The podcast came first

ISTS — "i sh0t the sheriff" began in 2006 as a Brazilian information security podcast with three hosts: Luiz Eduardo dos Santos, Nelson Murilo Rufino and .

Caprino's own account of how it started is unusually plain about the mechanics. The three worked in information security, lived in different cities — Luiz Eduardo in a different country altogether — and shared an affinity for the subject that sometimes converged and sometimes did not. It was Luiz Eduardo's idea, and he spent months insisting they record a pilot.

That detail matters for everything that followed. The event was not conceived as an event. It grew out of a recurring conversation between three people who already had an audience, and the conference kept the register of the thing it came from: unhurried, opinionated, and closer to a conversation among peers than to a lecture.

The podcast did not stop when the conference started. It is still recording, with scripts credited to the same three names and production by Halfmouth Podcasts; episodes past number 140 were being published in the mid-2020s. Nearly twenty years of continuous output makes it one of the longest-running security podcasts in Portuguese.

The three founders

Luiz Eduardo dos Santos — the one who pushed for the pilot, and the founder whose work has been most international. He has spent his career across countries, which is part of why the conference has never read as a purely local event.

Nelson Murilo Rufino — the author of chkrootkit, the rootkit detector that has been part of the Unix security toolkit since the late 1990s and is still being released: version 0.57 shipped in January 2023. That is an unusual thing to be able to say about a security tool, and it makes him one of the few conference founders anywhere whose own code is still installed on other people's servers decades later. He has given his own account of both the tool and the conference's founding in interviews.

Willian Caprino — the founder who has written most openly about how the event was actually made, in a piece whose title translates roughly as "how we made the most talked-about security event in Brazil". The organisation trades as STS Produções e Eventos.

What the event is, and the rule that shapes it

The first edition ran in 2007. By 2026 it had reached its eighteenth.

Three decisions define it, and all three are deliberate refusals to grow:

It is invitation-only. Attendance is by invitation from a sponsor. There is no open registration, which means the guest list is curated rather than sold.

The venue is secret. The location is chosen carefully and kept undisclosed, revealed only to those confirmed to attend.

The size is capped on principle. At the tenth edition the three founders opened by discussing the distance between the first and the tenth, and by describing their work to keep the event the same size — on the stated belief that more attendees would cost them the quality they had. Conferences almost never say this out loud, because the incentive runs the other way: sponsors pay for reach, and reach is headcount.

The result is a single day that behaves like a very good corridor track with talks attached. The stated aim is to bring the technical and managerial audiences into one room, which in most conferences is a slogan and here is a seating problem they actually solve.

The first edition, from a founder's own account

Caprino's write-up of how the event was assembled names the people they picked by hand from their own network for that first year, and the line-up says what they were reaching for:

Felix "FX" Lindner — the German hacker, who spoke on mobile device malware in the era of the first iPhone, Symbian, Windows Mobile and BlackBerry. Nobody was talking about Android yet.

Rodrigo "BSDaemon" Rubira Branco — on whether the world ends when an operating system kernel faults. He has since become one of the most requested keynote speakers in the country, to the point where the community joke is that inviting him guarantees at least one talk of real quality.

Augusto Paes de Barros — on detecting insider threats, a subject he introduced as the "not so cool" one.

Nick Farr — on hackerspaces, a topic then unheard of in Brazil. Alberto Fabiano, co-founder of and now deceased, told Caprino that this talk was the first time he ever heard of the idea. Garoa is today the best-known hackerspace in the country, and the chain runs back through that room.

The editorial rule behind those choices is stated just as plainly: content had to come first, with no product-pitch filler, and the speakers had to be names the founders themselves respected. The venue was to be a bar or a pub, with beer and caipirinha freely available, on the argument that learning and enjoying yourself are not mutually exclusive. And it had to mix technical talks with managerial ones, because at the time the gap between the two audiences was wide and nobody was bridging it.

The Brazilian names the room is known for

Nelson Brito — the creator of T50, the packet injection and stress-testing tool, and a researcher known for work published under names like Permutation Oriented Programming and Fingerprint. His speaking record runs through IME, CNASI, CONIP, SERPRO, ITA, , and , and he was the only Brazilian to present at PH-Neutral in Berlin in 2011.

Who has been on that stage

The programme has mixed people who built the international scene with people who built the Brazilian one — which is the clearest evidence of what the founders' reach actually is.

Jeff Moss — founder and creator of both and the Briefings, former Chief Security Officer at , a member of the CISA Cyber Security Advisory Council, and technical advisor to the television series Mr. Robot. The two conferences he created are the reference points against which every other security event in the world is described.

