BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.romhack.io//romhack-camp-2026//talk//ALJJBE
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-ALJJBE@cfp.romhack.io
DTSTART;TZID=CET:20261003T160000
DTEND;TZID=CET:20261003T170000
DESCRIPTION:Threat intelligence teams collect indicators\, follow threat ac
 tors and produce reports. SOC teams build detections and investigate alert
 s. Too often\, the connection between the two ends with a list of IP addre
 sses\, domains and hashes added to a SIEM.\n\nThis talk looks at how to mo
 ve beyond that model.\n\nUsing practical attack examples\, I'll walk throu
 gh how intelligence can be transformed from an IOC or threat report into a
 n investigative hypothesis\, observable attacker behaviour and ultimately 
 a detection. We will look at what information gets lost when intelligence 
 is reduced to indicators\, how to identify the behaviour behind those indi
 cators\, and how to decide which telemetry can actually expose it.\n\nThe 
 session follows a simple workflow:\n\nThreat Intelligence → Adversary Be
 haviour → Detection Hypothesis → Telemetry → Detection → Hunt → 
 Validation\n\nI'll also cover what happens after a detection fires: how in
 vestigation results can feed back into threat intelligence\, improve conte
 xt and help identify what should be hunted for next.\n\nThe goal is not to
  collect more intelligence or generate more alerts. It is to make threat i
 ntelligence operational enough to change what your SOC can detect.\n\nAn I
 OC may tell you what the attacker used. A good detection should help you f
 ind what the attacker did.
DTSTAMP:20260921T191043Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:From IOC to Detection: Turning Threat Intelligence Into Something Y
 our SOC Can Actually Use - Sanjay Kumar
URL:https://cfp.romhack.io/romhack-camp-2026/talk/ALJJBE/
END:VEVENT
END:VCALENDAR
