Hacking for hoodies: MISP edition — Jeroen Pinoy

Join us at hack.lu 2025 — Info & Registration

Duration: 30 min

Type: Talk

Speakers: Jeroen Pinoy

Abstract

Cyber threat information sharing continues to be important. The tools we use for this should be regularly scrutinized to ensure their security. The most common way of testing seems to be pentesting using automated tools. In this research I decided to use a different approach, focusing on manual code reviews and exploratory testing of MISP and associated tools, with help from LLM in some cases. This research led to a significant list of vulnerability findings.

Description

In this talk, I go over my approach to code review, and some of the security findings in MISP and associated tools.

View on pretalx

Video available