2024 live TRAINING classes

Update 9/29/2024 – ALL BSidesAugusta 2024 Training Events have been cancelled due to the impacts of Hurricane Helene on Augusta.

 

 

 

Check out our ticket page to find out what is included with every class and for answers to frequently asked questions!

 

 

Course Name: AI SecureOps: Attacking & Defending GenAI Applications and Services – CANCELLED

Format: 2-Day Class

Date(s): 10/2 – 10/3/2024

Training Time: 9-5 with one hour lunch

Trainer: Abhinav Singh

Trainer Bio: Abhinav Singh is an esteemed cybersecurity leader & researcher with over a decade of experience across technology leaders, financial institutions, and as an independent trainer and consultant. Author of “Metasploit Penetration Testing Cookbook” and “Instant Wireshark Starter,” his contributions span patents, open-source tools, and numerous publications. Recognized in security portals and digital platforms, Abhinav is a sought-after speaker & trainer at international conferences like Black Hat, RSA, DEFCON, BruCon and many more, where he shares his deep industry insights and innovative approaches in cybersecurity. He also leads multiple AI security groups at CSA, responsible for coming up with cutting-edge whitepapers and industry reports around safety and security of GenAI.

Course Description: By 2026, Gartner, Inc. predicts that over 80% of enterprises will engage with GenAI models, up from less than 5% in 2023. This rapid adoption presents a new challenge for security professionals. To bring you up to speed, this training provides essential GenAI and LLM security skills through an immersive CTF-styled framework. Delve into sophisticated techniques for mitigating LLM threats, engineering robust defense mechanisms, and operationalizing LLM agents, preparing them to address the complex security challenges posed by the rapid expansion of GenAI technologies. You will be provided with access to a live playground with custom built AI applications replicating real-world attack scenarios.

The course focuses on safeguarding both public GenAI services and proprietary enterprise LLM solutions. You will dive deep into creating specialized models to tackle unique security issues and also to deploy defense strategies across GenAI supply chain, utilizing both open-source and custom tools. This dual approach ensures comprehensive coverage of “securing GenAI technologies” alongside “leveraging GenAI for enhancing security”. Mastering these two dimensions is crucial for developing sophisticated defense infrastructures in enterprise environments.

This training will also cover the completely new segment of ethics and trustworthiness in GenAI services. Unlike traditional cybersecurity verticals, these unique challenges such as bias detection, managing risky behaviors, and implementing mechanisms for tracking information are going to be the key challenges for enterprise security teams. The sections will explore complex scenarios related to access rights and data privacy protection, ensuring secure usage of sensitive data in LLM application development(practical labs).

Target Audience: Security professionals seeking to update their skills for the AI era, Red & Blue team members, AI Developers & Engineers interested in the security aspects of AI and LLM models, and Product Managers & Founders looking to strengthen their PoVs and models with security best practices.

Knowledge/Experience/Prerequisites:

  • Familiarity with AI and machine learning concepts is beneficial but not required.
  • Ability to run python codes and notebooks.
  • Familiarity with common GenAI applications like OpenAI.

What attendees need to bring:

Labs, CTFs, walkthroughs and notebooks are all going to be available online so the pre-training setup is minimal for participants.

  • API keys for OpenAI & Langchain
  • Google account to run Colab notebooks
  • Complete the pre-training setup before the first day (basic setup and testing) 

Price: $649 (Discounts are available for active duty US Military and active US Federal civilian employees. E-mail info@bsidesaugusta.org for details.)

Registration Deadline: 9/30/2024

REGISTER HERE



Course Name: Security Onion Fundamentals for Analysts and Administrators
– CANCELLED

Format: 4-Day Class

Date(s): 9/30 – 10/3/2024

Training Time: 8-5 with one hour lunch

Trainer: Security Onion Solutions

Trainer Bio: Security Onion Solutions instructors have years of experience in threat hunting, enterprise security monitoring, and log management. They have worked in real-world operational security roles, engineered monitoring strategies and solutions, and handled real-world incidents. They bring their practical experience to the classroom, enabling students in both theory and hands-on application to hunt adversaries in environments large and small.

