Cybersecurity Roundup
Okay finally I should post this!
Sorry I'm late! >~<
This is to catalogue what I've learned that's information security related.
So, I'm not the vice president of women in cybersecurity at my college, which comes with lots of responsibilities. I joined and applied to propel myself forward in my career and to put me in a better position as a leader to those who want to get into the industry.
One big way I put my foot forward was attending a large Cybersecurity convention which I spoke of for the past few blogs, and this is me finally going over it!
It was two days long, and yeah...that preamble probably sounded more like "hi this is the big giant nerd convention!!" and it's true!
The first day was way less packed as it only focused on trainings, with there being only two time slots for the whole day.
As for what I chose, I picked a training on IoT device hacking and Reverse Engineering. I mentioned these briefly but will now speak in detail!
IoT Hacking
When it comes to information security, IoT devices increase the attack surface exponentially! Unless a company is smart enough to secure their network, there exists so many vectors of attack.
To elaborate, places with no IT teams, or infrequent ones may not secure these devices.
From PTZ cameras to thermostats to smart doors, switches, everything can potentially be compromised. Do note, I much prefer blue teaming along with governance, risk, and compliance when it comes to cybersecurity. That is to say...I like to be a defender and an analyst to ensure places are up to code and that assets are safe as well as people. Also, most Cybersecurity jobs end up in a position like that. Read teaming does exist, and there's also DevSecOps, which is for developing security tools, (I want to get into this one day!) but most people fail to realize this is a very difficult career and you are sadly nothing like "Hackers 1995."
You're more like....an office worker. It's not boring though, far from it, people just have to find the right role and go in with the right expectations. It's why I like teaching people and guiding them along the right path for that career choice.
Getting back on topic, IoT devices are easily hackable. Why? They tend to use insecure bluetooth/Wi-F standards, are usually connected to the main network, receive few updates, and can be quite invasive. From a commercial standpoint, the last one doesn't stand as much, but I am a very privacy first person, even if the blog along with how much I give away may seem otherwise, I like to protect other people's privacy first. I touched on it last blog, but I have my reasons for being so public.
Still, the last thing we need is a "smart" device feeding us ads and selling our data. IoT devices open that up...but at the same time offer that trade off when it comes to convenience.
The first training centered on the hardware side of IoT hacking. The presenter paired everyone in teams as he brought out his own kit of homemade Wi-Fi routers.
They were the cutest little things and we were tasked with using PuTTY and PulseView to gather information from them.
On the hardware side, IoT devices are just as vulnerable, and they can be reverse engineered for a whole host of malicious reasons. Also, the pinouts for different voltages can only be so much, with a skilled threat actor, they could find a way into a company's main network easily.
We used multimeters to find the ground pins and measure the various voltages of the device.

Really fun!!!
I hooked up my laptop to the device as it was the next step of the CTF, and we ran PulseView and could see the individual bits being sent and transmitted by the device! Wow! Afterwards we used PuTTY to remote into the device and enter it as a terminal.
Really cool!!!
Reverse Engineering
The next one was even cooler though, as I had never done reverse engineering before this, or really thought about it.
We were to write some code the presenter (who was a high level cybersecurity employee at Boeing) prepared so it became our own as reverse engineering tends to be mostly illegal. I knew at some point I'd have to learn C++, and that was my start. _ It was pretty cutesy, fun. We then broke the code down using assembly and split the entire code stack to view its insides and rummage around them...
It was lots of learning packed into a small 2 hour window, but it was invaluable information. Using assembly and stripping the code down to its insides, you can find hidden embedded information, and even fundamentally alter the code itself.
The presenter spoke of how this could be used for anything with code in it, or pcb boards. In his case he used his own coffee machine and attempted to reverse engineer it..he said he messed up on that one to showcase how it could go wrong, but you can even reverse engineer things like printers! Not only that but it applies for IoT devices too, imagine being so skilled that your trusty key fob has a new function embedded...something like that.
I took home with me lots of information about code stacks and will carry it with me. One of the most exciting parts of the training was when we decompiled the code and found a hidden password! That was at the very end, but embedded passwords truly are a security risk!
What a fun event. :)
The day then ended promptly, with not much to speak about besides excitement for the day after....now what would the conference hold for me?

