Meet TrainSec Co-Founder Uriel Kosayev at DEF CON 34

Uriel kosayev

Author

Uriel Kosayev
Uriel Kosayev is a cybersecurity researcher, reverse engineer, and author of MAoS and Antivirus Bypass Techniques. He’s led real-world red team ops, malware investigations, and incident response cases. As the founder of TrainSec Academy, he teaches professionals to think like attackers and defend with precision. His training is practical, focused, and based on real threats, not theory.

This August I am heading to DEF CON 34 in Las Vegas, and I am bringing a real story with me. My workshop, “The Silent Tunneler: A Real-World Incident Response Story”, runs at Malware Village on Friday, August 7. If you are going to DEF CON this year, this post is basically one long invitation.

What Is The Silent Tunneler Workshop About?

Now, this is not a slide deck about theory. The Silent Tunneler is a 90-minute workshop built on a real-world incident response investigation, and we will walk through it the way it actually happened: from the initial discovery, through the technical analysis, all the way to the response process.

The title gives you a hint about the adversary. If I’m as an attacker, I do not want my traffic to look like an attack. I want it to blend in, to tunnel quietly through channels the defenders already trust. That is exactly what makes these cases hard: the alert that starts the investigation is small, almost boring, and the real story only appears when you start pulling the thread. So in this workshop we will pull that thread together, step by step, and you will see how a small anomaly turns into a full incident response engagement.

If you have seen my analysis work before, like the WannaCry dropper walkthrough here in the knowledge library, you know the style: hands-on, practical, and grounded in what really happens in the field.

When and Where Can You Catch the Workshop?

Here are the details, so you can plan your Friday:

The workshop takes place on Friday, August 7, at 10:10 AM at Malware Village, DEF CON 34, Las Vegas. It is a 90-minute session, so we will have real time to go deep. You can find the session on the official Malware Village agenda here.

I am presenting this one with my other venture, Cipher Security Labs, where I am also a co-founder. Basically, the same mission drives both: teaching defenders to think like attackers, whether that is in a TrainSec course or on a DEF CON stage.

Why Should You Attend?

If you are a TrainSec student, a reader of this knowledge library, someone working through SOC Analyst Professional: Foundations, or just someone thinking about getting into malware analysis and incident response, this workshop is for you.

What This Means Practically

  • Add the workshop to your DEF CON 34 schedule: Friday, August 7, 10:10 AM, Malware Village, 90 minutes.
  • Check the official session page for the latest agenda details before you go.
  • If you cannot make it to Las Vegas, follow the TrainSec knowledge library; the practical lessons from cases like this one end up here and in my courses.

Keep Learning: Go Deeper Than a Workshop

A 90-minute workshop can show you how an investigation feels. Building the skill set behind it takes structured work. If you want to learn how to dissect the kind of malware that shows up in these incidents, start with Malware Analyst Professional Level 1, where I teach static and dynamic analysis from the ground up followed by practical reverse engineering skills. And if the defensive side of the story is your path, the SOC track builds the triage and detection mindset this whole case rests on.

So that is the invitation: Friday, August 7, 10:10 AM, Malware Village. Come and enjoy.


blue depth
Uriel kosayev

About the author

Uriel Kosayev
Uriel Kosayev is a cybersecurity researcher, reverse engineer, and author of MAoS and Antivirus Bypass Techniques. He’s led real-world red team ops, malware investigations, and incident response cases. As the founder of TrainSec Academy, he teaches professionals to think like attackers and defend with precision. His training is practical, focused, and based on real threats, not theory.