Home
Talks
CFP Guide
What is BSides?
About
Contact
Light
← All talks
Tool
BSides talks featuring Burp Suite
322
talks mention this tool across
81
BSides chapters.
Talks featuring Burp Suite
25:00
Bug Bounty Recon The Right Way
Khalil A. Lemtaffah
BSides Budabest
· 2022
Technical
OSINT
Web AppSec
Intermediary
Red
Talk
Open →
2023-06
32:48
G1234! - Cash in the Aisles: How Gift Cards are Easily Exploited - William Caput
BSides Las Vegas
Open →
2017-08
33:53
The Power of Recon
Orwa Atyat
BSides Ahmedabad
Technical
OSINT
Vulnerability Research
Web AppSec
Red
Talk
Open →
2024-05
47:57
Exploit Development Is Dead, Long Live Exploit Development!
Connor McGarr
BSides KC
· 2021
Technical
Reverse Engineering
Vulnerability Research
Advanced
Red
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2021-11
1:09:05
Demystifying Bug Bounties: Insights from a Decade of Experience
Yassine Aboukir
BSides Prishtina
· 2023
Technical
Supply Chain Security
Vulnerability Research
Red
Talk
Open →
2023-05
27:44
Hacking AAA Unreal Engine Games with Python
Ross Simpson
BSides Cape Town
· 2023
Technical
Reverse Engineering
Vulnerability Research
Red
Demo
Talk
Open →
2023-12
45:08
Scripting Myself Out of a Job - Automating the Penetration Test with APT2 - Adam Compton
BSides Knoxville
Open →
2016-06
25:28
If You Can Open The Terminal, You Can Capture The Flag: CTF For Everyone
BSides Detroit
Open →
2013-06
49:29
AutoRepeater: Automated HTTP Request Repeating With Burp Suite
Justin Moore
BSidesROC
· 2018
Technical
Tooling
Web AppSec
Demo
Talk
Open →
2018-04
46:12
BSidesMCR 2019: HTTP Desync Attacks: Smashing Into The Cell Next Door - James Kettle
BSides Manchester
Open →
2019-09
41:35
How to Write Your First Nuclei Template
Dhiyaneshwaran
BSides Ahmedabad
Technical
Vulnerability Research
Web AppSec
Talk
Open →
2023-02
19:32
Blackhat Python
Dan Frisch
BSides Toronto
· 2014
Technical
Talk
Open →
2014-12
31:58
Automating Web Application Bug Hunting
Jerry Gamblin
Jonathan Cran
BSidesSF
· 2019
Technical
OSINT
Vulnerability Research
Web AppSec
Talk
Open →
2019-03
58:45
Pentesting Hardware And IoT by Mark Carney
Mark Carney
BSides Leeds
· 2018
Technical
Demo
Open →
2018-02
37:09
Wędkarstwo Dla Myśliwych - Z Phishingiem Przygody Bezpiecznika
Adam Lange
BSides Warsaw
· 2018
Talk
Open →
2019-02
44:22
SWF Seeking Lazy Admin for Cross-Domain Action
Seth Art
BSides DC
· 2014
Technical
OWASP
Web AppSec
Talk
Open →
2014-10
42:25
Client-Side to Critical
Satyam Gothi
Kuldeep Pandya
BSides Ahmedabad
· 2025
Technical
Vulnerability Research
Web AppSec
Red
Talk
Open →
2025-05
27:48
Abusing Historical DNS Records for Fun & Profit
Mustafa Can IPEKCI
BSides Ahmedabad
· 2025
Technical
Talk
Open →
2025-05
15:37
Tale of Chaining Bugs for Account Takeover
Harsh Bothra
BSides Ahmedabad
· 2022
Technical
Vulnerability Research
Web AppSec
Red
Case Studies and Incidents Analysis
Talk
Open →
2023-02
39:50
2016 - James Kettle - Hunting Asynchronous Vulnerabilities
BSides Manchester
Open →
2016-09
24:17
PG - Pwn All The Mobile Porn Apps - Ben Actis
BSides Las Vegas
Open →
2017-08
51:26
BG - Pacu: Attack and Post-Exploitation in AWS - Spencer Gietzen
BSides Las Vegas
Open →
2018-09
16:42
Bug Bounty Show
Satyam Gothi
BSides Ahmedabad
· 2022
Open →
2023-02
45:09
2017 - Cracking The Lens: Targetting HTTP's Hidden Attack Surface
BSides Manchester
Open →
2017-08
28:50
Amazon Cognito (Mis)Configurations
BSides Ahmedabad
· 2021
Technical
Cloud IAM
Intermediary
Red
Talk
Open →
2022-03
1:05:00
You can't make web app security easy, but you can make it simple
Joseph McCray
BSides DC
· 2015
Technical
Web AppSec
Talk
Open →
2015-12
29:16
Damn GraphQL - Defending and Attacking APIs - Dolev Farhi
BSides Vancouver
Open →
2021-06
39:30
Pwning Cloud Contexts: From GitHub Token to Compromising an Entire GCP Organization
Ayoub Fathi
BSides Ahmedabad
· 2024
Technical
Cloud IAM
Supply Chain Security
Vulnerability Research
Red
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2024-04
42:33
Web Application Vulnerability Scanners: An Introduction & Discussion on Their Limitations
Robert Feeney
BSides Cape Town
· 2019
Technical
Vulnerability Research
Web AppSec
Talk
Open →
2019-12
32:02
Batch Firmware Analysis
Jeremy Richards
BSides Toronto
· 2014
Technical
Talk
Open →
2014-12
50:01
"Context Aware Content Discovery: The Natural Evolution"
Sean Yeoh
Patrick Mortensen
Michael Gianarakis
Shubham Shah
BSides Canberra
· 2021
Talk
Open →
2021-04
23:15
Circumventing egress filtering by exploiting HTTP "transfer-encoding: chunked" for faster web shells
Lorenzo Grespan
BSides London
· 2018
Technical
Advanced
Red
Talk
Open →
2018-06
8:30
PHP Execute After Redirect to SQL Injection
Kuldeep Pandya
BSides Ahmedabad
· 2022
Technical
Vulnerability Research
Web AppSec
Red
Demo
Open →
2023-02
25:39
Journey to Command Injection: Hacking the Lenovo ix4-300d
Rick Ramgattie
BSidesSF
· 2019
Technical
Hardware Hacking
Vulnerability Research
Web AppSec
Intermediary
Red
Demo
Open →
2019-03
10:48:30
BSides LV 2022 - Wednesday - Breaking Ground Track
BSides Las Vegas
Open →
2022-08
25:06
Adventures & Findings in ISP Hacking
Ian Foster
BSidesSF
· 2025
Technical
Talk
Open →
2025-06
52:48
Navigating Bug Bounties: From NAs to P1s
Animesh Acharya
BSides Canberra
· 2025
Career
Vulnerability Research
Web AppSec
Red
Case Studies and Incidents Analysis
Talk
Open →
2025-11
47:39
Mastering Android Security Research: A Guide for the Modern Security Researcher
Hahna Latonick
Jacob Swinsinski
BSides Tampa
· 2024
Technical
Mobile Security
Reverse Engineering
Vulnerability Research
Intermediary
Red
Talk
Open →
2024-05
42:09
BSidesSF 2021 - Offensive Javascript Techniques for Red Teamers (Dylan Ayrey • Christian Frichot)
Dylan Ayrey
Christian Frichot
BSidesSF
· 2021
Technical
Web AppSec
Red
Talk
Open →
2021-03
51:46
BSides Rochester 2016: Jamie Geiger: Android Application Function Hooking with Xposed
Jamie Geiger
BSidesROC
· 2016
Technical
Talk
Open →
2016-05
40:50
Building Burp Extensions
Jason Gillam
BSides Charleston
· 2015
Technical
Talk
Open →
2015-12
49:41
The Way of the Bounty
David Sopas
BSides Lisbon
· 2016
Career
Talk
Open →
2016-11
26:03
Automated Security Scanning of GraphQL APIs with Burp
Jared Meit
BSides Toronto
· 2022
Technical
Vulnerability Research
Web AppSec
Demo
Talk
Open →
2022-10
50:12
Attacking JSON Web Tokens
BSides Canberra
· 2019
Technical
Cryptography
Red
Talk
Open →
2019-05
19:06
Hacking a Hackathon for Fun and Profit
Alexei Kojenov
Alex Ivkin
BSides PDX
· 2018
Technical
Supply Chain Security
Vulnerability Research
Web AppSec
Red
Case Studies and Incidents Analysis
Talk
Open →
2018-03
10:36
Bug Bounty Show
Arman Pathan
BSides Ahmedabad
· 2022
Open →
2023-02
41:34
Knock Knock. Race Condition. Who's There?
