{"id":228080,"date":"2015-01-06T09:37:04","date_gmt":"2015-01-06T08:37:04","guid":{"rendered":"http:\/\/securite.intrinsec.com\/?p=1682"},"modified":"2015-01-06T09:37:04","modified_gmt":"2015-01-06T08:37:04","slug":"conference-botconf-2014-jour-1","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/conference-botconf-2014-jour-1\/","title":{"rendered":"Botconf 2014 Conference \u2013 Day 1"},"content":{"rendered":"<h1><\/h1>\n<p>Intrinsec was present at the second edition of Botconf, which took place from December 3rd to 5th in Nancy. Videos and slides are available at the following address: <a title=\"https:\/\/www.botconf.eu\/botconf-2014\/documents-and-videos\/\" href=\"https:\/\/www.botconf.eu\/botconf-2014\/documents-and-videos\/\">https:\/\/www.botconf.eu\/botconf-2014\/documents-and-videos\/<\/a><\/p>\n<p>This report concerns the first day, December 3, 2014.<\/p>\n<h2>Botnet Takedowns \u2013 Our GameOver Zeus Experience \u2013 Benedict Addis (ShadowServer) &amp; Stewart Garrick (UK National Crime Agency \u2013 Cybercrime Unit)<\/h2>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/nca.png\"><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-1691 size-medium\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/nca-300x211.png\" alt=\"nca\" width=\"300\" height=\"211\" \/><\/a>Slides: <a href=\"https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.2-Keynote-United-Kingdom%E2%80%99s-National-crime-agency-on-botnet-takedowns.pdf\">https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.2-Keynote-United-Kingdom%E2%80%99s-National-crime-agency-on-botnet-takedowns.pdf<\/a><\/p>\n<p>The speakers present the perspective of law enforcement in operations against the GameOver ZeuS botnet, which appeared in 2011 and was dismantled in 2014.<\/p>\n<p>They revisit the difficulties in understanding this type of threat. Cybercrime does not conform to a traditional pyramidal hierarchy. A botnet is made up of a multitude of machines and operators. Targeting individual elements does not work; they are quickly replaced.<\/p>\n<p>Two aspects are highlighted during the conference: raising awareness among the hierarchy of law enforcement agencies as well as the general public, and the need for international cooperation between government agencies and private security actors; a theme that will be recurrent in the conference.<\/p>\n<p>In order to capture the public&#039;s attention, communication in the United Kingdom relied on visible threats. It focused on Cryptolocker, a <em>ransomware<\/em> deployed on machines previously infected by ZeuS. Even though the threat posed by ZeuS is greater (theft of credentials and bank details), it is easier to refer to it as a ransom demand, easily visible to infected users.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/CL.png\"><img decoding=\"async\" class=\"aligncenter wp-image-1686 size-medium\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/CL-300x109.png\" alt=\"CL\" width=\"300\" height=\"109\" \/><\/a>In addition, various channels were used to disseminate information: appearances on television news programs, internal briefings for police officers, and the website &quot;GetSafeOnline&quot; (https:\/\/www.getsafeonline.org\/). The messages remained simple: &quot;Do not open emails from unknown senders,&quot; &quot;Use antivirus software,&quot; &quot;Update your software,&quot; and &quot;Back up your data.&quot;.<\/p>\n<p>The campaign results were generally positive: two-thirds of the UK&#039;s IP addresses stopped communicating with the <em>sinkholes<\/em> (fake DNS servers resolving domain names used by bots with unreachable IP addresses) and the use of antivirus software has increased significantly.<\/p>\n<p>From a technical standpoint, computers infected with Cryptolocker communicated with control and control (C&amp;C) servers bearing domain names ending in .com, .net, .biz, .ru, .org, .co.uk, and .info. The GameOver ZeuS botnet used communications <em>peer to peer<\/em>.<\/p>\n<p>Several jurisdictions were therefore involved, and a coordinated effort was required to carry out the dismantling operations:<\/p>\n<ul>\n<li>Private actors intervened to block communications <em>peer to peer<\/em> ;<\/li>\n<li>In the United States, the courts have mandated its Internet registry and about twenty internet service providers to implement <em>sinkholes <\/em>and block the domains used by the botnet;<\/li>\n<li>Police forces from eleven countries have seized servers.<\/li>\n<\/ul>\n<p>The operation of &quot;\u00ab\u00a0<em>takedown<\/em>\u00a0\u00bbThe operation was carried out in one go to prevent any undismantled parts from being exposed and thus unable to be directly neutralized. During this operation, and to guarantee its effectiveness, all actors shared information continuously.