SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Extended File Attributes are the Linux version of the NTFS ADS (Alternate Data Stream). They are use for the same kind of purposes but may sometimes contain very interesting data like payloads or encrypted data. This presentation will be split in two parts: First, I'll show you how to hide a simple payload in Extended File Attributes (the bad guy), then I'll show you how to can hunt for such attributes (the good guy).
This presentation sets the stage for a critical discussion on third-party risk management in cybersecurity. The agenda outlines a journey from awareness to action, covering why vendor risk matters, current practices, real-world breaches, limitations of questionnaires, recommended improvements, and key takeaways. It emphasizes the importance of rethinking how organizations assess and manage vendor relationships in an increasingly interconnected digital landscape.