Le Tour Du Hack

To see our schedule with full functionality, like timezone conversion and personal scheduling, please enable JavaScript and go here.
09:00
09:00
45min
Registration opens

Registration opens at this time

Track 1
09:45
09:45
15min
OPENING REMARKS
Team ENUSEC (Connor, Scott, Lewis, Xander & Eden)

Opening remarks, does what it says on the tin...

Track 1
10:00
10:00
30min
KEYNOTE - History’s Blueprint for Cyber Resilience
Gemma Barrow

How do you build cyber resilience when everything is moving fast? This keynote explores engineering thinking, human judgement and designing systems that can be trusted when the stakes are high.

Track 1
10:00
90min
Lockpicking & Physical Security Village

Come pick locks

Track 3
10:30
10:30
60min
Automating Chaos at Scale
Andy Gill

What happens when you stop treating AI like a chatbot and start treating it like an execution engine and give it access to untapped ADHD?

Track 1
11:30
11:30
10min
Tea Break
Track 1
11:30
10min
Tea Break
Track 2
11:30
10min
Tea Break
Track 3
11:40
11:40
30min
How does AI, Geopolitics impact on the cyber landscape ? What can you do to “hack” your brain for a resilient career !
James K.

We will explore the AI landscape, geopolitical challenges and how that impacts your career ! AI bubble (or not ?) will be contextualised in the face a continuous change to provide an opportunity to look at the horizon skills for the future (harder to predict than you think) !

James will demonstrate how he has pivoted his skills in a continuous learning path to ensure relevance to the market needs throughout his career.
We will explore the geopolitical situation and what it means for individuals and the challenges for a resilient cyber society
Learnings
AI and the geopolitical landscape trends and the potential impact on your career.
How to develop and maintain your personal resilience in the new evolving landscape.

Track 1
11:40
30min
You’ve Been Ph0ned: How Attackers Compromise Organisations Via Telephone Social Engineering
Luiz S

While organizations spent years training users against email phishing, attackers quietly perfected vishing attacks that bypass MFA and turn helpful helpdesk staff into unwitting accomplices - causing billions in damages across retail, automotive, and gaming industries. This talk combines real red-team war stories with a live AI voice cloning demo to show how modern vishing works and what defences actually stop it.

Track 2
12:10
12:10
30min
Lunch
Track 1
12:10
30min
Lunch
Track 2
12:10
30min
Lunch
Track 3
12:40
12:40
30min
Lunch
Track 2
12:40
30min
Lunch
Track 3
12:40
30min
Panel Discussion - What it’s really like to work in cyber security in a large organisation?

Featuring panellists from Lloyds, this panel discussion will be on working in cyber in large organisations. What is it really like?

Track 1
13:10
13:10
60min
Hiding in Plain Sight - OSINT CTF (workshop)
Luiz S

Hiding in Plain Sight - OSINT CTF

Track 3
13:10
30min
Securing ATMs: 101
Kerry Archibald

Join Kerry Archibald for an enlightening talk on securing ATMs in the real world. Drawing on over a decade of experience, this session discusses 15 essential rules for ATM security, debunks persistent industry misconceptions, and examines how criminal groups actually attack machines in practice. Kerry also tackles one of the toughest problems defenders face: why proven protections so often go unapplied.

Track 1
13:10
30min
The Dark Sorcery of Video Encoding
Del Angel Stormreul

This is a story all about how video takes up WAY more data than you think, a bit of history, and a dive into how we play with quality, motion vectors and even how our eyes perceive colour to compress it.

Track 2
13:40
13:40
30min
Ghosts in the Cluster - Hiding in Kubernetes for Years
Rory McCune

You've popped a Kubernetes cluster. You've got admin creds. Now the real question is how do you stay? Kubernetes abstracts away enormous complexity across multiple layers, from container runtimes to cluster APIs and each of those layers has dark corners where an attacker can set up shop and go unnoticed for months or even years.

This talk is a post-exploitation deep dive into Kubernetes persistence. We'll walk through a compromised cluster layer by layer, demonstrating how attackers can escape to cluster nodes, spin up containers invisible to kubectl, abuse the Kubelet API to dodge audit logging and admission control, and create phantom credentials that survive long after the initial breach is forgotten. If defenders aren't watching every layer of the stack, they won't see you coming, or going.

