Adversary Village
RSA Conference 2025

YBCA, Gallery 2, Opposite Moscone Center, San Francisco
28 April - 1 May, 2025.



Adversary Village at RSAC 2025!

Join us for Adversary Village Sandbox at RSAC 2025!
Adversary Village is a community initiative focused on adversary simulation, offensive cyber security tradecraft and purple teaming. The sandbox will feature talks, live demos, gamified table-top exercises, adversary/ransomware simulator, guided breach simulation, panels, and hands-on activities.


Adversary Village Sandbox timings:


  • Monday, April 28, 9:30 AM - 3:30 PM
  • Tuesday, April 29, 9:30 AM - 4:30 PM
  • Wednesday, April 30, 9:30 AM - 4:30 PM
  • Thursday May 1, 9:30 AM - 2:00 PM

Interactive session: Rise of augmented adversaries, hacking humans at next level

Adversary Village Sandbox | Gallery 2, Yerba Buena Center for the Arts (YBCA) | April 28th, 10:30 AM PT

Jon Baker

Len Noe

Technical Evangelist and Cyborg Hacker

Join us for an interactive deep dive into the evolving tactics of modern threat actors who are no longer just targeting systems - but the human psyche itself. We'll explore how adversaries are augmenting their capabilities with AI, automation, and behavioral manipulation to exploit human trust, bypass traditional defenses, and execute highly sophisticated social engineering campaigns. Get ready to unpack real-world scenarios, engage in live discussions, and discover how to build resilience against this new wave of human-centric cyber threats.

Panel Discussion: Building Cyber Defenses to Withstand Sophisticated Cyber Adversaries

SBV-W02 | RSAC Sandbox stage | Wednesday, Apr 30 | 9:40 AM - 10:30 AM PDT

Cyber attacks ranging from sophisticated ransomware to state-sponsored breaches have targeted critical infrastructure and major organizations, driving escalation in security efforts. Despite advanced tools, no organization is immune to adversaries. This panel will review the key breaches of 2024, discuss ongoing issues, and strategies for improving incident response, containment, and defense.

Jon Baker

Jonathan Baker

Director, Center for Threat-Informed Defense, MITRE

Director, Center for Threat-Informed Defense, MITRE Engenuity

Jorge

Vivek Ramachandran

Founder and CEO of SquareX

Daniel

Ken Kato

Chief Security Officer at Kindo, Former White House Fellow

#

Abhijith

Founder and Lead at Adversary Village


Hands-on activity
Choose-your-own-Adversary-Adventure Tabletop Game

Adversary Village Sandbox Area | 28 April-01 May, 2025 | 09:30 to 03:30 PM PT

Adversary adventure is a story-scenario based, interactive, cyber war-gaming, choose-your-own adventure model interactive game. This is a gamified version of table-top exercises which is presented to the participants as they can choose to play as an attacker, post exploitation OR a Defender who is defending against an attacker group-threat actor OR even play as a CISO who is dealing with an adversarial situation such as a ransomware incident.

Hands-on activity
AI-Assisted cyber incident response playbook generation

Adversary Village Sandbox Area | 28 April-01 May, 2025 | 09:30 to 17:00

In this hands-on activity, participants will use an open-source generative AI model to build a dynamic, effective incident response playbook to deal with real-world cyber threats. Using the GPT systems speed and adaptability, the participants get to collect and analyze threat intelligence, map potential attack scenarios, and outline step-by-step response actions for each phase from detection and containment to eradication and recovery.
Through interactive prompts and guided AI model collaboration, participants will craft a flexible, well-structured IR playbook designed to counter evolving adversary tactics and minimize organizational impact during an incident.

AI-Assisted Cyber Incidence Response Playbook Generation
April 29th, 1:00 PM PT - 3:00 PM PT | Gallery 2, Yerba Buena Center for the Arts (YBCA)
Speaker 3
Ken Kato
Cheif Security Officer at Kindo.AI, Former White House Fellow
Speaker 3
Bailey Williams
Cyber security Specialist and Intern at Kindo.AI

Hands-on activity
Guided Breach and Attack Simulation exercises

Adversary Village Sandbox Area | 28 April-01 May, 2025 | 09:30 to 03:30 PM PT

This area will feature guided breach simulation exercises for participants to engage with. There will be two activities, "Breach-the-Hospital" and "Breach-the-Office," based on two LEGO sets. A simulated cyber range will be available for each scenario, providing an exact replica of an enterprise production environment. We will provide a detailed walkthrough of the attack scenarios, including Tools-Techniques-and-Procedures (TTPs) commands and how-to guides, demonstrating how to attack and breach the hospital's infrastructure or the office environment.
The participants who complete the exercises and come to the top place will be rewarded with exciting goodies.

Hands-on activity
Table-top exercises and Roundtable discussions

Adversary Village Sandbox Area | 28 April-01 May, 2025 | 09:30 to 17:00

Short interactive table-tops and roundtable discussions focused on offensive cyber security, adversary attack simulation, and incident response. These sessions bring together industry experts to explore real-world attack scenarios, tactics, and defense strategies. Participants would collaborate, share insights, and strengthen their approach to handling cyber threats and incidents effectively.

Roundtable discussion: Recon operations for the modern adversaries
April 30th, 11:00 AM PT | Gallery 2, Yerba Buena Center for the Arts (YBCA)
Speaker 3
Shubham Mittal
Co-founder of RedHunt Labs and Co-founder of Recon Village at DEF CON

Hands-on activity
Adversary Simulator and Purple Teaming hands-on booth

Adversary Village Sandbox Area | 28 April-01 May, 2025 | 09:30 to 03:30

Adversary Simulator booth has hands-on adversary emulation plans specific to a wide variety of threat-actors, ransomware; these are meant to provide the participant/visitor with a better understanding of the Adversary tactics. This is a volunteer assisted activity where anyone, both management and technical folks can come in and experience different categories of simulation, emulation and purple scenarios.

Adversary Simulator booth will be having a lab environment focused on recreating enterprise infrastructure, aimed at simulation and emulating various adversaries. Visitors will be able to view, simulate and control various TTPs used by adversaries. The simulator is meant to be a learning experience, irrespective of whether one is hands-on with highly sophisticated attack tactics or from the management.

Hands-on interactive workshop
Collecting threat intel and crafting attack emulation plans with open source, uncensored AI

Adversary Village Sandbox | Gallery 2, Yerba Buena Center for the Arts (YBCA) | April 28th, 01:00 PM - 03:00 PM PT | April 30th, 01:00 PM - 03:00 PM PT

Jon Baker

Andrew Manoske

VP of Product at Kindo

In this hands-on workshop, leverage the power of White Rabbit Neo open-source generative AI model to power your cyber threat intelligence collection and attack emulation planning. Learn how to gather and analyze real-world threat-actors, adversary tactics, techniques, and procedures (TTPs), and transform them into realistic, actionable attack scenarios. Through practical exercises, the participants get to see how uncensored AI can accelerate adversary emulation, enhance operations, and push the boundaries of offensive cyber security. Get ready to learn with uncensored AI models and craft emulation plans like never before.

Adversary Village at
RSA Conference 2025

Sponsors





Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!