TippingPoint Digital Vaccine Laboratories
DID YOU KNOW... Most phishing sites are hosted on compromised Apache + PHP + MySQL servers located in the US. Our Digital Vaccine service includes filters specifically designed to prevent potential victims from reaching many of these malicious sites.

Appearances

Our researchers are regularly invited to speak on a variety of topics all over the security industry. Here are some of our upcoming and past speaking appearances, click on the entry to view the abstract as well as any available slides and code:

Archived: 2013

Pwn2Own 2013
Brian Gorenc, Scott Lambert, Matt Molinyawe, Jasiel Spelman, Dave Weinstein
Mar 6th, CanSecWest
Advanced Malware Deobfuscation
Scott Lambert
Mar 4th, CanSecWest
Introduction to Malware Analysis
Scott Lambert
Mar 2nd, CanSecWest

Archived: 2012

Mobile Pwn2Own
Brian Gorenc, Assad Khan, Jasiel Spelman, Steve Povolny, Scott Lambert, Jonathan Andersson
Sep 19th, EUSecWest
Understanding Vulnerabilities to Better Mitigate Threats
Steve Povolny
Sep 10th, HP Protect
State of Web Exploit Toolkits
Jason Jones
Jul 26th, BlackHat US
Active Exploitation Detection and the Arrhythmia of the Threat Landscape
Marc Eisenbarth
Jul 12th, Lockdown 2012
Know Your Enemy - Hackers Versus Executives Panel
Brian Gorenc
Jun 19th, Forrester Security Forum EMEA
Bug Hunting and Analysis
Aaron Portnoy, Zef Cekaj
Jun 11th, Recon 2012
Know Your Enemy - Hackers Versus Executives Panel
Brian Gorenc
May 25th, Forrester Security Forum
Classification of UDP Traffic for DDoS Detection
Marc Eisenbarth
Apr 24th, LEET 2012
Yo Dawg, I heard you like reversing...
Aaron Portnoy, Brandon Edwards
Apr 14th, Hackito Ergo Sum
Next Generation Blacklisting and Whitelisting
Marc Eisenbarth
Mar 25th, HP TechCon 2012
Pwn2Own 2012
Aaron Portnoy, Brandon Edwards, Logan Brown, Peter Vreugdenhil
Mar 7th, CanSecWest
Adventures in Implementing a Secure Software Development Lifecycle (SDLC)
Brian Gorenc
Feb 28th, RSA 2012
Vulnerability Panel: Is it ZERO Day or ZERO Care?
Dan Holden
Feb 27th, RSA 2012
Bug Hunting and Analysis 0x65
Aaron Portnoy, Zef Cekaj
Jan 31st, Private Venue (NYC)