Arriving after a peaceful morning ride to the same campus as the day prior, I didn't know what was in store for me. As to what I did know, was that it was a time for me to dress elegant, fancy, and cute. My dress was complimented quite a few times too! _
And to my surprise the place was packed! It was just a small gathering the day prior, I was blown away by the livelihood exhibited by this place. Now I did get there slightly late, by about 30 minutes or so, but it was actually fine! The keynote was just starting after that and there was lots of time for me to figure out what rooms I wanted to go to, how I would take notes, etc.
The main lobby was packed with lots of stands, free goodies, and so much more. I had to get past registration first but due to my badge from the previous day they just let me in!
In terms of networking...it was my goal to make it to every vendor stand and ask around, get my free tshirt and all that. I visited everyone, hung out, had some fun, got some free stuff, met new people.
I was curious about the actual conferences they had, but despite checking the website numerous times, I had arrived to no different conclusion....people told me to check the website but goodness I was stumped! There was a keynote panel about to start, but I chose to wander upstairs instead, to get another layout of the campus.
The building in total was three stories tall, but the third floor was off limits for this event.
I ended up settling into the same room the reverse engineering training was at the day prior, as I noted the keynote room was filling up and each room had a projector screen to showcase the whole facility.
I settled in and finally found the schedule for the day! I then got to work right away on my computer, planning to take notes and organize my day!
I had my Macbook with me, whereas I normally would have had my windows PC.
As for the keynote presentation, most of the notes were basic stuff, so I focused on planning.
In a way, finding out what room to go to for a class was vaguely similar to being in school. It is a nostalgic feeling for me. Uhm...it was, hehe.
Here was the schedule I decided on!

I also decided that I wanted to take all my notes and do everything on Windows 98 for the conference! I thought to myself (wow, this would be so silly...)
and it was!
To break down the list, it was as follows:
10 AM: Operational Technology and Information Technology 11 AM: PGP and Online Privacy 12 PM: Your secrets are showing OSINT 1 PM: Keynote Panel: Disruption 2 PM: Crisis Leadership 3 PM: Retro Intrusion Analysis 4 PM: Phishing Roundtable
Right before I walked to my first conference of the day, I heard rumors that food would be delivered at some point. This did pique my curiosity, but I was more focused on learning before anything!
10 AM: Operational Technology
So what is OT? OT typically includes the people who work with handles, valves, switches, gears, and other operational tech. This can include waste treatment plants, electrical plants, recycling centers, construction workers, electricians, plumbing, and so much more.
These are the factory workers, the people who do physical labor.
IT is information technology; computers, information, servers, storing info, almost everyone knows what IT is.
This conference was about how OT and IT have become increasingly reliant on one another, as smart valves, switches, and other electronic devices make OT work easier, the attack surface grows.
This was where it really did feel like class, since every room was a classroom, I settled into a good spot and got ready to take some notes.

