
Friday, May 15, 2026
Hands-On Training Day
Learn from people who do this stuff every day. Whether you're just getting started or looking to go deeper, there's a course for you.
Training Day is the day before the main conference. Each course has its own ticket; conference admission is also required.
“The quality and pricing of your trainings is second to none!”
— 2025 Training Participant
Plan Your Day
Mix and match a morning + afternoon course, or choose a full-day session.
Full Day Courses
9:00 AM - 5:00 PM
Introduction/EntryFull DayThreat HuntingSIEM$10Hunting Through The SIEM: Turning Logs Into Stories


Trey Bilbrey & Tyler Casey9:00 AM - 5:00 PMRoom 3704
Join our immersive full-day workshop where you'll dive deep into defensive cybersecurity by deploying a multi-staged threat via SCYTHE, and hunting for it across the SIEM! This hands-on experience will guide you through the intricacies of using enterprise tooling, such as Splunk (SIEM), to hunt for and identify malicious activity.
Sold outView details
Trey Bilbrey & Tyler Casey9:00 AM - 5:00 PMRoom 3704
Join our immersive full-day workshop where you'll dive deep into defensive cybersecurity by deploying a multi-staged threat via SCYTHE, and hunting for it across the SIEM! This hands-on experience will guide you through the intricacies of using enterprise tooling, such as Splunk (SIEM), to hunt for and identify malicious activity.
What you'll need
- Just a computer with a compatible web browser.
- Your appetite to learn.
Mid-RangeFull DayCloud Security$10Wrangling Identity and Access in AWS


Andrew Krug & Tara Schofield9:00 AM - 5:00 PMRoom 3705
In this full day training learners will navigate the world of identity and access management in the AWS. Sandbox environments will provided for every learner as we navigate policy grammar and becoming familiar with the PARC model (principal, action, resource, and condition), resource policies, permissions boundaries, and introduce guardrails like condition keys. Learners will be hands on in AWS and leveraging open source tools to simulate various identity misconfigurations.
Sold outView details
Andrew Krug & Tara Schofield9:00 AM - 5:00 PMRoom 3705
In this full day training learners will navigate the world of identity and access management in the AWS. Sandbox environments will provided for every learner as we navigate policy grammar and becoming familiar with the PARC model (principal, action, resource, and condition), resource policies, permissions boundaries, and introduce guardrails like condition keys. Learners will be hands on in AWS and leveraging open source tools to simulate various identity misconfigurations.
In this full day training learners will navigate the world of identity and access management in the AWS. Sandbox environments will provided for every learner as we navigate policy grammar and becoming familiar with the PARC model (principal, action, resource, and condition), resource policies, permissions boundaries, and introduce guardrails like condition keys. Learners will be hands on in AWS and leveraging open source tools to simulate various identity misconfigurations.
What you'll need
A laptop with a modern web browser and no corporate controls like EDR or always-on VPN.
Mid-RangeFull DayCertification Prep$35One‑Day CISSP Exam Review Course

Peter Bagley9:00 AM - 5:00 PMRoom 3711
A fast-paced, high-impact CISSP review designed to reinforce core concepts across all eight domains of the (ISC)² CISSP Common Body of Knowledge (CBK).
This course focuses on exam-relevant topics, test-taking strategies, and memory techniques to maximize exam readiness.
Sold outView details
Peter Bagley9:00 AM - 5:00 PMRoom 3711
A fast-paced, high-impact CISSP review designed to reinforce core concepts across all eight domains of the (ISC)² CISSP Common Body of Knowledge (CBK). This course focuses on exam-relevant topics, test-taking strategies, and memory techniques to maximize exam readiness.
What you'll need
Must have a strong grasp of cybersecurity and be currently preparing for the CISSP Exam. This will be a high-level course, but it will be very informative.
Morning Session
9:00 AM - 1:00 PM
Introduction/Entry3.5 HoursBinary Exploitation$60Binary Jiu-jitsu: White Belt Fundamentals

Joshua Connolly9:00 AM - 12:30 PMRoom 3708
Binary exploitation can feel overwhelming for beginners. With so many tools, techniques, and architectures to learn, it’s easy to get lost without a structured path. Binary Jiu-Jitsu is designed to guide students through the fundamentals of binary exploitation using a skill-based, hands-on approach inspired by martial arts training.
Sold outView details
Joshua Connolly9:00 AM - 12:30 PMRoom 3708
Binary exploitation can feel overwhelming for beginners. With so many tools, techniques, and architectures to learn, it’s easy to get lost without a structured path. Binary Jiu-Jitsu is designed to guide students through the fundamentals of binary exploitation using a skill-based, hands-on approach inspired by martial arts training.
What you'll need
Basic programming concepts help
Introduction/Entry4 HoursAI/ML Security$10Breaking AI: Prompt Injection, Data Exfiltration and Practical Defenses That Work

