ℹ️   Note:
- All times are in "Honolulu Time" (HST).
- Download the #OBTS v9.0 in-hand schedule, an easy-to-read view of all three conference days.
- If you are unable to attend in-person, all talks will be live-streamed via our YouTube channel.


Trainings
November 15th (Sunday) - 17th (Tuesday)
ℹ️   Note:
Trainings occur prior to the conference, from November 15th - 17th. They are separate from general conference attendance (and require separate registration and payment).

More information on the conference trainings can be found on the training page.

Training Room: Lahaina 1 (retail level)
10:00 am - 05:00 pm

"iOS Threat Hunting and Malware Analysis" (Matthias Frielingsdorf)
Training Room: Lahaina 2 (retail level)
10:00 am - 05:00 pm

"Threat Hunting macOS" (Jaron Bradley)
Training Room: Lahaina 3 (retail level)
10:00 am - 05:00 pm

"macOS Vulnerability Research Training" (Csaba Fitzl & Gergely Kalman)
Training Room: Lahaina 4 (retail level)
10:00 am - 05:00 pm

"AI for Mac Security" (Kimo Bumanglag)
Training Room: Maui Suite 1 (promenade level)
10:00 am - 05:00 pm


Talks
November 18th (Wednesday) - 20th (Friday)
ℹ️   Note:
Conference talks will be presented from November 18th - 20th.
All talks are presented in the Monarchy Ballroom (or can be freely live-streamed here).


Wednesday, Nov. 18th
08:30 am - 09:20 am (50 minutes)
Badge Pickup
Monarchy Foyer
Come pick up your conference badge. (Note: All that is needed is the email address you registered with).

09:30 am - 09:45 am (15 minutes)
Welcome and opening remarks

09:45 am - 10:10 am (25 minutes)
"Keychained Melody: Grabbing the Keys to the Cloud Kingdom on macOS" (Jaron Bradley & Alex Radocea)

10:15 am - 10:40 am (25 minutes)
"I Don't Even Need Your Permission to Track You - Bypassing iOS Cross-App Tracking" (Wojciech Reguła)

10:45 am - 11:25 am (40 minutes)
"Exploiting XNU: A Maze of Twisty Little Passages" (Dionysus Blazakis)

11:30 am - 12:00 pm (30 minutes)
"Inside Coruna and DarkSword - iOS Exploit Caught in the Wild" (Matthias Frielingsdorf)

12:00 pm - 01:30 pm (90 minutes)
Lunch

01:30 pm - 01:55 pm (25 minutes)
"Working on my DADBOD: An Open-Source Framework for Infostealer Detection" (Stuart Ashenbrenner)

02:00 pm - 02:25 pm (25 minutes)
"Unix Pipes" (Maggie Zirnhelt)

02:30 pm - 02:55 pm (25 minutes)
"Reversing and Breaking macOS Tahoe's ClickFix Paste Protections" (Ferdous Saljooki)

02:55 pm - 03:15 pm (20 minutes)
Afternoon Break

03:15 pm - 03:40 pm (25 minutes)
"Fastest Dev: Racing to Steal Credentials" (Lance Cain)

03:45 pm - 04:10 pm (25 minutes)
"Agents on the Hunt: From macOS Telemetry to an Agentic Hunt and Detection Program" (Kimo Bumanglag & Joseph Millman)

04:15 pm - 04:40 pm (25 minutes)
"Dancing Chollima: Fingerprints of What Makes a DPRK Drama" (Cat Self)

07:00 pm - 09:00 pm (120 minutes)
main(); Event
Napili Garden


Thursday, Nov. 19th
09:30 am - 09:45 am (15 minutes)
Welcome back

09:45 am - 10:10 am (25 minutes)
"AI LOTL — Investigating Agent-Driven Execution on macOS" (Shannon McCormick)

10:15 am - 10:40 am (25 minutes)
"macOS JIT Memory Internals" (Kyle Avery)

10:45 am - 11:25 am (40 minutes)
"The Best XCSSET Yet: Breaking Down the New and Improved XCSSET Variant" (Adva Gabay & Noa Dekel)

11:30 am - 12:00 pm (30 minutes)
"macOS Exploit Mixtape - Hack Like It's the 80s" (Csaba Fitzl & Gergely Kalman)

12:00 pm - 01:30 pm (90 minutes)
Lunch

01:30 pm - 01:55 pm (25 minutes)
"Lessons from Threat Hunting for Malware Triage" (Megan Carney)

02:00 pm - 02:25 pm (25 minutes)
"Mirror, Mirror, on the Wall, Is iPhone Locked After All?" (Jacob Prezant)

02:30 pm - 02:55 pm (25 minutes)
"AEMonitor: Monitoring Apple Events for Malware Analysis and Detection" (Pepe Berba)

02:55 pm - 03:15 pm (20 minutes)
Afternoon Break

03:15 pm - 03:40 pm (25 minutes)
"The Big Bang of iOS Backups" (Martina Tivadar)

03:45 pm - 04:10 pm (25 minutes)
"Kim Trails: The Forensic Artifacts of DPRK Crypto Heists" (K Singh)

04:15 pm - 04:30 pm (15 minutes)
"Nasty Code, Ahead of Time! Malware Techniques via Rosetta 2" (Nicole Reichert)

06:30 pm - 11:30 pm (300 minutes)
#OBTS Capture the Flag (CTF)
Halona Kai
Come participate in the Apple-themed CTF event and win prizes.


Friday, Nov. 20th
09:30 am - 09:45 am (15 minutes)
Welcome back

09:45 am - 10:10 am (25 minutes)
"Hunting With Agents on Data That Isn't Real: Agentic macOS Threat Hunting on Synthetic ESF Telemetry" (Sydney Marrone & Lauren Proehl)

10:15 am - 10:40 am (25 minutes)
"Bridges and Backdoors: Unmasking Operation FlutterBridge" (Noa Dekel, Ido Asher & Tom Fakterman)

10:45 am - 11:25 am (40 minutes)
"Library Injection Reloaded: Weaponizing Apple's Trusted Libraries for SIP Bypasses" (Francesco Benvenuto)

11:30 am - 12:00 pm (30 minutes)
"Exploitation under SPTM and Exclaves: What a Kernel Write Still Buys You" (Arni Hardarson)

12:00 pm - 01:30 pm (90 minutes)
Lunch

01:30 pm - 01:55 pm (25 minutes)
"Naughty or Nice: Alignment on the Cheap" (Pete Markowsky)

02:00 pm - 02:25 pm (25 minutes)
"Click Happens: Clickjacking on macOS WindowServer" (Yannis Hofmann)

02:30 pm - 02:55 pm (25 minutes)
"utmpwn and the Future of SIP Bypasses" (Jonathan Bar Or)

02:55 pm - 03:15 pm (20 minutes)
Afternoon Break

03:15 pm - 03:40 pm (25 minutes)
"The Forensics of Coruna & DarkSword" (Sarah Edwards)

03:45 pm - 04:10 pm (25 minutes)
"The Toolchain Is the Loader: Attributing Malicious Developer Artifacts on macOS" (Adel Karimi)

04:15 pm - 04:40 pm (25 minutes)
"TODO: Hack AI" (Patrick Wardle)

04:50 pm - 05:20 pm (30 minutes)
Closure (+ prizes!)

06:00 pm - 08:00 pm (120 minutes)
exit(); Event
Halona Kai


Download the #OBTS v9.0 in-hand schedule, an easy-to-read view of all three conference days.