OFFZONE 2022 will feature several workshops:
For details, click the tabs below.
The workshop will guide you into the basics of Linux kernel security. In a series of exercise‑driven labs, you are going to explore the process of exploiting kernel bugs in modern Linux distributions on the x86‑64 architecture.
The agenda covers:
(No knowledge about Linux kernel internals is required.)
Andrey Konovalov is a Managing Director at Xairy Labs and a security researcher focusing on the Linux kernel.
He found multiple zero‑day bugs in the Linux kernel and published proof‑of‑concept exploits to demonstrate their impact. Andrey is a contributor to several security‑related Linux kernel subsystems and tools: KASAN—a fast dynamic bug detector, syzkaller—a production‑grade kernel fuzzer, and Arm Memory Tagging Extension—an exploit mitigation feature.
Andrey spoke at security conferences such as OffensiveCon, Android Security Symposium, Linux Security Summit, LinuxCon North America, and PHDays. He also maintains a collection of Linux kernel security—related materials and runs a dedicated channel.
The entry fee is ₽30,000 (includes a Standard OFFZONE ticket).
You will learn how adversaries can use standard utilities (LOLBAS) and legitimate applications to attack Windows devices in 2022.
The workshop will delve into DLL hijacking, DLL side-loading, and other methods of adversaries. Additionally, you are going to gain a practical understanding of how to detect such threats.
Vladislav Burtsev is a Threat Intelligence Analyst at Kaspersky.
He started his career as a SOC analyst. After that, he became a technical expert, which helped him to understand the ins and outs of security systems administration. All this past experience comes in handy in his current position.
The workshop is free, you only need to buy an OFFZONE ticket and register.
Everyone knows about popular vulnerabilities in media content parsers like ImageMagick or such novelties as vulnerabilities in librsvg. But most experts do not examine these vulnerabilities broadly or persistently enough. All because it is not always obvious and you need to predict the behavior of a vulnerable library for every situation, and that leaves very little time for parsing.
As part of the workshop, Egor will explain how to identify cases with vulnerable media content parsers and conduct some attacks.
Egor is the CEO of CyberEd, the Founder of Singleton Security, and an expert in security analysis.
He has dedicated himself to working as a penetration tester for over 7 years, focused on researching the insecurity of web and Android mobile apps. Egor is a multiple‑time winner and medalist of The Standoff tournament at PHDays as a member of the True0xA3 team, a speaker at both Russian and international conferences, and various security meetups.
The workshop is free, you only need to buy an OFFZONE ticket and register.