Ross Simpson
BSides Cape Town
· 2025
Technical
Vulnerability Research
Web AppSec
Talk
Open →
2025-12
38:38
"Open, Sesame!" Unlocking Bluetooth Padlocks With Kind Requests - Miłosz Gaczkowski & Alex Pettifer
Miłosz Gaczkowski
Alex Pettifer
BSides London
Technical
Wireless Security
Talk
Open →
2024-02
26:29
Finding & Exploiting Client-Side Prototype Pollution in the Wild
BSides Ahmedabad
· 2021
Technical
Vulnerability Research
Web AppSec
Red
Case Studies and Incidents Analysis
Methodology
Talk
Open →
2022-02
35:29
Jonathan Echavarria | Pwning pwners like a n00b
BSides Orlando
Open →
2016-03
33:04
CSRFT, A Toolkit for CSRF Vulnerabilities
Paul Amar
BSides London
· 2014
Technical
Tooling
Web AppSec
Demo
Talk
Open →
2014-05
6:18:25
Security BSides Athens 2022 — Live Stream Part 2
BSides Athens
· 2022
Technical
Talk
Open →
2022-06
57:55
Seriously? You Want Me To Believe Cyber-Spies Want My Data
BSides Detroit
Open →
2012-06
48:51
What is blockchain security? - Dylan Dubief
Dylan Dubief
BSides Prishtina
· 2023
Technical
Talk
Open →
2023-05
49:18
Aarti Gadhia: There is no security skills shortage!
Aarti Gadhia
BSides Calgary
Career
Talk
Open →
2020-12
39:07
BSides Glasgow 2018 - Paul Ritchie - Hacking with Git
BSides Scotland
Open →
2018-05
30:48
A Two-part Saga: Continuing the Journey of Hacking Malware C2s
Vangelis Stykas
BSides Prague
· 2024
Technical
Malware Analysis
Vulnerability Research
Web AppSec
Red
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2024-04
27:38
BSidesPDX 101: Conference Organization, Capture the Flag, Contests & Events
BSides PDX
· 2019
Community
CTF
Panel
Open →
2019-11
27:11
Hacking with a Heads Up Display
David Scrobonia
BSidesSF
· 2019
Technical
Tooling
OWASP
Web AppSec
Talk
Open →
2019-03
14:38
Visualising TLS Fingerprints With TMAP To Hunt Malicious Domains
Amanda Thomson
BSides London
· 2025
Technical
Cryptography
Talk
Open →
2025-02
48:11
BSidesMCR 2018: Burp Replicator: Automate Reproduction Of Complex Vulnerabilities by Paul Johnston
BSides Manchester
Open →
2018-08
46:32
Anyone Can Hack APIs: A Crash Course For Pentesters And Bug Bounty Hunters
Alex Olsen
BSides London
· 2025
Technical
Vulnerability Research
Web AppSec
Red
Talk
Open →
2026-03
17:00
Run-time Tools to aid Application Security Assessments
Sasha Zivojinovic
BSides London
Technical
Intro
Talk
Open →
2014-05
23:35
Breaking Into Infosec or, How I hacked my way out of poverty - BSides Portland 2022
BSides PDX
Open →
2022-10
51:24
Red Blue Purple AI
Jason Haddix
BSides Boulder
· 2024
Technical
AI Security
OSINT
Blue
Purple
Red
Keynote
Open →
2024-09
41:29
The Art of Compromising C2 Servers
Vangelis Stykas
BSides Berlin
· 2023
Technical
Malware Analysis
Reverse Engineering
Web AppSec
Advanced
Red
Talk
Open →
2024-01
26:54
Introduction to OWASP Juice Shop
Tim Corless-Carter
BSides Manchester
· 2019
Technical
OWASP
Vulnerability Research
Web AppSec
Intro
Red
Demo
Open →
2019-09
28:33
Hook, Line, and Tinker: A Dive into Phishing Campaign Sites
Rick Ramgattie
BSidesSF
· 2024
Technical
OSINT
Threat Intel
Web AppSec
Intermediary
Case Studies and Incidents Analysis
Talk
Open →
2024-07
36:00
Attacking Authentication in Web Applications - Jake Miller
Jake Miller
BSides SATX
· 2018
Technical
Web AppSec
Red
Talk
Open →
2018-07
19:44
Uncommon And Advanced Techniques For Account Takeover Attacks by Ayoub Safa
Ayoub Safa
BSides Leeds
Technical
Vulnerability Research
Web AppSec
Red
Case Studies and Incidents Analysis
Talk
Open →
2023-07
40:05
Empowering Junior Testers: Strategies For Uncovering Critical Vulns In Web Applications
Tom Stacey
BSides Exeter
Technical
Web AppSec
Talk
Open →
2024-09
38:06
Como Hackear um Banco sem Sair do seu Quarto?
Arthur Aires
Matheus Wreck
Gustavo Oliveira
BSides São Paulo
· 2025
Technical
War Stories
Reverse Engineering
Vulnerability Research
Web AppSec
Advanced
Red
Talk
Open →
2025-06
40:17
Jakub Kaluzny - Proprietary network protocols - risky business on the wire.
