BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.pass-the-salt.org//pts2026//speaker//RU9UTJ
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-pts2026-8SANMK@cfp.pass-the-salt.org
DTSTART;TZID=CET:20260702T114500
DTEND;TZID=CET:20260702T122000
DESCRIPTION:Everyday\, all of us are flooded with phishing emails trying to
  impersonate many well-known brands (Netflix\, DHL\, Microsoft\, Google\, 
 Facebook & co). Some phishing campaigns are poorly prepared and can be eas
 ily spotted. On the other side\, some are really well crafted and\, be hon
 est\, who never clicked on a malicious link? If the flood is constant\, it
  means that it works! And thread actors expect to get our credentials. But
 \, is it really the case? How fast do they react once we disclosed them? T
 hat’s the purpose of our research.\n\nWe developed a tool\, called Phish
 Track\, that behaves as a honeypot but with more interaction with phishing
  kits. The tool is fed with phishing URLs. They are visited\, categorized 
 and\, if possible\, we provide unique credentials. Then\, we monitor the h
 oneypot and expect (crossing fingers) that our credentials will be re-used
 . We simulate classing landing pages and protocols: a web portal\, MS acco
 unt\, VPN login\, VNC\, SSH\, RDP (and maybe more soon). As an example\, o
 ur current record is 3 mins between the phishing page visit and the attemp
 t to (ab)use the credentials from Nigeria.\n\nThe talk will be split in tw
 o parts: We will introduce the tool\, what are the core components\, how i
 t works\, how we deployed it. The second part of the talk will be a review
  of our findings.
DTSTAMP:20260514T103253Z
LOCATION:Amphitheater 122
SUMMARY:Your credentials were leaked\, so what? - Xavier Mertens\, Teqagogo
URL:https://cfp.pass-the-salt.org/pts2026/talk/8SANMK/
END:VEVENT
END:VCALENDAR
