TOP-LEVEL PRESENTATIONS

We pay special attention to the choice of talks, especially valuing their originality and contribution to the community.

REDUCED BY CHOICE

Since our constitution, we have opted for a reduced congress in order to guarantee the best experience for the attendees.

NON-PROFIT

Under our philosophy of association, this congress is made possible by the countless hours of partners and sponsoring companies.

UNPRECEDENTED RELAXED ATMOSPHERE

From EuskalHack we are putting all our efforts to make - one more year - an unforgettable congress for all the attendees.

PARTICIPATION AND COLLABORATION

We encourage attendees to participate in the collective activities such as the hackathon, workshops, or cybersecurity challenges.

] PROGRAM [

Registration will open at 08.00 hours. Please arrive on time so as not to block the accreditation system.

Remember that if you are a student you will have to prove it with your ticket.

FRIDAY, 23 JUNE

TIME TALK LANG SPEAKER PDF
09:15h - 09:30h Presentation and opening of the Congress [ES][EN]
Miguel Angel Hernandez
Miguel Á. Hernández (EuskalHack Team)
09:30h - 10:15h Abusing ETCD: Injecting resources into (almost) unrestricted k8s [ES]
Luis Toro
Luis Toro
PDF
10:15h - 11:00h Offensive Tracking to take in (L)users [ES]
Josep Moreno
Josep Moreno
11:00h - 11:30h BREAK
11:30h - 12:15h Symbolic execution for security researchers [EN][ES]
Arnau Gàmez
Arnau Gàmez
PDF
12:15h - 13:00h Modern Attacks against Modern Solutions [EN]
Danijel Grah
Danijel Grah
PDF
13:00h - 13:30h V2X Hacking: New Horizons [ES]
Igor Pallin
Igor Pallin
13:30h - 15:00h LUNCH
15:00h - 15:30h Reversing vs desarrollo de malware: ¿Ratón o gato? [ES]
Mariano Palomo
Mariano Palomo
15:30h - 16:15h Testing invisible watermarks based on DFT [ES]
Tania Diaz
Tania Diaz
16:15h - 17:00h The ins and outs of Bluetrust [ES][EN]
Antonio Vázquez Jesús Mª Gomez
Antonio Vázquez & Jesús Mª Gomez
PDF

SATURDAY, 24 JUNE

TIME WORKSHOP LANG SPEAKER REGISTER
09:00h - 11:00h Malware analysis with CAPE sandbox - crash course [ES][EN]
Andriy Brukhovetskyy
Andriy Brukhovetskyy
PDF
09:00h - 11:00h Practical Explotation with Kraken [ES]
Raul Caro
Raul Caro
PDF
09:00h - 11:00h ReconFTW: a framework for assets discovery and more [ES]
Alexis Fernández
Alexis Fernández
PDF
09:00h - 11:00h Offensive Logon Sessions - How to find them and how to protect them [ES]
Jorge Escabias
Jorge Escabias
PDF
11:00h - 11:30h BREAK
TIME TALK LANG SPEAKER PDF
11:30h - 12:15h Modern binary diffing: Diaphora 3.0 [EN][ES]
Joxean Koret
Joxean Koret
PDF
12:15h - 13:00h Understanding a Payload's Life [ES]
Daniel López
Daniel López
PDF
13:00h - 13:45h What we did wrong while making Flipper Zero [EN]
Pavel Zhovner
Pavel Zhovner
13:45h - 14:15h Cybersecurity Award and closure [ES][EN]
EuskalHack Team
EuskalHack Team
14:15h - 17:00h FREE TIME
17:00h - 06:00h Hackathon Gau-Hack [ES]
Hackatón
Hacker Community

] WORKSHOPS [

MALWARE ANALYSIS WITH CAPE SANDBOX - CRASH COURSE

Speaker: Andriy Brukhovetskyy

The aim of this workshop is to enable attendees to understand and set up an automated malware analysis environment, with best practices and recommendations on how it works inside, in order to take full advantage of all its resources.

