Closing Ceremonies
Huxley Barbee
BSides NYC 2024 · Day 1 · Closing
Overview
The "Closing Ceremonies" at BSides NYC 2024, led primarily by Huxley Barbee, served as more than just a formal conclusion to the event; it was a vibrant affirmation of the conference's successful reboot and a celebratory reflection on the diverse technical and community contributions that defined it. This session, while not a traditional technical talk, provided a meta-perspective on the cybersecurity landscape by highlighting the cutting-edge solutions presented by sponsors, the practical skills honed in competitive events, and the overarching themes resonating within the security community. It underscored the critical role of community-driven conferences in fostering knowledge exchange, skill development, and professional networking, particularly in an environment committed to accessibility through a $0 ticket policy.

Key moments
- 0:00 Welcome and Pixie AI product security engineer
- 2:00 Pros Vs. Joes CTF winners revealed
- 3:20 Open CTF winners announced, Flipper Zero prize
- 4:00 BSides NYC general raffle starts
- 7:00 Drop Zone sponsor: AI security analyst and raffle
- 10:40 Organizer Huxley Barbee's closing remarks begin
- 11:20 BSides NYC conference achievements and improvements highlighted
- 12:30 First-ever PCB badges and $0 tickets for attendees
Closing Ceremonies
Speakers: Huxley Barbee
Conference: BSides NYC
YouTube: https://www.youtube.com/watch?v=nbJbzPPot1w
Overview
The "Closing Ceremonies" at BSides NYC 2024, led primarily by Huxley Barbee, served as more than just a formal conclusion to the event; it was a vibrant affirmation of the conference's successful reboot and a celebratory reflection on the diverse technical and community contributions that defined it. This session, while not a traditional technical talk, provided a meta-perspective on the cybersecurity landscape by highlighting the cutting-edge solutions presented by sponsors, the practical skills honed in competitive events, and the overarching themes resonating within the security community. It underscored the critical role of community-driven conferences in fostering knowledge exchange, skill development, and professional networking, particularly in an environment committed to accessibility through a $0 ticket policy.
Huxley Barbee, as the primary organizer, articulated the significant achievements of BSides NYC 2024, emphasizing its growth, the high caliber of its technical programming, and its expanded offerings. The ceremony showcased the collective effort of volunteers, sponsors, and attendees in creating a impactful event, implicitly detailing the current priorities and emerging trends in cybersecurity through the lens of the participating companies and challenges. This article will deconstruct the implicit technical narratives embedded within the closing remarks, drawing connections between the mentioned sponsors, CTFs, and the broader implications for the security industry, thereby providing a comprehensive overview of the conference's technical footprint.
Background
▶ Watch: Welcome and Pixie AI product security engineer (0:00)
BSides conferences emerged from the desire for more community-driven, accessible, and inclusive security events, often serving as an "unconference" alternative or complement to larger, more commercial security conferences. The philosophy behind BSides emphasizes open discourse, hands-on learning, and a platform for emerging talent and niche topics that might not find a home elsewhere. These events are typically organized by volunteers, operate on tight budgets, and prioritize knowledge sharing over profit, making them invaluable hubs for cybersecurity professionals and enthusiasts alike.
BSides NYC, in particular, has a rich but sometimes challenging history. The closing ceremonies explicitly referenced a period where the conference was perceived to have "died" or might not "exist again." However, the 2023 event marked a significant "reboot," and 2024 built upon that momentum, achieving unprecedented success. This background of revival and growth is crucial, as it highlights the resilience of the local security community and the dedication of organizers like Huxley Barbee to provide a vital platform for education and collaboration. The commitment to a $0 ticket price, despite the inherent logistical and financial challenges, further solidifies its role as a beacon of accessibility in the often-expensive world of professional development. This commitment ensures that financial barriers do not impede participation, thereby diversifying the voices and perspectives contributing to the cybersecurity dialogue. The conference's expansion into areas like an "entrepreneur track" and enhanced CTFs reflects a maturing ecosystem that recognizes the multifaceted nature of modern cybersecurity, encompassing not just technical defense but also innovation and practical application.
