Home
Talks
CFP Guide
What is BSides?
About
Contact
Light
← All talks
Tool
BSides talks featuring OSQuery
56
talks mention this tool across
29
BSides chapters.
Talks featuring OSQuery
53:47
Oh, the Places Your Packets Will Go!
James Pope
BSides SLC
· 2025
Technical
Talk
Open →
2025-10
32:07
Open Source Approach: The Next Best Thing in Cyber Incidence Management
Chris Ensey
BSides DC
· 2017
Talk
Open →
2017-10
41:33
Stop Writing Malware! The Blue Team Has Done It for You
Alberto Rodriguez
Erik Hunstad
BSides Augusta
· 2022
Technical
Advanced
Red
Talk
Open →
2022-10
37:51
Building an Effective Intrusion Detection Program
Jason Craig
BSidesSF
· 2017
Technical
DFIR
Detection Engineering
Threat Intel
Blue
Talk
Open →
2017-03
23:14
Network Security: It Just Makes pfSense
Kyle Goode
BSides Knoxville
· 2026
Technical
Detection Engineering
Network Security
Talk
Open →
2025-01
33:39
A year in the wild: fighting malware at the corporate level
Kuba Sendor
BSidesSF
· 2016
Technical
Blue
Talk
Open →
2016-04
15:44
Chrome Cookie Theft on macOS, and How To Prevent It
Nick Frost
BSides Las Vegas
· 2024
Technical
Malware Analysis
Reverse Engineering
Talk
Open →
2024-09
20:25
Leveraging Osquery for DFIR at Scale
Sohini Mukherjee
BSidesSF
· 2020
Technical
DFIR
Detection Engineering
Intermediary
Talk
Open →
2020-03
32:14
White Collars & Black Hats: Bitcoin, Dark Nets and Insider Trading by Ken Westin
Ken Westin
BSides Edmonton
· 2018
Talk
Open →
2018-09
19:52
Using an mTLS Identity Provider to achieve Password-less auth, Device Health Attestation, and low Earth orbit
Armen Tashjian
BSidesSF
· 2023
Technical
Cloud IAM
Cryptography
Blue
Talk
Open →
2023-05
24:24
One Search To Rule Them All: Threat Modelling AI Search
Kane Narraway
BSidesSF
· 2025
Technical
AI Security
Cloud IAM
Threat Modeling
Talk
Open →
2025-06
30:06
Windows Event Forwarding and OSSEC — You can do this!
Robert Wilson
BSides Augusta
· 2018
Technical
DevSecOps
Blue
Talk
Open →
2018-11
58:14
Velociraptor: Digging Deeper
Michael Cohen
BSides Sydney
· 2019
Technical
DFIR
Threat Intel
Blue
Demo
Talk
Open →
2019-09
24:30
Realtime Cyber Alerting with StreamAlert
Jeremy Stott
BSides Wellington
· 2017
Technical
Blue
Demo
Talk
Open →
2018-02
24:46
A Novel SIEM Solution That Doesn't Cost An Arm And A Leg
BSides Lisbon
· 2019
Talk
Open →
2019-12
36:54
Authenticode in-depth
Scott Piper
BSides SLC
· 2015
Technical
Cryptography
Talk
Open →
2015-04
59:25
Phoenix: The Open Source malware analysis appliance
Justin Borland
Greg Olmstead
BSides Augusta
· 2019
Technical
Tooling
Talk
Open →
2019-10
47:23
Open Source GitOps for Detection Engineering
Zach Wasserman
BSides Las Vegas
· 2023
Technical
Detection Engineering
DevSecOps
Blue
Demo
Talk
Open →
2023-10
50:24
From Kali and a Couple of VMs to NextGen Home Lab - An Approach to Practice and Develop your Skills
Bashar Shamma
BSides SATX
· 2020
Technical
Talk
Open →
2020-08
8:57:03
2016 BSidesLV - Common Ground - Day Two
BSides Las Vegas
· 2016
Technical
Talk
Open →
2016-08
29:57
Don't Repeat Yourself: Automating Malware Incident Response for Fun and Profit - Kuba Sendor
BSides Las Vegas
Open →
2016-08
25:02
Serverless Osquery Backend and Big Data Exploration
Geller Bedoya
BSidesSF
· 2020
Technical
Talk
Open →
2020-03
54:37
When a Security Architect Writes an Application
David Zendzian
BSides Charleston
· 2014
Technical
Web AppSec
Talk
Open →
2014-11
45:34
Purple Teaming Cloud Identity Simulation Labs for Red and Blue teams
Jason Ostrom
BSides Dallas/Fort Worth
· 2022
Technical
Cloud IAM
Detection Engineering
Threat Modeling
Purple
Technical Deep-dives
Demo
Talk
Open →
2022-11
29:18
Unraveling the Threat of Chrome Based Malware
Spencer Walden
Justin Warner
BSidesSF
· 2018
Technical
Web AppSec
Demo
Talk
Open →
2018-04
34:17
BSides Perth 2023: Sajeeb Lohani & Ben Christian: Achieving Supply Chain Security on a Budget
Sajeeb Lohani
Ben Christian
BSides Perth
· 2023
Technical
Supply Chain Security
Purple
Talk
Open →
2023-08
23:53
Applying Sysmon-type Filtering to Elastic Agent Process Auditing
Josh Brower
BSides Augusta
· 2023
Technical
DFIR
Detection Engineering
Blue
Demo
Talk
Open →
2023-10
38:26
Light in the Labyrinth: Breach Path Analysis for Anyone
Parker Shelton
BSidesSF
· 2025
Technical
Blue
Talk
Open →
2025-10
25:46
Live Interrogation With Osquery
Josh Brower
BSides Augusta
· 2018
Technical
DFIR
Detection Engineering
Threat Intel
Blue
Demo
Talk
Open →
2018-10
46:20
Xavier Mertens - All Your Logs Are Belong To You!
