{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.1.2"}, "schedule": {"url": "https://conference.wireshark.org/sharkfest-25-us-2024/schedule/", "version": "0.40", "base_url": "https://conference.wireshark.org", "conference": {"acronym": "sharkfest-25-us-2024", "title": "SharkFest'25 US", "start": "2025-06-14", "end": "2025-06-19", "daysCount": 6, "timeslot_duration": "00:05", "time_zone_name": "US/Eastern", "colors": {"primary": "#0052FF"}, "rooms": [{"name": "Grand Ballroom Salon E", "slug": "7-grand-ballroom-salon-e", "guid": "fe250091-3fe4-5aed-963b-0cb9a6a8d59a", "description": "Plenary Room", "capacity": 250}, {"name": "Grand Ballroom Salons A-D", "slug": "8-grand-ballroom-salons-a-d", "guid": "46f15a36-48f9-5553-99fb-2a6a030cd9ee", "description": "2nd Session Room", "capacity": 80}], "tracks": [{"name": "Beginner", "slug": "16-beginner", "color": "#00AB9B"}, {"name": "Intermediate", "slug": "17-intermediate", "color": "#2B9ECF"}, {"name": "Expert / Developer", "slug": "18-expert-developer", "color": "#9D6DEC"}, {"name": "Security", "slug": "19-security", "color": "#72B406"}, {"name": "A.I.", "slug": "20-ai", "color": "#E60757"}, {"name": "Pre-conference class", "slug": "21-pre-conference-class", "color": "#0C590D"}, {"name": "Organization", "slug": "22-organization", "color": "#3C8BC4"}], "days": [{"index": 1, "date": "2025-06-14", "day_start": "2025-06-14T04:00:00-04:00", "day_end": "2025-06-15T03:59:00-04:00", "rooms": {"Grand Ballroom Salon E": [{"guid": "d11cf4d6-0cad-51db-80ef-7ce6ac818dcf", "code": "RHMSGK", "id": 96, "logo": null, "date": "2025-06-14T09:00:00-04:00", "start": "09:00", "duration": "08:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-96-0-pre-conference-class-i-essential-wireshark-skills-practical-packet-analysis-2-day-class", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/RHMSGK/", "title": "Pre-conference class I: Essential Wireshark Skills: Practical Packet Analysis (2-day class)", "subtitle": "", "track": "Pre-conference class", "type": "Pre Conference Class", "language": "en", "abstract": "Level up your Wireshark skills and get ready for Sharkfest! This hands-on course will provide core Wireshark skills for IT pros of all experience levels. Participants will gain a solid understanding of how to use Wireshark to capture, analyze, and troubleshoot network traffic. The course is designed with beginners in mind, but even seasoned packet people will pick up new tips and tricks.", "description": "Topics Covered:\r\n\r\nIntroduction to network analysis and the role of Wireshark\r\nInstalling and configuring Wireshark\r\nAnalyzing captured packets, understanding protocol structures, and identifying network issues\r\nUtilizing powerful filtering techniques to isolate specific traffic and find the packets that matter\r\nDeep Dive into ARP, IP, ICMP, DNS, DHCP, TCP, UDP, QUIC, HTTP, TLS, and much more!\r\nWorking with command-line tools like TShark", "recording_license": "", "do_not_record": true, "persons": [{"code": "PXMJ8G", "name": "Chris Greer", "avatar": "https://conference.wireshark.org/media/avatars/Chris_New_mug_K5fG1wf.png", "biography": "Like you, Chris likes digging into packet captures to figure out how things work. When he is not teaching people the art of packet analysis in live courses, YouTube videos, or at conference seminars, you can find him in the packet trenches with clients from all over the world. Chris has been attending and speaking at Sharkfest since 2011 and enjoys learning new things right alongside attendees of all experience levels.", "public_name": "Chris Greer", "guid": "0c68084e-3d29-5ef1-8b33-42e9bdef9f99", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/PXMJ8G/"}, {"code": "LVXUVN", "name": "Ross Bagurdes", "avatar": "https://conference.wireshark.org/media/avatars/Bagurdes_Headshot_SjVuW0O.jpeg", "biography": "Ross has had a diverse career in engineering, beginning as a structural engineer, then project engineer for a gas utility, Ross was always quickly\r\nassigned the de-facto network administrator, typically after no one else was brave enough to break, and later fix, the network. This lead to working as a network engineer designing and implementing enterprise networks for a major university hospital. Here he worked with\r\nExtreme Networks, HP, Cisco, Tipping Point, among other network technology, as well as honed his Wireshark and protocol analysis skills. Ross\r\nspent 7 years teaching data networking at Madison College, and in 2017 started authoring and producing IT training videos in Wireshark/Protocol\r\nAnalysis, Cisco, and general networking topics for www.Pluralsight.com. In his free time, you'll find Ross and his dog at the beach swimming and\r\nsurfing, traveling, hiking, or snowboarding somewhere in the western US.", "public_name": "Ross Bagurdes", "guid": "0def5250-101e-527e-a22d-2ffc2ecf9ad9", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/LVXUVN/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/RHMSGK/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/RHMSGK/", "attachments": []}]}}, {"index": 2, "date": "2025-06-15", "day_start": "2025-06-15T04:00:00-04:00", "day_end": "2025-06-16T03:59:00-04:00", "rooms": {"Grand Ballroom Salon E": [{"guid": "aa2e58a5-57ca-5455-b5df-0e2b796c2096", "code": "RHMSGK", "id": 96, "logo": null, "date": "2025-06-15T09:00:00-04:00", "start": "09:00", "duration": "08:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-96-1-pre-conference-class-i-essential-wireshark-skills-practical-packet-analysis-2-day-class", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/RHMSGK/", "title": "Pre-conference class I: Essential Wireshark Skills: Practical Packet Analysis (2-day class)", "subtitle": "", "track": "Pre-conference class", "type": "Pre Conference Class", "language": "en", "abstract": "Level up your Wireshark skills and get ready for Sharkfest! This hands-on course will provide core Wireshark skills for IT pros of all experience levels. Participants will gain a solid understanding of how to use Wireshark to capture, analyze, and troubleshoot network traffic. The course is designed with beginners in mind, but even seasoned packet people will pick up new tips and tricks.", "description": "Topics Covered:\r\n\r\nIntroduction to network analysis and the role of Wireshark\r\nInstalling and configuring Wireshark\r\nAnalyzing captured packets, understanding protocol structures, and identifying network issues\r\nUtilizing powerful filtering techniques to isolate specific traffic and find the packets that matter\r\nDeep Dive into ARP, IP, ICMP, DNS, DHCP, TCP, UDP, QUIC, HTTP, TLS, and much more!\r\nWorking with command-line tools like TShark", "recording_license": "", "do_not_record": true, "persons": [{"code": "PXMJ8G", "name": "Chris Greer", "avatar": "https://conference.wireshark.org/media/avatars/Chris_New_mug_K5fG1wf.png", "biography": "Like you, Chris likes digging into packet captures to figure out how things work. When he is not teaching people the art of packet analysis in live courses, YouTube videos, or at conference seminars, you can find him in the packet trenches with clients from all over the world. Chris has been attending and speaking at Sharkfest since 2011 and enjoys learning new things right alongside attendees of all experience levels.", "public_name": "Chris Greer", "guid": "0c68084e-3d29-5ef1-8b33-42e9bdef9f99", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/PXMJ8G/"}, {"code": "LVXUVN", "name": "Ross Bagurdes", "avatar": "https://conference.wireshark.org/media/avatars/Bagurdes_Headshot_SjVuW0O.jpeg", "biography": "Ross has had a diverse career in engineering, beginning as a structural engineer, then project engineer for a gas utility, Ross was always quickly\r\nassigned the de-facto network administrator, typically after no one else was brave enough to break, and later fix, the network. This lead to working as a network engineer designing and implementing enterprise networks for a major university hospital. Here he worked with\r\nExtreme Networks, HP, Cisco, Tipping Point, among other network technology, as well as honed his Wireshark and protocol analysis skills. Ross\r\nspent 7 years teaching data networking at Madison College, and in 2017 started authoring and producing IT training videos in Wireshark/Protocol\r\nAnalysis, Cisco, and general networking topics for www.Pluralsight.com. In his free time, you'll find Ross and his dog at the beach swimming and\r\nsurfing, traveling, hiking, or snowboarding somewhere in the western US.", "public_name": "Ross Bagurdes", "guid": "0def5250-101e-527e-a22d-2ffc2ecf9ad9", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/LVXUVN/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/RHMSGK/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/RHMSGK/", "attachments": []}]}}, {"index": 3, "date": "2025-06-16", "day_start": "2025-06-16T04:00:00-04:00", "day_end": "2025-06-17T03:59:00-04:00", "rooms": {"Grand Ballroom Salon E": [{"guid": "90288646-acd6-50b1-a060-0af8bb27abab", "code": "9BUZJY", "id": 98, "logo": null, "date": "2025-06-16T09:00:00-04:00", "start": "09:00", "duration": "08:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-98-pre-conference-class-ii-tcp-analysis-masterclass", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/9BUZJY/", "title": "Pre-conference class II: TCP Analysis Masterclass", "subtitle": "", "track": "Pre-conference class", "type": "Pre Conference Class", "language": "en", "abstract": "Analyzing TCP connections is one of the biggest topics in network analysis in general, especially when troubleshooting applications or even multi-tiered deployments of servers. How TCP works and detecting problems is one of the 'easy to learn, hard to master' skills that is always in demand. Most Wireshark classes only touch the basics and do not go into the more complex scenarios, especially when it comes to multi point captures to track packet loss and timing issues. In this masterclass you will learn how to troubleshoot TCP in seemingly simple as well as complex and quite challenging cases.