Cris Thomas, "Space Rogue" — a member of , the first security research think tank, and creator of the Hacker News Network. He is one of the L0pht members who testified before the US Senate Committee on Homeland Security and Governmental Affairs, and has since worked at @stake, Guardent, Trustwave, Tenable and IBM X-Force.

Deviant Ollam, of TOOOL — the Open Organisation of Lockpickers — opened the fifth edition in May 2011 with a talk on the basics of lockpicking, and sold kits to the room afterwards. That edition set an attendance record, and the lockpicking talk was the one people talked about most.

Fábio Assolini presented at that same fifth edition on how Brazilian criminals put stolen personal data to work — two days after giving a different talk at GTS, which is what a dense week in the Brazilian calendar looks like.

Alongside them, the people who carry the Brazilian scene:

  • — founder of São Paulo, a figure at Garoa Hacker Clube, director of the 's Brazil chapter, and the author of the conference calendar that much of the Brazilian community plans its year around.
  • Nelson Novaes Neto — one of the partners behind the creation of C6 Bank, an MIT affiliated researcher, published in the Harvard Business Review on security leadership.
  • Rodrigo "Sp0oKeR" Montoro — threat detection engineer with two patented detection technologies, and a fixture across AppSec, SANS, Toorcon, SecTor and Black Hat Brazil.
  • Thiago Bordini — cyber threat intelligence lead, and part of the Security BSides São Paulo organisation.
  • Fábio Assolini and Fábio Marenghi — Kaspersky malware analysts working on the Latin American threat landscape, the region where Brazilian banking fraud is researched from the inside.
  • Gustavo Palazolo, Julio Della Flora, Letícia Freitas, Flávio Bontempo and others across detection, hardware, identity and awareness.

The event also runs formats that only work at its size, including a one-to-one debate between security executives on a topic drawn on the spot.

One structural detail is worth knowing, because it shapes the whole Brazilian May: YSTS is scheduled immediately after BSides São Paulo, on consecutive days. The free, open, community event runs on the Sunday and the invitation-only one on the Monday, and the same people move between them. treats the pair as a single weekend rather than as competitors.

The formats the size makes possible

InfoSec Arena was built for the event and run by Anchises Moraes from its second outing: the audience submits questions by Twitter and on paper forms, the topics are drawn at random, and whoever is in the room answers. In 2011 the questions that caused the most argument were certification and professional ethics, and the ones worth remembering were about embedded systems, metrics that justify security spending, and how few women were in the field. A debate where the agenda is drawn from a hat only works if the room can be trusted to carry it.

The modern equivalent is the CISO versus CISO anti-panel, where two security executives take opposite sides of a topic decided on the spot.

What the call for papers actually offers

The event's own call for papers is unusually explicit, and it explains the loyalty around it:

  • Travel support of USD 1,000 for international speakers, or R$ 1,200 for Brazilian speakers based outside São Paulo.
  • Meals throughout, and the official party before and after — plus, in the CFP's own phrasing, the unofficial ones.
  • Lifetime free admission to every future edition for anyone who has ever spoken. At an event you otherwise cannot buy your way into, that is the most valuable thing on the list.
  • Talks in both 30-minute and 15-minute formats, with first-time speakers explicitly welcomed and new research preferred — the CFP notes that people have released work at YSTS before taking it to the bigger conferences later in the year.

The people who make it happen

The founders name their crew publicly, which not every conference does: André Trindade, Carlos Cabral, Cleber "Clebeer" Brandão, Evelise Morais and Rodrigo Montoro have been thanked by YSTS for years of work behind the event. A conference whose whole proposition is a curated room and a secret venue depends entirely on the people managing both.

Why it matters beyond the guest list

Brazil's security community has a well-populated calendar — H2HC, BSides São Paulo, , Nullbyte and a long regional circuit. YSTS occupies a position none of the others do, and the reason is structural rather than editorial: it is the one that deliberately did not scale.

That choice has a cost, and it is worth stating. An invitation-only event with a hidden venue is, by construction, harder to enter for anyone without a sponsor relationship — the opposite of the BSides model, which exists precisely to lower that barrier. The two formats are not in competition so much as in balance, and a healthy scene needs both: one that anybody can walk into, and one where the people who run things end up talking to each other for a day.

What makes the arrangement durable is that the founders never stopped doing the thing that produced it. The podcast still records. Nearly two decades of that is what an invitation is actually backed by.

Sources