Jakub Kaluzny
BSides London
· 2015
Technical
Advanced
Red
Talk
Open →
2015-07
44:11
Training Citizen Cyber Warriors on the Michigan Cyber Range
BSides Detroit
Open →
2013-06
43:49
BSides DC 2016 - Beyond Automated Testing
Zachary Meyers
Andrew McNicol
BSides DC
· 2016
Technical
Talk
Open →
2016-10
39:58
BSidesMCR 2019: Fun With Frida! - James Williams
BSides Manchester
Open →
2019-09
39:37
Doppelgänger Devices: Investigating Fake iPhones & Security Implications
Ansie Brough
BSides Joburg
· 2024
Technical
Supply Chain Security
Demo
Talk
Open →
2024-08
33:12
Discord OSINT: Using the Power of Empathy
Zach Malinich
BSides Philly
· 2025
Technical
Talk
Open →
2025-02
4:14:50
Hardware Hacking Workshop
Jilles Vandermeulen
BSides Pakistan
· 2020
Technical
Hardware Hacking
IoT
Reverse Engineering
Intro
Workshop
Open →
2020-11
47:47
The Hunt For The Red DA by Neil Lines
BSides Scotland
Open →
2017-04
51:46
Project Ava - Can Machine Learning Be Used To Complement Web Penetration Testing? - Matt Lewis
Matt Lewis
BSides Cymru Wales
· 2019
Technical
Talk
Open →
2019-10
38:25
Matriux Leandros: An Open Source Penetration Testing and Forensic Distribution
Prajwal Panchmahalkar
BSides Las Vegas
· 2013
Technical
DFIR
Tooling
Talk
Open →
2017-01
26:36
BSides DC 2014 - Fighting Back Against SSL Interception (or How SSL Should Work)
BSides DC
Open →
2014-10
45:12
CG - Pentesting with Docker - Tom Steele
BSides Las Vegas
Open →
2016-12
40:18
Fighting Fraud in the Trenches
Amir Shaked
BSides Las Vegas
· 2018
Technical
Threat Intel
Web AppSec
Talk
Open →
2018-09
24:20
Concrete Steps to Create a Security Culture
Arkadiy Tetelman
BSidesSF
· 2019
Community
Career & Soft Skills
Intro
Talk
Open →
2019-03
28:31
Exploiting SNI SSRF To Access The AWS IMDSv2 - Oliver Morton
Oliver Morton
BSides Leeds
Technical
Talk
Open →
2024-09
49:27
The Tales of a Bug Bounty Hunter
Arne Swinnen
BSidesSF
· 2016
Technical
Web AppSec
Advanced
Red
Talk
Open →
2016-04
33:40
BSidesIOWA 2015 Track1: Intro to WebApp Testing with Mutillidae by Andrew Freeborn
BSides Iowa
Open →
2015-04
46:48
Look Ma, No Exploits! — The Recon-ng Framework
Tim Tomes
BSides Augusta
· 2013
Technical
OSINT
Tooling
Red
Demo
Talk
Open →
2013-09
53:29
The Pentester Blueprint: A Guide to Becoming a Pentester
Phillip Wylie
BSides SATX
· 2020
Career
Intro
Talk
Open →
2020-08
35:28
Hacking Mobile Apps with Frida
David Coursey
BSides Charleston
· 2018
Technical
Talk
Open →
2018-11
28:10
Pwn2Own Stories - Ben McBride
Ben McBride
BSides Albuquerque
War Stories
Reverse Engineering
Vulnerability Research
Red
Case Studies and Incidents Analysis
Talk
Open →
2024-08
44:09
BG - SECSMASH: Using Security Products to own the Enterprise - Kevin Dick & Steven Flores
BSides Las Vegas
Open →
2017-08
54:32
Tim Tomes - {JWT}.{Misuse}.&Abuse
Tim Tomes
BSides Augusta
· 2023
Technical
Cryptography
Web AppSec
Red
Talk
Open →
2023-10
40:27
A Practical Approach In Exploit Development For Embedded Devices
BSides Munich
Open →
2017-04
34:58
Certpinning, OpenSSL and Memory Patching
Isak van der Walt
BSides Joburg
· 2024
Technical
Advanced
Technical Deep-dives
Talk
Open →
2024-08
27:40
Ferris Bueller's Guide to Abuse Domain Permutations
Rob Ragan
Kelly Albrink
BSidesSF
· 2019
Technical
OSINT
Social Engineering
Threat Intel
Case Studies and Incidents Analysis
Empirical Research
Talk
Open →
2019-03
44:06
Justin Clarke - Practical Crypto Attacks Against Web Applications
Justin Clarke
BSides London
· 2014
Technical
Cryptography
Web AppSec
Talk
Open →
2014-07
29:35
The Bucket List: Experiences Operating S3 Honeypots
Cameron Ero
BSidesSF
· 2018
Research
Cloud IAM
Threat Intel
Blue
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2018-04
49:20
Whack A Phish
Geoffrey Chisnall
BSides Joburg
· 2025
Technical
Talk
Open →
2025-09
42:23
Forging Chains: The Java Blacksmith
Fabian Yamaguchi
David Baker Effendi
BSides Cape Town
· 2023
Technical
Reverse Engineering
Vulnerability Research
Advanced
Red
Technical Deep-dives
Talk
Open →
2023-12
56:01
21st Century War Stories
Ben Turner
BSides Manchester
· 2016
War Stories
OSINT
Social Engineering
Threat Intel
Red
Case Studies and Incidents Analysis
Talk
Open →
2016-09
24:02
Having fun while analyzing mobile applications
Álvaro Felipe Melchor
BSides Lisbon
· 2017
Technical
Mobile Security
Reverse Engineering
Talk
Open →
2017-11
52:56
How to Get Started in Cybesecurity - john Stoner
BSides Peru
Open →
2019-07
22:54
Introducing The OWASP Nettacker Project
Sam Stepanyan
BSides Athens
· 2020
Technical
Tooling
OWASP
Demo
Talk
Open →
2020-06
34:32
Introduction To Ethical Hacking
Brandon S. Keath
BSides Delaware
· 2018
Talk
Open →
2018-11
57:23
2016 - Ian Trump - Basic Malware Analysis – dispelling Malware FUD
BSides Manchester
Open →
2016-09
22:23
PG - Burpsuite Team Collaborator: Enabling Collaborative App Testing - Tanner Barnes
BSides Las Vegas
Open →
2019-10
24:47
BSides Berlin 2023: Jorge Gimenez - Phishing techniques for challenging environments
BSides Berlin
Open →
2024-01
53:19
XXE and the Cloud: the Sky IS Falling
Clint Kehr
Mark Schmidt
BSides NoVa
· 2021
Technical
Cloud IAM
Web AppSec
Red
Demo
Talk
Open →
2021-06
58:26
Tim Tomes - Recon-ng and Beyond
Tim Tomes
BSides Augusta
· 2015
Technical
OSINT
Web AppSec
Red
Talk
Open →
2015-09
11:03
Exploiting Firebase Apps with Baserunner
David Yates
BSides Joburg
· 2025
Technical
Cloud IAM
Red
Demo
Talk
Open →
2025-08
37:13
Take Down Cyberthreat Dwell Time With Optimum Security
Eric Payne
BSides Vancouver
· 2021
Technical
Detection Engineering
Threat Intel
Blue
Talk
Open →
2021-06
47:04
Intro to API Hacking
Jamy Casteel
BSides Dallas/Fort Worth
· 2022
Technical
OWASP
Web AppSec
Intro
Red
Talk
Open →
2022-11
15:31
Persistence Pays: From Flames To Firewalls
Oliver Ellis
BSides London
· 2025
Career
Vulnerability Research
Intro
Talk
Open →
2026-03
44:43
Hacking Mobile Apps With Frida
David Coursey
BSides Belfast
· 2018
Technical
Mobile Security
Reverse Engineering
Intro
Red
Talk
Open →
2018-10
25:27
How To Get Away With Hacking by Liam Follin
Liam Follin
BSides Leeds
· 2023
Career
Career & Soft Skills
Web AppSec
Intro
Talk
Open →
2023-07
24:48
Penetration Testing Using Windows Features - Niall Caffrey
Niall Caffrey
BSides Belfast
Technical
Talk
Open →
2024-03
18:38
Pentest Deep Dive: Anatomy Of A Weaponized Remote Code Execution Flaw
Robert Kugler
BSides Lisbon
· 2019
Technical
Red
Talk
Open →
2019-12
55:44
Burping for Joy and Financial Gain
Tim Tomes
BSides Augusta
· 2017
Technical
Web AppSec
Talk
Open →
2017-09
54:37
When a Security Architect Writes an Application
David Zendzian
BSides Charleston
· 2014
Technical
Web AppSec
Talk
Open →
2014-11
32:19
Locks on the Wire
Eldar Marcussen
BSides Canberra
· 2023
Technical
Network Security
Physical Security
Reverse Engineering
Red
Technical Deep-dives
Talk
Open →
2024-01
44:19
The Dynamic World of Bug Bounty Hunting Through My Personal Journey by Chan Nyein Wai