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "JJLHFE", "name": "Jasper Bongertz", "avatar": "https://conference.wireshark.org/media/avatars/32db88b741fd066a3afc295884850482_KxKZwQ8.jpg", "biography": "Jasper Bongertz is a network security expert with focus on network forensics and incident response at Airbus Defence and Space CyberSecurity. He started working freelance in 1992 while he was studying computer science at the Technical University of Aachen. In 2009, Jasper became a Senior Consultant and Trainer for Fast Lane, where he created a large training portfolio with a special focus on Wireshark and network hacking. In 2013, he joined Airbus Defence and Space CyberSecurity, before moving on to G Data Advanced Analytics in 2019 where he is now the head of the CyberSecurity Incident Response Team (CSIRT).\r\n\r\nJasper is the creator of the packet analysis tool TraceWrangler, which can be used to convert, edit and sanitize PCAP files. His blog regarding network analysis, network forensics and general security topics can be found at blog.packet-foo.com.", "public_name": "Jasper Bongertz", "guid": "01090920-dcf6-5bfc-8ce9-c09dfc5e857c", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/JJLHFE/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/9BUZJY/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/9BUZJY/", "attachments": []}, {"guid": "79202fb9-a74e-56d7-a48e-5878fb9f9883", "code": "SVDV8Z", "id": 99, "logo": null, "date": "2025-06-16T17:30:00-04:00", "start": "17:30", "duration": "03:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-99-sharkfest-25-us-welcome-dinner-sponsor-showcase", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/SVDV8Z/", "title": "SharkFest'25 US Welcome Dinner & Sponsor Showcase", "subtitle": "", "track": "Organization", "type": "Dinner", "language": "en", "abstract": "Let's kick off the conference in style", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/SVDV8Z/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/SVDV8Z/", "attachments": []}], "Grand Ballroom Salons A-D": [{"guid": "88d44e7d-fa2f-5c2a-b2f2-ae5192156e8d", "code": "L8ZM9P", "id": 97, "logo": null, "date": "2025-06-16T09:00:00-04:00", "start": "09:00", "duration": "08:00", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-97-pre-conference-class-iii-ssl-tls-troubleshooting-with-wireshark", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/L8ZM9P/", "title": "Pre-conference class III: SSL/TLS Troubleshooting with Wireshark", "subtitle": "", "track": "Pre-conference class", "type": "Pre Conference Class", "language": "en", "abstract": "The applications of today depend more and more on secure communication channels. For most internet applications the TLS protocol (still mostly referred to as SSL) is providing the secure channel to communicate over. To be able to troubleshoot problems with Applications that use (mutual) TLS, one must understand how TLS sessions are set up, how certificates and certificate authorities come into play and how you can look inside the encrypted traffic to analyse the (cleartext) application data. In this session you will gain a better understanding of the operation of the TLS protocol and more importantly, you will learn how to troubleshoot TLS based communications when things don't work as expected.", "description": "", "recording_license": "", "do_not_record": true, "persons": [{"code": "MZ9HCA", "name": "Sake Blok", "avatar": "https://conference.wireshark.org/media/avatars/profile-2025-400x400_hgdKmpu.png", "biography": "Sake has been analyzing packets for over 20 years. During his work, Sake started developing functionality for Wireshark while working with the analyzer in his day-to-day job. He also enhanced multiple protocol dissectors. In 2007, Sake joined the Wireshark Core Development team. In 2009, After working for a reseller of networking equipment for 8 years, he started the company SYN-bit to provide network analysis and training services to enterprises across Europe.", "public_name": "Sake Blok", "guid": "eeeda75a-cc6d-5a94-ba7c-2d3d6f14dd59", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/MZ9HCA/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/L8ZM9P/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/L8ZM9P/", "attachments": []}]}}, {"index": 4, "date": "2025-06-17", "day_start": "2025-06-17T04:00:00-04:00", "day_end": "2025-06-18T03:59:00-04:00", "rooms": {"Grand Ballroom Salon E": [{"guid": "85267551-9f45-594a-97b5-9d6ebba75409", "code": "UYU7BA", "id": 103, "logo": null, "date": "2025-06-17T09:00:00-04:00", "start": "09:00", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-103-keynote-things-i-love-about-wireshark-and-maybe-a-couple-of-things-i-don-t", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/UYU7BA/", "title": "Keynote: Things I Love About Wireshark (and maybe a couple of things I don't)", "subtitle": "", "track": "Organization", "type": "Organization", "language": "en", "abstract": "Gerald Combs & Friends talk about the new developments over the past year", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "LWSPRU", "name": "Gerald Combs", "avatar": "https://conference.wireshark.org/media/avatars/6db117a984c6529df88330dc49fb1ee4_4lajzWK.jpg", "biography": null, "public_name": "Gerald Combs", "guid": "e80ddc9a-7193-5265-8936-399d1dbe61a3", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/LWSPRU/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/UYU7BA/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/UYU7BA/", "attachments": []}, {"guid": "1db26519-8d51-57a6-b0b4-81aa3c068e2e", "code": "FKYN93", "id": 129, "logo": null, "date": "2025-06-17T10:15:00-04:00", "start": "10:15", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-129-new-kid-on-the-block-stratoshark", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/FKYN93/", "title": "New kid on the block: Stratoshark", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "Gerald has been working on a new tool that has just been released to the public: Stratoshark. It has the same look and feel of Wireshark (as it shares quite a bit of common code), but you can analyze (linux) system calls and (cloud) logs with it.\r\n\r\nAs per www.stratoshark.org:\r\n_Stratoshark lets you explore and investigate the application-level behavior of your systems. You can capture system call and log activity and use a variety of advanced features to troubleshoot and analyze that activity. If you've ever used Wireshark, Stratoshark will look very familiar! It's a sibling application that shares the same dissection and filtering engine and much of the same user interface. It supports the same file format as Falco and Sysdig CLI, which lets you pivot seamlessly between each tool. As an added bonus, it's open source, just like Wireshark and Falco._\r\n\r\nThis talk will give you an introduction to Stratoshark and some hints to get started your Stratoshark journey.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "MZ9HCA", "name": "Sake Blok", "avatar": "https://conference.wireshark.org/media/avatars/profile-2025-400x400_hgdKmpu.png", "biography": "Sake has been analyzing packets for over 20 years. During his work, Sake started developing functionality for Wireshark while working with the analyzer in his day-to-day job. He also enhanced multiple protocol dissectors. In 2007, Sake joined the Wireshark Core Development team. In 2009, After working for a reseller of networking equipment for 8 years, he started the company SYN-bit to provide network analysis and training services to enterprises across Europe.", "public_name": "Sake Blok", "guid": "eeeda75a-cc6d-5a94-ba7c-2d3d6f14dd59", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/MZ9HCA/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/FKYN93/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/FKYN93/", "attachments": []}, {"guid": "947eae5e-3a83-5384-9636-e526376b9be1", "code": "MVF9CL", "id": 93, "logo": "https://conference.wireshark.org/media/sharkfest-25-us-2024/submissions/MVF9CL/sharkx2_Kopie_gphNr0p.png", "date": "2025-06-17T11:30:00-04:00", "start": "11:30", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-93-sharkmon-packet-monitoring-using-tshark", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/MVF9CL/", "title": "Sharkmon - Packet Monitoring using Tshark", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "Using Sharkmon - Wireshark User can now finally start monitoring - using same syntax, same core technology - but for 1000s of pcap files - data over hours, days, months", "description": "Packet data exists everywhere in the network - in the data center, on assembly lines, in the service cloud, in cars - or in the home office.\r\nWireshark can be used to analyze every protocol with its fields  - but billions of network packets (100 Gbps = 134,217,728 bytes/sec) cannot be analyzed manually.\r\nFor fast and precise trend detection, anomaly recognition, incident alerting and cause-effect understanding, the analysis of all packet data and fields must be automated and in real time.\r\nSharkmon was developed to capture and analyze every  wireshark-\"known\" IT protocol with all defined protocol fields as needed and to keep it available in dashboards for months / years.