Security Events

Conferences, workshops, and CFP deadlines on the radar, alongside a record of talks already given by Debasis Mohanty.

Tool ReleaseAug 2023
Black Hat USA 2023 Arsenal

Daksh SCRA (Source Code Review Assist Tool)

Daksh SCRA (Source Code Review Assist Tool) is built to help reviewers work faster than grep-based pattern matching alone, structuring and semi-automating the early triage of large, unfamiliar codebases so a reviewer's time goes toward confirming and exploiting genuine findings rather than re-deriving them by hand. The tool first debuted a year earlier at the Black Hat USA 2022 "Source Code Review - Raise Your Bar Beyond Grep" training, where it was shared privately with attendees who completed the course. This appearance at Black Hat USA 2023 Arsenal was its first public release, making it available to the wider security community for the first time.

TrainingAug 2022
Black Hat USA 2022 Training

Source Code Review (Raise your bar beyond Grep)

A hands-on Black Hat USA training for security professionals and code reviewers looking to move beyond simple grep-based pattern matching. The course covered manual and semi-automated source code review methodology across multiple languages and frameworks, along with the vulnerability classes that keyword searches routinely miss. It also worked through practical triage workflows for auditing large, unfamiliar codebases under real engagement time constraints. Attendees got an early, private look at Daksh SCRA, the source code review assist tool built to support the techniques taught in the course.

Conference TalkNov 2021
BSides Delaware 2021

Software Security Engineering (Learnings from the past to fix the future) - Extended Version

This talk covered some crucial aspects of software security engineering and strategy that most organisations have overlooked or ignored. Primarily the presentation provides some insights on why we still continue to see two decades old bugs and recommendations to consider going ahead. This is a slightly extended version of the OWASP 20th Anniversary talk.

Conference TalkSep 2021
OWASP 20th Anniversary Event

Software Security Engineering (Learnings from the past to fix the future)

Presented at OWASP 20th Anniversary virtual event, this talk covered some crucial aspects of software security engineering and strategy that most organisations have overlooked or ignored. Primarily the presentation provides some insights on why we still continue to see two decades old bugs and recommendations to consider going ahead.

Kernel SecurityApr 2018
Roachcon 2017 (Insomnia Security)

The Path To Ring-0 (Windows Edition)

Presentation on Windows Kernel Exploitation providing insights into common Windows kernel exploitation techniques and the current state of kernel mitigation. Presented at Insomnia Security's internal security conference known as Roachcon (2017).