Key Findings
▶ Watch: Open CTF winners announced, Flipper Zero prize (3:20)
While "Closing Ceremonies" does not present traditional research findings, it delivers crucial insights into the health, growth, and strategic direction of BSides NYC as a premier cybersecurity event. The "findings" here pertain to the conference's operational success and the implicit validation of its content and community model.
Firstly, the most significant finding was the unprecedented growth and quality of BSides NYC 2024. Huxley Barbee proudly reported that the conference "surpassed every previous B-side that we have ever had." This success was quantified by several key metrics:
- Technical Track Excellence: The programming for the technical tracks was lauded as "beyond what we did in years past." This was supported by a highly selective 14% acceptance rate for speakers, implying that for every speaker who presented, six others were not accepted. This rigorous selection process directly translates to a high standard of technical content, ensuring attendees were exposed to cutting-edge research and practical insights.
- Attendee Growth: A major goal was to increase attendee count by approximately 25%, aiming to cross the 1,000 attendees mark. This goal was successfully achieved, indicating a strong and growing interest in the conference's offerings and its community.
- Expanded Offerings: The successful reintroduction of the entrepreneur track, which had been absent since 2018, represented a significant enhancement, catering to the business and innovation aspects of cybersecurity. The expansion of CTFs (Capture The Flag competitions) also provided more diverse hands-on learning opportunities.
- Innovation in Attendee Experience: For the first time in BSides NYC history, attendees received PCB badges. This seemingly small detail is significant within the hacker community, often signifying a commitment to technical craftsmanship and a tangible piece of collectible hardware that can itself be a platform for learning or hacking.
- Accessibility and Value: The continued commitment to a $0 ticket for all attendees was a cornerstone finding, reinforcing the community-first ethos. The estimated value of each ticket, including swag and access to talks, was calculated at $106, demonstrating the substantial return on investment for participants, made possible by generous sponsors and collaborators like John Jay College.
These findings collectively illustrate a thriving, high-quality, and accessible security conference that is not only recovering from past challenges but is actively innovating and expanding its reach, thereby strengthening the broader cybersecurity community.
Technical Deep Dive
▶ Watch: Drop Zone sponsor: AI security analyst and raffle (7:00)
While the closing ceremony itself was not a technical presentation, it served as a powerful meta-analysis of the technical landscape covered at BSides NYC 2024 through the lens of its sponsors, CTF challenges, and the implied scope of its 14% acceptance rate for talks. The mentions of various companies and competitions provide a direct insight into the prevailing concerns and advanced solutions within the cybersecurity industry.
1. AI in Security Automation and Triage (Pixie, Drop Zone):
The emergence of Artificial Intelligence (AI) as a transformative force in cybersecurity was a prominent theme. Pixie, for instance, is "building the world's, maybe first, AI product security engineer." Their focus is on automating the triage of static analysis results using an agentic AI, and crucially, "fixing the true positives by committing pull requests right to your GitHub." This highlights a significant shift towards DevSecOps automation, where AI moves beyond mere detection to proactive remediation, directly integrating into the software development lifecycle (SDLC). The promise is to "take all that pain right off your plate," addressing the perennial challenge of alert fatigue and developer burden in security.
Similarly, Drop Zone presented as an "AI soft analyst that essentially autonomously investigates your security alerts, saving your human analyst time and reducing risk." This points to the application of AI in Security Operations Centers (SOCs), automating tasks typically performed by human analysts, such as correlating events, enriching data, and initiating response actions. The goal is to improve Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) by offloading repetitive analysis to AI, allowing human experts to focus on complex threats.
2. Offensive and Defensive Cyber Warfare (Pros Vs. Joes CTF, Open CTF):
The Pros Vs. Joes CTF, run by Dichotomy, provided a live-action, team-based offensive/defensive exercise. This scenario-based competition involved "red team has broken in a long time ago and they have amazing dwell times, deep persistence, strong C2," challenging "Joes" (players) to "kick them out and claim those systems back, keep their services up and running." This encapsulates critical aspects of incident response, threat hunting, digital forensics, network defense, and endpoint detection and response (EDR). Participants gained hands-on experience in identifying and eradicating advanced persistent threats (APTs), maintaining service uptime, and restoring system integrity. The mention of "deep persistence" and "strong C2" (Command and Control) highlights sophisticated attacker techniques that defenders must understand and counter.
