BSides Berlin Security Training
State-recognized full-day workshop - 12 November 2026
Paid Education Leave (Bildungszeit)
This training is an officially recognized educational event under the Berlin Education Leave Act (Anerkannte Bildungsveranstaltung nach dem Berliner Bildungszeitgesetz, Bescheid der Senatsverwaltung II A 75 - 135944). Employees in Berlin are entitled to paid education leave (Bildungszeit) to attend this training.
Download the recognition notice and hand it to your employer together with your leave request. Most employers require the request several weeks in advance - apply early.
We are happy to provide the official recognition notice (Bescheid) by email upon request. Write to contact@bsides.berlin and we will send it over.
Similar laws (Bildungsurlaub) exist in most other German states. Attendees from outside Berlin should check their state's recognition rules with their employer.
About the Training
A Phishing Trip with the Bears
This beginner-friendly, hands-on malware analysis workshop is split into three parts: First, we trace the full attack chain of a real-world Fancy Bear (APT28) intrusion. Next, we dig into the backend infrastructure behind a Roundcube credential phishing operation. Finally, you'll put both skill sets to work on a multi-stage PDF sample attributed to Cozy Bear (APT29).
This workshop is designed and paced for beginners. No prior malware analysis experience is required. Basic familiarity with the Windows operating system is a plus.
You will learn
- How to analyze phishing emails and extract indicators from mail headers
- How to identify and dissect malicious Office documents
- How to spot persistence techniques in Windows
- How to reverse simple string obfuscation
- How threat actors repurpose open-source tools and abuse cloud services to blend into normal traffic
- How to identify open directories in attacker infrastructure and analyze credential phishing websites safely
- How to investigate Cross-Site-Scripting attack vectors
- How to analyze malicious PDF files and local malicious JavaScript
What to bring
A laptop with any operating system, a modern web browser and an archive tool that extracts encrypted ZIP files (e.g. 7-zip). No code is executed on your machine and no downloads are needed before the workshop; all exercise material is provided via the course platform. If you prefer working in a VM, the free REMnux distribution is a good option.
Program
Full-Day Agenda
Schedule as submitted to and approved by the Senatsverwaltung fur Arbeit und Soziales. Do not alter.
| Time | Unit | Content | Format |
|---|---|---|---|
| 08:30–09:00 | – | Registration and attendance check-in | – |
| 09:00–09:45 | 1 | Introduction: workshop flow and quiz platform; background on APT28 ("Fancy Bear") and the geopolitical context of phishing campaigns | Talk + short practical quiz |
| 09:45–10:30 | 2 | Payload delivery and exploitation: analyzing a real phishing email, indicators in mail headers, dissecting a malicious MS Office attachment with open-source tools | Short lecture + hands-on exercise, quiz review |
| 10:30–10:45 | – | Break | – |
| 10:45–11:30 | 3 | Installation, command and control, persistence: Windows persistence techniques, steganography, simple cryptography and deobfuscation, .NET malware analysis, abuse of cloud services | Short lecture + hands-on exercise, quiz review |
| 11:30–12:15 | 4 | Phishing backend investigation I: open directories in attacker infrastructure, anatomy of the Roundcube campaign, web attack vectors | Talk + short practical quiz |
| 12:15–13:15 | – | Lunch break | – |
| 13:15–14:00 | 5 | Phishing backend investigation II: safely analyzing credential phishing websites, investigating Cross-Site-Scripting vectors | Hands-on exercise validated via the quiz platform |
| 14:00–14:45 | 6 | APT29 PDF attack chain I: analyzing a malicious PDF file and local malicious JavaScript (guided) | Guided hands-on exercise, solo or in pairs |
| 14:45–15:00 | – | Break | – |
| 15:00–15:45 | 7 | APT29 PDF attack chain II: independent analysis of the multi-stage sample with trainer support; recap, transfer to your daily work, final quiz | Hands-on exercise + moderated wrap-up |
| 15:45–16:00 | – | Closing, handout of participation certificates | – |
Trainer
Marius Genheimer
DFIR Specialist & Threat Researcher, SECUINFRA Falcon Team
Marius Genheimer is a DFIR Specialist and Threat Researcher with the SECUINFRA Falcon Team in Berlin. He specializes in malware analysis and defensive security training, and is a training instructor for the five-day defensive OSDA training with the Red&Blue Alliance. In 2026 he has taught hands-on workshops at BSides Ljubljana, BSides Luxembourg, BSides Vilnius and Pass the SALT.
Supported by SECUINFRA
Registration
Training takes place with a minimum of 18 participants. In the event of cancellation, tickets are fully refunded.
Voluntary questions at registration
These questions are voluntary and anonymized. They are required for our report to the Berlin Senate under §11 BiZeitG (Bildungszeitgesetz).
- Are you attending via Berlin Bildungszeit? (yes / no)
- If yes:
- Gender
- Age bracket: under 25 / 25-34 / 35-44 / 45-54 / 55 or older
- Highest school qualification
- Vocational qualification: with degree / without degree / apprentice
- Nationality: German / other
- Employer type: private (up to 20 employees / 21-100 / over 100) or public sector
Participation certificate and a copy of the Bildungszeit recognition notice are provided free of charge to all attendees.