Archived: 2011

Black Box Auditing Adobe Shockwave
Aaron Portnoy, Logan Brown
Nov 8th, PacSec
Beyond IPS
Will Gragido
Oct 17th, SecTor
The Rise of the Chaotic Actor: Adapting to the Age of Anonymous
Will Gragido
Oct 13th, RSA Europe 2011
Dynamic Reverse Engineering
Aaron Portnoy
Oct 12th, Polytechnic Institute of NYU
Memory Disclosure and You
Brandon Edwards
Oct 7th, BsidesPDX
Exploitation and Obfuscation: Analyzing Stealthy Attacks
Brian Gorenc
Oct 6th, IEEE Metrocon
Operational Reviews and Code Audits
Brandon Edwards
Sep 26th, Polytechnic Institute of NYU
Experiments using IDA Pro as a data store
Aaron Portnoy, Ali Rizvi-Santiago
Sep 23rd, ekoparty
Advanced Malware Deobfuscation
Scott Lambert
Aug 2nd, BlackHat US
Bug Hunting and Analysis 0x65
Aaron Portnoy, Zef Cekaj
Jul 11th, Recon 2011
Bug Hunting and Analysis 0x65
Aaron Portnoy, Zef Cekaj
Jul 5th, Recon 2011
Reputation Digital Vaccine: Reinventing Internet Blacklists
Marc Eisenbarth
Jun 15th, Source Seattle
Economics of Vulnerabilities
Aaron Portnoy
May 27th, Hack in the Box Amsterdam
Black Box Auditing Adobe Shockwave
Aaron Portnoy, Logan Brown
Apr 8th, Hackito Ergo Sum
SCADA, the Forgotten Infrastructure?
Dan Holden
Apr 5th, NISSF 2011
Concentrated Fire: Black Box Auditing Adobe Shockwave
Aaron Portnoy, Logan Brown
Mar 9th, CanSecWest
Pwn2Own 2011
Aaron Portnoy, Logan Brown, Ali Rizvi-Santiago, Derek Brown, Jonathan Andersson,
, Peter Vreugdenhil, Kate Fly, Assad Khan
Mar 9th, CanSecWest
Reputation Digital Vaccine: Reinventing Internet Blacklists
Marc Eisenbarth
Mar 6th, HP Tech Con 2011
The Vulnerability Disclosure Debate Continues
Aaron Portnoy, Dan Holden
Feb 17th, RSA 2011
The Best Defense is a Good Offense: Building Security into Applications
Dan Holden
Feb 15th, RSA 2011
Active Exploitation Detection
Marc Eisenbarth
Feb 15th, Security B-Sides SanFran
The Modern Threat Landscape and Our Ability to React Intelligently
Marc Eisenbarth, Will Gragido
Feb 15th, Security B-Sides SanFran
Half Baked: Hardware Hacking Mixed with Sweet Software Reverse Engineering
Marc Eisenbarth
Jan 30th, ShmooCon
Active Exploit Detection
Marc Eisenbarth
Jan 18th, BlackHat DC

Archived: 2010

Analyzing Network-Based Attacks
Garett Montgomery
Oct 27th, HTCIA Austin
SCADA Threat Landscape 2010
Garett Montgomery
Oct 27th, Pacific Northwest Smart Grid Demonstration
The Vulnerability Threat Lifecycle
Dan Holden
Oct 13th, SANS Mnemonic RISK Summit
Lecture on Reverse Engineering (Part Two)
Aaron Portnoy, Peter Silberman
Oct 11th, Polytechnic Institute of NYU
The Vulnerability Threat Lifecycle
Dan Holden
Oct 9th, Les Assises de la Securite
Lecture on Reverse Engineering (Part One)
Aaron Portnoy, Peter Silberman
Oct 4th, Polytechnic Institute of NYU
Exploitation: Past, Present, and Future
Aaron Portnoy
Sep 14th, National Security Agency
Vulnerability Lifecycle for Software Vendors
Dan Holden
Sep 10th, AppSec US 2010
The Threat Landscape
Will Gragido
Sep 9th, ISSA Chicago
Electronic Weaponry or How to Rule the World While Shopping at Radio Shack
Tim Otto
Aug 1st, DEF CON 18
Through the rabbit hole: An Expose of Darknets and the Onion Routed Underground
Will Gragido
Jul 31st, Security BSides
Building a Better Mousetrap: Effective Techniques in Vulnerability Analysis and Intrusion Detection & Prevention
Rob King
Jul 24th, BlackHat USA 2010
Pixaxe: A Declarative, Client-Focused Web Application Framework
Rob King
Jun 23rd, USENIX
SCADA Threat Landscape
Garett Montgomery
May 18th, DoE Cyber Security Conference
SCREAM: Static Analysis of Regular Expressions for Analysis and Modifications
Rob King
Mar 25th, Erlang Factory
Pwn2Own 2010
Pedram Amini, Aaron Portnoy, Kate Fly, Ali Rizvi-Santiago, Zef Cekaj, Logan Brown
Mar 24th, CanSecWest
MOBOTS: A Pocketful of Pwnage
Derek Brown, Daniel Tijerina
Mar 5th, RSA 2010
Cracking Down on SCADA Security
Jason Avery
Mar 4th, RSA 2010
The Seven Most Dangerous New Attack Techniques and What Is Coming Next Session
Rohit Dhamankar
Mar 2nd, RSA 2010
SCREAM: Static Analysis of Regular Expressions for Analysis and Modifications
Rob King
Feb 18th, IEEE Central Texas Section Conference