<\/p>\n<p>The main lesson learned is the need for cooperation and trust between international actors, both governmental and private. The speakers cited the example of mandates imposing domain blocking: what will happen when they expire? They addressed this by suggesting the development of an &quot;Internet registry of last resort,&quot; an organization that would allow domains used for malicious purposes to be blocked permanently and free of charge.<\/p>\n<p>See also: Analysis of GameOver ZeuS&#039;s communication model: <a href=\"http:\/\/www.syssec-project.eu\/m\/page-media\/3\/zeus_malware13.pdf\">http:\/\/www.syssec-project.eu\/m\/page-media\/3\/zeus_malware13.pdf<\/a><\/p>\n<h2>Semantic Binary Exploration \u2013 Speeding up malware analysis \u2013 Laura Guevara &amp; Daniel Plohmann (Fraunhofer)<\/h2>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/SBE.png\"><img decoding=\"async\" class=\"aligncenter wp-image-1692 size-medium\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/SBE-300x224.png\" alt=\"SBE\" width=\"300\" height=\"224\" \/><\/a>Slides: <a href=\"https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.3-Semantic-Exploration-of-Binaries.pdf\">https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.3-Semantic-Exploration-of-Binaries.pdf<\/a><\/p>\n<p>IDAScope: <a href=\"https:\/\/bitbucket.org\/daniel_plohmann\/simplifire.idascope\/overview\">https:\/\/bitbucket.org\/daniel_plohmann\/simplifire.idascope\/overview<\/a><\/p>\n<p>The aim of the presentation was to highlight the similar characteristics that can be found during malware analysis, particularly through the use of the Windows API.<\/p>\n<p>Indeed, it is possible to infer the behavior of malware by studying its imports. For example, an executable importing the VirtualAlloc, CreateProcessMemory, and CreateRemoteThread functions has a high probability of performing DLL injection and thus injecting malicious code into other processes.<\/p>\n<p>Obviously, such an analysis is only possible if the malware is not &quot;packed&quot; or if it has been previously &quot;unpacked&quot;.<\/p>\n<p>After detecting the likely behavior of malware, its analysis can be accelerated by simplifying the execution flow graph through tracking the possible values assigned to different registers and the values of the strings present in the executable. Furthermore, the acceleration is further enhanced by removing branches from the graph that do not correspond to the inferred behavior.<\/p>\n<p>Finally, the presentation concluded with a demonstration of the IDAScope tool, which integrates this research as well as other tools designed to improve and facilitate binary analysis with IDA:<\/p>\n<ul>\n<li>YARA signature search;<\/li>\n<li>identification of cryptographic algorithms;<\/li>\n<li>Semantic Explorer (the tool presented above);<\/li>\n<li>function inspector (allowing you to see the calls with their associated parameters);<\/li>\n<li>integration of MSDN documentation directly into the tool.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>HAVEX RAT \u2013 The Full Story \u2013 Giovanni Rattaro &amp; Renaud Leroy (OpenMinded), Paul Rascagn\u00e8res (G-Data)<\/h2>\n<p>The speakers presented the HAVEX RAT (Remote Access Tool), which was first detected in January 2014. Two months later, the first IOCs (Indicators of Compromise) were published by Giovanni Rattaro (<a href=\"http:\/\/pastebin.com\/2x1JinJd\">http:\/\/pastebin.com\/2x1JinJd<\/a>).<\/p>\n<p>The infection by this malware is believed to have occurred via &quot;\u00ab\u00a0<em>water holing<\/em>\u00a0\u00bb (use of websites as an intermediary to compromise their regular visitors) on energy-related websites.<\/p>\n<p>A technical analysis outlines the main expected features of HAVEX: file upload and download, command execution, etc. However, this RAT also includes modules for interacting with ICS\/SCADA systems. Specifically, an OPC scanner has been identified: this is a process control system that bridges software and industrial systems. This module enables the identification of various PLC controllers on a given network.<\/p>\n<p>The discovery of this module sparked a buzz and some even went so far as to consider it a new Stuxnet.<\/p>\n<p>The rest of the presentation focuses on the content of the C&amp;C files, and more specifically on the testlog.php file, which contains information about the bots (IP address, user-agent, etc.). The data used by the script is automatically deleted once retrieved. However, information in these files indicates that machines have been infected since 2011.