The Open CTF, while not detailing its challenges, awarded prizes like a Raspberry Pi 5, Hack 5 Bash Bunny, and a Flipper Zero. These tools are synonymous with hardware hacking, physical penetration testing, social engineering, and IoT security. The inclusion of such prizes strongly suggests that the CTF challenges likely involved elements of these domains, encouraging participants to explore low-level system interactions, firmware analysis, and creative attack vectors that extend beyond traditional software vulnerabilities.
3. Comprehensive Application and Supply Chain Security (Mirror, Virtue Security):
Mirror's solution directly addresses critical challenges in Application Security (AppSec) and software supply chain security. They position themselves as an AppSec solution that "protects you against the most destructive CVE-less supply chain attacks," "determines the reachability of known vulnerabilities," and "provides a contextualized fixed plan." This is a profound statement, as CVE-less attacks are a growing concern, focusing on logic flaws, misconfigurations, or novel attack paths that don't have a designated CVE identifier. The concept of vulnerability reachability is also critical; not all vulnerabilities are equally exploitable or impactful depending on the application's specific context and configuration. Mirror's approach emphasizes risk prioritization based on actual exploitability and providing actionable, contextualized remediation guidance, moving beyond generic vulnerability scanning. Virtue Security, as an "application testing company," reinforces the importance of continuous and thorough AppSec practices.
4. Advanced Security Operations and Telemetry (Hunters):
Hunters presented a "SaaS SOC platform that reduces... MTDD, MTDI, MTDR, automating the alert triage and correlating all security telemetry to bubble up events that are interesting for remediation." This describes a modern Security Information and Event Management (SIEM) or Security Orchestration, Automation, and Response (SOAR) platform, possibly incorporating aspects of Extended Detection and Response (XDR). The focus on reducing Mean Time to Detect (MTTD), Mean Time to Investigate (MTDI), and Mean Time to Respond (MTDR) underscores the industry's drive for efficiency and speed in threat response. Correlating "all security telemetry" is crucial for building a complete picture of an attack, moving beyond siloed alerts to provide integrated contextualized threat intelligence.
5. Cloud-Native and Kubernetes Security (Taguera):
Taguera specialized in "end-to-end container Kubernetes security from deploy time, run time, compliance, cluster mesh, scanning, you name it." This addresses the complex and rapidly evolving domain of cloud-native security. As organizations increasingly adopt containers and Kubernetes for application deployment, securing this dynamic infrastructure becomes paramount. "Deploy time" security involves image scanning, vulnerability assessment, and policy enforcement in CI/CD pipelines. "Run time" security focuses on detecting anomalous behavior, unauthorized access, and policy violations within the running cluster. "Compliance" ensures adherence to regulatory standards, while "cluster mesh" refers to securing inter-service communication. This broad scope demonstrates the comprehensive security challenges inherent in modern distributed cloud environments.
In summary, the technical landscape implicitly detailed at BSides NYC 2024, as reflected through its sponsors and CTFs, spans the entire modern attack surface: from AI-driven DevSecOps and AppSec automation to sophisticated offensive/defensive operations, supply chain integrity, advanced SOC capabilities, and the intricacies of cloud-native infrastructure security. The conference evidently provided a deep dive into these critical areas, offering both theoretical knowledge and practical skills development.
Demo / Proof of Concept
▶ Watch: Organizer Huxley Barbee's closing remarks begin (10:40)
While the "Closing Ceremonies" itself did not feature a live technical demonstration, the entire conference, as reflected in the remarks, was replete with opportunities for attendees to engage with demos and proofs of concept. The very nature of a security conference, especially one that emphasizes hands-on learning, relies heavily on these practical showcases.