Archived: 2009

Cybercrime: The Latest Wave
Jason Avery
Oct 21st, SX Security Exchange 2009 Conference Singapore
Cybercrime: The Latest Wave
Jason Avery
Oct 16th, SX Security Exchange 2009 Conference Thailand
Botnets and 0day Exploits: The Building Blocks of Today's Organized Internet Crime Syndicates
Marc Eisenbarth
Oct 14th, Hawaii's 16th Annual ISSA Discover Security Conference
The Latest Wave of Cybercrime Attacks: Report from the Trenches
David Endler
Oct 7th, European Security and Information System Congress
Lecture on Reverse Engineering
Aaron Portnoy
Oct 2nd, Polytechnic Institute of NYU
Effective Techniques in Vulnerability Analysis and Intrusion Prevention
Rohit Dhamankar, Rob King
Sep 18th, SANS Network Security 2009
Mostrame la guita! Adventures in buying vulnerabilities
Pedram Amini
Sep 17th, Ekoparty 2009
2009 Threat Landscape
Wayne Blackard
Sep 17th, ISSA Puget Sound
Building Security In – Security Throughout the SDLC
Brian Gorenc
Aug 17th, IEEE MetroCon
Reverse Engineering on Windows: Application in Malicious Code Analysis
Pedram Amini, Ero Carrera
Jul 25th, Black Hat USA 2009 Training
Building a Better Mousetrap: Effective Techniques in Vulnerability Analysis and Intrusion Prevention
Rohit Dhamankar, Rob King
Jul 25th, Black Hat USA 2009 Training
Reversing Microsoft DirectShow and 3rd Party Codecs
Aaron Portnoy
Jun 22nd, You Sh0t The Sheriff
Evolving Landscape of Security Threats in Higher Education
Jason Avery
Jun 17th, University of California Computing Services Conference 2009
Botnets and 0day Exploits: The Building Blocks of Today's Organized Internet Crime Syndicates
Marc Eisenbarth
Jun 2nd, Techno 2009 Security Conference
Industrial Control System Security
Ganesh Devarajan
May 13th, SMi Cyber Defence 2009
Exploiting Online Games
Aaron Portnoy
Apr 23rd, RSA Conference 2009
Botnets and 0day Exploits: The Building Blocks of Today's Organized Internet Crime Syndicates
Marc Eisenbarth
Apr 22nd, InfoSecurity San Juan
Reverse Engineering on Windows: Application in Malicious Code Analysis
Pedram Amini, Ero Carrera
Apr 15th, Black Hat Europe 2009 Training
Pwn2Own 2009
Aaron Portnoy
Mar 19th, CanSecWest
Reverse Engineering on Windows: Application in Malicious Code Analysis
Pedram Amini, Ero Carrera
Feb 16th, Black Hat Federal 2009 Training
Static Analysis and Transformation of Regular Languages for Encoding
Rob King
Jan 28th, PENTCIRT Pentagon Security Forums