\r\nThe combination of deep packet analysis on Wireshark core level and monitoring is unique in the industry.\r\nSharkmon was developed to bridge this gap - between  longtime base data and  shortime Wireshark data.\r\nThe data that the users needs is collected and evaluated at the deep Wireshark level.\r\nThe results are indexed, threshold-checked, aggregated, stored in the database for a long time and can be displayed in clear dashboards and reports. This makes it possible to immediately identify problems and trends - and react precisely.\r\n\r\nSharkmon Short list\r\n- Network packet data in Pcap format \u2013 from anywhere \u2013 also distrubuted sources\r\n- tens of thousands of PCPA files over long periods of time\r\n- Wireshark metrics for automated analysis\r\n- parallel data analysis of data from multiple sources / locations\r\n- Cloud or on-premise installation\r\n- Web application with web dashboards, user sharing enables easy collaboration\r\n- hierarchical indexing of metrics, sessions, protocols and technology enables immediate assignment of critical events to the corresponding technologies and details\r\n- hierarchical dashboards \u2013 top: index value by technology -> down \u2013 per second line chart / data table per critical metric / user session\r\n- automated reporting and data export", "recording_license": "", "do_not_record": false, "persons": [{"code": "QN3NPR", "name": "Andreas Diedrich", "avatar": "https://conference.wireshark.org/media/avatars/IMG_8832_a8vwsae.jpeg", "biography": "since 1990 working in the IT - starting with network technology, network analysis  and monitoring platforms a la  spectrum\r\n1996 founder of Interview Company - focus on network analysis, service monitoring \r\n2015 starting developing software - bridging the gaps between existing solution and user demands \r\nsince 2018 working one sharkmon - the solution to monitor on wireshark level", "public_name": "Andreas Diedrich", "guid": "306ab5bd-44b8-590a-98f8-2353d642f02a", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/QN3NPR/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/MVF9CL/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/MVF9CL/", "attachments": []}, {"guid": "fbd1ebb7-2301-500e-8440-667aa07eb96e", "code": "UPKZY8", "id": 92, "logo": null, "date": "2025-06-17T13:30:00-04:00", "start": "13:30", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-92-chase-the-latency", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/UPKZY8/", "title": "Chase the latency", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "End users and application teams complain to you about the latency,  but we want to prove it is not network, how about that? The latency lies everywhere, not only in the network round trip time.", "description": "In this session, you can learn how to divide latency properly between the client OS/apps, the server OS/apps, and the network side, including reasonable ways to debug latency problems. We can find the root cause of the latency with TCP/UDP analysis TIPS and tricks using Wireshark.", "recording_license": "", "do_not_record": false, "persons": [{"code": "MQPULF", "name": "Megumi Takeshita", "avatar": "https://conference.wireshark.org/media/avatars/ea73b656018238499cd621f442bec89d_hPlCb4o.jpg", "biography": "Megumi Takeshita, packet otaku, runs a packet company, ikeriri network service in Japan. Ikeriri offers services such as packet analysis for troubleshooting, debugging, security inspection. Ikeriri is also a reseller of wired/wireless capture and analysis products. Megumi has authored 10+ books about Wireshark and packet analysis. She also instructs Wireshark for Japanese companies including Japan Self Defense Forces and Chuo university as lecturer. She is one of contributors to the Wireshark projects including Japanese localization.", "public_name": "Megumi Takeshita", "guid": "21f525f3-2a01-5598-b519-0228df74f377", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/MQPULF/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/UPKZY8/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/UPKZY8/", "attachments": []}, {"guid": "7dc09569-d45c-51d4-9b60-439ba1669ce5", "code": "DE8CQW", "id": 102, "logo": null, "date": "2025-06-17T14:45:00-04:00", "start": "14:45", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-102-wireshark-packet-capture-is-like-real-estate-location-matters", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/DE8CQW/", "title": "Wireshark Packet Capture is like Real Estate: Location Matters", "subtitle": "", "track": "Beginner", "type": "Presentation", "language": "en", "abstract": "Wireshark and packet analysis shows us what happened but to understand the why behind what we see, we apply our expectation of what should happen to what we actually observe.  To set the proper expectation, how we actually capture and the location of our diagnostic tool is important.  This is a discussion of how we can determine where and how a capture is taken based on what we observe in our pcap files.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "CL7YAB", "name": "George Cragg", "avatar": null, "biography": "Network Engineer who has worked in the Industrial Control and Medical Device industries", "public_name": "George Cragg", "guid": "827e9676-181d-51ba-b98f-1154df44906d", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/CL7YAB/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/DE8CQW/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/DE8CQW/", "attachments": []}, {"guid": "582f7c8e-d78d-523a-b4ee-75afa5d90d11", "code": "VZL737", "id": 116, "logo": null, "date": "2025-06-17T16:00:00-04:00", "start": "16:00", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-116-i-m-exploiting-your-ipv4-network-with-ipv6", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/VZL737/", "title": "\"I'm exploiting Your IPv4 Network with IPv6\"", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "26 years after the initial release of IPv6 we observe that many networks are not formally implementing IPv6, however, most modern desktop, server, and network OS's have had IPv6 enabled for 15+ years. That means many IT departments and technologists don't understand that IPv6 is in fact all over their networks nor what the potential implications are.\r\n\r\nThis session will encompass the access/recon/exploit of an \"IPv4 only\" network using IPv6...and yes, Wireshark will be used!", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "9UDAFX", "name": "Jeff Carrell", "avatar": "https://conference.wireshark.org/media/avatars/JeffCarrell_2.37x1.87_MC0tDNt.jpg", "biography": "Jeff Carrell\r\nMaster Technologist, HPE Services, Education\r\nHewlett Packard Enterprise\r\n\r\nJeff is a Networking, Container, and Data Analytics technologies Instructor/Course Developer at Hewlett Packard Enterprise.\r\n\r\nJeff is a frequent industry speaker, technical writer, IPv6 Forum Certified Trainer, and prior to HPE was a network instructor and course developer to major networking manufacturers. He is a technical lead and co-author for the book, Guide to TCP/IP: IPv6 and IPv4, 5th Edition and lead technical editor on Fundamentals of Communications and Networking, Second Edition. Jeff has been in the computer industry since 1979 and built his first LAN in 1986.", "public_name": "Jeff Carrell", "guid": "a4daf8c1-f404-5641-abb3-a5d6b47561a1", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/9UDAFX/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/VZL737/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/VZL737/", "attachments": []}, {"guid": "20a1a9a0-9b03-559d-b8d3-721fd775b1bf", "code": "NBJN8M", "id": 115, "logo": "https://conference.wireshark.org/media/sharkfest-25-us-2024/submissions/NBJN8M/FromPowerLinesToPackets_SessionImage_3MQ5cTN.png", "date": "2025-06-17T17:15:00-04:00", "start": "17:15", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-115-from-power-lines-to-packets-network-troubleshooting-in-the-power-grid", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/NBJN8M/", "title": "From Power Lines to Packets: Network Troubleshooting in the Power Grid", "subtitle": "", "track": "Beginner", "type": "Presentation", "language": "en", "abstract": "Did you know that communication networks play a critical role in the power grids reliability and safety? In this session, we will look at the power grid from a bird\u2019s eye view, highlighting its key components: generation, transmission, distribution, and consumers. Each area is interconnected through various networks, which play a crucial role in the efficient operation of the power grid. We will then focus on the devices that are essential for safeguarding the power grid and communicating critical information to other devices and SCADA systems. To bring these concepts to life, we will walk through a real customer issue and highlight the critical role Wireshark played in troubleshooting and determining root cause.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "GVFMCK", "name": "Daniel Lopez", "avatar": "https://conference.wireshark.org/media/avatars/SEL_Profile_Picture_Bn5XRpX.jpg", "biography": "Daniel is a dedicated professional currently serving as a Lead Integration & Automation Engineer at Schweitzer Engineering Laboratories. In this role, Daniel works in the R&D Forensics group, where they analyze field failures to determine root cause and provide recommendations to customers.