<\/p>\n<p>The presentation concludes with a few figures:<\/p>\n<ul>\n<li>92 countries concerned;<\/li>\n<li>263 C&amp;C servers identified, of which 56 are still in operation;<\/li>\n<li>22,548 bot IP addresses identified.<\/li>\n<\/ul>\n<p>In conclusion, the concept of a CERT 2.0 is presented. The idea is to improve collaboration and coordination among different communities in order to act more effectively against this type of threat.<\/p>\n<p>&nbsp;<\/p>\n<h2>The Many Faces of Mevade \u2013 Martijn Grooten (Virus Bulletin) &amp; Jo\u00e3o Gouveia (AnubisNetworks)<\/h2>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/mevade.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1690 size-medium\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/mevade-300x171.png\" alt=\"mevade\" width=\"300\" height=\"171\" \/><\/a>Slides: <a href=\"https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.5-The-Many-Faces-of-Mevade.pdf\">https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.5-The-Many-Faces-of-Mevade.pdf<\/a><\/p>\n<p>The speakers presented an analysis of Mevade and its variants. The malware&#039;s primary activity is generating fake search results on Bing, Yahoo!, and Google. It is unique in that it uses Tor for its communications with the command and control network.<\/p>\n<p>The analysis relied on a network of probes controlled by AnubisNetworks, located in several countries. These probes primarily sample the DNS and HTTP traffic passing through them. The next step is to analyze this data to detect patterns specific to botnet behavior: domain generation algorithms, geographic distribution of requests, etc.<\/p>\n<p>Other elements of the infrastructure then allow it to act as <em>sinkhole<\/em> and to access the data streams destined for the C&amp;C servers.<\/p>\n<p>In the case of Mevade, the initial detection came from DNS queries to .su domains originating from a domain generation algorithm (<em>DGA<\/em>). THE <em>sinkholes<\/em> The measures put in place made it possible to obtain samples of communications with the C&amp;C in the form of HTTP requests with a unique identifier and binary data.<\/p>\n<p>An initial analysis of these communications established that the protocol used was not that of other known botnets (Citadel, Sality, ZeroAccess). Apparently at a dead end, the speakers turned to\u2026 Google. By searching for elements within the collected data, they were able to discover information leading to a new domain in no-ip.biz, distributing a <em>adware<\/em> and other domains used by the botnet.<\/p>\n<p>Finally, the replay of requests intercepted by the infrastructure of <em>sinkhole<\/em> generated error messages related to a bitcoin mining protocol.<\/p>\n<p>In conclusion, botnet hunting doesn&#039;t necessarily begin with analyzing a malware sample, and can even do without it entirely\u2026 as long as the appropriate infrastructure is in place. Public sources of information shouldn&#039;t be overlooked, and it&#039;s important to keep in mind that <em>adware<\/em> may contain other malicious payloads besides their advertisements.<\/p>\n<p>&nbsp;<\/p>\n<h2>Splicing and Dicing 2014: Examining this Year&#039;s Botnet Attack Trends \u2013 Nick Sullivan (CloudFlare)<\/h2>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/CloudFlare.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1687 size-medium\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/CloudFlare-300x225.png\" alt=\"CloudFlare\" width=\"300\" height=\"225\" \/><\/a>Slides: <a href=\"https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.6-Splicing-and-Dicing-2014-Examining-this-Year%E2%80%99s-Botnet-Attack-Trends1.pdf\">https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.6-Splicing-and-Dicing-2014-Examining-this-Year%E2%80%99s-Botnet-Attack-Trends1.pdf<\/a><\/p>\n<p>During this presentation, Nick Sullivan reviewed the 2013-2014 trends in attacks involving botnets.<\/p>\n<p>Four types of attacks are presented:<\/p>\n<ul>\n<li>DDoS;<\/li>\n<li>DNS flood;<\/li>\n<li>HTTP flood;<\/li>\n<li>sophisticated attacks (<em>weaponized<\/em> <em>attacks<\/em>).<\/li>\n<\/ul>\n<p>The DDoS attacks identified by Cloudflare primarily use amplification and reflection techniques. Originally, these techniques targeted the DNS protocol, but other UDP-based protocols can also be exploited. Since 2013, the NTP protocol has also been used (the Spamhaus attack in March 2013, where traffic reached 400 Gbps). The question remains: which protocol will be exploited next (SNMP?).