Žan Urbančič
Žan Urbančič is a penetration tester and cybersecurity specialist with a comprehensive skill set in offensive security, vulnerability assessment, and security implementation. He holds multiple industry-recognized certifications, including CCNA, eJPT, eCPPTv2, CRTP, CRTE, and OSCP, demonstrating deep expertise in network security, Active Directory exploitation, and advanced penetration testing methodologies. Passionate about staying ahead of emerging cyber threats, vulnerabilities (CVEs), and security trends, he proactively identifies, analyzes, and mitigates risks to strengthen organizational security postures. His experience includes testing and deploying XDR solutions such as Cynet, SentinelOne, and Sophos, as well as working with SIEM platforms like QRadar and Splunk to enhance threat detection, incident response, and threat hunting capabilities. Žan has also participated in Locked Shields and Crossed Swords, the largest NATO cyber exercises, where he gained hands-on experience in real-world cyber warfare simulations and both defensive and offensive cybersecurity operations. These experiences have further sharpened his ability to respond to advanced persistent threats (APTs), conduct red team engagements, and support blue team operations in high-stakes environments.
Session
Preboot Execution Environment (PXE) is a widely used network boot technology that allows machines to boot over a network without local storage. However, this convenience comes with security risks. In this session, we will explore how PXE works and how attackers can exploit misconfigurations to extract passwords and gain unauthorized access. Through practical demonstrations, we will analyze real-world attack scenarios, discuss potential countermeasures, and provide security best practices to defend against PXE-based attacks.