\r\n\r\nDaniel graduated from LeTourneau University in 2020 with a bachelor's degree in Electrical Engineering. During his time in the Forensics group, he discovered Wireshark and quickly became captivated by its capabilities. This newfound interest led him to pursue the WCNA certification, further enhancing his expertise in network analysis.", "public_name": "Daniel Lopez", "guid": "29dfb55b-001c-5a53-8f60-439d815c1e69", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/GVFMCK/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/NBJN8M/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/NBJN8M/", "attachments": []}, {"guid": "d0cee119-85cb-5138-ae7f-ca61ef69ad75", "code": "TSVX8C", "id": 100, "logo": null, "date": "2025-06-17T18:30:00-04:00", "start": "18:30", "duration": "03:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-100-sponsor-technology-showcase-reception-treasure-hunt-dinner", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/TSVX8C/", "title": "Sponsor Technology Showcase Reception, Treasure Hunt & Dinner", "subtitle": "", "track": "Organization", "type": "Dinner", "language": "en", "abstract": "Join us for a fun night with an opportunity to enjoy wonderful conversations and win some nice prizes!", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/TSVX8C/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/TSVX8C/", "attachments": []}], "Grand Ballroom Salons A-D": [{"guid": "67fb24fe-4871-5d7c-a477-94cdd5a4e341", "code": "K8HXC9", "id": 118, "logo": "https://conference.wireshark.org/media/sharkfest-25-us-2024/submissions/K8HXC9/sharkfest_OAkchht.jpg", "date": "2025-06-17T10:15:00-04:00", "start": "10:15", "duration": "01:00", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-118-are-you-ready-for-post-quantum-encryption", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/K8HXC9/", "title": "Are You Ready for Post Quantum Encryption?", "subtitle": "", "track": "Security", "type": "Presentation", "language": "en", "abstract": "While many people like Ray Kurzweil and Sabine Hossenfelder point out that that we have not really seen any real cause for concern that quantum computing is about to actually work, much less crack the world\u2019s encryption technologies, there are regulations in the works  such as FIPS 203 (as well as FIPS 204 & FIPS 205), to migrate to quantum safe algorithms. In this talk, I plan to use Wireshark to sniff out TLS handshakes using Microsoft Edge and Google Chrome to see the algorithms negotiated, which are threatened by quantum computing \u201cShor\u2019s Algorithm\u201d and why it may actually be faster anyway to migrate.", "description": "In a TLS handshake, we see the client offer the cipher suites it supports; 1a-asymmetric for key agreement, 1b-asymmetric for signing  (Note: only asymmetric algorithms are affected by Shor's algorithm)\r\n2) Symmetric for data encryption (not affected)\r\n3) Hashing for data integrity (not effected)\r\n\r\nUsing Wireshark is my favorite way to see if a client is actually capable of what the vendor claims (~_^)", "recording_license": "", "do_not_record": false, "persons": [{"code": "UHEJLB", "name": "Larry Greenblatt", "avatar": "https://conference.wireshark.org/media/avatars/HeadShot_0PvKHxk.jpg", "biography": "Cybersecurity Pioneer & Packet Analysis Expert\r\nWith over 40 years of experience spanning the U.S. Department of Defense, intelligence communities, and the private sector, Larry is a renowned cybersecurity expert and CISSP instructor. A pioneer in network security and packet analysis for over 30 years, he has trained countless professionals in decrypting network traffic, detecting threats, and securing critical infrastructure. His expertise extends into cryptography, AI security, and ethical hacking, shaping the next generation of cyber defenders. Beyond cybersecurity, he is a dedicated martial artist, musician, and futurist, advocating for responsible AI integration to build a more secure and harmonious digital future.", "public_name": "Larry Greenblatt", "guid": "d7a5ff6a-6239-5cfd-9208-a7be2b6c16f3", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/UHEJLB/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/K8HXC9/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/K8HXC9/", "attachments": [{"title": "PDF of my presentation", "url": "/media/sharkfest-25-us-2024/submissions/K8HXC9/resources/SharkFest25-PQC_TBv7gP0.pdf", "type": "related"}]}, {"guid": "cf7143a2-a945-58f2-99b5-6be100ce70f5", "code": "3EVGHM", "id": 111, "logo": "https://conference.wireshark.org/media/sharkfest-25-us-2024/submissions/3EVGHM/c6d1c262-b70c-4b4d-b39f-3135fda6fa6c_4YdBotG.png", "date": "2025-06-17T11:30:00-04:00", "start": "11:30", "duration": "01:00", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-111-talk-with-your-packets-ai-powered-natural-language-interaction-with-packet-captures", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/3EVGHM/", "title": "Talk with Your Packets: AI-Powered Natural Language Interaction with Packet Captures", "subtitle": "", "track": "Expert / Developer", "type": "Presentation", "language": "en", "abstract": "Unlock a groundbreaking approach to packet analysis with \"Talk with Your Packets,\" where cutting-edge AI and Large Language Models (LLMs) meet the world of .pcap and .pcapng files. This session explores how natural language, combined with artificial intelligence and a Retrieval Augmented Generation (RAG) pipeline, can transform traditional packet analysis.\r\n\r\nWe\u2019ll dive into how packets are converted into JSON representations via the CLI, chunked for efficient processing, embedded as vectors, and stored in ChromaDB for retrieval. Democratizing access to advanced packet analysis and making it easier for users to ask meaningful questions about their packet captures.\r\n\r\nWhile this solution augments Wireshark by aiding in the filtering and crafting of high-value .pcaps (garbage in, garbage out), it does not replace Wireshark. Instead, it empowers analysts with a more intuitive and streamlined way to interpret packet data.", "description": "This will be a mix of slides and live demonstrations as well as Q&A and interactivity with the audience", "recording_license": "", "do_not_record": false, "persons": [{"code": "KRGTQN", "name": "John Capobianco", "avatar": "https://conference.wireshark.org/media/avatars/SBducZEp_400x400_atflUfm.jpg", "biography": "John Capobianco is a visionary leader, author, and evangelist at the forefront of IT operations, artificial intelligence, and automation. With over 25 years of experience in IT Operations across public and private sectors, John has served as a Technical Leader in AI at Cisco and is currently a Product Marketing Evangelist at Selector AI. His career blends deep technical expertise with a passion for innovation, helping bridge the gap between technology and business value.\r\n\r\nJohn is the author of several influential works, including Automate Your Network and Cisco pyATS: Network Test and Automation Solution. A recognized thought leader, he frequently speaks at global conferences on topics such as AIOps, network automation, and the transformative impact of AI. His engaging style and real-world insights inspire professionals to embrace the future of IT operations.", "public_name": "John Capobianco", "guid": "a0cda325-ac56-56dc-8410-bf7e76244793", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/KRGTQN/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/3EVGHM/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/3EVGHM/", "attachments": []}, {"guid": "9fd0557f-dffa-5c4c-9d1d-a331e7955a89", "code": "WDQNXL", "id": 117, "logo": null, "date": "2025-06-17T13:30:00-04:00", "start": "13:30", "duration": "01:00", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-117-walk-through-3gpp-packet-flow", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/WDQNXL/", "title": "walk through 3GPP packet flow", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "In this talk we will go over the packet flow when your cell phone acquires a LTE network, and what the packets look like once you are connected. We will also cover how wireshark tools can be used to look at traffic with tunneling protocols used in LTE.", "description": "In this talk we will go over the packet flow when your cell phone acquires a LTE network, and what the packets look like once you are connected. We will also cover how wireshark tools can be used to look at traffic with tunneling protocols used in LTE.", "recording_license": "", "do_not_record": false, "persons": [{"code": "LKKWAR", "name": "Mark Stout", "avatar": null, "biography": "Currently working for T-Mobile with 5G feature development and support. While supporting the existing LTE infrastructure for the last 13 years. In the packet trenches everyday.", "public_name": "Mark Stout", "guid": "52f4461d-c166-5b72-91c6-ed3edd7dcbac", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/LKKWAR/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/WDQNXL/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/WDQNXL/", "attachments": []}, {"guid": "7dc3eea9-4aa7-55ec-8317-fea0900e691f", "code": "AFUCXC", "id": 136, "logo": "https://conference.wireshark.org/media/sharkfest-25-us-2024/submissions/AFUCXC/1735868870726_DlRFfoh.jpeg", "date": "2025-06-17T14:45:00-04:00", "start": "14:45", "duration": "02:15", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-136-detecting-evil-with-network-traffic-analysis", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/AFUCXC/", "title": "Detecting Evil with Network Traffic Analysis", "subtitle": "", "track": "Security", "type": "Workshop", "language": "en", "abstract": "Learn how to recognize and detect malicious activity on the wire.", "description": "What does badness look like on the wire? How can you recognize a DDoS versus nmap scan vs remote access vs data exfiltration? Understanding network protocols (yes, RFCs!) and being able to extract artifacts from network traffic is essential in many fields - incident response, forensics, security operations - the list goes on. Recognizing the hallmarks of various types of attacks is also key. In this workshop we will walk through custom packet captures to explore examples of various types of attacks.  \r\n\r\nThis workshop is designed for a variety of experience levels. We will start with the basics of TCP/IP and review how network traffic flows, then ease into the analysis part. I encourage anyone with an interest to participate. For more advanced students there will be additional questions/challenges to keep you occupied.", "recording_license": "", "do_not_record": false, "persons": [{"code": "XKGJQJ", "name": "Marcelle Lee", "avatar": "https://conference.wireshark.org/media/avatars/marcelle-vegas-headshot_7JgEvGA.jpg", "biography": "Marcelle is security practitioner but also an educator at heart, and delivers many talks and workshops. Marcelle's passion lies in several areas but network traffic analysis is at the top of the list. She has delivered traffic analysis workshops at Thotcon, SkyDogCon, BSidesCharm, etc. but always uses fresh captures to demonstrate relevant and current topics.\r\n\r\nLinkedIn: https://www.linkedin.com/in/marcellelee/", "public_name": "Marcelle Lee", "guid": "9cf80b19-0cdd-5173-9bb1-0087ee47c8db", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/XKGJQJ/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/AFUCXC/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/AFUCXC/", "attachments": []}, {"guid": "8df4df10-f97e-520e-acda-fdbd69ff4864", "code": "CWX3JT", "id": 147, "logo": null, "date": "2025-06-17T17:15:00-04:00", "start": "17:15", "duration": "01:00", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-147-the-making-of-the-wireshark-certified-analyst-wca-exam", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/CWX3JT/", "title": "The Making of the Wireshark Certified Analyst (WCA) Exam", "subtitle": "", "track": "Organization", "type": "Presentation", "language": "en", "abstract": "The Wireshark Certified Analyst exam is here. This is an exciting step for the Wireshark Community! \r\n\r\nIn this session, Chris and Ross, who helped to develop the WCA, go into the steps that were taken to create, develop and deliver the exam. Beyond sharing the objectives, we will explore the intended audience, how to prepare, sample labs, and what types of jobs this certification will support. Time will be taken for live training labs that feature exam objectives, as well as for Q+A about the certification. \r\n\r\nCome learn more about the certification and find out if you are ready to become one of the first WCA\u2019s in the world!", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "PXMJ8G", "name": "Chris Greer", "avatar": "https://conference.wireshark.org/media/avatars/Chris_New_mug_K5fG1wf.png", "biography": "Like you, Chris likes digging into packet captures to figure out how things work. When he is not teaching people the art of packet analysis in live courses, YouTube videos, or at conference seminars, you can find him in the packet trenches with clients from all over the world. Chris has been attending and speaking at Sharkfest since 2011 and enjoys learning new things right alongside attendees of all experience levels.", "public_name": "Chris Greer", "guid": "0c68084e-3d29-5ef1-8b33-42e9bdef9f99", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/PXMJ8G/"}, {"code": "LVXUVN", "name": "Ross Bagurdes", "avatar": "https://conference.wireshark.org/media/avatars/Bagurdes_Headshot_SjVuW0O.jpeg", "biography": "Ross has had a diverse career in engineering, beginning as a structural engineer, then project engineer for a gas utility, Ross was always quickly\r\nassigned the de-facto network administrator, typically after no one else was brave enough to break, and later fix, the network. This lead to working as a network engineer designing and implementing enterprise networks for a major university hospital. Here he worked with\r\nExtreme Networks, HP, Cisco, Tipping Point, among other network technology, as well as honed his Wireshark and protocol analysis skills. Ross\r\nspent 7 years teaching data networking at Madison College, and in 2017 started authoring and producing IT training videos in Wireshark/Protocol\r\nAnalysis, Cisco, and general networking topics for www.Pluralsight.com. In his free time, you'll find Ross and his dog at the beach swimming and\r\nsurfing, traveling, hiking, or snowboarding somewhere in the western US.", "public_name": "Ross Bagurdes", "guid": "0def5250-101e-527e-a22d-2ffc2ecf9ad9", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/LVXUVN/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/CWX3JT/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/CWX3JT/", "attachments": []}]}}, {"index": 5, "date": "2025-06-18", "day_start": "2025-06-18T04:00:00-04:00", "day_end": "2025-06-19T03:59:00-04:00", "rooms": {"Grand Ballroom Salon E": [{"guid": "675c888e-400b-5c60-bac4-f9f30c14fc5f", "code": "QDHWWZ", "id": 151, "logo": null, "date": "2025-06-18T08:45:00-04:00", "start": "08:45", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-151-cloud-doesn-t-have-packets", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/QDHWWZ/", "title": "Cloud doesn\u2019t have Packets!", "subtitle": "", "track": "Beginner", "type": "Presentation", "language": "en", "abstract": "It\u2019s easy to laugh at the apocryphal executive quote \u201cCloud doesn\u2019t have Packets!\u201d, but is there something to it? What might they have meant?\r\n \r\nWhat are the differences between traditional On-premise and Cloud networking and architectures, and what does this tell us about attitudes towards network based security and trouble-shooting?\r\n \r\nIn this talk we will look at how Cloud differs from On-prem networking, what common Cloud architectures look like, and how they can confound established practice. We will review options for Packet Capture and network based tools in Cloud compared to On-prem environments, and discuss whether it is practical, beneficial, and necessary.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "3MTJ77", "name": "Stephen Donnelly", "avatar": "https://conference.wireshark.org/media/avatars/dd9b73de6604fe1aa5b498fb631c4ff2_Z6LnIt5.jpg", "biography": "Dr Stephen Donnelly is CTO at Endace, a proud Wireshark Foundation Platinum Sponsor. He is a sometime Wireshark contributor, and repeat Sharkfest attendee and speaker having missed only a few since the conference began. Stephen received his Ph.D. from Waikato University in precision timing of packet capture on data networks, and continued this work at Endace as a developer and problem solver for over 20 years.", "public_name": "Stephen Donnelly", "guid": "f3ab1550-4987-5443-9dba-51a557913170", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/3MTJ77/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/QDHWWZ/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/QDHWWZ/", "attachments": []}, {"guid": "beee5267-309e-5dbd-b6b1-85132e5887f0", "code": "PEDGXJ", "id": 135, "logo": null, "date": "2025-06-18T10:00:00-04:00", "start": "10:00", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-135-building-support-for-an-in-house-performance-engineering-team", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/PEDGXJ/", "title": "Building support for an in-house performance engineering team", "subtitle": "", "track": "Beginner", "type": "Presentation", "language": "en", "abstract": "While many companies have a network engineer that becomes the de facto packet analyst, building a full performance engineering (PE) team takes time and effort, as well as support from upper management.  This talk will chronicle one team's experience with building and maintaining a high-achieving PE team over the past 13 years.\r\nThis is designed to be an interactive discussion of what Performance Engineering is and what the future is for packet experts.  Come ready to share your stories and challenges.", "description": "", "recording_license": "", "do_not_record": true, "persons": [{"code": "TL9MZA", "name": "Tim DeLamatre", "avatar": null, "biography": "I am an Ohioan by birth and current residence, but wandered a bit before returning to the state.  I grew up on a farm and had a penchant for all things mechanical, so got a degree in mechanical engineering and worked on fighter jet propulsion systems as my first job before deciding I wanted to try something different.  \r\nThat something different took me to Africa, as I joined the U.S. Peace Corps to teach high-school calc and trig in Mali, then stayed there for a total of 4.5 years as a computer consultant and teacher.  \r\nAfter returning from Mali, I obtained a master's in Information Networking and have been in IT for nearly 30 years, most of it as a network performance analyst using packet traces and statistical modeling to analyze and predict performance of distributed systems.  \r\nI am married with two (mostly) grown kids and a clowder of cats, although the older cats make it more of a glaring at times when the young ones become too rambunctious.", "public_name": "Tim DeLamatre", "guid": "8f212ff9-c7a9-5fb9-8b64-22e5389f5bb7", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/TL9MZA/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/PEDGXJ/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/PEDGXJ/", "attachments": []}, {"guid": "d6dd13b2-85de-57d5-96c1-222725d9798d", "code": "WEM9ES", "id": 107, "logo": null, "date": "2025-06-18T11:15:00-04:00", "start": "11:15", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-107-vint-cerf-keynote-the-good-the-bad-the-ugly-internet-from-2025-on", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/WEM9ES/", "title": "Vint Cerf Keynote: The Good, the Bad, the Ugly: Internet from 2025 on...", "subtitle": "", "track": "Organization", "type": "Presentation", "language": "en", "abstract": "RFC 3271 spoke about the Internet being for everyone. Even today, in 2025, it isn't. Its functionality keeps growing and changing - new protocols are created - a good reason that Wireshark has a future! Despite its penetration, the Internet is not yet reliably for everyone. In this talk, I will review technical and policy considerations that must be treated to overcome to achieve an Internet that really is for everyone. Will AI help? A question worthy of exploration.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "PRR7NT", "name": "Vint Cerf", "avatar": null, "biography": "Vinton G. Cerf is vice president and Chief Internet Evangelist for Google. He is the co-designer of the TCP/IP protocols and the architecture of the Internet. He has served in executive positions at ICANN, the Internet Society, MCI, the Corporation for National Research Initiatives and the Defense Advanced Research Projects Agency. A former Stanford Professor and former member of the US National Science Board, he is also the past President of the Association for Computing Machinery, Emeritus Chairman of the Marconi Society and serves in advisory capacities at NIST, DOE, NSF, US Navy, JPL and NRO. He earned his B.S. in mathematics at Stanford and M.S. and Ph.D. degrees in computer science at UCLA. Cerf is a recipient of numerous awards for his work, including the US Presidential Medal of Freedom, US National Medal of Technology, the Queen Elizabeth Prize for Engineering, the Prince of Asturias Award, the Japan Prize, the IEEE Medal of Honor, and the Legion d\u2019Honneur.", "public_name": "Vint Cerf", "guid": "d0c72bc2-11e6-565e-9917-bff9c4b3c54b", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/PRR7NT/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/WEM9ES/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/WEM9ES/", "attachments": []}, {"guid": "426ad1ec-48fe-50c8-a1f5-2266fe31fde9", "code": "A383HZ", "id": 104, "logo": null, "date": "2025-06-18T13:15:00-04:00", "start": "13:15", "duration": "01:30", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-104-the-packet-doctors-are-in-packet-trace-examinations-with-the-experts", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/A383HZ/", "title": "The Packet Doctors are in! Packet trace examinations with the experts", "subtitle": "", "track": null, "type": "Packetdoctors Session", "language": "en", "abstract": "The experts on this panel have been asked to look at a trace file and help find a reason for certain behaviors by attendees at many SharkFests. Based on this, they\u2019ve decided to create a public forum for examining individual trace files with a broader audience for a collective learning experience. Trace files will be gathered from attendees prior to SharkFest and only given to the panel members during the session so that the \u201cnot-\r\nknowing what to expect and whether it can be solved\u201d experience of working through an unknown trace file can be preserved.\r\nCome to this session and learn to ask the right questions and look at packets in different ways.\r\nPLEASE SEND PERPLEXING TRACE FILES FOR ANALYSIS BY THE PANEL TO jasper@packet-foo.com PRIOR TO SHARKFEST!", "description": "", "recording_license": "", "do_not_record": true, "persons": [{"code": "PXMJ8G", "name": "Chris Greer", "avatar": "https://conference.wireshark.org/media/avatars/Chris_New_mug_K5fG1wf.png", "biography": "Like you, Chris likes digging into packet captures to figure out how things work. When he is not teaching people the art of packet analysis in live courses, YouTube videos, or at conference seminars, you can find him in the packet trenches with clients from all over the world. Chris has been attending and speaking at Sharkfest since 2011 and enjoys learning new things right alongside attendees of all experience levels.", "public_name": "Chris Greer", "guid": "0c68084e-3d29-5ef1-8b33-42e9bdef9f99", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/PXMJ8G/"}, {"code": "LVXUVN", "name": "Ross Bagurdes", "avatar": "https://conference.wireshark.org/media/avatars/Bagurdes_Headshot_SjVuW0O.jpeg", "biography": "Ross has had a diverse career in engineering, beginning as a structural engineer, then project engineer for a gas utility, Ross was always quickly\r\nassigned the de-facto network administrator, typically after no one else was brave enough to break, and later fix, the network. This lead to working as a network engineer designing and implementing enterprise networks for a major university hospital. Here he worked with\r\nExtreme Networks, HP, Cisco, Tipping Point, among other network technology, as well as honed his Wireshark and protocol analysis skills. Ross\r\nspent 7 years teaching data networking at Madison College, and in 2017 started authoring and producing IT training videos in Wireshark/Protocol\r\nAnalysis, Cisco, and general networking topics for www.Pluralsight.com. In his free time, you'll find Ross and his dog at the beach swimming and\r\nsurfing, traveling, hiking, or snowboarding somewhere in the western US.", "public_name": "Ross Bagurdes", "guid": "0def5250-101e-527e-a22d-2ffc2ecf9ad9", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/LVXUVN/"}, {"code": "MZ9HCA", "name": "Sake Blok", "avatar": "https://conference.wireshark.org/media/avatars/profile-2025-400x400_hgdKmpu.png", "biography": "Sake has been analyzing packets for over 20 years. During his work, Sake started developing functionality for Wireshark while working with the analyzer in his day-to-day job. He also enhanced multiple protocol dissectors. In 2007, Sake joined the Wireshark Core Development team. In 2009, After working for a reseller of networking equipment for 8 years, he started the company SYN-bit to provide network analysis and training services to enterprises across Europe.", "public_name": "Sake Blok", "guid": "eeeda75a-cc6d-5a94-ba7c-2d3d6f14dd59", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/MZ9HCA/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/A383HZ/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/A383HZ/", "attachments": []}, {"guid": "689e2ee7-88dd-551c-b954-a9b07bb41b79", "code": "KDLCBH", "id": 110, "logo": null, "date": "2025-06-18T15:00:00-04:00", "start": "15:00", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-110-how-do-you-know-wi-fi-device-is-the-problem", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/KDLCBH/", "title": "How do you know Wi-Fi Device is the Problem?", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "Wireless environments are complicated. Sometimes devices do not behave the way we expect. When these strange situations occur, how do you know whether your client device, AP, or other server resource is the issue? This presentation will review how to determine if devices are following the IEEE 802.11 standard and how to approach Wi-Fi issue resolution between client device and AP vendors.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "AGSWSA", "name": "Eva Santos", "avatar": "https://conference.wireshark.org/media/avatars/Eva_Santos_Headshot_QGQZ1NO_pAGK2hE.jpg", "biography": "Eva has been a wireless professional for over 5 years and currently resides in Northern Virginia. Her experience includes deploying Wi-Fi as a consultant. Most recently, she has worked at Cisco Meraki troubleshooting potential product issues with wireless products. In her spare time, she enjoys gardening and traveling.", "public_name": "Eva Santos", "guid": "98e8f7b9-2736-586a-8b71-f982b3523452", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/AGSWSA/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/KDLCBH/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/KDLCBH/", "attachments": []}, {"guid": "725028a1-06b5-5a5e-91f1-4e06ca9709ec", "code": "LZAXYA", "id": 124, "logo": null, "date": "2025-06-18T16:15:00-04:00", "start": "16:15", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-124-the-next-gen-network-engineer", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/LZAXYA/", "title": "The Next Gen Network Engineer", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "Being a network engineer today requires much more than an understanding of subnets, spanning tree, and packet capture decodes. All the traditional skills matter, but many more are required in today's increasingly software-centric world. You can add on many of the new skills desired, and this presentation takes you through new topics for your consideration, and approaches to learning and acquiring skills in ways that fit your interest and job needs.