
Moritz Oettle
Head of Incident Response @ HvS-Consulting GmbH, @moettle_
Moritz Oettle is an experienced Incident Responder and Head of Incident Response at HvS-Consulting GmbH. Having encountered a wide range of security incidents, he has developed deep expertise in managing, remediating, and mitigating security incidents. Passionate about sharing knowledge, Moritz contributes to the cybersecurity community through writing and training.
Key Expertise & Contributions:
- Extensive experience handling identity theft, fraud, ransomware, insider threats, and APT attacks.
- Leads response efforts in coordination, containment, analysis, monitoring, and remediation.
- Author of the blog DFIR-Delight(https://dfir-delight.de/ ), providing insights into digital forensics and incident response.
- Certified SIM3 Auditor (https://opencsirt.org/csirt-maturity/certified-auditors/ )
- CBT trainer for the Cyber Security Incident Management course, educating professionals on the topic of Incident Management.
- Certified X-Ways X-Pert.
- Co-author of TI report about a orchestrated campaign of the APT group Lazarus https://www.hvs-consulting.de/en/lazarus-report/ (2020)
- Co-author of TI report about the APT fallout of vulnerabilities such as ProxyLogon in Exchange (Hafnium), OGNL injection, and log4shell https://www.hvs-consulting.de/en/threat-intelligence-report-emissary-panda-apt27/ (2022)
talks & Q&A
The Threat from Within – Bad Insider Incidents
Description
Everybody always talks about ransomware incidents, but hardly anyone talks about bad insider incidents, when your own employees and admins become the threat. It’s true that these kinds of incidents are less common, but that also means organizations are much less prepared for them.
In this talk, we will take a deep dive into Bad Insider Incidents, look at how they differ from more common cases (Spoiler: they are very different in terms of forensics and response), and discuss how to adapt accordingly. The best part is that we will bring real-world insights from a variety of cases handled by the HvS incident response team over the years.