The speaker was fantastic and he walked through how reliance on IT in OT fields can lead to various breaches, compromises, and more. I am going to be skimming over all of this, but eventually when I set up the cyberseucrity portfolio section of my blog, I will go into more detail!
Nonetheless, a key factor the speaker brought up was how OT is deathly important. It controls water pressure, temperature, and sanity control. The theory, which this has happened before, is with the increased attack surface of lights, switches, anything digital; that these systems can be compromised. I can go into specifics a different time of course, but this has already happened.
It's not the scariest thing in the world as we are aware of it now, but it was intriguing to hear how these threats are being mitigated.
Future threats are posed by this, but with increased security, we can defend!
11 AM Privacy Conference
After the lovely first two hours, I chose to go to a privacy conference. I already know a decent amount about the more intense privacy choices, but I still could always use a refresher. I am not very private on here at all, but my rationale is the low number of people who will find this combined with the fact that cybersecurity people like me are supposed to be found...in a way.
We're supposed to be the shield so others can stay safe. My info is out there so others won't. It's a bit of a "knightly" view on things, but I like it.
This one focused mainly on PGP and various encryption methods for digital signatures. It didn't go over too much that I didn't already know, but it's always good to hear more about PGP.
It's not the end of the world to not have it enabled, or to not have your own web server, or to be missing...something, but it's at least good to stay educated.
One topic which came up that I do find interesting as well is the topic of companies breaking their encryption promise. I learned, through this meeting actually, that Discord broke their encryption policy. Now, it wasn't really a surpise, but the reason people get upset about these situations is because it sets a precedent. If I can give Apple one thing, they have never broken their encryption, which can be admirable. Yes, there is a difficult line between if info should be given out or not, but again, there's the precedent. I'm still trying to figure out where I stand on partially broken encryption, but what I can say is that...a promise is a promise. A company breaking a promise, while common, holds a higher weight when it comes to encryption, personal data, photos, contacts, everything.
Then again, if we refer to Apple, they're big on telemetry even though they try to act like they're not. They're quite uncouth in so many other places, but I digress.
Nice little privacy talk.
12 PM Your Secrets are Showing
This one I was not able to get many notes for as my copy of Win98 crashed...seems the virtual floppy had an issue! I lost my notes, but I can still remember bits and bobs.
This one was about OSINT, which stands for open source intelligence. In the defender's playbook, OSINT is one of the most powerful tools possible. This could be for pen testing or for defense.
As you can see the notes are barren due to it crashing...I did want to use word for that one because of fun purple text...anyways.
OSINT is also about seeing how much people share online, when some people really, really shouldn't. In my career, this mainly refers to corporate people, some who share their entire corporate structure along with their names, phone numbers, hours they work. It is...quite a mess.
OSINT can be used for good and as a defender of course, we can education on why this is bad, to have so much out there, how to mitigate it, and also to let people know to NOT share when they're going on vacation and the office is closed for a week when it comes to private companies.
There again is much more to go over, but this is just a roundup, I will update my portfolio in time.
1 PM: Keynote 2
I headed back downstairs for this and...there was so much yummy food now! Lots of donuts, treats, everything. During the previous conference, some people were running to grab some and the guy in front of me kept asking me questions and thought my Win98 installation was pretty cool too. I love old tech!
This keynote was ....mm it was okay. It was about disruption, which in Cyber is...disrupting a sypply chain or a service. It was about understanding flaws with all major companies and their systems, ports, privacy laws, and on daring to disrupt. This mainly was advocated to verbally talk about this, but I am unsure what else they were encouraging hehe!
As for food, I got a delicious donut, some yummy cookies, and a nice little salad....yum!
2 PM Crisis Leadership
Geared towards leaders, which I am, but aspire to be one in the cyber field, this was about leading through crisis. There exists many such models on this, but this one one of many.
(crisis command framework)
As you can see by my notes, most of the info explains itself. The main thing to consider is, in Cybersecurity, crisis management is much different, and much scarier sometimes. You may have to be up super late, attempting to work with your already stressed out team to work towards some goal, to fix something. This is...even worse when dealing with an emerging incident of course...but it's exciting at the same time!
This was great for future leadership experience. Some examples from leaders were brought up too. Preventing burnout seems to be the number one priority...
3 PM Retro Intrusion
This one was probably my favorite, as it went over retro intrusion, placing an emphasis on one of the oldest depictions of a cyber attack. First and foremost, the speaker was so friendly and encouraged us to read the book "The Cuckoo's Egg," which is told like a fiction book, but is actually non-fiction.
Essentially this was about employing modern analysis models such as the Diamond Model or the Cyber Kill Chain to an old intrusion event. This was by far the one which I had the most fun at.
We did a diamond model analysis and walked through how the threat was uncovered, how it continued, and how it ended. It's quite the story but it ended up with about three German hackers getting arrested after they were revealed to be state actors working for the KGB...interesting stuff! This was back in the 80s! It was also an opportunity for me to step back and observe how I approach these situations as a blue teamer. Like, I ask myself: If modern analysis applies to these older threats, then surely some of these methods are still in use?
I'll have to keep in mind!
4 PM, Phishing Roundtable
What a great way to cap off the day!

