BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.ozsecurity.org//ozsec-2026//speaker//7XXHWE
BEGIN:VTIMEZONE
TZID:CST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T080000Z
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T090000Z
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-ozsec-2026-PN8GXW@cfp.ozsecurity.org
DTSTART;TZID=CST:20261023T133000
DTEND;TZID=CST:20261023T141500
DESCRIPTION:Technical knowledge alone does not make someone ready to defend
  an organization. Cybersecurity professionals must interpret incomplete in
 formation\, correlate evidence from multiple systems\, make decisions unde
 r pressure\, and explain why their response is justified.\n\nWSU Tech’s 
 Cyber Range provides learners with a broad collection of realistic simulat
 ions modeled on real-world threats and security incidents. Working through
  varied scenarios allows a learner to practice responding to different att
 ack methods while developing the investigative reasoning and technical jud
 gment required in the workplace.\n\nThis session demonstrates that process
  using a simulated FIN7 intrusion as a case study. The investigation begin
 s when law enforcement reports finding an organization’s financial infor
 mation in a threat actor’s possession. Learners must determine what happ
 ened\, identify the affected systems\, establish the scope of the compromi
 se\, and recommend an appropriate response.\n\nLearners correlate SIEM ale
 rts\, firewall traffic\, Windows events\, and system artifacts to uncover 
 a phishing-enabled compromise\, lateral movement\, persistence\, financial
 -data staging\, and exfiltration. Observable performance criteria evaluate
 s ability to identify the initial compromise\, reconstruct the attack\, co
 nfirm data loss\, and propose defensible containment and recovery actions.
 \n\nFIN7 represents one of the many scenarios available in the Cyber Range
 . Exposure to multiple incidents helps a learner develop transferable capa
 bilities rather than memorize a single investigative process. Structured d
 ebriefing then turns missed evidence and incomplete conclusions into targe
 ted opportunities for additional practice.\n\nAttendees will leave with a 
 practical understanding of how they and their teams can use WSU Tech’s C
 yber Range to develop\, refine\, and evaluate job-ready cybersecurity comp
 etencies through realistic\, scenario-based practice.
DTSTAMP:20260920T112712Z
LOCATION:Redbud B
SUMMARY:From Classroom to Cyber Incident: Building Job-Ready Defenders in W
 SU Tech’s Cyber Range - Matthew Lewis\, Jacob Buck\, Adam Shah
URL:https://cfp.ozsecurity.org/ozsec-2026/talk/PN8GXW/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-ozsec-2026-NSU3GN@cfp.ozsecurity.org
DTSTART;TZID=CST:20261024T100000
DTEND;TZID=CST:20261024T160000
DESCRIPTION:How would you respond if law enforcement reported finding your 
 organization’s financial information in a threat actor’s possession?\n
 \nThis drop-in Village invites participants to investigate a simulated FIN
 7 intrusion using WSU Tech’s Cyber Range. Participants can join at any t
 ime\, work individually or with others\, and explore one or more stages of
  the incident.\n\nThe investigation uses SIEM alerts\, firewall traffic\, 
 Windows events\, and system artifacts to reveal phishing-enabled access\, 
 network reconnaissance\, command-and-control activity\, lateral movement\,
  scheduled-task persistence\, financial-data staging\, and exfiltration.\n
 \nParticipants may focus on identifying the initial compromise\, tracing a
 ttacker movement\, confirming data loss\, or developing containment and re
 covery recommendations. Those who remain longer can continue through the c
 omplete incident sequence.\n\nFIN7 represents one of the many realistic si
 mulations available through WSU Tech’s Cyber Range. Participants will le
 ave with practical investigative experience\, a clearer understanding of t
 heir current capabilities\, and specific cybersecurity skills to continue 
 developing.
DTSTAMP:20260920T112712Z
LOCATION:Village 1
SUMMARY:Inside the Breach: Investigating FIN7 in WSU Tech’s Cyber Range -
  Matthew Lewis\, Jacob Buck\, Adam Shah
URL:https://cfp.ozsecurity.org/ozsec-2026/talk/NSU3GN/
END:VEVENT
END:VCALENDAR
