← back to blog // article

FIC 2022

The International Cybersecurity Forum 2022 took place on June 7th, 8th and 9th at Lille Grand Palais (France) and I was able to go there for the first time in my life. I wrote a short article to share my feelings on this forum.

As soon as we arrived, we can see that the whole building is filled with stands of the FIC partner companies, animating talks, discussing their projects and what their company has to bring to the cyber community, as a simple student I was very well received on each of them

A sample talk at the capgemini stand

The conferences

The first reason I came to the FIC was to be able to attend a wide variety of talks on a lot of different topics, so I tried to attend everything that could interest me:

Day 1:

Talk from : ACCEDIAN

The talk was about how a deep and complete network traffic analysis combined with AI and Machine Learning can detect in real-time what endpoints and firewalls solutions can’t detect.

Talk from : SOPRA STERIA

Animated by : Alexandre CABROL-PERALES and Margaux QUITTELIER

During this talk, they combined the MITRE frameworks (CVE, CWE, CAPEC, Attack and Defend) in order to define potential operating modes, link them to the associated groups of attackers and thus set up a defense mechanism adapted to the threat. This method has enabled the speaker to design a managed detection and response plan in one hour and to effectively anticipate any potential attack.

Talk from : SALT SECURITY

A demo of Salt Security’s patented approach to API security including:

  • Generating a comprehensive inventory of your APIs

  • Detecting active attacks against your APIs

  • Defending against the OWASP API Security Top 10

Talk from : SOLAR WINE

Animated by : Aris ADAMANTIADIS

Hack-a-sat (https://hackasat.com/) is a “Capture-the-flag” contest organized by the American government, whose goal is to test certain space technologies, in particular those of satellites, against hackers. The French-speaking team Solar Wine participated in the first two editions of this challenge and won the first prize of $50,000 in the second edition.

Talk from : SNYK

Animated by : Chaaban BARAKAT

Snyk is a security platform for developers integrated directly into development tools workflows and automation pipelines. In this presentation, we have explored the 4 products that make the Snyk platform:

  • Snyk Open Source to detect vulnerabilities and license issues in Open Source dependencies

  • Snyk Code - A dev-friendly SAST tool performing fast scans with a reduced number of false positives and example fixes to guide developers in fixing the issues detected

  • Snyk Container to scan images and get recommendations on base images

  • Snyk Infrastructure as Code to detect and remediate misconfigurations in Terraform, CloudFormation, ARM and Kubernetes files

Talk from : WAVESTONE

Animated by : Arnaud SOULLIE

In this talk, the speaker shared a global vision of the level of security observed in the field (network security, remote access, maintaining security conditions, resilience, etc.) with a new focus on the industrial cybersecurity governance implemented by their clients

Day 2:

Talk from : MANDIANT

Animated by : Arnaud GARNIER

During this presentation, the speaker described the information gathering phases on the attacker’s TTPs (Techniques, Tools and Procedures) and then he launched an attack on a network.

Talk from : VARONIS

Animated by : Pierre-antoine FAILLY-CRAWFORD

This one was about how a big-game ransomware attack works and how to defend against it in an attack-and-respond simulation!

They have highlighted how ransomware gangs operate and showcase common tactics, techniques, and procedures (TTPs) that will help you prepare for an attack. Then they ran a step-by-step attack simulation and show us how an IR team could respond at each and every phase.

This scenario showed a threat actor controlling a device in the network, escalating privileges, accessing sensitive data, and then exfiltrating it. They highlighted how they can gain control of the organization’s DC server and perform a DCSync Attack, finally deploying ransomware to encrypt the file server’s contents.

**Animated by : **Maurice-Michel DIDELOT

A talk about work done in collaboration with the ESA and the company CYSEC, It’s condensed in the following blog post:

https://www.deadf00d.com/post/how-to-hack-an-esa-experimental-satellite.html

This presentation had the same goal as this article: to demonstrate the possibilities of hacking a satellite and its strategic applications. Also, to present the risks and evolutions of the “New Space” technologies and their implication in terms of security.

Talk from : FORTINET

Animated by : Christophe AUBERGER

The future of new generation network infrastructure embeds security in hybrid environments and enables the interconnection of users, data, and resources safely, using the zero-trust principles.

In this presentation, we have seen how the innovative approach of Fortinet which brings agile connectivity and security in hybrid environments from anywhere, covers those requirements.

Talk from : SEMPERIS

Animated by : Matthieu TRIVIER

The explosion of ransomware attacks has made companies realize the importance of defending Active Directory (AD). Mandiant researchers reported that 90% of the breach incidents they investigate involve AD. By leveraging oversights such as an unpatched Zerologon vulnerability or excessive domain admin permissions, cybercriminals can use AD as an entry point, deploying malware that can lurk for months before wreaking havoc.