Register

PRACTICAL EXPLOTATION WITH KRAKEN

Speaker: Raul Caro

The aim of the workshop is to dive into the inner workings of Kraken, modify and add new components (modules/agents), as well as solve scenarios where post-exploitation via the web is difficult. In short: a hands-on Kraken training!

Register

RECONFTW: A FRAMEWORK FOR ASSETS DISCOVERY AND MORE

Speaker: Alexis Fernández

ReconFTW is becoming an industry standard for asset discovery by Red Team, Pentesters or Bug Hunters. In this workshop we will analyze in depth how reconFTW works, the configuration options it has and how we can adapt it to our needs or those of our clients.

Register

OFFENSIVE LOGON SESSIONS - HOW TO FIND THEM AND HOW TO PROTECT THEM

Speaker: Jorge Escabias

During this workshop, students will understand the different existing ways to access a machine to interact with it remotely, when these accesses are cached, what protections Windows offers to avoid it, how to delete these cached credentials and, finally, what a pentester must understand to avoid it during an exercise.

Register

] SPONSORS [

PLATIN

GOLD

SILVER

BRONZE

] COLLABORATORS [

] LOGISTICS PARTNERS [

] EUSKALHACK CYBERSECURITY AWARD 2023 [

In this sixth edition we want to continue to recognise one of the people whose contribution to cybersecurity has been meritorious in the last year. At EuskalHack we would like to be able to distinguish all those individuals, often anonymous, whose efforts have been more than beneficial to the cybersecurity community, professional environment, and citizens.

WINNER: Pavel Zhovner

Pavel Zhovner

FULL LIST OF WINNERS

] GAU-HACK [

In this sixth edition we would like to offer ESC attendees a relaxed space to share experiences, knowledge and of course a good time.

Throughout the afternoon/evening of Saturday 24th June you will be able to join our hackathon "gau-hack" where you will work in groups on a series of projects related to hacking proposed both by the organisation and by yourselves.

DATES OF INTEREST

10/02/2023Hackathon general publication.
15/02/2023Presentation of the Collaborative CTF initiative and start of the receipt of proofs.
01/06/2023Sharing and selection of projects in the Telegram group.
24/06/2023Day of the event.

PLANNED TIMETABLE

17:00* OLARAIN (UNUS & DUO)Reception of participants.
18:30* OLARAIN (UNUS & DUO)Exhibition of projects, creation of groups, and start of the Gau-Hack.
06:00* OLARAIN (UNUS & DUO)Eviction.

* Capacity limited to 50 participants, prioritising by order of registration to the event.

] LOCATION [

COLEGIO MAYOR OLARAIN
Paseo de Ondarreta 24
Donostia - San Sebastián | Gipuzkoa

Where to park?

] DISCOUNTS[

ACCOMMODATION

We have agreed a 10% discount with the Olarain Residence,
place where the congress itself will take place:

Reservations via email: [email protected]
Indicating the matter: "Reserva EuskalHack"

Offer subject to availability

booking + Info

TRAIN

5% off.

Tell us your Locator
Go to renfe.com
Select the Destination
Choose dates and times
Use the Promo Code.

BUS

15% off.

Go to alsa.es
Select the Destination
choose the dates
Use the Promo Code.
Time selection

BUY TICKET

This ticket gives you access to the congress for both days, Welcome Pack, Hackathon, and other congress initiatives.

* Reduced Ticket: Students and unemployed (They must prove it irrefutably at the entrance)

Price list:

[SECTION 1] > 01 of March to 31 of March : 70€ [SECTION 2] > 01 of April to 31 of May: 80€ [SECTION 3] > 01 of June to 15 of June: 95€

BUY TICKET

EuskalHack Security Congress is an initiative of the first Ethical Hacking Association of Euskadi, a non-profit organisation constituted in Donostia and made up of various professionals linked to computer security research and computer forensics

Our goal is to promote the community and culture of digital security to any type of interested public (experts or beginners who want to enter the world of security), through the promotion and dissemination of mainly technical knowledge.

This exclusive congress is shaping up to be the most important in the Basque Country, with an estimated capacity of 200 people in this sixth edition.