J. Fridley
10:00 am - 10:50 am
Shared threat frameworks have transformed how defenders describe adversary behavior and coordinate response. As attackers increasingly target software supply chains, application runtimes, and AI-enabled systems, defenders face new challenges applying existing models consistently. This session shares lessons from the Application Attack Matrix, a community-driven effort involving contributors from organizations such as Mandiant (Google Cloud), Microsoft, AWS, Meta, and others, exploring how application-layer attack techniques can be systematically described and operationalized.
J. Fridley is a Solutions Engineer at Oligo, where he helps security and engineering teams better understand real application risk. His work focuses on challenges that don’t fit neatly into traditional vulnerability management, including third-party and open-source risk, security concerns introduced by embedded and agentic AI, and why defending against attack techniques is often more effective than focusing only on individual CVEs. Before joining Oligo, J. supported application security programs and developer security tooling. He is especially interested in the practical side of security: how teams build software, how findings reach developers, and why prioritizing risk in modern cloud environments remains difficult.
Matthew Gracie
11:00 am - 11:50 am
The Human Centered Investigation Playbook (HCIP) standard is a YAML-based syntax for writing investigation playbooks that correspond to a particular alert, artifact, or attack. The goal is to have an investigation methodology that both guides the analyst and also integrates into defensive tooling to make necessary data easily available during the investigation. I will discuss the standard, explore its purpose and use cases, and demonstrate its functionality in a free and open monitoring platform.
Matthew Gracie is a defensive security specialist with twenty years of Blue Team experience in higher education, manufacturing, financial services, and healthcare. He is currently a Senior Engineer at Security Onion Solutions, as well as an adjunct professor in the Cybersecurity graduate program at Canisius University. Matt is also the lead organizer of Infosec 716, a monthly meetup for security enthusiasts in Western New York, and the BSides Buffalo technology conference. He enjoys microcontrollers, mountain bikes, open source security tools, and college hockey, and can be found on Bluesky as @InfosecGoon.
Naga Krishna Reddy Muppidi
1:00 pm - 1:50 pm
Infrastructure-as-Code reviews often miss risk because reviewers see individual files without enough context about blast radius, ownership, cloud exposure, and deployment history. This talk introduces SecReviewAgent, a practical pattern for AI-assisted security review that combines deterministic checks, architecture memory, and LLM-assisted reasoning while keeping sensitive repository context protected and final authority in human review and CI/CD policy gates.
Naga Krishna Reddy Muppidi is a Senior Cloud / Platform Engineer with 10+ years of experience designing and operating AWS, Kubernetes, Terraform, CI/CD, observability, cloud security, FinOps, and automation platforms for enterprise and financial-services environments. His recent independent research focuses on bounded LLM-assisted infrastructure systems, including CostAgent for cloud cost optimization and SecReviewAgent for context-aware Infrastructure-as-Code security review.
Dr. Catherine J. Ullman
2:00 pm - 2:50 pm
Imagine starting your first day on the job with a single clue: a five-second gap in the logs that absolutely shouldn’t exist. What happened in the missing moment? This talk uses that small but mysterious anomaly to illustrate the heart of digital forensics. Attendees will learn how people actually break into computer forensics and the skills that matter. We’ll examine the core personality traits that make one effective in this career, including the ability to clearly communicate what the evidence does (and does not) prove. The session also sets realistic expectations for daily work in digital forensics. Attendees will understand not only what it takes to be a forensicator but what it feels like to think, work, and solve problems like one.
Dr. Catherine J. Ullman is the Principal Technology Architect, Security at the University at Buffalo. She is a contributor to O’Reilly’s 97 Things Every Information Professional Should Know, the author of Wiley’s The Active Defender, and has presented at many infosec/hacker conferences. In her (minimal) spare time, she enjoys visiting her adopted two-toed sloth Flash at the Buffalo Zoo, researching death and the dead, and learning more about hacking to make the world a more secure place.