This was a group effort between cybersecurity professionals such as myself to go over simulated phishing attacks. I partnered with a high up executive at a local cybersecurity company and we all spoke about our experiences with simulated phishing, what works and what doesn't.
When it came time to quiet down the discussion, I whipped ou my Win98 again and it got a chuckle out from a guy...imagine a girl in full gothic lolita smashing away at the keys in her purple space copy of win98! X3 (meee!)
Nonetheless, simulated phishing attacks can both be punishment while also being something rewarding. A key aspect for any good cybersecurity analyst is to never demonize the end users. They need to be approached with respect, care, and with the right mindset in order to sow positive growth in any workspace.
To teach and educate is insurmountable! We must value it!
Afterwards the day was ending, I was full of additional knowledge, met lots of great people, and also met the advisor to my college's Cybersecurity club. Right around this time, I had just become the vice president of women in cybersecurity at my school, so it was great to meet him! I'm collecting all my side quests, certifications, and moving on up. : )
These may be college clubs, but they offer so much more than that hehe...we do CTF events, engage in community outreach, get scholarship, study abroad opportunities...it's all fun. I may be meeting all sorts of new people but I'm still pretty much doing this alone. I don't mind it at all, these club members and all sorts of other people in the field are great. It's just not the same; still fun though.
As for the end of the day, I felt like walking. Thus, I walked....through unfamiliar and yet painfully familiar streets.
My destination was a Wendy's. The walk was around 2 hours or so, but walking is how I live. There are times I want to remember on purpose, which is almost every time.
I listened to music and saw a huge stadium to my right, flowers, a train station, and one street where so much happened.
Then came the unfamiliar.
Then...I settled in at Wendy's...and waited.
Crowdstrike Wbenair
In the weeks following the conference, another was planned on the 28th. For a brief excursion between meetings, I attended a Crowdstrike Webnenair! It was mostly a resume workshop, but going over it with real cybersecurity professionals and real resumes instilled a sense of confidence. Also, they were conscious of their past mistakes as a company and showcased a surprising amount of humility considering what happened. They're still a heavily trusted vendor in spite of everything.
They had some breakout rooms and I joined the threat intelligence and detection one. The speaker I partnered with used to be an Apple technician at the genius bar, we had a cute little laugh about my position as an Apple Tech and leader of those services at my job hehe.
I got some notes on further ways to enhance resumes, get around resume AI auto detection, and various other tips.
Cybersecurity conference 2
On the 28th, so just a few days ago, a smaller conference was planned. This was also a meeting between several members of my club and others, I had a few sidequest markers popup while I was here.
After work, a coworker actually took me to the venue, admission was free but wow this event felt huge, yet intimate. It was a smaller one focusing on culture in cybersecurity, getting hired with no experience, and highlighting local cybersecurity experts who contributed to the future of the industry.
Honestly I was quite surprised by the food they had! On the website it mentioned "light refreshments..." goodness, does this look light to you?!?! hehe.

I wasn't complaining at all though...good food and good conversation as they say! I met up with one of my club members as I got a nice bottle of water from their bar. Speaking of which...they had tons of free beer?! I don't drink, and would prefer to never, but the fact they just had tons of free beer and tons of so called "light refreshments" was certainly a little treat; just before Halloween at that.
The bartenders were kind of like a comedic duo, with one being real silly and teasing me when I asking for water, he looked super depressed and looked down, didn't say anything lol...he then teased me more when I asked if I could take another plate and kept doing "I'm watching you!" eyes just to mess with me haha. He was great, lots of laughs as he did his little act.
I met with some people with unique backgrounds too, shook lots of hands as we exchanged our genius germs. I met a girl who about 20 years ago used to work for Geek Squad and we talked about my position there. Also, I ran into the vice president of the Cybersecurity club, who recruited me on a sidequest.
He asked me to join the programming club... which just needed one more member to make it a reality. I said...hmm..I'm already in 3 clubs...ah what the heck! Why not one more! I took his offer to heart and took note on the fact that I would be seeing him throughout the night.
I also came to realize a fact somewhere between this event. This conference...er, convention in a way? Well, conventions have always been like...home! to me at least. I've always felt the most safe, most...loved? going to one. I've got cosplays planned but my hands still tremble in some aspects to return to the scene. Meanwhile, my professional side as a cybersecurity analyst and going to these events is a great substitution...it's just that atmosphere of joy I really like...
I also got to share my knowledge with some people who were looking to gain certifications, how to study, what to do, and on where they should start. I also noticed that there were lots of other girls there, which was great to see. : )
The keynotes were about to start and as I spoke to my clubmembers and divided up who would go to which presentation, they were interested in the career experience one, and on how to get a cyber job with no experience. To be honest, I was too, and I let them know that, but that for the sake of notetaking I would go to the other keynote.
We split up for around an hour and then met back up right before the final event, the keynote panel regarding culture, and how it's "the real firewall" in cybersecurity...lol.
The final event, me, my two clubmembers and the VP of the cybersecurity club all sat together. As I put my bag on my lap, the VP of the Cyber club pointed out my little keychains I always carry everywhere with me. He asked me about them and I was like "oh! uhm..."
So...these are two keychains I always carry with me.

