12:15 PM
Learning adversary emulation through real-world attack techniques
Shana Buhaisa PAssociate Security Consultant, BreachSimRange
c0c0n is a 19 years old platform that is aimed at providing opportunities to showcase, educate, understand and spread awareness on Information Security, data protection, and privacy...
Hey hackers, here at c0c0n, we are all hackers. Whether you have been hacking for years, just getting started, or are simply curious about what happens behind the screen, we all started somewhere.
Some of us break things, some build things, some hunt bugs, some defend systems, and some are just curious enough to ask, "What happens if I try this?"
Hacker Hangout is an open space to explore that curiosity. It brings different parts of hacker culture into one place. There is no single path into hacking, and we want the space to reflect that. You might be into offensive security, cyber defense, AI attacks, bug hunting, hardware hacking, lock picking, malware, research, or something completely different. There is room for all of it.
We will bring together security professionals, researchers, hackers, senior executives and enthusiasts to share what they work on, demonstrate their skills and tools, talk about their experiences, and interact with participants. Some sessions will be technical, some will be hands-on, and some might simply be a conversation around an interesting idea or project.
The space will stay open for people to come and explore. You can join a talk, try a challenge, play games, experiment with a tool, watch a demonstration, ask questions, or just see what other hackers are up to.
Hey hackers, welcome to Hacker Hangout!
Hacker Hangout is mainly aimed at beginners and people who are new to cyber security, but there is plenty here for professionals and experienced hackers too.
Throughout the track, there will be technical talks, workshops, tool demonstrations, hands-on challenges, hands-on hacking and activities, games, and plenty of space to hang out. The idea is to keep things open, practical, and interactive, giving everyone a chance to learn something new, meet interesting people, and experience different sides of hacking.
You do not need to know everything before you join in. Come with your curiosity, learn from someone, share what you know, or simply find something interesting and give it a try.
The track will feature technical talks covering cyber security research, offensive security, threat actors, attack techniques, security tools, and real-world security challenges. The sessions can vary in length and depth, ranging from short technical presentations to detailed research sessions. Speakers can use these sessions to present their research, demonstrate techniques, share findings from security assessments, or talk about practical experiences from their work.
The format will also give speakers room to present smaller research findings, interesting techniques, experiments, or lessons learned from real-world engagements. The focus will be on practical and technical knowledge that participants can take away and explore further.
The hands-on workshop will focus on practical learning and guided activities where participants can work directly with cyber security tools, techniques, and simulated environments. Workshops can cover areas such as adversary emulation, ransomware emulation, web security, active directory, malware analysis, threat intelligence, offensive security, and security testing.
The sessions will combine demonstrations with practical exercises, allowing participants to understand how a technique works and then apply it in a controlled environment. Where required, the environments and tools will be prepared in advance so that participants can spend their time working through the exercise rather than dealing with installation and configuration.
The workshops can be designed at different difficulty levels, allowing beginners to participate without feeling overwhelmed while still providing useful practical content for participants with previous cyber security experience.
Participants will use pre-configured devices to compromise a vulnerable cyber range with the assistance of a locally hosted AI model. The entire environment will operate offline on a closed internal network, with all devices physically connected to the cyber range infrastructure. No external connectivity will be provided.
Participants will first move to the adjacent area, where they will perform the same attack chain manually through a guided exercise. This will give them a chance to understand the techniques involved and how the different steps of the attack chain connect together.
They will then proceed to Frontier Breach, where they can observe a locally hosted AI model carrying out the same attack against the Active Directory cyber range. Participants will be able to follow the attack as it happens and compare it with the techniques they performed manually.
The activity is designed to give participants a direct look at how AI can be used in offensive security operations while keeping the underlying attack techniques at the center of the experience. The side-by-side format will allow participants to see the difference between traditional hands-on attacks and AI-assisted offensive operations within a controlled lab environment.
The track will include dedicated sessions for demonstrating cyber security tools, research utilities, open-source projects, and tools developed by the professionals. Speakers can showcase tools they have built, use, or contribute to and demonstrate how they fit into real security workflows.
These sessions can focus on a particular problem, explain the approach taken by the tool, and demonstrate its capabilities through practical examples.
The track will include short and interactive cyber security activities that participants can join throughout the event. These activities are intended to make the track more engaging and give participants an opportunity to test their knowledge outside formal sessions.
The format will be quick and accessible, allowing participants to join between sessions without committing to a long activity.
Attack of the APTs will be the primary hands-on challenge within Hacker Hangout. The challenge will be based on attack techniques associated with real-world threat actors and documented through threat intelligence reports and security research.
Participants will work through a simulated attack scenario where multiple techniques are connected together to form an attack chain. The scenario can involve activities such as reconnaissance, credential access, persistence, lateral movement, discovery, and data exfiltration. Instead of treating each technique as an isolated task, the challenge will show how individual actions can connect together during an attack.
The challenge will be designed around an approximate completion time of 15 to 20 minutes, with scenarios ranging from easy to medium difficulty. Laptops will be provided on-site with the required tools and environment already prepared, allowing participants to walk up, receive the scenario, and begin the challenge without any setup.
The challenge is intended to give participants an opportunity to experience an offensive security scenario in a controlled environment and understand how different attack techniques come together as part of a larger operation.
A dedicated hangout space will be formed as part of the track. Participants, speakers, researchers, professionals, and students can use the space to meet and interact outside the scheduled sessions.
The space will encourage casual conversations around cyber security projects, research, tools, career opportunities, learning paths, and experiences. Participants can discuss ideas, share projects, ask questions, find people with similar interests, or simply spend time with members of the cyber security community.
The space will also provide an opportunity for researchers and tool developers to show smaller projects, discuss ongoing work, and receive feedback from other practitioners. The goal is to create an environment where conversations can continue beyond the scheduled sessions.
Shana Buhaisa PAssociate Security Consultant, BreachSimRange
Nimna SreedharanCybersecurity Professional | Digital Forensics & Incident Response Leader
Allen JamesCyber Security Analyst, HackIT
Sreehari HaridasOffensive Security Lead, FinTech
Krishnapriya K RAssociate Director, Deloitte
Alestin ShelmonCyber Security Analyst, HackIT
Fahad FaisalCyber Security Researcher, BreachSimRange
9–10 October 2026 · Grand Salon 1, Grand Hyatt
11:30 AM – 04:30 PM
11:30 AM – 4:30 PM
Supported by
Together with organizations that support collaboration, innovation and a stronger cybersecurity community.