Botconf 2017 Workshops

Tuesday, 5 December 2017 12:00 PM - 6:00 PM CET

Université de Montpellier, 14 rue Cardinal de Cabrières, Montpellier, Hérault, 34000, France

Register Now


Sale ended

Botnet Tracking and Data Analysis Using Open-Source Tools (Olivier Bilodeau, Masarah Paquet-Clouston) Partial Approval - €70.00

4 hours - Fully understanding a botnet often requires a researcher to go beyond standard reverse-engineering practice and explore the malware’s network traffic. The latter can provide meaningful information on the evolution of a malware’s activity. However, it is often disregarded in malware research due to time constraints and publication pressures. The workshop is about overcoming such constraints by providing a powerful workflow to conduct quick analysis of malicious traffic. The data science approach presented capitalizes on open-source tools (Wireshark/Tshark, Bash with GNU parallel) and valuable python libraries (ipython, mitmproxy, pandas, matplotlib). During the workshop, participants will do practical technical labs with datasets from our recent botnet investigation. They will learn how to quickly find patterns, plot graphs and interpret data in a meaningful way. Although the exercises will focus on botnet’s data, the tools and skills learned will be useful to all sorts of

sales ended

Cyber Threat Intel & Incident Response with TheHive, Cortex & MISP (Saâd Kadhi and Jérôme Leonard, TheHive Project) Partial Approval - €70.00

Cyber Threat Intel & Incident Response in 2017 MISP, TheHive & Cortex Overview Installing & configuring the product stack Bringing it all together An IR case study Dealing with notifications How CTI feeds IR How IR feeds CTI The CTI-IR cycle: case study

Sale ended

Python and Machine Learning: How to clusterize a malware dataset (Sébastien Larinier) Partial Approval - €70.00

The goal of this workshop is to present how to use python to make machine learning. We take examples of security data like malware and we explain how to transform data to use algorithms of machine learning. We detail the different algorithms and the different librairies Scikit-learn and Tensorflow. The algorithms help to clusterize quickly a malware database to create yara signatures for using in Incident Response. The participants will work on a small dataset, develop some code based on these librairies and create yara signature.

Enter your discount code

  • Subtotal (excluding fees and discounts)
  • Fee
  • Total amount

1. Select Seats

2. Review and Proceed

Tuesday, 5 December 2017 12:00 PM - 6:00 PM CET

Cabrières, Université de Montpellier, Montpellier, Hérault, 34000, France.

This is a separate registration for attending workshops at Botconf 2017 (December 5th 2017 in Montpellier, France)


International Botnet Fighting Association

Contact the Organizer