Archived: 2008

Under the iHood
Cameron Hotchkies
Oct 8th, SecTor
Reverse Engineering Dynamic Language Multiplayer Online Games
Aaron Portnoy, Ali Rizvi-Santiago
Oct 1st, BA-Con Applied Security Conference
SCADA Networks: Security tools and Vulnerability assessments
Ganesh Devarajan
Sep 9th, Reboot Conference
Under the iHood
Cameron Hotchkies
Aug 8th, DEFCON 16
The Art of Developing Effective Intrusion Detection/Prevention Signatures
Rohit Dhamankar, Rob King
Aug 2nd, Black Hat USA 2008 Training
Reverse Engineering on Windows: Application in Malicious Code Analysis
Pedram Amini, Ero Carrera
Aug 2nd, Black Hat USA 2008 Training
Reverse Engineering Python Applications
Aaron Portnoy, Ali Rizvi-Santiago
Jul 28th, USENIX WOOT
Under the iHood
Cameron Hotchkies
Jun 13th, REcon
Reverse Engineering Dynamic Languages, a Focus on Python
Aaron Portnoy, Ali Rizvi-Santiago
Jun 13th, REcon
Arms Race: Next-Gen Vulnerability Discovery
Pedram Amini
Jun 2nd, Techno Security Conference
The Seven Most Dangerous New Attack Techniques and What's Coming Next
Rohit Dhamankar
Apr 23rd, Infosecurity Europe
Reverse Engineering Cookbook
Aaron Portnoy, Cameron Hotchkies
Apr 19th, Toorcon Seattle
Fast Money and Easy Vulnerabilities: True Crime from the Internet
Mike Dausin, Rohan Kotian
Apr 10th, RSA Conference 2008
The Emerging Architecture of Secure Networks
Brian Smith
Apr 9th, RSA Conference 2008
What's to Come: The Next Generation of Attacks
David Endler
Apr 8th, RSA Conference 2008
The Seven Most Dangerous New Attack Techniques, and What's Coming Next
Rohit Dhamankar
Apr 8th, RSA Conference 2008
Reverse Engineering on Windows: Application in Malicious Code Analysis
Pedram Amini, Ero Carrera
Mar 25th, Black Hat Europe 2008 Training
Pwn2Own 2008
Aaron Portnoy
Mar 19th, CanSecWest
Top VOIP Security Threats
David Endler
Mar 18th, VoiceCon Orlando 2008
IP Telephony Security Threats and Countermeasures
David Endler
Mar 17th, VoiceCon Orlando 2008

Archived: 2007

RPC Auditing Tools and Techniques
Aaron Portnoy, Cody Pierce
Nov 22nd, DeepSec In-Depth Security Conference
Advanced Fuzzing with Sulley
Pedram Amini, Aaron Portnoy
Oct 25th, BlackHat Japan
Reverse Engineering on Windows
Pedram Amini, Ero Carrera
Oct 23rd, BlackHat Japan
SCADA Protocols Detailed For Better Security
Ganesh Devarajan
Oct 17th, National Petrochemical and Refiners Association
Fuzzing Sucks!
Pedram Amini, Aaron Portnoy
Sep 27th, Microsoft BlueHat
IP Telephony Security Threats and Countermeasures
David Endler, Mark Collier
Aug 20th, VoiceCon Fall
Real-time Steganography with RTP
Dustin D. Trammell
Aug 3rd, DEFCON 15
Unraveling SCADA Protocols: Using Sulley Fuzzer
Ganesh Devarajan
Aug 3rd, DEFCON 15
PyEmu: A Multi-Purpose Scriptable x86 Emulator
Cody Pierce
Aug 2nd, BlackHat US
Fuzzing Sucks!
Pedram Amini, Aaron Portnoy
Aug 2nd, BlackHat US
PISA: Protocol Identification via Statistical Analysis
Rohit Dhamankar, Rob King
Aug 1st, BlackHat US
Reverse Engineering on Windows
Pedram Amini, Ero Carrera
Jul 28th, Black Hat US
VoIP Security
David Endler
May 24th, Interop
Mnemonic Password Formulas
Dustin D. Trammell
May 16th, IEEE Computer Society, Austin Chapter
DisAsterisk Sneak-Peek
Dustin D. Trammell
May 12th, ToorCon Seattle (Beta)
RPC Auditing Tools and Techniques
Aaron Portnoy
May 12th, Toorcon Seattle
SCADA Protocol Fuzzer and The Next Generation of Inline Devices
Ganesh Devarajan
May 6th, LayerOne
VoiP Security: No Silver Bullet
David Endler
Apr 27th, Infosecurity Europe
Encrypted Protocol Identification via Statistical Analysis
Rob King, Rohit Dhamankar
Mar 23rd, ShmooCon
Pwn2Own 2007
Aaron Portnoy
Mar 23rd, CanSecWest
IP Telephony Security Threats and Countermeasures
David Endler
Mar 7th, VoiceCon Spring
VoIP Attacks!
Dustin D. Trammell
Mar 2nd, EUSecWest
Reverse Engineering on Windows
Pedram Amini, Ero Carrera
Feb 26th, Black Hat Federal
VoIP Attacks!
Dustin D. Trammell
Feb 22nd, IEEE Consultants Network of Central Texas
Exploiting VoIP Networks
David Endler, Mark Collier
Feb 7th, RSA

