Our Sponsors

A huge thank you to our incredible sponsors for their generous support of ROOTCON 18. Your contributions were instrumental in making this premier hacking conference possible.

The community deeply appreciates your continued commitment to advancing the hacking scene and helping us deliver an unforgettable experience. Together, we’re pushing the boundaries of knowledge, research, and innovation.


Elite




Established in 2015, Pentera is the market leader in Automated Security Validation, empowering companies to proactively test all their cybersecurity controls against the latest cyberattacks. Pentera identifies true risk across the entire attack surface, guiding remediation to effectively reduce exposure. The company's security validation capabilities are essential for Continuous Threat Exposure Management (CTEM) operations. Thousands of security professionals around the world trust Pentera to close security gaps before threat actors can exploit them.

www.pentera.io


Platinum




Eclypsium establishes trust in every endpoint, server and network appliance in enterprise infrastructure (IT, cloud, data centers, network) by identifying, verifying and fortifying 3rd-party software, firmware and hardware in every device.

Eclypsium’s platform continuously monitors firmware, hardware and software within each critical asset for threats, backdoors, implants and vulnerabilities, and mitigates supply chain risks throughout the asset lifecycle.

Powered by world-class research team, Eclypsium was named as Gartner Cool Vendor, and a winner of Fast Company’s most innovative security companies, CNBC Upstart 100, Cyber Defense Magazine’s Most Innovative Supply Chain Security, and CRN’s Stellar Startups awards.

www.eclypsium.com



The Information Security Officers Group (ISOG) was organized by a team of current and now retired Chief Information Security Officers (CISOs) from different financial institutions. Its members initially consisted of CISOs and IT security professionals that come primarily from Bangko Sentral ng Pilipinas (BSP) Supervised Financial Institutions, referred to as BSFIs.

isog-org.ph



We are a pure-play cybersecurity provider with deep experience across the Asia-Pacific region and beyond, delivering defense, offense, and incident response services to organizations of all sizes and industries.

www.theos-cyber.com



Cloudtrace secures innovation in the cloud, providing offensive and defensive cyber expertise that protects SaaS applications against emerging security threats. Our offerings include penetration testing, red teaming, incident response and 24/7 cloud-native managed security services.

www.cloudtrace.com.au



Sophos defeats cyberattacks with innovative, adaptive defenses, AI-powered analysis, and unmatched expertise to protect your business, end users, and data from complex cyber threats. Shift power back to the defender and neutralize threats with an integrated ecosystem that offers unbeatable protection at every point in the attack chain

www.sophos.com/en-us



For over 30 years, Nexus Technologies has empowered Philippine enterprises with trusted IT solutions built to protect, detect, and respond.

As its dedicated security services arm, Orion Managed Services, with over a hundred professionals, delivers end-to-end managed cybersecurity services ensuring protection for its client partners.

From infrastructure to a full range of cybersecurity solutions and services, Nexus has IT covered.

www.nexustech.com.ph



XM Cyber is a leader in hybrid cloud exposure management that’s changing the way organizations approach cyber risk. XM Cyber transforms exposure management by demonstrating how attackers leverage and combine misconfigurations, vulnerabilities, identity exposures, and more, across AWS, Azure, GCP and on-prem environments to compromise critical assets. With the XM Cyber platform, you can operationalize Exposure Management end-to-end – from holistic discovery of interconnected exposures, to context-based prioritization and factual validation, to guided remediation options – for measurable security posture improvements. XM Cyber gives you full contextual understanding of exposures across attack surfaces – from external to internal –to efficiently prioritize your remediation efforts and reduce risk. Founded by top executives from the Israeli cyber intelligence community, XM Cyber has offices in North America, Europe, Asia Pacific and Israel.

www.xmcyber.com



Traditional browsers operate without necessary protections from cyberthreats, exposing users to attacks. Menlo Security protects your browsers while preserving choice by: Managing the browser attack surface by deploying browser-security policies and forensics instantly Protecting the user and defending your enterprise Securing access and data to the last mile with trusted and proven defense As a pioneer of browser security, Menlo Security delivers a solution with a comprehensive approach to enterprise browser security, protecting users where they work and securing applications from internet-borne attacks.

www.menlosecurity.com



Qualys, Inc (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Enterprise TruRisk Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit

www.qualys.com



Gold




YesWeHack is a leading Bug Bounty and Vulnerability Management Platform whose clients include Maya, Tencent, Ant Group, and Decathlon. Founded in 2015, YesWeHack connects organisations worldwide to tens of thousands of ethical hackers, who uncover vulnerabilities in websites, mobile apps and other digital assets. YesWeHack products include Bug Bounty, Vulnerability Disclosure Policy (VDP), Pentest Management and Attack Surface Management platforms.