Track 1
13:40
15min
Not Just Tech: The People and Politics of Cyber
Imogen McCall

Short overview of the importance of breaking out of a purely technical silo to examine the policy and human factors that play an increasing role in cybersecurity

Track 2
13:55
13:55
25min
Afternoon Break
Track 2
14:10
14:10
10min
Afternoon Break
Track 1
14:10
10min
Afternoon Break
Track 3
14:20
14:20
30min
Testing What the Scanner Missed: A Bug Bounty Perspective
Suresh Aydi

I have been doing bug bounties for like 6 years now. I have seen most of the people use the scanners to find the issues however those scanners are not that much effective. As someone who has worked as a security expert for six years, I would say that the most interesting exploits are those that cannot be detected through any scanners. The subject of this lecture is manual testing where you go through the application to find the issues in it by yourself that where you find the most interesting stuff which the scanners can't

Track 2
14:20
30min
The eCrime Ecosystem: How Cybercriminals Operate and How We Track Them
David Rowney

I would like to propose a talk exploring the broader cybercriminal ecosystem, drawing on my experience as an Intelligence Analyst at CrowdStrike. The talk will introduce key concepts in Cyber Threat Intelligence (CTI) and how analysts use it to track and understand adversary behaviour, before exploring how eCrime operates as a structured, business-like underground economy. During the session I will focus on real threat actors I track in my day-to-day work, offering attendees a rare, practitioner-level insight into how adversaries operate at scale. I believe CTI remains an underrepresented career path in the industry, and I hope this talk will inspire students — particularly those drawn to analytical rather than purely technical roles — to consider it as a rewarding and exciting avenue within cyber security.

Track 1
14:50
14:50
60min
From Data to Defense: Real-World Cyber Threat Intelligence & Threat Hunting
Ayush Aggarwal

Cyber attacks don’t start with alerts — they start long before, hidden in data.

This talk explores how Cyber Threat Intelligence (CTI) transforms raw data into actionable insights, enabling defenders to move from reactive to proactive security.

Through real-world examples, including large-scale event targeting scenarios, we’ll break down how attackers operate, how defenders detect them, and how you can start threat hunting effectively.

Track 2
14:50
60min
Meet the Fixers: How One Social Engineering Technique Spawned a Family and How to Catch It
Cameron Cottam

Last year at LTDH I did a talk on ClickFix — the fake-CAPTCHA trick that gets users to paste malicious commands into the Run dialog. I thought I was done with the topic.

A year on, ClickFix has grown a family. FileFix moves the trick to File Explorer. ConsentFix (APT29) does it through OAuth and bypasses MFA and passkeys without ever touching the endpoint. CrashFix deliberately breaks your browser, then offers the fix. And a DPRK-nexus actor used a ClickFix-style fake job interview to compromise an Axios maintainer putting 100M weekly npm downloads in the blast radius.

Part one: how the family grew up. Part two: how we catch them — SIEM queries, Conditional Access, browser hardening, the lot. Part three: why none of this stays solved, because custom ClickFix GPTs and AI-generated lures are about to make the next variant cheaper than the last.

Track 1
15:50
15:50
30min
Burning the candle at all ends - a burnout talk
Kit

Life sucks. Between the chaos of work/uni life and personal life, it can be hard to make time for some R&R. We will be discussing what you can do to better manage the chaos as well as activities you can do to unwind and disconnect from the world for a bit.

Track 2
15:50
30min
The Nightmare before Christmas
Samantha Varley

Do hackers take holidays? Join me as I discuss a real DFIR incident where a employees brand new device is compromised via SEO poisoning, and find out how Christmas saved a company from a full-scale ransomware attack!

Track 1
16:20
16:20
30min
Dumb shit in history 3.0
Jon

History is full of people making terrible decisions with absolute confidence. “Dumb Shit in History Part 3” dives into absurd real-world events — including fake armies, corpse trials, poisoned aristocrats, and wars over almost nothing — before drawing uncomfortable parallels to modern cyber security. Equal parts comedy, history lesson, and cautionary tale.

Track 2
16:20
60min
Hot Singles In Your Area Want Your Session Tokens
Michael Varley

A live demonstration of modern BEC attacks, MFA bypass, and how attackers monetise trust.

Track 1
17:20
17:20
30min
No Signature, No Problem: Detecting the Coming 0-Day Flood
Aidan McLaughlin

AI models like Mythos are finding exploitable vulnerabilities faster than the industry can disclose, patch, or write signatures for them. The inevitable consequence: a flood of 0-days in the wild. Every signature-based detection you own is, by definition, blind to them. This talk makes the case that statistical anomaly detection is no longer an optional "ML in security" side quest. It's the only class of detection that can catch the exploitation of things nobody knows exist yet. Drawing on production experience building ML detection, we'll cover what works, what doesn't, and why your UEBA tab isn't going to save you.

Track 1
17:50
17:50
15min
CLOSING REMARKS
Team ENUSEC (Connor, Scott, Lewis, Xander & Eden)

The remarks that close

Track 1
18:30
18:30
60min
AFTERPARTY

At this time, the afterparty at the Fountainbridge Fox will begin. 18+ only, have wristbands ready

Track 1