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "KXVFXL", "name": "Scott Robohn", "avatar": null, "biography": "Scott Robohn has over 30 years of experience designing, building, and operating large-scale Internet Infrastructure and associated technologies for US Government organizations, Telcos, ISPs, Data Center Operators, and Enterprises. He\u2019s served in a variety of network operator and vendor roles in network operations, support, engineering, architecture, technical sales, training, community development, and leadership. His vendor employee experience includes Cisco, Juniper Networks, Nokia, and DriveNets. He founded TechSalesCraft (TSC) for fractional CTO and GTM services, serves as the co-founder of the Network Automation Forum (NAF), and created the Total Network Operations project and podcast (TNOps). He's also a seasoned presenter and keynote speaker. Scott's engagements span a wide variety of interesting clients and projects in Networking, AI, Automation, Data Centers, Operations, Mobility Security, Silicon, staying up-to-date with the critical trends and technologies.", "public_name": "Scott Robohn", "guid": "8a325818-0114-5bff-9e87-71f0e8e54d86", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/KXVFXL/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/LZAXYA/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/LZAXYA/", "attachments": []}, {"guid": "c02e17e5-4315-5eb0-a893-dfc27a95d4d4", "code": "VCD7PX", "id": 113, "logo": null, "date": "2025-06-18T17:30:00-04:00", "start": "17:30", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-113-containerlab-a-modern-way-to-design-deploy-and-test-network-labs", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/VCD7PX/", "title": "Containerlab - a Modern way to Design, Deploy, and Test Network Labs", "subtitle": "", "track": "Beginner", "type": "Presentation", "language": "en", "abstract": "Containerlab is a modern open source tool to orchestrate and manage container based labs. During this session, we will provide an introduction to Containerlab and its features, deployment examples with container and VM based images followed by packet capture methods using Wireshark and Edgeshark.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "KWJD7X", "name": "Saju Salahudeen", "avatar": null, "biography": "Saju Salahudeen is a Principal Consulting Engineer for IP Networks at Nokia and a member of NANOG Education Committee. He has 19 years of experience in the industry with 13 years in IP Networking and Multi-Vendor Network Automation. In his current role, his focus area is to help Webscale networks adapt to the current and future demands of the industry. Prior to this, he was a Senior Sales Engineer for IP and Network Automation at Nokia.", "public_name": "Saju Salahudeen", "guid": "e3fadda1-68e8-54a9-9641-8f45e3957c61", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/KWJD7X/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/VCD7PX/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/VCD7PX/", "attachments": []}, {"guid": "9979f10b-175a-59b5-9169-04256e50b99a", "code": "8YFL7L", "id": 109, "logo": null, "date": "2025-06-18T18:30:00-04:00", "start": "18:30", "duration": "03:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-109-sponsor-technology-showcase-reception-espcape-group-packet-challenge-and-dinner", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/8YFL7L/", "title": "Sponsor Technology Showcase Reception, esPCAPe Group Packet Challenge and Dinner", "subtitle": "", "track": "Organization", "type": "Dinner", "language": "en", "abstract": "Sake's esPCAPe Group Packet Challenge is back!", "description": "Sake's esPCAPe Group Packet Challenge is back!", "recording_license": "", "do_not_record": false, "persons": [{"code": "MZ9HCA", "name": "Sake Blok", "avatar": "https://conference.wireshark.org/media/avatars/profile-2025-400x400_hgdKmpu.png", "biography": "Sake has been analyzing packets for over 20 years. During his work, Sake started developing functionality for Wireshark while working with the analyzer in his day-to-day job. He also enhanced multiple protocol dissectors. In 2007, Sake joined the Wireshark Core Development team. In 2009, After working for a reseller of networking equipment for 8 years, he started the company SYN-bit to provide network analysis and training services to enterprises across Europe.", "public_name": "Sake Blok", "guid": "eeeda75a-cc6d-5a94-ba7c-2d3d6f14dd59", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/MZ9HCA/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/8YFL7L/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/8YFL7L/", "attachments": []}], "Grand Ballroom Salons A-D": [{"guid": "ed1c2317-405b-5867-93e6-332e6ee462f3", "code": "8K9FHW", "id": 149, "logo": null, "date": "2025-06-18T08:45:00-04:00", "start": "08:45", "duration": "01:00", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-149-solving-cybersecurity-with-ja4-network-fingerprinting", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/8K9FHW/", "title": "Solving Cybersecurity with JA4+ Network Fingerprinting", "subtitle": "", "track": "Security", "type": "Presentation", "language": "en", "abstract": "In this presentation I will explain how JA4+ network fingerprinting works and show you how to use it to detect malware clients, their c2 servers, reverse SSH shells, connections from proxies and VPNs, estimating the location of the true client behind the proxy or VPN, and a lot more, all just by passively looking at the network traffic with JA4+ and without the need to break encryption. \r\n\r\nJA4+ is free and available across a wide range of open source and vendor tools you already use including Wireshark, Zeek, Arkime, Suricata, Censys, Vectra, etc.", "description": "", "recording_license": "", "do_not_record": true, "persons": [{"code": "HVYVCB", "name": "John Althouse", "avatar": "https://conference.wireshark.org/media/avatars/John_Althouse_BHutfxp.PNG", "biography": "John Althouse was previously at Salesforce for 10 years as the Director of Threat Detection. While there, John and his team created notable network fingerprinting methods such as JA3/S, JARM, and HASSH, used throughout the industry. He is now working on JA4+ network fingerprinting to solve as many cybersecurity challenges as possible.", "public_name": "John Althouse", "guid": "61396cc9-4f1b-5cc6-9f3d-3d952e72c824", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/HVYVCB/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/8K9FHW/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/8K9FHW/", "attachments": []}, {"guid": "70e1a890-2638-56ba-91d7-d3c279cc90ae", "code": "SWZ3VP", "id": 130, "logo": null, "date": "2025-06-18T10:00:00-04:00", "start": "10:00", "duration": "01:00", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-130-packet-stories", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/SWZ3VP/", "title": "Packet Stories", "subtitle": "", "track": "Expert / Developer", "type": "Presentation", "language": "en", "abstract": "To be the network or not to be the network!\r\n\r\nThis is a question we face a lot. The network is blamed by default, but is it really the network. During this session a couple of real life cases will be presented. What was the problem, how was it analyzed, what can we learn about the process and off course the answer to the question: was it the network?", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "MZ9HCA", "name": "Sake Blok", "avatar": "https://conference.wireshark.org/media/avatars/profile-2025-400x400_hgdKmpu.png", "biography": "Sake has been analyzing packets for over 20 years. During his work, Sake started developing functionality for Wireshark while working with the analyzer in his day-to-day job. He also enhanced multiple protocol dissectors. In 2007, Sake joined the Wireshark Core Development team. In 2009, After working for a reseller of networking equipment for 8 years, he started the company SYN-bit to provide network analysis and training services to enterprises across Europe.", "public_name": "Sake Blok", "guid": "eeeda75a-cc6d-5a94-ba7c-2d3d6f14dd59", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/MZ9HCA/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/SWZ3VP/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/SWZ3VP/", "attachments": []}, {"guid": "8f4580e9-16cb-59b3-a8bb-986f04c760f2", "code": "LXN79C", "id": 108, "logo": null, "date": "2025-06-18T15:00:00-04:00", "start": "15:00", "duration": "02:15", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-108-tales-of-a-system-call-spelunker-using-sysdig-and-stratoshark-to-examine-system-internals", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/LXN79C/", "title": "Tales of a System Call Spelunker - Using sysdig and Stratoshark to examine system internals", "subtitle": "", "track": "Expert / Developer", "type": "Workshop", "language": "en", "abstract": "Ahead of time, please ensure you have both Wireshark (www.wireshark.org) and Stratoshark (www.stratoshark.org) installed, and download the session resources from Github: https://github.com/je-clark/sharkfest-25-us-stratoshark\r\n\r\nWith the recent release of Stratoshark, we finally have a familiar tool that helps us understand how the internals of servers and operating systems function. This talk will walk through some basic examples of how to set up and run sysdig to gather system call captures, and how to use Stratoshark to gain a deeper understanding of what runs on our networks.