In this session, we have seen how to:

  • Detect threats that target AD, including malware that evades detection by SIEMs

  • Automatically roll back unwanted or malicious AD changes

  • Fully recover the AD forest in the event of a cyber disaster, without reintroducing malware that can make your organization vulnerable to a second attack

Talk from : KLEE GROUP

Animated by : Philippe CHRÉTIEN and Renaud FELTEN

To better understand a cyberattack, it is to be able to target remediation measures and protect your information systems in an effective way!

We put ourselves in the shoes of a hacker and learn, like him, to detect the vulnerabilities of an information system :

  • Identify the key elements of an attack

  • Better understand the hacker’s modus operandi (target identification, information gathering, compromise, persistence and trace coverage)

  • Know the vulnerabilities (human, software, system, etc.) and their consequences, which can lead to the compromise of an entire system

  • Reflect on the solutions that could have been put in place to prevent or limit the attack

Day 3:

I did not follow any conferences during the third day because many of them were repetitions of the previous ones, moreover, I wanted to focus my attention on the EC2

European Cybercup

The EC2 is a cyber security competition mixing several types of challenges, in which teams (representing their companies or schools) compete for the first place on the leaderboard.

It took place during the last 2 days of the FIC, from the 8th to the 9th of June and it was held in the main hall of Lille Grand Palais just after the partner companies’ stands.

The challenges

Below, my feedback on each challenges:

  • Forensic

  • Escape game

  • OSINT

  • Bug bounty

  • OT Operational Technology, i.e. industriel

  • IA

  • Gaming

  • CTF

Forensic

This event was composed of 19 scenarios, themselves composed of 5 challenges each, and took place on Wednesday 8th from 9:30 am to 6:30 pm.

The platform offering the challenges was dedicated, available, functional and clear. The challenges were of high quality, realistic and functional.

Escape Game

This test lasted 25 minutes. Each team was given a time slot (Wednesday or Thursday) and 3 members of the team were allowed to compete in the event, without any equipment (no phones, lockpicks, computers or other). The slots could fall during other events. Some teams were more or less advantaged/penalized by this.

The description of the event was as follows:

In the mode of an escape game, each team will have to put itself in the shoes of a team of investigators of ComCyberGend, hired after a Ransomware attack on a small business. They will have to manage the crisis,
find out who attacked the company and collect the digital evidence necessary for the investigation.

OSINT

This event offered ~40 to 50 challenges (4 full scenarios, ~10 challenges per scenario) and was hosted on a dedicated platform. The event took place from wednesday 8th at 11:30 am to the next day 3 pm (without interruption during the night). The creators of the event were present, available, invested, listening, in short nothing to say. The scenarios were original, logical, and complete, etc.

Bug bounty

The bug bounty event was organized by Yes We Hack and EC2 joined it. It took place from wednesday 8th at 10am to the next day at 4pm (without interruption at night, except for the submission of reports). The Yes We Hack platform was used here.

IA

In this event, the challengers had to automatically classify deepfakes or real images. Although this event was spread over the two days of the competition, a lot of work was required beforehand to prepare a working base, adjust the parameters and models chosen, etc.

OT

This event, separated into two 15-minute challenges, took place between Wednesday and Thursday, with one challenge per day. The chosen industrial theme was: nuclear power plant crisis. It was chosen to offer an industrial cybersecurity challenge against the clock.

Gaming

The gaming/sports event took place between Wednesday 8 and Thursday 9, with 7 games of 15 minutes max. proposed spontaneously.

The 7 games were the following:

  • Tetris (~5min) : a Tetris competition.

  • Snake (5min) : a game of Snake

  • Zutom (~10min) : a game of Zutom

  • Geoguessr (~5min) : a game of GeoGuessr

  • Pédantix (~15min) : a game of Pédantix

  • Stéganographie vidéo (10min) : the messy message appeared less than a second on a 3 minutes video.

  • Stéganographie audio (10min) : a message was hidden in a spectrogram in one of several sounds to be inspected.

CTF

This event took place on both days of the EC2.

6 challenges were proposed

  • 4 reverse of “Godot”, not very adapted to the cyber business, but very original and in phase with the CTF culture.

  • 1 realistic VM : RCE by zip slip on a web application then privilege escalation by GTFObins. Although this challenge had some unavailability, the organizers were available and present and quickly corrected the problems.

  • 1 reverse/pwn VM with custom instruction sets.

In conclusion, it was a very rewarding experience, it was one of the very first times I saw so many people passionate about the same field as me gathered in the same place there is no doubt that I would do it again next year