Jacob Buck

Jacob Buck is a Program Director at WSU Tech, helping faculty and students alike with learning Cybersecurity and IT skills for a digital future. Jacob has been teaching for 3 years and working in Education for 5, in addition to having a mixed background in VFX for film using code and IT at places such as Textron Aviation.


Sessions

10-23
13:30
45min
From Classroom to Cyber Incident: Building Job-Ready Defenders in WSU Tech’s Cyber Range
Matthew Lewis, Jacob Buck, Adam Shah

Technical knowledge alone does not make someone ready to defend an organization. Cybersecurity professionals must interpret incomplete information, correlate evidence from multiple systems, make decisions under pressure, and explain why their response is justified.

WSU Tech’s Cyber Range provides learners with a broad collection of realistic simulations modeled on real-world threats and security incidents. Working through varied scenarios allows a learner to practice responding to different attack methods while developing the investigative reasoning and technical judgment required in the workplace.

This session demonstrates that process using a simulated FIN7 intrusion as a case study. The investigation begins when law enforcement reports finding an organization’s financial information in a threat actor’s possession. Learners must determine what happened, identify the affected systems, establish the scope of the compromise, and recommend an appropriate response.

Learners correlate SIEM alerts, firewall traffic, Windows events, and system artifacts to uncover a phishing-enabled compromise, lateral movement, persistence, financial-data staging, and exfiltration. Observable performance criteria evaluates ability to identify the initial compromise, reconstruct the attack, confirm data loss, and propose defensible containment and recovery actions.

FIN7 represents one of the many scenarios available in the Cyber Range. Exposure to multiple incidents helps a learner develop transferable capabilities rather than memorize a single investigative process. Structured debriefing then turns missed evidence and incomplete conclusions into targeted opportunities for additional practice.

Attendees will leave with a practical understanding of how they and their teams can use WSU Tech’s Cyber Range to develop, refine, and evaluate job-ready cybersecurity competencies through realistic, scenario-based practice.

Redbud B
10-24
10:00
360min
Inside the Breach: Investigating FIN7 in WSU Tech’s Cyber Range
Matthew Lewis, Jacob Buck, Adam Shah

How would you respond if law enforcement reported finding your organization’s financial information in a threat actor’s possession?

This drop-in Village invites participants to investigate a simulated FIN7 intrusion using WSU Tech’s Cyber Range. Participants can join at any time, work individually or with others, and explore one or more stages of the incident.

The investigation uses SIEM alerts, firewall traffic, Windows events, and system artifacts to reveal phishing-enabled access, network reconnaissance, command-and-control activity, lateral movement, scheduled-task persistence, financial-data staging, and exfiltration.

Participants may focus on identifying the initial compromise, tracing attacker movement, confirming data loss, or developing containment and recovery recommendations. Those who remain longer can continue through the complete incident sequence.

FIN7 represents one of the many realistic simulations available through WSU Tech’s Cyber Range. Participants will leave with practical investigative experience, a clearer understanding of their current capabilities, and specific cybersecurity skills to continue developing.

Village 1