<\/p>\n<p>DNS attacks (<em>DNS flood<\/em>) consist of a request from a non-existent subdomain (traditionally randomly generated) to force the server to request a resolution from its authority servers and thus slow down the chain.<\/p>\n<p>On the HTTP protocol, DDoS attacks are also carried out using random URI requests. It is therefore possible to implement filtering on the <em>user-agent<\/em> or based on recurring patterns identified during the attack. However, this type of attack remains dangerous when large botnets are involved. Cloudflare has observed attacks involving between 1,000 and 50,000 bots.<\/p>\n<p>Regarding threats from IPv6, and according to CloudFlare, these constitute only 0.05% of malicious traffic.<\/p>\n<p>Finally, more complex attacks are also used. These rely primarily on web vulnerabilities from the OWASP Top 10, such as Shellshock or Heartbleed. Studies show that scans can begin as early as one hour after a vulnerability is published.<\/p>\n<p>&nbsp;<\/p>\n<h2>Virus Tracker \u2013 Peter Kleissner (Kleissner &amp; Associates)<\/h2>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/virustracker.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1685 size-medium\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/virustracker-300x168.png\" alt=\"virustracker\" width=\"300\" height=\"168\" \/><\/a>Slides: <a href=\"https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.7-Virus-Tracker.pdf\">https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.7-Virus-Tracker.pdf<\/a><\/p>\n<p>The speaker presents his company, which specializes in botnet monitoring, looks back on its creation in 2012 and gives feedback on the difficulties encountered.<\/p>\n<p>The principle is to create and maintain a database of botnets in order to then attribute samples of suspicious traffic to a specific malware or botnet. The objectives are then to enable the monitoring of botnet evolution, the sharing of data with clients and the general public, and the prevention of attacks against potentially affected organizations.<\/p>\n<p>For a small organization with limited resources in terms of time, money, and equipment, the following problems arose:<\/p>\n<ul>\n<li>We must take into account the different operating methods of botnets: HTTP, <em>peer to peer<\/em>, IRC, raw TCP, etc.; ;<\/li>\n<li>An initial entry point must be discovered for each botnet: analyzing the domain name generation algorithm <em>(DGA)<\/em>, find the initial peers for the bots <em>peer to peer<\/em>, etc. ;<\/li>\n<li>THE <em>sinkholing<\/em>It comes at a cost: approximately \u20ac6 per year per domain name. This amount becomes significant when thousands of names need to be registered; ;<\/li>\n<li>Botnets sometimes implement protections: authentication against the <em>crawling<\/em> for botnets <em>peer to peer<\/em>, blocking traffic to specific domains against the <em>sinkholing, etc.; ;<br \/>\n<\/em><\/li>\n<li>It is necessary to take into account scalability for information storage; ;<\/li>\n<li>Legal aspects may come into play: handling of complaints if areas are seized in dismantling operations or added to blacklists.<\/li>\n<\/ul>\n<p>The solution offered by the speaker: automate as much as possible, using tools developed specifically in-house: <em>crawlers <\/em>to browse botnets <em>peer to peer<\/em>, domain registrars, filters for data collection to store only relevant information\u2026<\/p>\n<p>To extract information from the collected data, a correlation and visualization tool was implemented. In the future, the speaker also plans to make the information available to the general public via an API.<\/p>\n<p>Discussions following the conference also highlighted a domain name indexing service used for the <em>sinkholing<\/em> to avoid their being added to blacklists: <a href=\"https:\/\/sinkdb.abuse.ch\">https:\/\/sinkdb.abuse.ch<\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>How to dismantle a botnet: legal aspects behind the scenes \u2013 Karine e Silva (PhD student at Tilburg University (Netherlands) \u2013 @kar1nekks)<\/h2>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/dismantle_botnet_legal.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1688 size-medium\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2014\/12\/dismantle_botnet_legal-300x224.png\" alt=\"dismantle_botnet_legal\" width=\"300\" height=\"224\" \/><\/a>Slides: <a href=\"https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.8-How-to-Dismantle-a-Botnet-the-Legal-Behind-the-Scenes.pdf\">https:\/\/www.botconf.eu\/wp-content\/uploads\/2014\/12\/2014-1.8-How-to-Dismantle-a-Botnet-the-Legal-Behind-the-Scenes.pdf<\/a><\/p>\n<p>The speaker presents the legal aspects of dismantling operations, what makes them possible, and the differences in approach between Europe and the United States. She draws on two case studies: GameOver ZeuS and Bredolab.