Conference talks and presentations I’ve given over the years.
Beyond Quick Cash: Rethinking Bug Bounties for Greater Impact
A look at how bug bounty programs can deliver outcomes beyond payouts: signal quality, coverage, and program health.
Conference talks and presentations I’ve given over the years.
A look at how bug bounty programs can deliver outcomes beyond payouts: signal quality, coverage, and program health.
Using purple teaming to close the gap between detection engineering and adversarial emulation.
Chapter 4 of the rebuilding-a-blue-team series: standing up a purple team alongside the blue.
Presented at SANS Pentest Hackfest.
Post-exploitation tool that automates compromise of configuration-management servers (Chef, Puppet, Ansible, SaltStack). Presented at DEF CON 27, BSidesSF 2020, and BSides Boulder 2020.
Presented at NLIT 2018.