Program Sikkerhetsfestivalen 2026

Offensive Security

I Like Big Shares and I Cannot Lie

Onsdag 1 · Frimurerlosjen, rom 2

EnglishDetailed 40 min

Egil Aspevik

Egil Aspevik

Netsecurity, RedTeam

Egil has been doing IT since Monkey Island 1, Turbo Pascal and DOS. He is a member of the Netsecurity RedTeam and has worked in IT his whole life.

He takes these speaker biography descriptions as an opportunity to create a false image of himself, and he is usually recognized as the smartest and most handsome man in the room. He is also the strongest person on earth.

In this cloud-centric zero-access AI-driven passwordless SaaS/PaaS-lifted modern world, one stubborn old bastard from the 80s refuses to die on the Azure-deployed IaC servers: SMB shares. The backup of the Sharepoint lift and shift (aka the new common drive), the VHD dumps from 2019, the export files from the business app SaaS migration, the sql backup files, the Keepass exports... they live on these SMB shares with forgotten permission sets. As a red-team operator / pentester, digging through the piles of data can often yield treasure, but it slow and tedious, prone with false positives and manual typing. And painful to do over SOCKS proxies... until now!

This talk presents "smbhoarder" - a tool that perform threaded scans of SMB shares via Impacket, generates searchable indexes, and plugs directly into fzf for instant filtering by filename, extension, path patterns, and size/date. Key features:

* Threaded SMB enumeration towards hosts with tcp/445 open.

* Fuzzy search via fzf

* Download of one or several files from different SMB shares in one keycombo.

* Differential enumeration: quickly seeing what Account B can access that Account A cannot, useful when you’re latmoving/privescing.

* SOCKS proxy aware via proxychains-support.

The result is a practical "SMB search engine" you can run during an engagement. And did we mention it works flawlessly over SOCKS proxies?

  1. The Invisible Privileged User: Attack Path Mapping Across Your Software Delivery Chain 1 · Frimurerlosjen, rom 1
  2. Cryptography and export controls 10 · HeartBox ,Teatersalen
  3. Når OT møter Cloud-Native – muligheter og risikoer i skjæringspunktet 10 · HeartBox, Byscenen
  4. AI-agenter og personvern: Trenger jeg en DPIA? 11- Breiseth, Storlon
  5. How to prioritise within OT in light of a chaotic time 2 · Home hotel Hammer, moen nede
  6. Når fysisk sikkerhet blir Shadow IT – hvem eier egentlig kameraene, adgangskontrollen og IoT-enheten 2 · Home hotel Hammer, moen oppe
  7. Kartlegging av høyrisikoroller og menneskelige sårbarheter 3 · Hvelvet, Gullsalen
  8. Våre Sårbare Nettverk 4 · Kommunestyresalen, Lillehammer rådhus
  9. Deepfake Detection in the Real World 5 · Kulturhuset Banken, Expedisjon
  10. Offense is the best defense: The Evolution of Ukrainian Cyber Capabilities and Lessons for Europe 5 · Kulturhuset Banken, Festsalen
  11. Bli en del av Norges beredskap 5 · Kulturhuset Banken, Holbøsalen
  12. Design Intent vs Digital Residue: Inside a Forensic Research Pipeline 5 · Kulturhuset Banken, Kafeen
  13. Governance Theatre vs Reality: Fixing the Operating Model Behind Control Failures 6 · Lillehammer kino, sal 2
  14. Sikkerhetskultur: erfaringer fra en innenfra-og-ut-tilnærming! 6 · Lillehammer kino, sal 4
  15. When threats become multifaceted: How the police prioritize in a complex environment 9 · Victoria Scandic, sal 1+2
  16. Hvem eier krisen? – Når sikkerhetshendelsen treffer på tvers av 200 autonome team 9 · Victoria Scandic, sal 3
  17. Fra analyse til gjennomføring- effektiv fysisk sikring i politiet 2 · Home hotel Hammer, moen oppe