<\/p>\n<p>The United States has been heavily involved in actions against GameOver ZeuS. Government agencies have pursued three main lines of action:<\/p>\n<ul>\n<li>Legitimizing their jurisdiction: as long as American citizens are infected, American law allows for prosecution of the perpetrator, even if they reside in a foreign country; ;<\/li>\n<li>Launching destabilization actions: the FBI has issued an arrest warrant against the alleged creator of the botnet;<\/li>\n<li>Cooperating with agencies from other countries: joint actions have been launched with several European countries.<\/li>\n<\/ul>\n<p>The actions against Bredolab were primarily carried out by the Netherlands:<\/p>\n<ul>\n<li>The cybercrime branch of the Dutch police launched an operation resulting in the takeover of the botnet.<\/li>\n<li>The authorities then directly used the C&amp;C interface to inform affected users.<\/li>\n<\/ul>\n<p>In both cases, the operations were &quot;intrusive&quot; for end users from a privacy standpoint. While feedback on the operation in the United States was generally positive, the Dutch authorities were criticized for their intrusion into victims&#039; systems, even if their intention was benevolent.<\/p>\n<p>These results illustrate the differences in perceptions across cultures, and highlight the difficulty for authorities to protect citizens without infringing on their right to privacy.<\/p>\n<p>See also: A publication by the speaker on the European approach to cybersecurity: <a href=\"http:\/\/policyreview.info\/articles\/analysis\/europes-fragmented-approach-towards-cyber-security\">http:\/\/policyreview.info\/articles\/analysis\/europes-fragmented-approach-towards-cyber-security<\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Lightning talks \u2013 first session<\/h2>\n<p>Similar to SSTIC, the <em>lightning talks<\/em> allow you to present a topic in three minutes.<\/p>\n<p><strong>Jumping over the airgap with Fancy Bear <\/strong>: presentation of the Fancy Bear malware which is capable of infecting a computer not connected to the Internet via USB key and sending and receiving commands via this medium.<\/p>\n<p><strong>3-Minute Incident Handling\u00a0<\/strong>: a tool for representing network communications via a graph system by comparing them with known malware sources: Malcom (<a href=\"https:\/\/github.com\/tomchop\/malcom\">https:\/\/github.com\/tomchop\/malcom<\/a>).<\/p>\n<p><strong>Coordinated Malware Eradication\u00a0<\/strong>Microsoft has launched a project to provide assistance and exchange in the fight against cybercrime (<a href=\"http:\/\/www.microsoft.com\/security\/Portal\/mmpc\/cme\/malware_eradication.aspx\">http:\/\/www.microsoft.com\/security\/Portal\/mmpc\/cme\/malware_eradication.aspx<\/a>).<\/p>\n<p><strong>Qakbot\u00a0<\/strong>: presentation of the evolution of data storage in the Qakbot malware, which in its latest version uses an encryption system based on RC4.<\/p>\n<p><strong>Auto decryption of malware samples\u00a0<\/strong>: presentation of a tool allowing the unpacking, decryption and recovery of configuration files as well as webinjects from malware of the type <em>banker<\/em>.<\/p>\n<p><strong>Macaroni\u00a0<\/strong>: presentation of a browser extension compatible with VirusTotal and allowing searches based on tags.<\/p>\n<p><strong>Data at scale\u00a0<\/strong>Discussion about migrating simple data to standard data types <em>\u00ab&quot;Big data&quot;\u00bb<\/em> by adding a layer of abstraction on top of the raw data.<\/p>","protected":false},"excerpt":{"rendered":"<p>Intrinsec \u00e9tait pr\u00e9sent lors de la seconde \u00e9dition de la Botconf qui s&rsquo;est d\u00e9roul\u00e9e du [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":1689,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,19,22],"tags":[],"class_list":["post-228080","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-evaluation-securite","category-soc-securite-operationnelle","category-veille-securite"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Conf\u00e9rence Botconf 2014 - Jour 1 - INTRINSEC<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/conference-botconf-2014-jour-1\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Conf\u00e9rence Botconf 2014 - Jour 1\" \/>\n<meta property=\"og:description\" content=\"Intrinsec \u00e9tait pr\u00e9sent lors de la seconde \u00e9dition de la Botconf qui s&rsquo;est d\u00e9roul\u00e9e du [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/conference-botconf-2014-jour-1\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2015-01-06T08:37:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/03\/Digital-Marketing-Partners-6.