Chan Nyein Wai
BSides Myanmar
· 2024
Career
Talk
Open →
2025-01
13:51
OWASP Honeypot Threat Intelligence Project
Kartik Adak
BSides London
· 2025
Research
OWASP
Web AppSec
Technical Deep-dives
Talk
Open →
2025-02
51:17
Robert Coccaro - Remote Browser Isolation - Stop Browser Betrayal During OSINT Investigations
Robert Coccaro
BSides Augusta
· 2022
Technical
Talk
Open →
2022-10
36:07
Attacking .NET Web Services
Ryan Wincey
BSides Charleston
· 2022
Technical
Talk
Open →
2022-11
22:23
I Spy With My Little Eye
Mike Polydorou
Vangelis Stykas
BSides Cymru Wales
· 2019
Technical
IoT
Vulnerability Research
Web AppSec
Red
Talk
Open →
2019-10
29:37
Bypassing Next Generation 2FA & MFA Implementation
Muhammad Shahmeer
BSides Athens
Technical
Red
Open →
2024-06
21:24
2016 - Andrew Pannell - 50 Million downloads and all I got was malware
BSides Manchester
Open →
2016-09
18:36
Making your website vulnerable for fun and security awareness
Kenny Jansson
BSides Oslo
· 2019
Community
Technical
Web AppSec
Talk
Open →
2019-06
42:43
It's not stalking, it's investigating
Robert Bui Moore
BSides Belfast
· 2017
Talk
Open →
2017-10
30:45
Bsides Orlando - Joey Belans - Hacking Like It's 1999
BSides Orlando
Open →
2013-04
24:48
PG - Breaking The Giants With Logic
BSides Las Vegas
Open →
2021-08
29:07
SOC Analyst's Arsenal: Essential Tools, Tips & Tricks For Effective Investigations
Samuel Kavaler
BSides Munich
· 2023
Technical
DFIR
Detection Engineering
Tooling
Intermediary
Blue
Talk
Open →
2023-10
27:09
2017 - Security Testing As Part Of The Release Pipeline by David Brownhill and Craig Scott Angell
BSides Manchester
Open →
2017-08
34:40
Attacking the Front-End: Modern-Day Client-Side Security
Kaif Ahsan
BSides Sydney
· 2023
Technical
Reverse Engineering
Web AppSec
Intermediary
Talk
Open →
2023-09
25:14
Securing Fast and Furious DevOps Pipelines
Abdessamad Temmar
BSides Las Vegas
· 2019
Technical
DevSecOps
Supply Chain Security
Blue
Talk
Open →
2019-10
42:25
Boston BSides - Pentesting for Fun and Profit by William Reyor
BSides Boston
Open →
2016-07
25:44
APIcalypse Now: Hunting APIs to Profit
Nithin Ravi
BSides Galway
Technical
Talk
Open →
2025-03
46:29
The Anatomy of Web Client Attacks
Jason Gillam
BSides Charlotte
· 2015
Technical
Web AppSec
Intermediary
Red
Talk
Open →
2015-06
51:16
Ghost in the Droid - Josh Wright
BSides Boston
Open →
2017-05
39:09
Breaking the Barrier: Exploring Modern WAFs
Ethan Havinga
BSides Cape Town
· 2025
Technical
Vulnerability Research
Web AppSec
Red
Talk
Open →
2025-03
36:27
BSidesSF 2018 - From Bounties to Bureaucracy (Brian Gorenc)
BSidesSF
Open →
2018-04
33:35
GTFO Mr. User
David Sopas
BSides Lisbon
· 2017
Talk
Open →
2017-11
45:10
Reversing Bytecode into Bounties: Uncovering Vulnerabilities in Jira and Confluence Plugins
Giuliana De Bellis
Jamal Hopwood
BSides Canberra
· 2025
Technical
Reverse Engineering
Vulnerability Research
Web AppSec
Intermediary
Red
Talk
Open →
2025-12
24:58
What's Inside The Open Directory From 96 Different Threat Actors?
Alana Witten
BSides London
· 2025
Research
Case Studies and Incidents Analysis
Empirical Research
Talk
Open →
2025-02
24:06
I Love my BFF (Brute Force Framework) - Kirk Hayes
BSides Las Vegas
Open →
2016-09
46:48
InfoSec, Just Doing It
Rob Jorgensen
BSides SLC
· 2015
Career
Career & Soft Skills
Intro
Talk
Open →
2015-04
20:58
BSidesSLC 2015 - Hey Guys, I'm a Pentester! - Metacortex
BSides SLC
· 2015
Career
Intro
Talk
Open →
2015-04
43:43
Attacking OWASP: Exploiting the Top 10
David Coursey
BSides Augusta
· 2015
Technical
OWASP
Talk
Open →
2015-09
37:05
The Single-Packet Shovel: Digging For Desync-Powered Request Tunnelling - Thomas Stacey
Thomas Stacey
BSides Exeter
Technical
Talk
Open →
2025-09
29:21
Leaking Kakao: How I Found A 1-Click Exploit In Korea's Biggest Chat App
Dawin Schmidt
BSides Munich
· 2025
Technical
Mobile Security
Vulnerability Research
Web AppSec
Red
Talk
Open →
2024-11
49:29
HTTP and De-Sync Attacks
Cary Hooper
BSides Dallas/Fort Worth
· 2021
Technical
Vulnerability Research
Web AppSec
Red
Technical Deep-dives
Talk
Open →
2021-11
44:28
Terribly Layered Security
Connor du Plooy
Andre Lopes
BSides Joburg
· 2024
Technical
Cryptography
Mobile Security
Web AppSec
Demo
Talk
Open →
2024-07
35:33
BSidesIOWA 2015 Track1: Integrating Vuln Scanning into the SDLC by Eric Johnson
BSides Iowa
Open →
2015-04
52:02
G1234! - SSO Wars: The Token Menace - Alvaro Munoz & Oleksandr Mirosh
BSides Las Vegas
Open →
2019-10
31:14
Stalking the Stalkers
Vangelis Stykas
Felipe Solferini
BSides Sofia
· 2023
Research
Technical
Malware Analysis
Privacy
Vulnerability Research
Advanced
Case Studies and Incidents Analysis
Technical Deep-dives
+1
Open →
2023-03
20:57
Introduction to AWS Serverless Exploitation
Sankalp Paranjpe
BSides Mumbai
· 2024
Technical
Intro
Red
Talk
Open →
2025-03
25:47
CookieMonstruo: Hijacking The Social Login
Martin Von Knobloch
BSides Munich
· 2017
Technical
Web AppSec
Red
Talk
Open →
2017-04
25:20
Evil Neighbour Attacks On SaaS Platforms Cloudflare, Bitbucket, Etc by Yash Kadakia
Yash Kadakia
BSides London
· 2023
Technical
Talk
Open →
2023-05
35:27
Masande Mtintsilana - Junk Hacking to skill up
BSides Cape Town
Open →
2017-12
30:02
Connected Chaos: Uncovering Router Vulnerabilities Via Cloud API Connections
Vangelis Stykas
BSides London
· 2024
Technical
Cloud IAM
Network Security
Vulnerability Research
Red
Talk
Open →
2024-02
14:43
Exploiting Vulnerabilities in Cookie-Based Authentication
Harsh Bothra
BSides Berlin
· 2021
Technical
Cryptography
Web AppSec
Red
Talk
Open →
2021-09
21:23
PG - I’m a hunter! Cyber Intelligence in the New(ish) Frontier - Yasmine Johnston-Ison
BSides Las Vegas
Open →
2019-10
33:27
Front end Security
Martin Stoynov
Spas Genov
BSides Sofia
· 2022
Technical
Web AppSec
Red
Talk
Open →
2022-04
58:18
Tim Tomes - Web Application Authorization: Taming the Perfect Storm
Tim Tomes
BSides Augusta
· 2025
Technical
OWASP
Web AppSec
Talk
Open →
2025-10
12:13
Security in Continuous Integration and Continuous Development
Yiannis Koukouras
BSides Athens
· 2017
Technical
Talk
Open →
2017-10
25:35
Low Hanging Blue Fruit: Defending With Open-Source Tools
Yaron King
BSides TLV
· 2019
Technical
Blue
Talk
Open →
2019-11
35:25
Between You and Me and the Network Security Boundary
Patrick Fussell
BSides DC
· 2017
Technical
Red
Talk
Open →
2017-10
45:00
Adventures With Internet Telephony Appliances - Darren Martyn
Darren Martyn
BSides Basingstoke
Technical
Talk
Open →
2024-09
38:49
Pentesting on steroids using performance monitoring
JB Aviat
BSides Lisbon
· 2022
Technical
Web AppSec
Red
Demo
Talk
Open →
2022-12
28:13
A Hitchhackers Guide to the IoT: Security from a FMCG Perspective
Jerome de las Alas
BSides Charleston
· 2022
Technical
Hardware Hacking
IoT
Vulnerability Research
Talk
Open →
2022-11
30:58
Introduction to CTF - For All!
