This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Purple

GoSec 2026Panel46 minFrench
Download resources

About this session

"Purple" is a GoSecure conference panel that walks the phases of a cyberattack -- reconnaissance, enumeration, vulnerability analysis, exploitation and post-exploitation -- to test red-team and blue-team stereotypes against each other. Five panelists, including a red teamer, a SOC manager, and executives from two Quebec security vendors, answer audience polls (curious versus vigilant, methodical versus creative) and argue the split is messier than it looks: blue teams must independently explore and revalidate incomplete asset inventories just as red teams map poorly scoped attack surfaces, and both rely on the same external-exposure tooling for opposite ends. On vulnerability triage, panelists push past raw CVSS scores toward attack-chain thinking and the EPSS real-world-exploitation metric, since only a small share of published CVEs are ever exploited, arguing for prioritizing critical assets over patching everything AI-accelerated scanning surfaces. The exploitation-phase segment covers evasion, the pyramid of pain, and why purple exercises are the best collaboration zone. Closing remarks turn to real wins: a dark-web ad for ransomware tooling built to hunt compliance dirt, and a shared push to find patient zero after any incident.

Red Team + Blue Team : attaquer pour mieux défendre. Des experts offensifs et défensifs confrontent leurs approches pour comprendre comment transformer les tests, les simulations d’attaque et les apprentissages terrain en améliorations concrètes de la posture de sécurité.

Key takeaways

  • Add EPSS (real-world exploitation likelihood) alongside CVSS when prioritizing patches, since only a small fraction of newly published CVEs are ever exploited in the wild.
  • Treat vulnerability triage as attack-chain analysis anchored on critical assets and the paths that lead to them, not a flat CVSS-sorted backlog of everything AI-accelerated scanning surfaces.
  • Put governance around every new access grant and keep revalidating your own asset inventory: it goes stale within weeks, and that gap is exactly what red teams, and real attackers, exploit.
  • When an incident happens, find patient zero before reopening operations; skip that step and attackers who learned your controls the first time come back through the same door.
  • Monitor your own external exposure (leaked credentials, exposed cloud assets) with the same tooling attackers use, and fold in human and physical signals, like what staff post publicly, that technical scanning alone will miss.

Speakers

Charles F. Hamilton
Charles F. Hamilton
Director Offensive Security · CYPFER
Charles Hamilton is a Red Teamer with over twelve years of experience delivering offensive testing services for various government clients and commercial sectors. In recent years, Charles has specialized in covert Red Team operations targeting… Read moreRead less

Charles Hamilton is a Red Teamer with over twelve years of experience delivering offensive testing services for various government clients and commercial sectors. In recent years, Charles has specialized in covert Red Team operations targeting complex and highly secured environments. These operations have enabled him to refine his skills in stealthily navigating client networks without detection. Since 2014, he has been the founder and operator of the RingZer0 Team website, a platform dedicated to teaching hacking fundamentals. The RingZer0 community currently boasts over 50,000 members worldwide. Charles is also a prolific toolsmith and trainer who has delivered this training more than 20 times, both online and onsite. He is a speaker in the InfoSec industry, known under the handle

Olivier Bilodeau
Olivier Bilodeau
Principal Cybersecurity Researcher · Flare
Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur… Read moreRead less

Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur passionné, Olivier a présenté lors de conférences telles que AtlSecCon, BlackHat, DEFCON, SecTor, Derbycon, et bien d’autres. Très impliqué dans sa communauté, il coorganise MontréHack, est président de NorthSec, et anime son Hacker Jeopardy.

Michael Mazza
Michael Mazza
MXDR SOC Manager · GoSecure
Michael Mazza is the SOC MXDR Manager at GoSecure, where he leads Security Operations Center activities and the delivery of managed detection and response services. He oversees cybersecurity monitoring, incident investigation, threat hunting… Read moreRead less

Michael Mazza is the SOC MXDR Manager at GoSecure, where he leads Security Operations Center activities and the delivery of managed detection and response services. He oversees cybersecurity monitoring, incident investigation, threat hunting, detection engineering, and response operations while supporting the continued development of SOC analysts, processes, and technologies.

His experience includes Microsoft Defender XDR, Microsoft Sentinel, Fortinet security technologies, security automation, and the creation of detection rules and incident response procedures. Michael is focused on improving SOC operational maturity, strengthening client security programs, and ensuring threats are identified, investigated, and addressed effectively.

William Georges Khouri
William Georges Khouri
CEO · Sentrix
Avec plus de 20 ans d'expérience en TI et 15 ans d'expérience en Cybersécurité, j'ai pu appliquer mes connaissances et mes compétences dans des dizaines de mandats et de réponses à Incident à travers les différentes compagnies de Cybersécurité que… Read moreRead less

Avec plus de 20 ans d'expérience en TI et 15 ans d'expérience en Cybersécurité,
j'ai pu appliquer mes connaissances et mes compétences dans des dizaines de
mandats et de réponses à Incident à travers les différentes compagnies de
Cybersécurité que j'ai fondées ou co-fondées.

Anne-Marie Faber
Anne-Marie Faber
Founder · Sercle - Sustainable Cybersecurity
As the Chief Marketing Officer at GoSecure, a leading provider of cybersecurity solutions, I leverage my 15+ years of experience in the IT industry and my MBA degree to drive the company's growth and differentiation in the market. I have a proven… Read moreRead less

As the Chief Marketing Officer at GoSecure, a leading provider of cybersecurity solutions, I leverage my 15+ years of experience in the IT industry and my MBA degree to drive the company's growth and differentiation in the market. I have a proven track record of helping various companies evolve into market leaders with double digit revenue growth, thanks to my strategic planning and business strategy skills.

I believe in the importance of a close partnership with all sales channels, direct and indirect, and the ability to think creatively and differently than competitors. I also lead a talented and diverse team of marketing professionals who share my passion and vision for security innovation and customer success.

Resources

Photos

Tags

More from GoSec 2026

Also from Charles F. Hamilton

On the same topic