BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidescbr.com.au//bsides-canberra-2026//talk//CNKXQ
 T
BEGIN:VTIMEZONE
TZID:Australia/Sydney
BEGIN:STANDARD
DTSTART:20250926T000000
TZNAME:AEST
TZOFFSETFROM:+1000
TZOFFSETTO:+1000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20251005T030000
RDATE:20261004T030000
TZNAME:AEDT
TZOFFSETFROM:+1000
TZOFFSETTO:+1100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20260405T030000
RDATE:20270404T030000
TZNAME:AEST
TZOFFSETFROM:+1100
TZOFFSETTO:+1000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Malicious Entra ID Apps - what they are\, how to find them and how
  to stop them - Sam Brazier-Hollins
DTSTART;TZID=Australia/Sydney:20260926T110000
DTEND;TZID=Australia/Sydney:20260926T112500
DTSTAMP:20260727T191823Z
UID:pretalx-bsides-canberra-2026-CNKXQT@cfp.bsidescbr.com.au
DESCRIPTION:We've all heard of password guessing and MFA bypass techniques
  that are used to attack M365 - but those are old news now! The newer and 
 more interesting vector - to both attackers and defender alike - are malic
 ious Entra ID (formerly Azure AD) apps. In this presentation I'll explain 
 what Entra ID apps are (and what makes some malicious)\, how attackers tri
 ck users/victims into registering them\, how you can find any that may alr
 eady be in your environment\, and what you can do to stop more in the futu
 re.\n\nThis presentation is designed for technical audiences (or those wan
 ting to become technical) to understand an emerging vector and what can be
  done to defend against them. The content is based on both our firsthand e
 xperience (as both attackers and defenders) as well as that from our partn
 ers.
LOCATION:Off-Main Track
URL:https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CNKXQT/
END:VEVENT
END:VCALENDAR
