>_ TRAINING

[SESSION.LIST] ROLAND SANOU — TAUGHT FROM WORK DONE, NOT FROM SLIDES COLLECTED.
ON SITE OR REMOTE, IN FRENCH OR ENGLISH.

AI tools for everyone

AUDIENCE · Any team — administration, HR, finance, teaching, management

No code, no jargon. What the tool does, and where it invents.

For people who have been told to use these tools without being told how they fail. Writing a usable request, recognising a confident answer that is wrong, and knowing what must never be pasted into a chat window — a payroll file, a patient record, a contract under negotiation.

WHAT IT COVERS
  • Writing a request that returns something usable
  • Spotting an answer that is fluent and false
  • What must never be pasted in, and why
  • Concrete uses for your own daily work

Using AI tools in technical work

AUDIENCE · Technical teams, analysts, developers

Claude and its peers, used with judgement rather than faith.

What these tools genuinely accelerate and where they quietly produce plausible nonsense. Verification discipline, what must never leave the organisation, and self-hosted inference for teams that cannot send their data out — a setup I run in production rather than one I read about.

WHAT IT COVERS
  • Real capabilities and real failure modes
  • Verifying output you did not write
  • Confidentiality: what never leaves the building
  • Self-hosted models for sensitive contexts

OSINT and exposure mapping

AUDIENCE · Security teams, SOC, audit and risk

Building a map of what an organisation exposes, without touching it.

Passive sources and what each one actually establishes, the line between passive and active, and the mistakes that make a map confident and wrong. Worked through on real methodology, not on a tool demo.

WHAT IT COVERS
  • Passive sources and their limits
  • Certificate transparency and forgotten assets
  • The authorisation boundary, in practice
  • Reporting in three states, never two

Reverse engineering and binary analysis

AUDIENCE · Analysts and security engineers

Reading a file that was not written to be read.

Binary formats and how to parse them safely when the input is hostile by design: overflowing counts, offsets outside the buffer, chunks that spin a naive loop forever. Grounded in a parser I wrote, and in the bug that taught me not to trust a round-trip test.

WHAT IT COVERS
  • PE, ELF and Android binary XML
  • Static triage without executing the sample
  • Packers, and what a missing feature really means
  • Testing a parser against a format, not against itself

REGISTER FOR A SESSION

Duration, format and dates are agreed with you: an intra-company session is scoped to the team, not sold off a shelf.

Kept for 365 days, then deleted automatically. Never passed on to anyone. Ask at any time and it goes immediately.

How this data is handled
OP_CENTER
STATUS: ENCRYPTED
SYS_BOOT.exeDOSSIER.exeREGISTRY.exeNOTES.logSERVICES.exeFORMATIONS.dirEXPOSURE.shCV_DATA.dirSECURE_CONNECT