Skip to main content

My journey at OBTS v8.0 - Trainings, Talks & CTF

·6 mins· loading · loading · ·
Table of Contents

First of all, I would like to thank everyone who made this possible: the Objective-See Foundation, the organizers, the trainers, speakers, sponsors, and all the attendees who made the week so welcoming.
But most importantly: thank you to Andy Rozenberg and Patrick Wardle for selecting me for a full scholarship to attend Objective by the Sea (OBTS) v8.0! It covered my flight, hotel, training and conference ticket.


What’s OBTS v8.0?
#

Objective by the Sea (OBTS) is one of the must-attend conferences for Apple platform security (macOS, iOS, watchOS, etc.).
OBTS v8.0 took place in Ibiza (Spain) in October 2025, with:

  • 3 days of training (October 12th to 14th)
  • 3 days of talks (October 15th to 17th)
  • plus community events, including a CTF

The conference is organized by the Objective-See Foundation, a non-profit that creates free macOS security tools, supports the community, and runs programs like Objective-We (mentorship, training, scholarships, conference etc.).

If you are into Apple security, OBTS is basically the best conference for you since it’s the one and only that is completely dedicated to Apple systems.


Why I applied for a scholarship
#

A few months before OBTS, I attended OFTW v3.0 in London (also organized by the Objective-See Foundation). I wrote a full debrief here:

At OFTW I met Andy & Patrick, and Andy encouraged me to apply for the OBTS scholarship.

I’m currently a French cybersecurity student (Master’s degree) at Γ‰cole 2600 and I’ve spent the last few years learning about forensic, IR, reverse and a bit later on, Apple security, especially iOS. I also do a lot of CTF solo and with my college team Phreaks2600.


Training
#

At OBTS v8.0, I attended:

iOS Threat Hunting & Malware Analysis
#

This training by Matthias Frielingsdorf was exactly what I was looking for:

  • It connected perfectly with my current interests: iOS internals and forensics on cool stuff like spyware 🀠
  • It helped me structure things I had learned “piece by piece” into a clearer mental model: what to collect, what to look for, how to reason about artifacts, and what “good” looks like when you do mobile triage / threat hunting.

One of my favorite parts was simply being able to ask questions and have direct feedback.


Talks
#

The talk lineup was stacked. Instead of trying to summarize everything, here are a few talks that I personally loved and that I recommend watching / reading about (everything is available on OBTS Youtube channel or website):


The OBTS CTF
#

There was a CTF during the conference which was pretty cool!

I wrote some writeups so don’t hesitate to check this out: https://jaybird1291.github.io/blog-cyber/posts/obts-v8/


Community / networking
#

Technical content is really cool, but OBTS is also about the community and networking.

I had conversations with:

  • students who are grinding just like me,
  • really cool and interesting researchers,
  • people working in incident response / threat intel / product security,
  • and people who have been in Apple security for a long time.

Being in that environment makes you raise your own standards and really motivate you to work harder.


About the scholarship
#

What I put forward in my application was:

  • A clear technical focus (Apple platform security, especially iOS) and why it matters to me.
  • Proof of work: blog posts, writeups, CTF etc.
  • Relevant experience (what I’ve done in internships etc., what I’ve learned from classes, CTF etc.).
  • A concrete reason OBTS was the right place (specific trainings/talks that matched my interests, and what I hoped to learn).
  • What I would do with the opportunity afterward: keep publishing, keep practicing, and convert the week into output rather than letting it fade.

Also: I tried to make it easy for the reviewers to understand my trajectory in two minutes. If you apply, keep it simple: show that you’re serious, that you’ve already started to learn, and that the scholarship will actually amplify momentum that already exists.

Most importantly, just ask. Be polite, be honest about your constraints, and show that you’re ready to work. Even if you don’t get it, you lose nothing and sometimes you get what you wanted.


Don’t hold back, apply, ask, try
#

It really sounds stupid LinkedIn stuff but it’s actually true lol. Just, never self-reject for no good reasons. I say this because it happened a lot for me and friends.

Don’t assume you’re “not good enough” to apply to a scholarship, a conference, a training, a job, a mentorship program, a CTF team, etc.

  • Apply.
  • Ask.
  • Work.
  • Try (even if you could eventually fail).

Even when you don’t get what you want the first time, you still get something: experience, feedback, connections, and momentum. And over time, that gets rewarded.

So if OBTS / OFTW / anything like this is what you want just go for it.


How to get the most out of OBTS
#

Such a conference can be overwhelming, especially as a student / noob. If you’re coming as a student a few simple habits will make a massive difference:

  • Prepare your “professional surface area.”
    Refresh your LinkedIn, make sure you have a clean way to share your work (a blog, GitHub etc.), and publish a couple of notes/writeups you’re comfortable standing behind. Also, have a dedicated contact channel ready (a professional email address, a Discord handle you actually monitor, etc.).

  • Do a small “pre-OBTS warm-up” the week before.
    Skim past OBTS/OFTW talks & slides, refresh the basics you know you’ll need (macOS internals, iOS architecture, reversing fundamentals, common security primitives).

  • Set a goal that’s realistic and measurable.
    Mine was: (1) learn more about iOS security, (2) leave with a concrete resources list (talks, articles, blog posts, trainings etc.), and (3) meet people I can learn from.

  • Treat trainings like a lab, not like a lecture.
    Take notes in a way you can reuse later: commands, decision points, “if X then Y” logic, and pitfalls. After each day, rewrite the messy notes into a short checklist while it’s still fresh.

  • Ask questions early, even if they feel “basic”.
    Think about the gap between “I kind of get it” and “I can apply it”.

  • Use the hallway track intentionally.
    Pick 2-3 topics you genuinely care about (iOS security, forensics / malware / threat hunting) and start conversations around those. It’s easier than trying to “network” in the abstract, and you’ll meet the right people naturally.

  • Follow up after the conference.
    Send a short message to people you met (“thanks for the chat about X, here’s what I’m reading/trying next”). If you publish a writeup/debrief, share it.

If you’re hesitating because you think you’re “not advanced enough” that feeling is normal. I felt it too, and I guess most people do. But after receiving scholarships for OFTW v3 and OBTS v8 etc., I realized that actually most people in this community are genuinely approachable and truly want to help.


Resources
#

Official links:

Other write-ups / references (worth reading):