniques for identifying, mapping, and prioritizing an organization's external targets.

Black Hat USA Arsenal 2016

Black Hat
Overview: "SERPICO"

Demonstrated the Serpico penetration-test report generation and collaboration tool, including data imports, bundled reporting, and findings trending.

Black Hat USA 2015

Exploiting XXE in File Upload Functionality thumbnail
Video: "Exploiting XXE in File Upload Functionality"

Showed how XML external entity attacks could be embedded in XML-based upload formats such as DOCX, XLSX, and PPTX, using examples from products and bug-bounty findings.

Black Hat Webcast November, 2015

Black Hat
Webinar: "Exploiting XXE in File Upload Functionality"

Extended the file-parsing XXE material to additional formats, including PDF and image metadata in JPG and GIF files.

BeaCon 2015

Black Hat USA Arsenal 2015

Black Hat
Overview: "SERPICO"

Demonstrated Serpico's customizable penetration-test report generation workflow, including Nessus imports and automated presentation generation.

Black Hat Europe 2014

Black Hat
Video/Slides: "Blended Web and Database Attacks on Real-Time, In-Memory Platforms"

Examined SAP HANA attack paths that combined web and database behavior, including access to deleted data, server-side JavaScript through SQL, and insecure analytics integrations.

I couldn't make the talk unfortunately.

Troopers 2014

Troopers
Video: "Hiding the breadcrumbs: Anti-forensics on SAP systems"

Presented techniques attackers could use to evade SAP logging and post-attack forensic analysis, along with mitigations.

Troopers 2014

Troopers
Video: "SAP BusinessObjects Attacks: Espionage and Poisoning of Business Intelligence platforms"

Demonstrated techniques for compromising SAP BusinessObjects deployments, including risks to the confidentiality and integrity of business-intelligence data, and discussed mitigations.

BlackHat Arsenal 2014

Black Hat
Overview: "SERPICO"

Introduced Serpico, a collaboration and report-generation tool designed to reduce the time needed to produce customizable penetration-test reports.

Rapid7 Whiteboard Wednesday

Rapid7
Post/Video: "There's a Hole in 1,951 Amazon S3 Buckets"

Reported research that identified 12,328 Amazon S3 buckets, including 1,951 that were publicly readable and exposed a wide range of data.

Defcon Skytalks 20 (2012)

Defcon 19 (2011)

Metasploit vSploit Modules thumbnail
Video: "Metasploit vSploit Modules"

Presented with Marcus Carey and David Rude, this talk demonstrated Metasploit auxiliary modules that emulated network attacks to test firewalls, IDS, IPS, and DLP controls.

Defcon Skytalks Las Vegas 2011

BSides Las Vegas 2011

OWASP AppSec USA 2010

Hacking SAP Businessobjects thumbnail
Video: "Hacking SAP Businessobjects"

Covered a penetration-testing methodology for SAP BusinessObjects, including reconnaissance, exposed SOAP services, and attacks against the platform.

SOURCE Barcelona 2010

Hacking SAP Businessobjects thumbnail
Video: "Hacking SAP Businessobjects"

Covered a penetration-testing methodology for SAP BusinessObjects, including reconnaissance, exposed SOAP services, and attacks against the platform.