Matthew Haynes
Daniel Card
BSides Leeds
· 2020
Technical
CTF
Intro
Blue
Red
Demo
Talk
Open →
2020-07
46:02
A Look At TR-06FAIL And Other CPE Configuration Disasters by Darren Martyn
BSides Scotland
Open →
2017-04
33:41
Start Hacking APIs
Corey Ball
BSides Edmonton
· 2023
Technical
Vulnerability Research
Web AppSec
Red
Talk
Open →
2023-11
20:20
Click here for free TV! Chaining bugs to takeover Wind Vision account
Leonidas Tsaousis
BSides Athens
· 2021
Technical
Mobile Security
Vulnerability Research
Red
Case Studies and Incidents Analysis
Technical Deep-dives
Demo
Talk
Open →
2021-07
26:44
Kettle of Fish in a Barrel: Cloud Automation for Subdomain Takeovers
Matt Bosack
BSides Philly
· 2020
Technical
Cloud IAM
OSINT
Vulnerability Research
Case Studies and Incidents Analysis
Methodology
Talk
Open →
2020-12
56:48
Passwords are dead? Long live WebAuthn!
Alex Lauerman
BSides KC
· 2021
Technical
Cryptography
Web AppSec
Intro
Demo
Talk
Open →
2021-11
55:47
Web AppSec 101
Andrii Kudiurov
BSides Ukraine
· 2018
Technical
OWASP
Web AppSec
Intro
Blue
Talk
Open →
2018-05
1:15:24
Attacking & Defending Android Apps Training
Romansh Yadav
BSides Athens
· 2021
Technical
OWASP
Workshop
Open →
2021-06
43:55
Where and how to implement Security in Software Development
Radostina Kondakova
Jordan Popov
BSides Sofia
· 2022
Technical
DevSecOps
Threat Modeling
Web AppSec
Methodology
Talk
Open →
2022-04
45:25
Cryptography Pitfalls
BSides Peru
Open →
2016-06
1:48:57
0-day Research Disassembled
Chris Lyne
BSides DC
· 2019
Research
Advanced
Red
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2019-10
56:51
Hacking the OWASP Top 10: An Intro to Web Application Security
Greg Sternberg
BSides Denver
· 2020
Technical
OWASP
Web AppSec
Intro
Talk
Open →
2020-10
39:01
Atomic Honeypot – A MySQL Honeypot That Fights Back
Alexander Rubin
BSides SLC
· 2025
Technical
Vulnerability Research
Web AppSec
Advanced
Red
Talk
Open →
2025-06
50:35
Building A Secure Development Lifecycle On A Shoestring Budget
John Overbaugh
BSides SLC
· 2016
Technical
DevSecOps
Talk
Open →
2016-05
25:56
API Security Testing Automation: A story of shifting left
Ignatios
BSides Athens
· 2022
Technical
Web AppSec
Talk
Open →
2022-06
49:50
Intro to HTTP and De-Sync Attacks
Cary Hooper
BSides SATX
· 2021
Technical
Web AppSec
Intro
Talk
Open →
2021-06
22:33
Bypassing Browser-Based MFA for Outlook Web Application
David Storie
BSides Toronto
· 2023
Technical
Cloud IAM
Red
Talk
Open →
2023-11
31:15
Web Application Penetration Testing on a Budget: Building an In-House Program
Harshal Chandorkar
Natalia Wadden
BSides Toronto
· 2017
Technical
Vulnerability Research
Web AppSec
Talk
Open →
2018-01
33:05
Mike Erman & Alex Gonzalez - Stealing the Network via Cisco Anyconnect VPNs
Mike Erman
Alex Gonzalez
BSides Augusta
· 2019
Technical
Talk
Open →
2019-10
14:50
TryHackingMy Way From Cyber Sales to Cyber SOC
R4ck4tt4ck
Michael Rack
BSides London 2025
Career
Career & Soft Skills
Detection Engineering
Intro
Blue
Talk
Open →
2026-03
30:22
Psst, Come Check Out My Lair!! #notacreeper
Justin Larson
BSides SLC
· 2015
Tooling
Demo
Open →
2015-04
1:00:03
Red Teaming Reimagined: War Stories, AI, and Innovation at Scale
Evan Peña
BSides Prishtina
· 2026
Technical
AI Security
Mobile Security
Vulnerability Research
Web AppSec
Red
Keynote
Open →
2026-02
24:52
Intro to CTF
Trion
BSides Canberra
· 2025
Technical
CTF
Intro
Talk
Open →
2025-12
46:46
What the Function: A Deep Dive into Azure Function App Security
Karl Fosaaen
BSides PDX
· 2024
Technical
Cloud IAM
Talk
Open →
2024-11
27:23
DevSecOps Process Management
Evan Gertis
BSides Augusta
· 2022
Technical
DevSecOps
Talk
Open →
2022-10
47:09
Presentation -- Hacking the IoT: A case study
BSides Asheville
Open →
2018-05
29:02
Navigating the Modern Battlefront of JWT Security
Viktor Mares
BSides Sofia
· 2024
Technical
Cryptography
Web AppSec
Technical Deep-dives
Talk
Open →
2024-04
34:31
The Hacker Evolution: What have we become?
