Skip to content

Keynotes

GrrCON 2026

Keynotes

Five stage-defining sessions across two days. 

keynote1

GrrCON Awakening: Truth, Tactic, Talent – How Humans Win

George Kamide, Dr. Louis DeWeaver, Dr. Chase Cunningham

What happens when the strategist who built modern Zero Trust, the raw voice of the human element, and the unfiltered truth-teller who still operates in the trenches are locked in one room with one rule: no filters, no slides, no escape? For years, the industry has been drowning in AI hype, vendor theater, and frameworks that look good on paper but die in reality. Most talks promise answers. This one is different.

Three minds. Three very different weapons. One will bring the architecture that actually holds up under fire. One will expose the human truths everyone pretends not to see. One will say the things that usually get people uninvited from stages. They’re not here to play it safe. And they’re not here to give you another checklist. What they are bringing is something that can’t be tweeted, summarized, or replayed later.

Because the real question isn’t whether humans can still win in this game. The real question is: What are you willing to do when you finally hear what it actually takes? And that answer… will only be revealed in the room. September 24th. GrrCON x15. Grand Rapids. Be there when it happens.

Wood

Thursday Afternoon Keynote

The Alert Still Fires: Defending against Frontier Model Coordinated Attacks

Aoibh Wood

Frontier AI changes the speed and scale of intrusion more than it changes the underlying tradecraft. Zero-day development remains a separate problem, largely beyond what a Security Operations Center can address in real time. But AI-coordinated attackers also use familiar techniques faster, in greater volume, and with behavioral patterns that may break human-era assumptions about triage and response. This talk examines how corporations can adapt existing controls, telemetry, and operating models for adversaries working at machine speed. The insights are that frontier model attacks are surprisingly mundane in their approach but much more capable at scale.

Mohammad Eshan

Thursday Closing Keynote

I Sent AI Agents to Call the Scammers Back

Mohammad Eshan

Scam call centers make money by keeping people on the phone. So we kept them on the phone instead.

We collected dozens of scam center phone numbers and deployed a cluster of AI voice agents to call them back. Not once. Continuously. For days. The agents wasted their time, tied up their lines, and made it harder for them to reach real victims. The entire scam playbook depends on manipulating a human into action. Buy the gift card. Read the numbers. Wire the money. But you can’t tell an AI agent to redeem a card. It’ll play along forever, and the scammer can’t tell the difference.

We didn’t stop at phone calls. Using computer-use agents through RMM tooling, we got into their infrastructure, watched how they operated, and saw how they moved money.

This talk covers the full operation: how we sourced the numbers, deployed AI voice agents at scale, and pivoted from tying up phones to accessing systems. You’ll hear real calls between our agents and actual scammers, and walk away with a blueprint for pointing offensive AI tooling at the people who actually deserve it.

Ringmast4r (Patrick Quirk)

Friday Opening Keynote

17 Governments Audited, Zero Exploits, Bloomberg Called Me Criminal

Ringmast4r (Patrick Quirk)

I have a Master’s in Cybersecurity and couldn’t get a single interview. AI gutted the job market and recruiters ghosted me, so I stopped refreshing LinkedIn and started doing passive OSINT against government infrastructure from my garage in Atlanta. Venezuela was first. Forty-eight hours later I had 167 GB of publicly accessible government data from 38 organizations without logging into anything.

The operation grew to 17 countries, 26,500+ domains scanned, 180+ government organizations affected, and 342 GB of exposed data. 314 credential sets recovered. 760,000+ PII records exposed including 572,103 Venezuelan voter records, 186 million Mexican federal records, and 86,578 Haitian national IDs. 114 git repositories dumped. A parallel global git dump across 58 countries recovered 302 GB of government source code containing 3,895 credentials and 4,801 developer identities. No exploits. No credentials tested. No auth bypassed. Strictly passive OSINT.

I founded ODINT, the Observatory for Digital Infrastructure and Network Transparency, now pending 501(c)(3). Then on February 25, 2026, Bloomberg called it a sophisticated AI-powered cyberattack. A $61M Israeli startup called Gambit Security repackaged my passive OSINT as their launch-day spectacle and fifty media outlets ran the story without contacting me. The industry that wouldn’t return my calls called me a criminal for documenting what was already public and blamed AI, the same technology that locked me out of the job market. I have publicly said on social media that it was me and nobody believes me. This talk is the actual researcher on stage with the real methodology, the real tools, and the real data.

Eliad Kimhy

Friday Closing Keynote

The History of Malware: 40 Years of Viruses, Worms, and Other Strange Creatures

Eliad Kimhy

The history of malware is weirder, funnier, and more instructive than most people realize. A ninth-grader wrote one of the first Apple II viruses as a prank because his friends had wised up to his tricks and refused to take any of his floppy disks. A macro virus from the late 90s would hijack your Word document and then play a generated audio file of someone laughing at you. A botnet author in 2005 was releasing variants so fast he started leaving angry messages for antivirus researchers embedded in the code.

But underneath the stories, there’s a consistent pattern. Each major technology shift (personal computers, the internet, and more recently, AI) triggers the same cycle: experimentation, creative mischief, and weaponization. Many of the techniques we think of as modern had all existed at one point or another, in one form or another. And for our part, we seem to consistently forget the lessons of the past, whenever a new-fangled technique comes on the scene.

This talk is a research-driven walkthrough of over 40 years of malware history, built from primary sources and forgotten security publications. We’ll trace the full arc from Creeper in 1971, through boot sector viruses spreading at the speed of sneaker shoes, the macro virus epidemic that overtook all other malware within three years, the formation of the first botnets, banking trojans that learned to drop ransomware, and the multistage attack chains we deal with today. We close by turning this historical lens toward the present moment. If every major technology shift has followed this pattern, and generative AI is the defining technology of this decade, where are we in this cycle? And what does 40 years of malware history suggest about what comes next?