Ants, Bricks and Spiders: Threat Emulation on the VMware Stack

Despite acquisitions, changes in names and pricing models, the VMware private cloud remains a high-value target for threat actors. From ransomware gangs to nation states, breaching vCenter or getting a shell on an ESXi host presents a range of opportunities with new TTPs observed in each campaign. But how can security teams build defences proactively? This talk will provide a guide for conducting threat-led simulations against Broadcom VCF or vSphere environments. We will also introduce a free repository containing a comprehensive collection of 80+ reproducible VMware attack techniques - complete with detection advice. Building on freely available resources and experience from red and purple team engagements, we will aim to empower security teams to turn the tables and defend the target-rich, detection-poor attack surface of VMware stacks.

    Speaker

    FURTHER SESSIONS

  • 1979 called. They already figured it out.

  • A Few Dollars to Disappear: Breaking C2 Beaconing Detection

  • Capture The Flag

  • Clickfix: Copy, Paste, Compromise

  • Join us in Amsterdam!

    November 19, 2026

    Hang out, learn something awesome and make new friends.

    Get Tickets