Jason Gillam
BSides Charleston
· 2016
Open →
2016-11
24:40
MFA: A Golden Attack Vector
Parth Shukla
BSides Newcastle
· 2022
Technical
Vulnerability Research
Web AppSec
Red
Talk
Open →
2022-09
54:56
Building CTFs To Teach Non-Security Folks
Joe Kuemerle
BSides Boston
Community
Technical
CTF
Career & Soft Skills
Intro
Talk
Open →
2020-11
48:05
Mallet — an Intercepting Proxy for Arbitrary Protocols
Rogan Dawes
BSides Cape Town
· 2018
Technical
Tooling
Network Security
Reverse Engineering
Web AppSec
Red
Talk
Open →
2019-02
13:29
Router Fail
John Garrett
BSides Charleston
· 2015
Technical
Hardware Hacking
Network Security
Red
Demo
Talk
Open →
2015-12
41:46
Vulnerability Regression Testing with Nuclei Framework
Domagoj Vratarić
BSides Zagreb
Technical
Detection Engineering
DevSecOps
Vulnerability Research
Case Studies and Incidents Analysis
Talk
Open →
2025-03
30:14
BSidesWLG 2017 - Josh Brodie - Ethics in penetration testing
BSides Wellington
Open →
2018-02
37:19
Autonomous Discovery of Logic-based API Vulnerabilities
Taha Biyikli
Dvir Lazar
BSides Las Vegas
· 2025
Research
Technical
AI Security
Vulnerability Research
Web AppSec
Advanced
Technical Deep-dives
Talk
Open →
2025-12
35:11
Rudder Nonsense: Steering Smart Rowers Off Course
Shane Kell
BSides PDX
· 2024
Technical
Red
Demo
Talk
Open →
2024-11
49:27
Beginning Pentesting Android Applications
James McKee
BSides Boulder
· 2020
Technical
Intro
Talk
Open →
2020-11
16:19
ChatGPT ASST. Hacking: Pentesting Roku Apps for Fun & Profit
Aakash Kharade
BSides Mumbai
· 2024
Technical
Talk
Open →
2025-03
24:44
0 to 100 with Mobile Application Pentesting
James Kennedy
BSides KC
· 2019
Technical
Mobile Security
Talk
Open →
2019-06
39:44
The Pentester Blueprint: A Guide to Becoming a Pentester
Phillip Wylie
BSides Delhi
· 2020
Career
Career & Soft Skills
Intro
Talk
Open →
2020-11
24:48
Speaking to a City of Amazon Echoes
Karl Fosaaen
BSides PDX
· 2018
Technical
Red
Talk
Open →
2018-03
24:24
Robust Defense for the Rest of Us
Russell Mosley
BSides Las Vegas
· 2017
Technical
Detection Engineering
Network Security
Threat Modeling
Blue
Talk
Open →
2017-08
29:41
Hop The Fences, Steal The Cars
Ciarán McNally
BSides Dublin
· 2021
Technical
Threat Intel
Vulnerability Research
Web AppSec
Red
Case Studies and Incidents Analysis
Talk
Open →
2021-05
28:07
From Cockroaches to Marble Floors: What Happens when You Turn On the Lights?
Daniel Tobin
Paul Karayan
BSidesSF
· 2020
Technical
Talk
Open →
2020-03
25:07
What Are We Missing in Web Applications?
Mirza Burhan Baig
BSides SLC
· 2021
Technical
Vulnerability Research
Web AppSec
Red
Talk
Open →
2021-12
51:14
BSides Glasgow 2018 - Paul Johnston - Replicator: Helping Developers to Replicate Pen Test Findings
BSides Scotland
Open →
2018-05
43:32
BSIDESKyiv 2018 - ALEX RESHETNYK JS - SECURING THE HIPSTER STACK
BSides Ukraine
Open →
2018-05
52:53
BSidesIA 2017 Track2: Want to break JavaScript and APIs in web apps? – Andrew Freeborn
BSides Iowa
Open →
2017-04
39:47
Building AppSec In
Seth Law
BSides SLC
· 2015
Technical
OWASP
Web AppSec
Talk
Open →
2015-04
23:35
Defrauding Merchants Like It's Y2K by Yuk Fai Chan and Craig Barretto at BSides Toronto 2022
BSides Toronto
Open →
2022-11
38:48
Password Sprays: Still a Concern?
Michael Berardi
BSides Greenville
· 2020
Technical
Talk
Open →
2020-06
55:15
Welcome to the Jungle: Pen Testing AWS
Mike Felch
BSides Tampa
Technical
Cloud IAM
Vulnerability Research
Red
Talk
Open →
2023-09
45:09
Cookie Monster: Exfiltrating Data and More, Byte by Tasty Byte
Eric Kuehn
Mic Whitehorn-Gillam
BSides Las Vegas
· 2022
Technical
DFIR
Network Security
Web AppSec
Red
Demo
Talk
Open →
2022-09
25:56
I'm in
Richard Appleby
BSides Canberra
· 2025
Community
Talk
Open →
2025-12
20:54
Nintendon't Look at my GitHub: DMCA Dodging and Other Shenanigans
James Martindale
BSides PDX 2025
Technical
Talk
Open →
2025-12
25:32
Federal Bug Bounty Programs
Shane Lawrence
BSides SLC
· 2017
Technical
War Stories
Vulnerability Research
Web AppSec
Red
Talk
Open →
2017-06
47:28
Faces in the Fog – Unconventional User Enumeration
Seth Law
BSides SLC
· 2025
Technical
Web AppSec
Red
Talk
Open →
2025-06
42:40
Breaking MFA
Mishaal Khan
BSides Delaware
· 2020
Technical
Talk
Open →
2020-12
24:22
Health Platform Pwnage - You Are Now Diabetic
Faisal Tameesh
BSides KC
· 2019
Technical
Red
Talk
Open →
2019-06
50:03
Purple-teaming outbound HTTPS
Anon Hacker
BSides PDX
· 2023
Technical
Purple
Demo
Talk
Open →
2023-10
20:02
PwnSpoof by Daniel Oates-Lee
Daniel Oates-Lee
BSides Dublin
· 2022
Open →
2022-05
57:55
Extracting Secrets from IoT Devices - Isaiah Davis-Stober
Isaiah Davis-Stober
BSides KC
· 2026
Technical
Talk
Open →
2025-06
42:06
Breaking and Fixing .NET Web Apps
Owais Mehtab
BSides Edmonton
· 2020
Technical
Web AppSec
Red
Talk
Open →
2020-09
41:58
Pentesting Android Apps: Harsh Modi
Harsh Modi
BSides Edmonton
· 2023
Technical
Red
Talk
Open →
2023-11
21:54
Show me the traffic! Intercepting and testing encrypted mobile application traffic
Andi Anastasi
BSides Athens
· 2021
Technical
Mobile Security
Reverse Engineering
Red
Demo
Talk
Open →
2021-07
27:50
IoT Devices and why they desperately need help
Christian Halbert
Issa Hafiri
BSidesROC
· 2018
Technical
Talk
Open →
2018-04
35:54
2015 - Iain Smart - Burping Up Data What Your Apps Reveal About You
BSides Manchester
Open →
2015-10
40:43
Cookie Monsters in your Browsers: Cookie Exfiltration for Hungry Hackers
Andrew Gomez
Antero Guy
BSides Augusta
· 2025
Technical
Web AppSec
Advanced
Red
Talk
Open →
2025-10
1:12:01
BSides Knoxville 2018 (Second Track, KEC, afternoon sessions)
BSides Knoxville
· 2018
Technical
OSINT
Intermediary
Red
Talk
Open →
2018-05
37:51
Automated Pentesting with AI: From Recon to Reporting
Jay Panchal
BSides Edmonton
· 2025
Technical
Red
Demo
Talk
Open →
2025-10
32:20
BSIDESKyiv 2018 - STANISLAV BRESLAVSKYI REVISITING SUPPLY CHAIN ATTACK
BSides Ukraine
Open →
2018-05
42:16
Twice The Pride, Double The Fall: Why 2FA Isn't The Cure We Thought It Was by Boglarka Ronto
BSides Scotland
Open →
2017-04
21:30
Domain Name Stupidity
Liam Follin
BSides Bristol
· 2025
Technical
DFIR
Network Security
Advanced
Red
Technical Deep-dives
Talk
Open →
2024-01
29:27
LightBulb Framework: Shedding Light on the Dark Side of WAFs and Filters
Ioannis Stais
BSides Athens
· 2017
Technical
Web AppSec
Talk
Open →
2017-10
20:48
Attack of the Clones! How AI can boost your API Security!