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"378\" \/>\n\t<meta property=\"og:image:height\" content=\"148\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/\"},\"author\":{\"name\":\"Admin\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/5636e3e5276b952facbd0aadb12a858a\"},\"headline\":\"Conf\u00e9rence Botconf 2014 &#8211; Jour 1\",\"datePublished\":\"2015-01-06T08:37:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/\"},\"wordCount\":3052,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/Digital-Marketing-Partners-6.webp\",\"articleSection\":[\"S\u00e9curit\u00e9 offensive &amp; Audit\",\"SOC S\u00e9curit\u00e9 Op\u00e9rationnelle\",\"Veille S\u00e9curit\u00e9\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/\",\"name\":\"Conf\u00e9rence Botconf 2014 - Jour 1 - INTRINSEC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/Digital-Marketing-Partners-6.webp\",\"datePublished\":\"2015-01-06T08:37:04+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/Digital-Marketing-Partners-6.webp\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/Digital-Marketing-Partners-6.webp\",\"width\":378,\"height\":148},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/conference-botconf-2014-jour-1\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Conf\u00e9rence Botconf 2014 &#8211; Jour 1\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/5636e3e5276b952facbd0aadb12a858a\",\"name\":\"Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"caption\":\"Admin\"},\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Botconf 2014 Conference - Day 1 - INTRINSEC","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/conference-botconf-2014-jour-1\/","og_locale":"en_US","og_type":"article","og_title":"Conf\u00e9rence Botconf 2014 - Jour 1","og_description":"Intrinsec \u00e9tait pr\u00e9sent lors de la seconde \u00e9dition de la Botconf qui s&rsquo;est d\u00e9roul\u00e9e du [&hellip;]","og_url":"https:\/\/www.intrinsec.com\/en\/conference-botconf-2014-jour-1\/","og_site_name":"INTRINSEC","article_published_time":"2015-01-06T08:37:04+00:00","og_image":[{"width":378,"height":148,"url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/03\/Digital-Marketing-Partners-6.webp","type":"image\/webp"}],"author":"Admin","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Admin","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/"},"author":{"name":"Admin","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/5636e3e5276b952facbd0aadb12a858a"},"headline":"Conf\u00e9rence Botconf 2014 &#8211; Jour 1","datePublished":"2015-01-06T08:37:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/"},"wordCount":3052,"commentCount":0,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/03\/Digital-Marketing-Partners-6.webp","articleSection":["S\u00e9curit\u00e9 offensive &amp; Audit","SOC S\u00e9curit\u00e9 Op\u00e9rationnelle","Veille S\u00e9curit\u00e9"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/","url":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/","name":"Botconf 2014 Conference - Day 1 - INTRINSEC","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/03\/Digital-Marketing-Partners-6.webp","datePublished":"2015-01-06T08:37:04+00:00","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/#primaryimage","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/03\/Digital-Marketing-Partners-6.webp","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/03\/Digital-Marketing-Partners-6.webp","width":378,"height":148},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/conference-botconf-2014-jour-1\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"Conf\u00e9rence Botconf 2014 &#8211; Jour 1"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/5636e3e5276b952facbd0aadb12a858a","name":"Admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","caption":"Admin"},"url":"https:\/\/www.intrinsec.com\/en\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/228080","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=228080"}],"version-history":[{"count":0,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/228080\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media\/1689"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=228080"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=228080"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=228080"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}