I told him the pink one was "Hatsune Miku" which he had no clue who that was...! Oh no! He then said he doesn't watch "much anime," oh dear! However...the purple one...he said "is that hamtaro." but he said it like "hahhmtaro"
Him knowing the second one was quite funny. Yes that is hamtaro, correct boy lol.
When the event itself started, it was geared more towards leaders but I still filled about 5 pages in my notebook regardless. I will be a leader in infosec someday, might as well act like it heh.
They brought up about 5 local cybersecurity experts from different backgrounds...ones with their own startup, others from retired military, one from a university. The varied ideas and experiences, even more so on how they had a different approach to culture in the cybersecurity framework showcased how open minded most leaders are in the field. Above all, implementing zero trust policies and the principal of least privilege, while not just slapping down a huge list of compliance and HR policies is not the way to go.
There is no culture in a workplace which doesn't truly see you. This is doubly so for Cyber in both ways. No one wants to know they're the one who caused the breach. At companies with worse regulations and a toxic work culture, a display out of them may be made, they may be laughed at, belittled, and generally disliked or even fired.
That is never the way to do it, and I'm glad everyone in that room agreed too. Luckily this isn't a problem for most C suite execs, but more so for obnoxious CEOs and shareholders. (all of them) In fact I heard stories from some people of CEOs which just scream and yell and never do anything. (all of then)
Still, I already employ this principal, as no one can learn, nor want to learn if the SOC team is focused on punishment as opposed to growth. Yes, incidents are stressful, but for as silly as it sounds...culture is the real firewall!
At the end of the event, we got some more food and...ah wait sorry I forgot the accordion guy.
Yeah so there was an accordion guy who performed a silly little tune about robots taking over jobs. At the least, cybersecurity ironically has lots of job security, and presenters already spoke on how some companies which already tried to use "AI" to replace people backfired horrifically, and they are suffering for it...horray!
This goes not just for IT, but any company, bleh. It is reassuring to hear it from these high level people.
At the end though, we all took a huge group photo in front of the sign for the place, which mind you it was in a part of a city I never knew existed. It was on the outskirts of this huge downtown area which almost always gives me some headaches due to my past, but I just felt happy that night.
I also got to use my photography skills to take photos of the main speakers as they needed someone to do so. The VP of the cyber club tried to do it but I was like (ah no you need to angle the whole sign in the photo!!!) and he was like (shouldn't the camera person be doing this.) and yes I should have which is why I did...lol they all said "let her take the picture!!"
When we were saying our goodbyes, I pulled out one of my random blank floppies I carry with me for no reason, (I have multiple) and handed one to the P of the cyber club. It was a promise for me to accept his sidequest and join the programming club haha.
And then...a quiet, gentle exit.
A flop-tastic kitty modeling some of my floppies.
Kind of related, but again this is all an overview, I'll do deep dives in the portfolio. I wanted to bring up some fun old tech I have been playing with lately. I recently acquired an early 2000s SONY Walkman and it has been a blast. I brought it to work and was wearing it on my skirt, listening to the radio >_<.
All of my coworkers loved it. I also got an Evangelion mixtape for extra immersion...love it!

I also recently acquired a 1997 Satelite computer...it still works! Also I am not just buying random old tech...I get some fun stuff for free heh.

I can't wait to have some fun with this little puppy...arf.
I acquired a nice vinyl player too, been having some fun listening to vinyl and experimenting with all sorts of tech.
TO BE CONTINUED IN DEEP DIVES UNDER THE NEW PORTFOLIO!...unfinished....er...uhhmmm..meow?
Take care of yourselves everyone!
- Victoria