Loading Events

Zero Day Hire: Can You Spot the Spy? (Session 2)

Please Note: Lab experiences do not require registration and are available on a first-come, first-served basis. The room will be cleared after each session to accommodate the next group.

“If your hiring process relies solely on traditional background checks, you’re already behind. You think you’re hiring a Senior Backend Engineer. You’ve reviewed the resume, passed the technical interview, and cleared the automated background check. But you’ve actually just handed a corporate laptop to a spy.
This 60-minute workshop puts the attendee in the seat of an OSINT lead during a live-fire exercise. This isn’t a lecture; it’s a test to stop a breach before it starts. Attendees will be provided with the same “”evidence”” a recruiter would see, and the goal is simple: perform a background check to identify fake personas. You have 60 minutes. Can you do it?
Key Takeaways:
– Learn why standard background checks miss AI-generated personas and synthetic identities
– Leave with a practical, legally-conscious verification process you can use by Monday morning
Note: Please bring your own laptop. Attendees should be comfortable installing and using common OSINT tools to participate in the live investigation.”

Michael Reimsbach

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services. He obtained multiple industry certifications such as OSCP, GCPN, and CISSP. A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information. Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.

Rishi

Rishi is a London-based security researcher with experience in vulnerability research, threat intelligence, and enterprise risk analysis. His work focuses on identifying zero-day vulnerabilities and emerging CVEs, with a particular interest in building detection logic before threats are publicly weaponised. He works across both offensive and defensive disciplines, developing threat models grounded in real-world TTPs, writing detection rules, and automating reconnaissance to uncover exposed assets at scale. Attack surface management and OSINT are areas he keeps coming back to, specifically the challenge of mapping exposure that organisations often don’t know exists. Outside of his day job, Rishi contributes to open source security tooling through Project Discovery and OWASP, he is part of the leadership team of the UK OSINT Community, and occasionally speaks at community events including DEF CON, OWASP and BSides.

Event Information

  • Start Time: August 7, 2026 1:30 pm
  • End Time: August 7, 2026 2:30 pm
  • Venue: SEC Labs Room W320

Details

  • Date: August 7
  • Time:
    1:30 pm - 2:30 pm

Venue

  • SEC Labs Room W320