Dr. Sunny Wear
BSides Tampa
Technical
Web AppSec
Talk
Open →
2024-06
37:38
BSides Edmonton 2023 Keynote: Alissa Knight
Alissa Knight
BSides Edmonton
· 2023
Keynote
Open →
2023-10
53:24
BSides Iowa 2018: "Better Burping – Improving Efficiency with Plugins and DIY"
BSides Iowa
Open →
2018-04
30:57
Under the Hood of Ransomware.live: Building an Open-Source Ransomware Observatory
Julien Mousqueton
BSides Bournemouth
· 2025
Research
Technical
Malware Analysis
OSINT
Threat Intel
Intermediary
Case Studies and Incidents Analysis
Empirical Research
+1
Open →
2025-09
28:28
Pwning into Power System Center
Omkar Joshi
BSides Budabest
· 2023
Technical
Red
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2025-03
16:25
No more alert(1) - Gr4y R0se
Liam Follin
BSides Belfast
Technical
Web AppSec
Red
Demo
Talk
Open →
2025-02
50:40
Pen Testing for NOT Dummies
Alex Holden
BSides NYC
· 2023
Technical
Red
Talk
Open →
2023-06
23:39
Decoder Improved: An Improved Burp Suite Decoder
Justin Moore
BSidesROC
· 2017
Tooling
Web AppSec
Demo
Talk
Open →
2018-01
17:04
API Security From The Lens Of An AppSec Engineer by Abhinav Khanna
Abhinav Khanna
BSides Dundee
Technical
OWASP
Web AppSec
Talk
Open →
2022-08
36:51
BSides Toronto 2019 Jamie Baxter
BSides Toronto
Open →
2019-10
50:32
PW - Are your secrets safe - How mobile applications are leaking millions of credentials
BSides Las Vegas
Open →
2023-10
39:38
I Know What You Did Last Summer… I'm Still Hacking Your Small Business
Vincent Matteo
BSides KC
· 2022
Technical
Red
Case Studies and Incidents Analysis
Talk
Open →
2022-10
29:25
Injecting Automation into Pentesting
Akshar Tank
BSides Vancouver
· 2022
Technical
Tooling
DevSecOps
Vulnerability Research
Web AppSec
Talk
Open →
2022-07
42:12
Securely storing & transmitting information on mobile/IoT devices
Nicolas Boeckh
BSides Islamabad
· 2020
Technical
Talk
Open →
2020-11
33:25
Chris Dorman - Open Source and Leaked Malware
Chris Dorman
BSides Belfast
· 2017
Talk
Open →
2017-10
44:21
Mobile Penetration Testing Hybrid
Buddy Smith
BSides Tampa
· 2021
Technical
Talk
Open →
2021-04
26:57
BsidesRDU 2018 07 - When it rains it pours - Sam Granger
BSides RDU
Open →
2018-10
18:24
The Dark Side of GraphQL
Parth Shukla
BSides SLC
· 2023
Technical
Talk
Open →
2023-06
21:08
Embedding Web Apps in MITMProxy Scripts
Chris Czub
BSides Las Vegas
· 2015
Technical
Talk
Open →
2016-12
38:24
Penetration Testing Experience and How to Get It
Phillip Wylie
BSides Las Vegas
Career
Career & Soft Skills
Intro
Talk
Open →
2024-09
49:50
Phillip Wylie - The Pentester Blueprint: A Guide to Becoming a Pentester
Phillip Wylie
BSides Boston
Career
Career & Soft Skills
Intro
Talk
Open →
2020-11
26:25
Cookie Monster: Tasty Tasty Bytes
Eric Kuehn
BSides Charleston
· 2018
Talk
Open →
2018-11
45:29
Web Hacking 101: Hands-on with Burp Suite
David Rhoades
BSides Philly
· 2018
Technical
Web AppSec
Intro
Workshop
Open →
2018-11
45:28
Rahul Raghavan: The Clutter That's Choking AppSec
Rahul Raghavan
BSides Calgary
Talk
Open →
2020-12
50:35
Occupy Burp Suite: Informing the 99% of What the 1%'ers Are Knowingly Taking Advantage of
James Lester
Joseph Tartaro
BSides Las Vegas
· 2012
Community
Technical
Tooling
Web AppSec
Talk
Open →
2017-03
21:35
The Need for Speed: Exploiting Race Conditions in Web Applications
Harriet Schofield
BSides Bournemouth
· 2025
Technical
Vulnerability Research
Web AppSec
Red
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2025-09
39:01
Ochaun Marshall: Samurai Web Training Framework 5.0
Ochaun Marshall
BSides Calgary
· 2021
Open →
2021-12
36:52
BSidesROC 2023 Hacking and Defending APIs - Robert Wagner
BSidesROC
Open →
2024-09
21:13
Write Your Damn Report
Paul Johnson
BSides Lancashire
· 2026
Career
Technical
Talk
Open →
2024-05
26:44
How to Review a Mobile (Android) App
James Kinninger
BSides Greenville
· 2020
Technical
Talk
Open →
2020-06
36:19
ATGP - Underground Wi-Fi Hacking for Web Pentesters - Greg Foss
BSides Las Vegas
Open →
2016-12
26:39
Gitdigger: Creating Useful Wordlists From Public GitHub Repositories
WiK
Mubix
BSides Las Vegas
· 2013
Technical
Tooling
OSINT
Vulnerability Research
Talk
Open →
2017-01
42:55
Martin Holste - Beyond Math Practical Security Analytics
Martin Holste
BSides Augusta
· 2016
Talk
Open →
2016-09
42:34
Examining Access Control Vulnerabilities in GraphQL: A Field Case Study
Bogdan Tiron
BSides Galway
Technical
OWASP
Web AppSec
Red
Case Studies and Incidents Analysis
Talk
Open →
2025-03
33:43
From Hardware to Zero-Day by Pietro Oliva at BSides Toronto 2020
BSides Toronto
Open →
2021-11
52:23
Asynchronous Intelligence Gathering with Python
Jeff Bowie
BSides Denver
· 2020
Technical
OSINT
Tooling
Web AppSec
Red
Talk
Open →
2020-10
57:41
BSidesGVL 2020 - Kevin Johnson - "Removing the Cobwebs: Upgrading Our Web App Testing"
Kevin Johnson
BSides Greenville
· 2020
Technical
Web AppSec
Talk
Open →
2020-06
34:20
OfCORS! How To Do Cross Origin Resource Sharing (Im)Properly
Cory Turner
BSides Bristol
· 2025
Technical
Web AppSec
Talk
Open →
2025-01
25:13
The Security Hitchhiker's Guide to API Security
Timothy De Block
BSides Augusta
· 2023
Technical
Web AppSec
Talk
Open →
2023-10
32:24
Using Large Language Models To Augment AppSec Testing
Thomas Ballin
BSides Newcastle
· 2025
Technical
AI Security
Detection Engineering
Web AppSec
Intermediary
Talk
Open →
2025-01
30:17
Video Games, Quality Assurance, and Business Logic - Paul Hardin
Paul Hardin
BSides Albuquerque
Talk
Open →
2024-08
19:04
This one weird trick will secure your web server
David Coursey
BSides Augusta
· 2016
Technical
Web AppSec
Intro
Blue
Talk
Open →
2016-09
34:18
Behind Enemy Lines: Engaging and Disrupting Ransomware Web Panels
Vangelis Stykas
BSides Amsterdam
· 2025
Technical
Malware Analysis
Threat Intel
Web AppSec
Advanced
Red
Case Studies and Incidents Analysis
Technical Deep-dives
+1
Open →
2026-01
22:24
XSS is dead – Browser Security Features that Eliminate Bug Classes
Javan Rasokat
BSides Las Vegas
· 2025
Technical
Web AppSec
Blue
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2025-12
37:23
Who Scans the Scanner? Exploiting Trend Micro Mobile Security
Lucas Carmo
BSides Las Vegas
· 2025
Technical
Mobile Security
Reverse Engineering
Vulnerability Research
Advanced
Red
Technical Deep-dives
Talk
Open →
2025-12
21:47
Hunter Hardman - Adventures in RAT dev
Hunter Hardman
BSides Augusta
· 2016
Technical
Talk
Open →
2016-09
25:10
Offensive Wfuzz for Web Bug Hunters
Xavi Mendez
BSides Barcelona
· 2019
Technical
Tooling
Web AppSec
Red
Demo
Talk
Open →
2022-01
39:42
Stop Committing Your Secrets: Git Hooks To The Rescue!
