
DEF CON 33 - Locked Down, Not Locked Out: How I Escaped Yr Secure Operator Workstation - Aaron Boyd
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 24:37
Based on the feedback and the transcript, here's a revised summary that more accurately captures the content, structure, and emphasis of Aaron Boyd's presentation:
Revised Summary:
"Locked down" operator workstations in industrial environments consistently fail to provide real security due to fundamental implementation gaps and cultural issues, necessitating a shift from checklist compliance to adversarial testing and ownership 12:12-12:18.
Key Vulnerabilities:
• Bypassed Controls: Misconfigured GPOs and allow-listing tools allow attackers to rename malicious executables (e.g., PowerShell as "alarms.exe") to bypass restrictions, exploiting the gap between policy intent and enforcement 1:29-3:01.
• Ineffective Allow-Listing: Tools like McAfee Solid Core or App Locker are frequently left in "learning mode," creating a false sense of security while permitting unapproved binaries and living-off-the-land techniques (e.g., bitsadmin, regsvr32) 4:16-5:02.
• Pervasive Default Credentials: Vendor-supplied passwords are reused system-wide; in 39 recent assessments of a specific DCS solution, 38 used identical credentials 5:57-6:58.
• Exploitable Login Scripts: Editable scripts often contain hard-coded secrets or can be modified to create privileged accounts, enabling lateral movement via pass-the-hash attacks 8:23-8:16.
Root Causes:
- Vendor/Integrator Shortcuts: Pressure for rapid deployment leads to reused, unvalidated configurations and "set-it-and-forget-it" security tools 9:59-10:11.
- Compliance Over Security: Checklists (e.g., "Is allow-listing enabled?") replace adversarial testing, creating blin
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
I definitely appreciate y'all coming to hear me ramble for 30 minutes or 25 minutes how I do what I do for a living. I do apologize that you're not able to see things on the screen, but I'm going to do my best to try to narrate what's on my screen as possible, but you can always feel free to watch the recording. So, my name is Aaron Boyd. My job title by day is a system engineer for a company called Liberty Energy. We do a lot of things in oil and gas, utility, and all that fun stuff. My former life has been spent with the NSA. I've done a lot of pentesting at Red Daming for Draos. And I've been basically pentesting as a hobbyist since around 2003, which is when I was in high school. And once I learned OT, I like breaking into refineries. It's addicting. So, after doing this for as long as…