Pavan Reddy9:00 AM - 1:00 PMRoom 3707
AI systems don’t break like software, they fail in silence, misclassify with confidence, and hallucinate under pressure. This 4-hour hands-on workshop exposes the core vulnerabilities of modern AI, from adversarial image attacks to LLM manipulation. The focus is practical: how do these attacks work, how can you launch them, and what can actually stop them?
Sold outView details
Pavan Reddy9:00 AM - 1:00 PMRoom 3707
AI systems don’t break like software, they fail in silence, misclassify with confidence, and hallucinate under pressure. This 4-hour hands-on workshop exposes the core vulnerabilities of modern AI, from adversarial image attacks to LLM manipulation. The focus is practical: how do these attacks work, how can you launch them, and what can actually stop them?
What you'll need
Basic Python (not required but helps) Docker (Is required for the Code Execution Module) Laptop with sufficient RAM that can run a lightweight container and a browser without lags. Their curiosity (this tutorial will be very interesting)
Mid-Range4 HoursThreat Hunting$10Threat Hunting using MITRE ATT&CK™ TTPs to Identify Adversarial Behaviors

Joel Sierra9:00 AM - 1:00 PMRoom 3709
Participants will assume the role of a security analyst and be asked to identify any undetected threats on AcmeCorp's network.
Sold outView details
Joel Sierra9:00 AM - 1:00 PMRoom 3709
Participants will assume the role of a security analyst and be asked to identify any undetected threats on AcmeCorp's network.
What you'll need
- Must bring your own laptop (BYOL). This is a hands-on lab -- a laptop is required. A second screen is recommended.
- Must pre-register on the Fortinet training & hands-on lab platform in advance: training.fortinet.com
- Highly recommended -- complete these self-paced courses before the event:
Afternoon Session
1:30 PM - 5:00 PM
Mid-Range4 HoursHardware Security$99From Datasheet to .data Section

RJ Crandall1:00 PM - 5:00 PMRoom 3708
This fast-paced workshop teaches you how to red team microcontroller code protection features. You will analyze a real-world consumer device microcontroller, review the datasheet, discover a flawed configuration, use custom tooling to recover the protected internal flash, and load it into a disassembler to reverse engineer.
Sold outView details
RJ Crandall1:00 PM - 5:00 PMRoom 3708
This fast-paced workshop teaches you how to red team microcontroller code protection features. You will analyze a real-world consumer device microcontroller, review the datasheet, discover a flawed configuration, use custom tooling to recover the protected internal flash, and load it into a disassembler to reverse engineer.
What you'll need
Introduction/Entry2 HoursCloud SecurityServerless$10Kraken in the Clouds: A Hands on FaaS Defense Workshop



Shivam Dhar, Nimish Sharma & Niveadita Razdan1:30 PM - 3:30 PMRoom 3707
While serverless abstracts the underlying infrastructure, it doesn’t reduce responsibility. In highly dynamic, event-driven cloud environments, security teams face fast-moving threats that traditional models weren’t designed to handle. Misconfigurations, fuzzy trust boundaries, and insecure integrations create new attack surfaces, including vulnerable libraries, leaky secrets, wildcard IAM roles, and misconfigured triggers.
Sold outView details
Shivam Dhar, Nimish Sharma & Niveadita Razdan1:30 PM - 3:30 PMRoom 3707
While serverless abstracts the underlying infrastructure, it doesn’t reduce responsibility. In highly dynamic, event-driven cloud environments, security teams face fast-moving threats that traditional models weren’t designed to handle. Misconfigurations, fuzzy trust boundaries, and insecure integrations create new attack surfaces, including vulnerable libraries, leaky secrets, wildcard IAM roles, and misconfigured triggers.
What you'll need
Bring your laptop. Wifi/internet access (venue has wifi).
Mid-Range3 HoursThreat Modeling$35Stop Reacting, Start Predicting: Practical Threat Modeling

Mudassir Syed1:30 PM - 4:30 PMRoom 3709
Threat Modeling is the most underrated skill, yes its a skill, that can be honed. We will explore how threat modeling helps teams move from a reactive security mindset to a proactive, design-first approach. You will learn how to identify vulnerabilities before they become incidents, map out potential attack paths, and make risk-informed decisions.
Sold outView details
Mudassir Syed1:30 PM - 4:30 PMRoom 3709
Threat Modeling is the most underrated skill, yes its a skill, that can be honed. We will explore how threat modeling helps teams move from a reactive security mindset to a proactive, design-first approach. You will learn how to identify vulnerabilities before they become incidents, map out potential attack paths, and make risk-informed decisions.
What you'll need
Bring your own laptop.
Students are encouraged to review the OWASP Top 10 - https://owasp.org/Top10/2025/
Mid-Range1 HourNetwork Security$10Branch of the Future


Christa McHugh & Jason Czaplewski4:00 PM - 5:00 PMRoom 3707
Vendor agnostic walk through of network and cybersecurity design best practices of the store or branch office architecture. Includes how to implement and operationalize a zero trust network architecture, including network segmentation, IoT, WiFi, Cloud access and AI safely and securely in a branch environment.
Sold outView details
Christa McHugh & Jason Czaplewski4:00 PM - 5:00 PMRoom 3707
Vendor agnostic walk through of network and cybersecurity design best practices of the store or branch office architecture. Includes how to implement and operationalize a zero trust network architecture, including network segmentation, IoT, WiFi, Cloud access and AI safely and securely in a branch environment.
Vendor agnostic walk through of network and cybersecurity design best practices of the store or branch office architecture. Includes how to implement and operationalize a zero trust network architecture, including network segmentation, IoT, WiFi, Cloud access and AI safely and securely in a branch environment.
What you'll need
Prerequisites: Intermediate understanding of network architecture and general cybersecurity literacy
Ready to register?
Pick a course above and grab your ticket. Conference admission is a separate purchase.