The CTFs (Capture The Flag), particularly the "Pros Vs. Joes" event, served as a large-scale, live-action proof of concept for offensive and defensive cybersecurity techniques. Participants actively demonstrated their ability to achieve "deep persistence" and "strong C2" (offensive) or to "kick them out and claim those systems back" (defensive). This simulated environment allowed for the real-world application of theoretical knowledge, proving the efficacy (or inefficacy) of various tools and strategies in a controlled setting. The prizes for the Open CTF (Raspberry Pi 5, Hack 5 Bash Bunny, Flipper Zero) further imply challenges that involved physical hardware interaction and the demonstration of vulnerabilities in embedded systems or network peripherals.
Furthermore, the numerous sponsors mentioned—Pixie, Hunters, Mirror, Drop Zone, Virtue Security, and Taguera—undoubtedly operated booths throughout the conference where their advanced security solutions were demonstrated. Companies like Pixie, with their "agentic AI" for static analysis triage and pull request generation, would have showcased the automated workflow. Hunters would have demonstrated their SaaS SOC platform's ability to correlate "security telemetry" and automate "alert triage." Mirror would have provided live examples of how their AppSec solution identifies "CVE-less supply chain attacks" and determines "vulnerability reachability." Drop Zone would have shown their "AI soft analyst" in action, autonomously investigating alerts. Taguera would have demonstrated their "end-to-end container Kubernetes security" solutions, covering scanning, runtime protection, and compliance in a live or simulated cloud-native environment. These sponsor demonstrations are integral to a technical conference, allowing attendees to see cutting-edge technologies in action and understand their practical applications in solving real-world security problems.
Defensive Implications
▶ Watch: First-ever PCB badges and $0 tickets for attendees (12:30)
The diverse technical themes implicitly covered at BSides NYC 2024, as evidenced by the sponsors and CTFs, highlight several critical areas for defenders to focus on in the current threat landscape. The insights gleaned from these areas provide a roadmap for strengthening an organization's security posture.
- Embrace AI-Driven DevSecOps and SOC Automation: The solutions presented by Pixie and Drop Zone underscore the necessity of integrating AI into both development and operations. Defenders should explore AI-powered Static Application Security Testing (SAST) triage and automated remediation tools to shift security left, catch vulnerabilities earlier, and reduce developer overhead. In the SOC, AI-driven platforms like those from Hunters and Drop Zone can significantly reduce Mean Time to Detect (MTTD), Mean Time to Investigate (MTDI), and Mean Time to Respond (MTDR) by automating alert correlation, contextualization, and initial investigation, freeing human analysts for more complex threat hunting and strategic tasks. This requires careful evaluation of AI models for bias and accuracy, but the efficiency gains are undeniable.
- Prioritize Application and Software Supply Chain Security: Mirror's focus on "CVE-less supply chain attacks" and "vulnerability reachability" signals a mature approach to AppSec. Defenders must move beyond simple CVE scanning to implement comprehensive Software Composition Analysis (SCA), Software Bill of Materials (SBOM) generation, and in-depth application security testing (SAST, DAST, IAST) that considers the actual context and exploitability of vulnerabilities within their specific application environment. Understanding the attack surface of third-party components and open-source libraries is paramount. Organizations should also adopt robust processes for vetting and securing their entire software supply chain, from development environments to deployment pipelines.
- Invest in Offensive Security Knowledge and Hands-On Training: The "Pros Vs. Joes CTF" highlights the critical importance of understanding attacker methodologies, including "deep persistence" and "strong C2." Defenders should actively participate in or simulate red team exercises and threat hunting activities to gain firsthand experience with common attacker Tactics, Techniques, and Procedures (TTPs). This proactive approach enhances an organization's ability to detect, contain, and eradicate real-world threats. Providing internal training and opportunities for security teams to engage in CTFs or labs (e.g., using tools like Raspberry Pi, Hack 5 Bash Bunny, Flipper Zero) fosters practical skills in areas like physical security, hardware hacking, and low-level system exploitation.
- Secure Cloud-Native Environments End-to-End: Taguera's comprehensive approach to "container Kubernetes security" emphasizes that securing modern cloud infrastructure requires a holistic strategy. Defenders need to implement security controls across the entire lifecycle of cloud-native applications:
- Deploy Time: Implement image scanning, vulnerability checks, and policy enforcement in CI/CD pipelines to prevent insecure configurations from reaching production.