\r\n\r\nFrom this talk, expect:\r\n- Detailed sysdig and Stratoshark capture information\r\n- Examples showing how packet data from Wireshark shows up in a Stratoshark capture\r\n- Examples of real life troubleshooting with Stratoshark", "description": "", "recording_license": "", "do_not_record": true, "persons": [{"code": "LJMB8P", "name": "Josh Clark", "avatar": "https://conference.wireshark.org/media/avatars/a6cf3a193a4d11c2267b2c91698d3492_ikPSVyM.jpg", "biography": "Josh has both academic and real-world experience in the world of protocol analysis. He holds an M.S. degree in Computer Engineering with a focus in network engineering and has spent the past 8 years designing, troubleshooting, and optimizing networks and applications. He is a Wireshark Certified Analyst.", "public_name": "Josh Clark", "guid": "29a8c981-dca2-5ee5-aa17-869b6103ca3b", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/LJMB8P/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/LXN79C/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/LXN79C/", "attachments": []}, {"guid": "466242e7-9e1e-5405-85e0-82177e071a4f", "code": "XMXZMK", "id": 122, "logo": null, "date": "2025-06-18T17:30:00-04:00", "start": "17:30", "duration": "01:00", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-122-cybershark-3001-capture-and-decrypt-wifi-traffic-from-any-device", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/XMXZMK/", "title": "CyberShark 3001 - Capture and Decrypt Wifi Traffic from any device", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "Ever struggled with capturing traffic from your mobile device or felt stumped by encrypted applications? Dive into this comprehensive session to build your very own wired or wireless traffic sniffer using a Raspberry Pi.", "description": "n this engaging workshop, you'll explore:\r\n\r\n\u2022 Selecting the ideal Raspberry Pi hardware and components. \u2022 Choosing the best Raspbian OS versions. \u2022 Building proper interface and routing configurations. \u2022 Setting up a wireless AP. \u2022 Generating and installing certificates. \u2022 Setting up a TLS proxy to export session keys. \u2022 Connecting devices to capture their traffic. \u2022 Limitations of the device and configuration. \u2022 Addressing critical security and privacy considerations associated with the device. Walk away with the confidence and knowledge to construct a wireless capture device, granting you the power to decrypt and troubleshoot applications with ease(results may vary)", "recording_license": "", "do_not_record": false, "persons": [{"code": "LVXUVN", "name": "Ross Bagurdes", "avatar": "https://conference.wireshark.org/media/avatars/Bagurdes_Headshot_SjVuW0O.jpeg", "biography": "Ross has had a diverse career in engineering, beginning as a structural engineer, then project engineer for a gas utility, Ross was always quickly\r\nassigned the de-facto network administrator, typically after no one else was brave enough to break, and later fix, the network. This lead to working as a network engineer designing and implementing enterprise networks for a major university hospital. Here he worked with\r\nExtreme Networks, HP, Cisco, Tipping Point, among other network technology, as well as honed his Wireshark and protocol analysis skills. Ross\r\nspent 7 years teaching data networking at Madison College, and in 2017 started authoring and producing IT training videos in Wireshark/Protocol\r\nAnalysis, Cisco, and general networking topics for www.Pluralsight.com. In his free time, you'll find Ross and his dog at the beach swimming and\r\nsurfing, traveling, hiking, or snowboarding somewhere in the western US.", "public_name": "Ross Bagurdes", "guid": "0def5250-101e-527e-a22d-2ffc2ecf9ad9", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/LVXUVN/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/XMXZMK/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/XMXZMK/", "attachments": []}]}}, {"index": 6, "date": "2025-06-19", "day_start": "2025-06-19T04:00:00-04:00", "day_end": "2025-06-20T03:59:00-04:00", "rooms": {"Grand Ballroom Salon E": [{"guid": "87c46c23-7224-52c8-9dba-d55c922f8c35", "code": "CSJGR9", "id": 105, "logo": null, "date": "2025-06-19T09:00:00-04:00", "start": "09:00", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-105-sharkbytes", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/CSJGR9/", "title": "SharkBytes", "subtitle": "", "track": "Organization", "type": "Organization", "language": "en", "abstract": "Come and enjoy an interesting session with learning interesting stuff about each other!", "description": "SharkBytes are great fun and a highlight of the SharkFest conferences. Each year, attendees offer glimpses into their lives by speaking about a particular interest or hobby (unrelated to Wireshark!) that reveals a side of them that fellow SharkFesters would not otherwise know.\r\nIf you want to volunteer to present a 5-minute Byte, please send us an email:\r\nsharkfest@wireshark.org", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/CSJGR9/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/CSJGR9/", "attachments": []}, {"guid": "a130e492-b537-52c1-9d5e-1799a7dfd51e", "code": "UPXCGM", "id": 112, "logo": null, "date": "2025-06-19T10:15:00-04:00", "start": "10:15", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-112-pcap-ng-packets-and-packet-like-objects", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/UPXCGM/", "title": "pcap-NG, packets, and packet-like objects", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "Pcap gives us a way to log packets - but pcap-NG gives us a way to log packets, packet-like objects, and environmental metadata to fully understand the capture.  An introduction to generating pcap-NG logs from multiple (even hundreds) of interfaces, metadata, custom packet types, and custom meta-data.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "DJRGWV", "name": "Mike Kershaw", "avatar": null, "biography": "Mike Kershaw is the creator and maintainer of Kismet, a wireless discovery and IDS system.  He has worked on enterprise Wi-Fi security, Android phones, radio protocol manipulation, and now works for Hak5 on the WiFi Pineapple and other red-team tools.", "public_name": "Mike Kershaw", "guid": "133da8ac-a2ab-5acd-a959-18ee0f92d15d", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/DJRGWV/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/UPXCGM/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/UPXCGM/", "attachments": []}, {"guid": "658d7caf-615d-5c30-85cd-3691d79e29bd", "code": "YBBEH7", "id": 95, "logo": null, "date": "2025-06-19T11:30:00-04:00", "start": "11:30", "duration": "01:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-95-capturing-in-unusual-places", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/YBBEH7/", "title": "Capturing in unusual places", "subtitle": "", "track": "Intermediate", "type": "Presentation", "language": "en", "abstract": "This session will demonstrate the capability for Wireshark and tshark to be a more versatile tool for packet capture.", "description": "Capturing on stuff beyond traditional pure network cables, like:\r\n\r\n* Google Chrome network logs\r\n* Bluetooth\r\n* USB", "recording_license": "", "do_not_record": false, "persons": [{"code": "RFDHVJ", "name": "Roland Knall", "avatar": "https://conference.wireshark.org/media/avatars/RFDHVJ_Twx9SMI.webp", "biography": "I am a Wireshark Core Developer since 2016 and interested in all things Wireshark", "public_name": "Roland Knall", "guid": "eee7cd60-caea-5893-9691-e622c7a61f95", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/RFDHVJ/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/YBBEH7/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/YBBEH7/", "attachments": []}, {"guid": "05abf51b-53a0-5ab6-9203-b4f347cd8e34", "code": "NXSMZR", "id": 101, "logo": null, "date": "2025-06-19T12:30:00-04:00", "start": "12:30", "duration": "02:00", "room": "Grand Ballroom Salon E", "slug": "sharkfest-25-us-2024-101-lunch-closing-remarks-and-farewell-reception", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/NXSMZR/", "title": "Lunch, Closing Remarks and Farewell reception", "subtitle": "", "track": "Organization", "type": "Organization", "language": "en", "abstract": "Closing Remarks and Farewell reception", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/NXSMZR/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/NXSMZR/", "attachments": []}], "Grand Ballroom Salons A-D": [{"guid": "682ed0c5-527d-55a3-8dae-23606dc0d6cc", "code": "EKZSBK", "id": 148, "logo": null, "date": "2025-06-19T10:15:00-04:00", "start": "10:15", "duration": "02:15", "room": "Grand Ballroom Salons A-D", "slug": "sharkfest-25-us-2024-148-0-wireshark-plus-advanced-analytics-better-together-2-part-session", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/EKZSBK/", "title": "Wireshark plus Advanced Analytics \u2013 Better Together (2 part session)", "subtitle": "", "track": "Expert / Developer", "type": "Workshop", "language": "en", "abstract": "Real life troubleshooting a difficult 3rd party software performance issue with using Wireshark and Advanced Analytics", "description": "Join us for a troubleshooting deep dive into solving a difficult problem occurring within Webex login from 2018, known as the 98% hang condition.  We\u2019ll showcase how the partnership of Wireshark and Advanced Analytics can be leveraged to quickly isolate the fault domain.  Captures will be provided for use during the session.  Session is half presentation and half hands-on lab with Wireshark.", "recording_license": "", "do_not_record": false, "persons": [{"code": "C7MNXL", "name": "John Pittle", "avatar": null, "biography": "As a Performance Management Strategist, John helps his customers develop and execute strategies for integrating Performance Management as an IT discipline across the organization. He has been actively focused on Performance Engineering and Analysis for networks, systems, and applications since the early 90s; performance troubleshooting is his passion and joy. His packet analysis toolbox includes Wireshark (of course), as well as NetShark, AppResponse, Packet Analyzer, and Transaction Analyzer.", "public_name": "John Pittle", "guid": "a0c62c9e-a48b-504e-be3e-c6b14d4764c8", "url": "https://conference.wireshark.org/sharkfest-25-us-2024/speaker/C7MNXL/"}], "links": [], "feedback_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/EKZSBK/feedback/", "origin_url": "https://conference.wireshark.org/sharkfest-25-us-2024/talk/EKZSBK/", "attachments": []}]}}]}}}