Anerkannte Bildungsveranstaltung - Berlin Bildungszeitgesetz

BSides Berlin Security Training

State-recognized full-day workshop - 12 November 2026

Training
"A Phishing Trip with the Bears" - Hands-on APT Malware Analysis
Date & Time
Thursday, 12 November 2026 - 09:00-16:00 (doors open 08:30)
Location
CIC Berlin, Lohmuhlenstrasse 65, 12435 Berlin
Trainer
Marius Genheimer - DFIR Specialist & Threat Researcher, SECUINFRA Falcon Team
Capacity
Maximum 30 seats - named tickets, fixed group for the full day
Price
179 EUR early bird / 239 EUR regular
What to bring
A laptop with a browser - no malware analysis experience required
Included
All training materials, participation certificate (free of charge)

Paid Education Leave (Bildungszeit)

This training is an officially recognized educational event under the Berlin Education Leave Act (Anerkannte Bildungsveranstaltung nach dem Berliner Bildungszeitgesetz, Bescheid der Senatsverwaltung II A 75 - 135944). Employees in Berlin are entitled to paid education leave (Bildungszeit) to attend this training.

Download the recognition notice and hand it to your employer together with your leave request. Most employers require the request several weeks in advance - apply early.

We are happy to provide the official recognition notice (Bescheid) by email upon request. Write to contact@bsides.berlin and we will send it over.

Similar laws (Bildungsurlaub) exist in most other German states. Attendees from outside Berlin should check their state's recognition rules with their employer.

A Phishing Trip with the Bears

This beginner-friendly, hands-on malware analysis workshop is split into three parts: First, we trace the full attack chain of a real-world Fancy Bear (APT28) intrusion. Next, we dig into the backend infrastructure behind a Roundcube credential phishing operation. Finally, you'll put both skill sets to work on a multi-stage PDF sample attributed to Cozy Bear (APT29).

This workshop is designed and paced for beginners. No prior malware analysis experience is required. Basic familiarity with the Windows operating system is a plus.

You will learn

  • How to analyze phishing emails and extract indicators from mail headers
  • How to identify and dissect malicious Office documents
  • How to spot persistence techniques in Windows
  • How to reverse simple string obfuscation
  • How threat actors repurpose open-source tools and abuse cloud services to blend into normal traffic
  • How to identify open directories in attacker infrastructure and analyze credential phishing websites safely
  • How to investigate Cross-Site-Scripting attack vectors
  • How to analyze malicious PDF files and local malicious JavaScript

What to bring

A laptop with any operating system, a modern web browser and an archive tool that extracts encrypted ZIP files (e.g. 7-zip). No code is executed on your machine and no downloads are needed before the workshop; all exercise material is provided via the course platform. If you prefer working in a VM, the free REMnux distribution is a good option.

Full-Day Agenda

Schedule as submitted to and approved by the Senatsverwaltung fur Arbeit und Soziales. Do not alter.

Time Unit Content Format
08:30–09:00Registration and attendance check-in
09:00–09:451Introduction: workshop flow and quiz platform; background on APT28 ("Fancy Bear") and the geopolitical context of phishing campaignsTalk + short practical quiz
09:45–10:302Payload delivery and exploitation: analyzing a real phishing email, indicators in mail headers, dissecting a malicious MS Office attachment with open-source toolsShort lecture + hands-on exercise, quiz review
10:30–10:45Break
10:45–11:303Installation, command and control, persistence: Windows persistence techniques, steganography, simple cryptography and deobfuscation, .NET malware analysis, abuse of cloud servicesShort lecture + hands-on exercise, quiz review
11:30–12:154Phishing backend investigation I: open directories in attacker infrastructure, anatomy of the Roundcube campaign, web attack vectorsTalk + short practical quiz
12:15–13:15Lunch break
13:15–14:005Phishing backend investigation II: safely analyzing credential phishing websites, investigating Cross-Site-Scripting vectorsHands-on exercise validated via the quiz platform
14:00–14:456APT29 PDF attack chain I: analyzing a malicious PDF file and local malicious JavaScript (guided)Guided hands-on exercise, solo or in pairs
14:45–15:00Break
15:00–15:457APT29 PDF attack chain II: independent analysis of the multi-stage sample with trainer support; recap, transfer to your daily work, final quizHands-on exercise + moderated wrap-up
15:45–16:00Closing, handout of participation certificates

Marius Genheimer

DFIR Specialist & Threat Researcher, SECUINFRA Falcon Team

Marius Genheimer is a DFIR Specialist and Threat Researcher with the SECUINFRA Falcon Team in Berlin. He specializes in malware analysis and defensive security training, and is a training instructor for the five-day defensive OSDA training with the Red&Blue Alliance. In 2026 he has taught hands-on workshops at BSides Ljubljana, BSides Luxembourg, BSides Vilnius and Pass the SALT.

Supported by SECUINFRA

Early Bird
179 EUR
Regular: 239 EUR
Named ticket - max 30 seats
Get your ticket

Training takes place with a minimum of 18 participants. In the event of cancellation, tickets are fully refunded.

Voluntary questions at registration

These questions are voluntary and anonymized. They are required for our report to the Berlin Senate under §11 BiZeitG (Bildungszeitgesetz).

  • Are you attending via Berlin Bildungszeit? (yes / no)
  • If yes:
  • Gender
  • Age bracket: under 25 / 25-34 / 35-44 / 45-54 / 55 or older
  • Highest school qualification
  • Vocational qualification: with degree / without degree / apprentice
  • Nationality: German / other
  • Employer type: private (up to 20 employees / 21-100 / over 100) or public sector

Participation certificate and a copy of the Bildungszeit recognition notice are provided free of charge to all attendees.

This is a standalone full-day training on 12 November 2026. The BSides Berlin conference talks take place on 13 November 2026 and require a separate conference ticket. Get conference tickets here.