Course Description: This four-day course is geared for analysts and administrators of Security Onion. Students will gain a foundational understanding of the platform – how to architect, deploy, and manage their Security Onion grid. The course also covers major analyst workflows, reinforced through real-world case studies.

The class will cover the following topics:
● Security Onion Console
● Security Onion System Architecture
● Security Onion Workflows
__○ Alert Triage & Case Creation with SOC Alerts and Cases
__○ Threat Hunting with SOC Hunt and Dashboards
__○ Detection Engineering
● Grid Management
__○ Users
__○ Firewalls
__○ Monitoring
__○ Troubleshooting
● Tuning the Grid
__○ Berkeley Packet Filters
__○ Performance Tuning – Zeek and Suricata
__○ Data Pipeline Tuning – Logstash and Elasticsearch
__○ Alert Tuning
● Customizing Security Onion Console
● Integrating Endpoint Telemetry
● Capstone Capture the Flag Event
● Multiple Labs and Case Studies

Target Audience: Users of Security Onion – Analysts, Administrators, Security Engineers

Knowledge/Experience/Prerequisites: Security Onion Essentials HERE (2 hours; free) Students should have a basic understanding of networks, TCP/IP, and standard protocols such as DNS, HTTP, SSL, etc. Knowledge/experience with Linux is recommended, but not required.

What attendees need to bring: Laptops and coursebooks will be provided to students. Students may want to bring writing utensils to take notes in their course books.

Price: $3299 (Discounts are available for active duty US Military, active US Federal civilian employees, as well as active members of ISSA and Infragard. E-mail info@bsidesaugusta.org for details.)

Registration Deadline: 9/23/2024

REGISTER HERE


Course Name: Windows Internals for Security Analysts – CANCELLED

Format: 2-Day Class

Date(s): 10/2 – 10/3/2024

Training Time: 9-4 with one hour lunch

Trainers: Adam Duby

Trainer Bios: Adam Duby has twelve years experience in cyber security across operational, research, and academic roles with specialties in digital forensics and Windows malware analysis. He led an operational malware analysis cell before serving as an assistant professor of computer science at West Point (United States Military Academy). At West Point, Adam instructed courses in digital forensics and cyber security engineering. Additionally, he acts as an adjunct professor at Norwich University, where he developed and taught the malware forensics curriculum. Adam received his Ph.D. from the University of Colorado where he researched malware classification using machine learning.

Course Description: This immersive hands-on training is a deep dive into the inner workings of Windows with an emphasis on security topics. Guided by the instructor, participants will write and compile programs using C/C++, then inspect the compiled binaries in IDA/Ghidra to examine the internals of some of the most prevalent Win32 API calls. We will examine executables and subsystem DLLs in IDA to gain insight into their functionality and trace function calls from user space into native system calls. Malware use cases are explored with emphasis on interactions with the kernel. Lab topics include DLL injection, process injection, hooking, handle tables, Heaven’s gate, and more. Some Python and PowerShell is used to examine runtime behavior and explore system artifacts. Participants will acquire enhanced proficiency in explaining host-based behaviors and software reverse engineering techniques tailored for Windows environments. Code and lab walkthroughs will be provided.

Target Audience: Intermediate malware analysts, threat hunters, host analysts, or anyone needing a deeper understanding of Windows internals

Knowledge/Experience/Prerequisites: Participants should have some basic knowledge of C or C++ programming. Some exposure to reverse engineering and x64-86 assembly would be helpful, though not required.

What attendees need to bring: Laptop w/ Windows 11, IDA (Free), and Visual Studios 2022 installed (or an equivalent Windows VM)

Price: $499

Registration Deadline: 9/28/2024

REGISTER HERE