APWG adds four cybercrime workshops ahead of eCrime 2026
APWG will open eCrime 2026 on Nov. 2 in Cambridge, Massachusetts, with four training workshops on adversary analysis, threat modeling, phishing infrastructure investigation and cybercrime-data exchange. The sessions are aimed at helping researchers, investigators and security teams turn threat intelligence into faster operational response.
Why it matters: - APWG is trying to give cybercrime defenders more practical ways to move from isolated threat reports to coordinated action. - The workshops are built for researchers, investigators, developers and security professionals who need usable methods for forensic work, intelligence operations and day-to-day security response. - The program centers on four areas that often sit in separate silos: adversary behavior, system resilience, infrastructure investigation and shared data exchange.
What happened: - APWG eCrime 2026 will open with a counter-cybercrime Training Day on Nov. 2 in Cambridge, Massachusetts. - The training runs Monday from noon to 5:30 p.m. - APWG scheduled four expert-led sessions on adversary analysis, threat modeling, phishing infrastructure investigation and cybercrime-data integration. - The workshops are part of the eCrime 2026 conference week.
The details: - Pete Herzog, co-founder of ISECOM, will lead “Modeling Adversaries Through Chaos,” a three-hour introduction to the Adversarial Analysis Model. - The adversary-analysis session focuses on a state-based framework that helps analysts assess what an attacker may be positioned to do next, rather than only what the attacker has already done. - Participants will examine behavioral states through multiple observational perspectives and use four analytical operations: Mirror, Twin, Opposite and Lever. - The workshop includes a live case involving an anonymized phishing operator and hands-on exercises. - Laurin Weissinger of the University of California, Berkeley will lead an interactive threat-modeling workshop. - That session will cover threat-modeling terminology, processes and approaches before moving into small-group exercises. - Participants will identify threats to a sample system, evaluate significance and develop mitigations. - The workshop ends with group review and discussion of how threat modeling connects to risk analysis, assessment, evaluation and treatment. - Sven Krohlas of Spamhaus will lead “Amplify the Signal: Investigating Phishing Campaigns Through Domain Clustering.” - The phishing-investigation session will show how one verified phishing report can reveal related malicious domains, hosting infrastructure and rogue networks. - Participants will use passive DNS techniques and real-world phishing examples. - The session highlights how threat intelligence can move among service providers, registries, registrars, security vendors, governments and law-enforcement agencies. - Shared indicators can support coordinated disruption, including protection for users before formal takedowns occur. - Carlos Ramirez of APWG Engineering will present “Practical API Integration: Connecting Applications to the eCrimex eXchange Data Clearinghouse.” - The API workshop is aimed at developers, analysts and technical researchers. - The session will cover eCrimex API authentication, endpoints, methods, queries and response formats. - Participants will make test calls with Postman or cURL and review workflows for retrieving and submitting cybercrime information. - The workshop will also cover common integration pitfalls and practices for reliable API use. - APWG says the program is designed to help turn dispersed observations into shared knowledge and faster operational action. - APWG says the training supports its broader goal of linking researchers, financial institutions, technology companies, infrastructure providers, governments and law enforcement in a collective response to cybercrime.
Between the lines: - The workshop lineup suggests APWG sees cybercrime defense as an end-to-end pipeline, from analysis to disruption to data sharing. - The emphasis on hands-on exercises and interoperable platforms points to a practical goal: making threat intelligence easier to use outside the lab. - The inclusion of an API integration session also signals that technical coordination is becoming as important as individual research findings.
What's next: - The four workshops will take place on Nov. 2 during eCrime 2026 conference week. - APWG is positioning the Training Day as a way to prepare attendees for more coordinated cybercrime response work after the conference. - More information is available through APWG's social channels, including Facebook and X.
The bottom line: - APWG is using eCrime 2026 to push cybercrime responders toward shared methods, shared data and faster collaboration across the public and private sectors.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Boston Technology Review
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.