Session

The Kill Chain - From Phish to Sysadmin on SQL Server

Most security talks start at sysadmin, real attackers start with a bored employee and a PDF.

In this live, two-screen session there are no slides, just two terminals: one of us attacks while the other defends, in real time. We follow the whole chain, one click to catastrophe: a phished user, a foothold on a workstation, a pivot into SQL Server as a low-privilege login, and a single everyday misconfiguration that escalates us to sysadmin.

From there the data is exfiltrated and the backups burn. Then we run it backwards: the defender closes each door, often with a single line of T-SQL, until the exact same attack fails at every step.

You will leave able to name every link in the chain and the one control that cuts it. Entry-level and fast-paed: if you run, build on, or protect SQL Server, this is the hour that shows you how the breah really happens and how to stop it.

Danny de Haan

Database Security & Infrastructure Advocate

Roermond, The Netherlands

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top