- Run Time: Deploy Container Runtime Security solutions to monitor container behavior, detect anomalies, and enforce network policies (e.g., network segmentation, micro-segmentation for cluster mesh).
- Compliance: Ensure Kubernetes configurations and container images adhere to industry standards and regulatory requirements.
- Vulnerability Management: Continuously scan containers and Kubernetes clusters for known vulnerabilities and misconfigurations.
This demands specialized expertise in cloud platforms and container orchestration technologies.
- Enhance Security Telemetry and Response Capabilities: The emphasis by Hunters on correlating "all security telemetry" and automating "alert triage" points to the need for robust Security Information and Event Management (SIEM) or Extended Detection and Response (XDR) solutions. Defenders should ensure they have comprehensive logging and monitoring across endpoints, networks, applications, and cloud infrastructure. The goal is to aggregate and normalize this data to enable effective threat detection, investigation, and rapid response. Prioritizing the reduction of MTTD, MTDI, and MTDR should be a key performance indicator for security operations.
By addressing these defensive implications, organizations can build more resilient and proactive cybersecurity programs capable of defending against the evolving threat landscape illuminated by the BSides NYC conference.
Key Takeaways
- BSides NYC's Resurgence and Growth: The conference successfully rebooted and achieved unprecedented growth in 2024, surpassing previous attendance records with over 1,000 attendees and a highly selective 14% speaker acceptance rate, indicating a high-quality technical program.
- Commitment to Accessibility: Maintaining a $0 ticket price, while providing an estimated $106 value per attendee, underscores the conference's dedication to community-driven knowledge sharing and inclusivity within the cybersecurity field.
- AI as a Transformative Security Force: Solutions from Pixie and Drop Zone highlighted the growing role of AI in automating DevSecOps (static analysis triage, PR generation) and SOC operations (autonomous alert investigation, MTTR reduction), signaling a shift towards intelligent security automation.
- Holistic Application and Supply Chain Security: Mirror's focus on "CVE-less supply chain attacks" and "vulnerability reachability" emphasized the need for advanced AppSec strategies that go beyond simple vulnerability scanning to contextualize and prioritize real-world risks.
- Hands-On Offensive and Defensive Skill Development: The Pros Vs. Joes CTF and other challenges, supported by prizes like the Flipper Zero and Hack 5 Bash Bunny, showcased the critical importance of practical skills in red teaming, blue teaming, incident response, and hardware hacking for effective defense.
- End-to-End Cloud-Native Security: Taguera's comprehensive approach to Kubernetes and container security, covering deploy time, runtime, and compliance, underlined the complex and critical requirements for securing modern, cloud-native infrastructure.
About the Speaker(s)
Huxley Barbee served as the pivotal figure and primary organizer for BSides NYC 2024. His remarks during the closing ceremonies underscored his significant dedication and leadership in the local cybersecurity community. Barbee spearheaded the successful "reboot" of BSides NYC in 2023 and continued to drive its expansion and excellence in 2024, achieving record-breaking attendance and a highly competitive speaker selection process. His commitment to creating a high-quality, accessible, and community-focused event was evident in the conference's $0 ticket policy, the introduction of PCB badges, and the expansion of technical tracks and CTF offerings. Barbee's efforts were instrumental in bringing together volunteers, sponsors, and attendees, fostering a vibrant platform for knowledge exchange and professional development within the New York City cybersecurity landscape. His closing remarks reflected not just a successful event, but a deep personal investment in the growth and well-being of the BSides NYC community.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
This isn't a talk — it's a closing ceremony: thank-yous, sponsor shoutouts, CTF prize announcements, and attendance numbers dressed up in AI-generated prose. There is no technical content to evaluate, no research to critique, and no signal here that couldn't be extracted from a conference recap blog post in under two minutes.
Heather Calloway (CISO) — PASS
This is a closing ceremony, not a talk — and no amount of editorial inflation changes that. There is no research, no argument, no defensible claim, and no decision anyone can make from it.