Xavier Mertens
BSides London
· 2014
Talk
Open →
2014-09
31:04
Host-Hunting on a Budget
Leo Bastidas
BSides Augusta
· 2019
Technical
DFIR
Detection Engineering
Threat Intel
Blue
Talk
Open →
2019-10
36:26
Adventures in Open Source Security Software - Jordan Wright
Jordan Wright
BSides SATX
· 2018
Community
Career & Soft Skills
Talk
Open →
2018-07
37:06
Julian Wayte - Resource Smart Detection with YARA and osquery
BSides Boston
Open →
2020-11
33:09
Fe-fi-fo-FIM, I Smell The Monitoring Of An Elastic Stack!
Brett Calderbank
BSides Manchester
· 2019
Technical
Detection Engineering
GRC
Talk
Open →
2019-09
47:12
Have Lab, Now What?
Kelsey Seymour
Aaron Everson
BSides Buffalo
Career
Talk
Open →
2024-06
41:32
Dispelling the Myth of "Maturity" in Threat Hunting
Kelsey Seymour
BSides Buffalo
· 2023
Technical
Blue
Talk
Open →
2023-06
37:32
Keeping on Top of Security Advisories
Michael Fincham
Filip Vujičić
BSides Wellington
· 2017
Technical
Detection Engineering
DevSecOps
Threat Intel
Talk
Open →
2018-02
25:13
Josh Bower - Enriching Osquery with Actionable Context
BSides Augusta
Open →
2019-10
46:15
Everything You Always Wanted to Know About Linux Logging
Kevin Kaminski
BSides Tampa
· 2021
Technical
Blue
Talk
Open →
2021-04
36:56
Practical Defense
Sean Whalen
BSides Cincinnati
· 2017
Talk
Open →
2017-05
52:37
Building the Panopticon: Centralized Logging and Alerting With Free Tools
Matthew Gracie
BSidesROC
· 2018
Technical
Blue
Talk
Open →
2018-04
51:54
Wes Lambert - Augmenting the (Security) Onion: Facilitating Enhanced Detection and Response
Wes Lambert
BSides Augusta
Technical
DFIR
Detection Engineering
Threat Intel
Blue
Talk
Open →
2019-10
25:35
GT - Can Data Science Deal With PAM? - Leila Powell
BSides Las Vegas
Open →
2018-09
43:52
JOINing Across the Stack: Structured Security Analytics for the Modern Attack Surface
Eric Kaiser
BSides Las Vegas
· 2021
Technical
Cloud IAM
Container Security
Detection Engineering
Blue
Talk
Open →
2021-08
52:09
Securing the Distributed Workforce
William Bengtson
BSidesSF
· 2016
Technical
Talk
Open →
2016-04
54:53
Augmenting osquery Visibility on Windows Through Reverse Engineering
Guillaume Ross
Marcos Oviedo
BSides Austin
Technical
Talk
Open →
2024-02
37:20
Yeet the Leet with Osquery
Sebastiaan Provost
BSides Newcastle
· 2021
Technical
Detection Engineering
Malware Analysis
Threat Intel
Talk
Open →
2021-10
24:07
What the deuce: Strategies for splitting your alerts
John T. Myers
BSides Philly
Technical
Talk
Open →
2017-08
34:56
Emulate.Go: Adversary Emulation for CTI Analysts
Haydn Johnson
BSides Toronto
· 2020
Technical
Detection Engineering
Threat Intel
Purple
Demo
Open →
2021-11
27:05
Comparing apples to Apple
Adam Mathis
BSides Augusta
· 2018
Technical
Blue
Talk
Open →
2018-10
38:12
BSidesCharm - 2018 - Adam Mathis - Using Atomic Red Team to Test Endpoint Solutions
BSides Charm
Open →
2021-05
32:29
Cleaning the Apple Orchard: Using Venator to Detect macOS Compromise
Richie Cyrus
BSides Charm
· 2019
Technical
DFIR
Malware Analysis
Threat Intel
Intermediary
Blue
Case Studies and Incidents Analysis
Technical Deep-dives
+2
Open →
2021-05
42:40
The Declarative Future
Liam Randall
BSides Charm
Technical
Container Security
Detection Engineering
Web AppSec
Keynote
Open →
2021-05
30:38
Approaching Parity: Considerations for Adapting Enterprise Monitoring to IaaS
BSides RDU
· 2018
Technical
Cloud IAM
Intermediary
Blue
Talk
Open →
2018-10
31:21
Tony Drake Incident Response for the Overwhelmed, Understaffed, and Unprepared
Tony Drake
BSides Boulder
Career
DFIR
Talk
Open →
2021-08
33:05
Defensible Secure Architecture
Oxana Sannikova
BSides St. John's
Technical
Detection Engineering
Threat Intel
Threat Modeling
Blue
Talk
Open →
2025-05