10th (Conference) & 11th (Workshops) September 2026

Germany's community InfoSec conference

Goethe University Frankfurt

0Attendees
0Talks
0Workshops
0Editions
Lineup

Featured Speakers

Full schedule →
Jörn Schneeweisz

Jörn Schneeweisz

Principal Security Engineer, Gitlab

"Keynote"

Jörn Schneeweisz is a Principal Security Engineer at GitLab who managed to turn a decade of breaking other people's broken Ruby on Rails code into a legitimate corporate career, because apparently, getting paid to tell companies how bad their security is qualifies as a real job.

LinkedIn
Christian Biehler

Christian Biehler

Managing Director, bi-sec GmbH

"Pentesting in the age of AI - where are we?"

With over a decade of experience in the field, Christian Biehler is a seasoned IT security expert who combines the perspectives of a hacker, penetration tester, consultant, and trainer. His technical focus lies in securing Windows infrastructures and the Microsoft Cloud stack, including Entra ID, Azure, and M365. Christian holds a Master's degree in IT Security and the CISSP certification. He has successfully delivered over 300 projects across diverse sectors, establishing deep expertise in security architecture, risk management, and penetration testing for web, mobile, and operating systems. Since 2019, Christian has been the Managing Director of bi-sec GmbH, leading a firm dedicated to expert consulting, rigorous penetration testing, and specialized security training.

Maurice Fielenbach

Maurice Fielenbach

Founder, Hexastrike Cybersecurity

"What Windows 11 Remembers (And Most Investigators Miss)"

With over 10 years of experience in cybersecurity, Maurice Fielenbach started on the offensive side before moving into defensive security. He has worked hundreds of cyber investigations, including major ransomware and APT cases across industries affecting millions of people. Among them was one of the largest ransomware incidents in German history, targeting a communal IT service provider and disrupting public infrastructure at scale. Today he focuses primarily on threat intelligence and malware analysis. He is the founder of Hexastrike Cybersecurity, where he trains blue teams in digital forensics, malware analysis, and threat hunting through hands-on, scenario-driven sessions built from real incidents. His research is regularly featured in leading cybersecurity publications and cited by industry peers. He speaks at security conferences and contributes open-source tooling and detection content used by security teams worldwide.

Tim Schmidt

Tim Schmidt

IT Security Researcher & Penetration Tester

"Hacking Consumer Drones: From Flash Dumping to Root Exploits"

Tim Schmidt is an IT security researcher and penetration tester with over a decade of experience in competitive Capture The Flag (CTF) environments. While his core expertise lies in web and application penetration testing, his technical background also spans IoT and embedded reverse engineering and smart contract audits. An avid builder, Tim frequently develops software projects and custom IoT appliances from scratch in his free time. As an educator, he has delivered specialized trainings on modern authentication technologies and cryptographic attacks for corporate clients in Germany and at international security conferences, such as HITB Amsterdam.

Kolja Grassmann

Kolja Grassmann

Security Researcher, Neodyme

"Keyless Entry: Hacking SwitchBot Smartlocks"

Kolja is a Security Researcher and Trainer at Neodyme. He specializes in Windows and Active Directory security. He has found vulnerabilities in widely used security products and has extensive exploit development, pentesting, and red teaming experience.

Stephan Berger

Head of Investigations, InfoGuard

"Deconstructing Modern macOS Initial Access Vectors"

Stephan Berger is the Head of Investigations for an Incident Response team at InfoGuard, a Swiss-based cybersecurity firm. With over a decade of experience investigating complex network compromises, he specializes in the technical intersection of offensive tradecraft and defensive forensics. Stephan is the author of the DFIR.ch technical blog and is a regular speaker at international security conferences, including FIRST, Troopers, and hack.lu. He holds a Bachelor's degree in Computer Science and a Master's degree in Engineering and is the founder of Malmium, a specialized technical training provider.

Aaron Jewitt

Principal Detection Engineer, Elastic

"Lessons learned while building an Agentic SOC: The good, the bad, and the scary."

Aaron Jewitt is a Principal Detection Engineer on the Elastic Infosec team. A 20-year security veteran with 10 years of offensive experience at the NSA and 10 years of experience defending networks, he specializes in detection engineering and high-velocity automation. Aaron is currently leading internal efforts to integrate AI agents into daily SecOps. Aaron lives in Germany and is a two-time speaker at BSides Frankfurt, dedicated to sharing practical, real-world lessons from the front lines of defense.

Our Sponsors

Made possible by

BSidesFrankfurt wouldn't exist without the generous backing of our sponsors and partners.

Gold Sponsors

Silver Sponsors

Bronze Sponsors

Community Partners

NVISO Made possible by
★ Community initiative

BSides Women

A BSides Frankfurt initiative supporting more women in cybersecurity - discounted tickets thanks to NVISO, plus a welcoming space for speakers, attendees, and partner communities.

Learn more →
Latest

Updates

All updates →
Tickets · 20 Mar 2026

Early-bird tickets now available

Limited early-bird tickets at reduced price are on sale. Student rate also available with valid university enrollment.

What is BSides

A conference built by the community

BSides is a community-driven framework for organizing information security conferences. Originally conceived in the US in 2009 to remove the barrier to entry and provide a more intimate atmosphere for networking and collaboration.

Community

BSidesFrankfurt is organized by the community, for the community. Our goal is to provide a platform for knowledge sharing, networking, and collaboration among information security professionals, researchers, and enthusiasts. We believe in an open and inclusive environment where everyone is welcome to participate and contribute.

Technical

We focus solely on technical content. You won't find any vendor pitches or marketing presentations at BSidesFrankfurt. Our talks and workshops are selected based on their technical merit and relevance to the security community. We cover a wide range of topics, including offensive security, defensive strategies, forensics, reverse engineering, and more.