Archived: 2006

Hackers and Internet Security Threats
Rohit Dhamankar
Dec 18th, Arirang TV Interview, Seoul
Keynote: Internet Security Threats 2006 and Beyond
Rohit Dhamankar
Dec 13th, CONCERT: Conference of Asian CERTs
Steganography Primer
Dustin D. Trammell
Nov 30th, IEEE Consultants Network of Central Texas
SANS Top-20
Rohit Dhamankar
Nov 13th, UK NISCC Security Conference
Steganography Primer
Dustin D. Trammell
Oct 12th, Austin Linux Users Group
VoIP Attacks!
Dustin D. Trammell
Oct 1st, ToorCon 8
Sender Policy Framework
Dustin D. Trammell
Sep 27th, AHA!
Investigating Evil Websites with Monkeyspaw
Tod Beardsley
Aug 3rd, Black Hat US
Hacking VoIP Exposed
David Endler, Mark Collier
Aug 2nd, Black Hat US
Reverse Engineering on Windows
Pedram Amini, Ero Carrera
Aug 1st, Black Hat US
PaiMei - Reverse Engineering Framework
Pedram Amini
Jun 18th, RECON
SANS Top 20 Launch
Rohit Dhamankar
May 23rd, AusCERT
Voice over IP (VoIP) Security
David Endler
Mar 17th, Managing VoIP Security
VoIP Security: Managing Risk
David Endler
Mar 8th, Voicecon
Phishing and Intrusion Prevention
Tod Beardsley
Feb 15th, RSA
Voice over IP Security
David Endler
Feb 14th, RSA
Reverse Engineering for Fun and BoF it!
Pedram Amini, Chris Eagle
Jan 13th, ShmooCon

Archived: 2005

The Top Five VoIP Security Challenges: And What You Can Do About Them
David Endler
Dec 13th, Interop New York
SANS Top-20
Rohit Dhamankar
Nov 22nd, UK NISCC Security Conference
Keynote on Intrusion Prevention Systems
Rohit Dhamankar
Oct 7th, ICETE 2005
Security Concerns and VoIP
David Endler
Sep 22nd, VON
Process Stalking - Run Time Visual RCE
Pedram Amini
Sep 17th, ToorCon
Preventing Exploitation of Your VoIP Network
Rohit Dhamankar, David Endler
Sep 13th, RSA 2005 Power Days
A Primer on Phishing Tactics
Tod Beardsley
Jun 3rd, SummerCon
Preventing Exploitation of Your VoIP Network
Rohit Dhamankar
Feb 15th, RSA 2005
Preventing Exploitation of Your VoIP Network
Rohit Dhamankar, David Endler
Feb 15th, RSA 2005
Tutorial on Intrusion Prevention Systems
Rohit Dhamankar
Feb 14th, RSA 2005