BSides Tampa
Technical
Supply Chain Security
Talk
Open →
2023-03
25:01
Wrangle Your Defense Using Offensive Tactics
Matt Dunn
Bsides CT
· 2019
Technical
Blue
Talk
Open →
2019-11
25:05
The Need for Speed: Exploiting Race Conditions in Web Applications - Harriet Schofield
Harriet Schofield
BSides Belfast
· 2025
Technical
Web AppSec
Red
Demo
Talk
Open →
2025-12
41:50
GraphQL Security: Penetration Testing and Automated Vulnerability Detection
Jared Meit
BSides Calgary
· 2022
Technical
Vulnerability Research
Web AppSec
Intermediary
Red
Technical Deep-dives
Demo
Talk
Open →
2022-12
26:54
Examining Access Control Vulnerabilities in GraphQL — A Feeld Case Study
Bogdan Tiron
BSides Bournemouth
· 2025
Technical
Vulnerability Research
Web AppSec
Intermediary
Red
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2025-09
50:50
Dynamic Web Scanning at Massive Scale
Erik Peterson
BSidesSF
· 2012
Technical
DevSecOps
Web AppSec
Talk
Open →
2017-11
41:35
How to Find a Companys BreakPoint
BSides Philly
Open →
2017-08
21:23
Capture The Fun - Gamified Learning by Andras Borbely
Andras Borbely
BSides Cheltenham
· 2022
Career
CTF
Career & Soft Skills
Intro
Talk
Open →
2022-07
29:15
Curiosity of a Hacker: The Power of Asking “What If?”
Nik Shivasa
BSides Göteborg
· 2026
Career
Talk
Open →
2026-03
30:31
What Will Go Wrong When ZAP Is Driven By GenAI
Gerald Benischke
BSides Newcastle
· 2025
Technical
AI Security
Tooling
Web AppSec
Technical Deep-dives
Demo
Talk
Open →
2025-11
26:33
Writing Our Own DNS Tunneling Protocol, And Other AWS Misadventures, All In A Pen Test
Sunny Chau
BSides Basingstoke
Technical
Talk
Open →
2024-09
28:29
Do Scanners Suck? I Have The Receipts - Thomas Ballin
Thomas Ballin
BSides Leeds
· 2026
Talk
Open →
2025-08
49:15
Imperial Stout: Building Bolder BurpSuite Functionality
Jason Gillam
BSides Greenville 2020
Technical
Tooling
Web AppSec
Red
Demo
Talk
Open →
2020-06
33:58
Industrial Scale Hardware Hacking - Anthony Clark
Anthony Clark
BSides Albuquerque
· 2024
Technical
Hardware Hacking
IoT
Reverse Engineering
Red
Methodology
Talk
Open →
2024-08
35:13
Vesta Admin Takeover - Exploiting Reduced Seed Entropy In Bash $RANDOM - Adrian Tiron
Adrian Tiron
BSides Basingstoke
· 2025
Technical
Cryptography
Talk
Open →
2025-09
22:12
These Are NOT the Vulnerabilities You Are Looking For: Hiding Vulnerabilities in Containers
Q
BSides Seattle
· 2026
Technical
Container Security
Vulnerability Research
Red
Demo
Talk
Open →
2026-03
38:17
Vesta Admin Takeover — Exploiting Reduced Seed Entropy in Bash $RANDOM
Adrian Tiron
BSides Exeter
· 2026
Technical
Cryptography
Vulnerability Research
Web AppSec
Advanced
Red
Talk
Open →
2026-05
39:02
The HMAC Trap: Security or Illusion?
Marluan Cleary
BSides Las Vegas
· 2025
Technical
Cryptography
Red
Talk
Open →
2025-12
37:32
Breaking the Guest List: Hacking Invitation Systems for Fun and Profit
Ali Kabeel
BSides Las Vegas
· 2025
Technical
Threat Modeling
Web AppSec
Red
Case Studies and Incidents Analysis
Talk
Open →
2025-12
47:46
Get your head in the clouds by Sean Verity
Sean Verity
BSides Austin
Talk
Open →
2024-02
34:22
Salman, Khwaja: Story of Implementation of SecDevOps in Fin Tech Organization and beyond
BSides Calgary
· 2021
DevSecOps
Talk
Open →
2021-12
45:01
BG - The Savage Curtain 0 Tushar Dalvi & Tony Trummer
BSides Las Vegas
Open →
2016-12
26:01
PG - How I Learnt Hacking in High School - Lokesh Pidawekar
BSides Las Vegas
Open →
2016-12
51:39
Vaccinating Android
Milan Gabor
Danijel Grah
BSides Las Vegas
· 2014
Research
Technical
Mobile Security
Reverse Engineering
Vulnerability Research
Advanced
Red
Demo
+1
Open →
2016-12
32:48
AksharTank
Akshar Tank
BSides Calgary
· 2022
Technical
Vulnerability Research
Web AppSec
Talk
Open →
2022-12
8:19:32
Bsides Asheville Information Security Conference 2015
BSides Asheville
Open →
2018-04
35:30
Flex Seal Your CI/CD Pipeline
Ochaun Marshall
BSides Columbus
· 2020
Technical
Cloud IAM
DevSecOps
Blue
Talk
Open →
2020-08
29:27
Building the Flight Deck: Tools and Technologies for a Robust AppSec Program
Chris Koehnecke
BSides Albuquerque
Technical
Talk
Open →
2024-08