www.yeswehack.com



Electronic Transfer & Advance Processing Inc., or eTap Inc., is the leading and largest homegrown manufacturer and solutions provider of self-service technology in the country, having operated in the industry for the past ten years. Before entering the self-service technology space in 2015, our founders developed the first mobile banking app in the Philippines. Our transformative solutions include the customization of self-service machines, software development, nationwide cash and machine-managed services, biller integration, and data analytics. We have partnered with over 800 billers and merchants—including traditional and digital banks, e-wallet services, telecommunications companies, government agencies, and utility providers—to enhance financial accessibility and transform customer experiences through our 7,000+ self-service cash-in machines nationwide, all deployed through our clients. Our Domain Expertise: - Customizable machine manufacturing - Custom machine software development - Managed services - Biller Integration - Data and Analytics

www.etap.com.ph



RidgeBot® by Ridge Security is an AI-powered automated penetration testing platform that simulates real-world cyberattacks to identify and validate exploitable vulnerabilities across networks, applications, and APIs. It continuously tests security postures using a vast library of exploits and delivers detailed, risk-based reports with attack paths and remediation guidance. With features like ransomware simulation, web API testing, and OWASP-aligned assessments, RidgeBot® enables efficient, scalable, and low-touch security validation

Technopath Solutions Inc. is a Philippine-based IT solutions provider specializing in cybersecurity, data management, and cloud adoption. They offer a range of services—including business intelligence, managed IT operations, and environmental sustainability solutions—designed to simplify, secure, and synergize business processes. Technopath collaborates with global partners like CrowdStrike, Splunk, and Ridgeboth to deliver tailored technology solutions that drive operational efficiency and resilience for local enterprises

ridgesecurity.ai/ridgebot/
technopathsolutions.com



Cyble empowers organizations to take control of their cyber risks with AI-driven, cybersecurity platforms. We specialize in uncovering critical insights from across the Deep Web, Dark Web, and Surface Web, ensuring that our clients stay ahead of emerging threats in an ever-evolving digital landscape.

With over three decades of leadership in the Philippine tech landscape, we drive impactful digital transformation through innovations in AI, cloud computing, and big data. Committed to empowering clients and communities, we deliver purposeful solutions that shape the future with integrity and innovation. As a trusted partner, NOVARE continues to push the boundaries of technology, fostering a sustainable and inclusive digital future.

cyble.com/solutions
www.novare.com.ph/



RT&Co. Cybersecurity, formerly Mantua Cybersecurity: Safeguarding your digital fortress.

We are a premier cybersecurity services company providing unparalleled protection for your business. Our expert team deploys cutting-edge technologies and advanced threat intelligence to defend against cyber threats, ensuring the confidentiality, integrity, and availability of your critical assets.

RTCyber is a CREST-certified organization for Penetration Testing and a Security Operations Center (SOC). From robust network security monitoring solutions to comprehensive vulnerability assessments and penetration testing, code review, ISMS consulting, monitoring, and digital forensics, we offer tailored strategies that adapt to your unique needs. Partnered with Reyes Tacandong and RT&Co. DigIT Inc., to fortify your defenses, minimize risks, and preserve the trust of your customers. Your security is our priority.

rtcocyber.com



NinjaOne is a unified IT operations platform designed to simplify and automate endpoint management, patching, remote support, and software deployment. Built for modern IT teams, NinjaOne gives full visibility and control over all endpoints from a single, intuitive dashboard—whether on-prem or remote. Trusted globally by MSPs and internal IT teams, NinjaOne helps reduce complexity, increase efficiency, and improve security posture without the need for on-prem infrastructure or multiple point solutions.

www.ninjaone.com



ABP Securite is a leading cybersecurity and network performance Value-Added Distributor (VAD). Incorporated in November 2015, ABP Securite is headquartered in Singapore with regional offices in Southeast Asia and continuous plans to expand across the Asia Pacific region. Our team is composed of professionally certified experts and offers a varied range of services, including security architecture advisory, after-sales support services, solution integration, and cloud-managed services.

ConquestIT provides military grade training at the price and simplicity of SaaS. Our cloud native cutting edge cyber range helps governments and enterprises boost cyber resilience and mitigate the risk of detrimental cyberattacks through continuous training and assessment.

www.abpsecurite.com



Viettel Cyber Security (VCS) is the largest Managed Security Service Provider in Vietnam and a member of Viettel Group — the most valuable telecommunications brand in Southeast Asia. With over 14 years of experience and customers across 15 countries, we deliver end-to-end cybersecurity solutions trusted by governments, enterprises, and SMBs. We are now setting up in the Philippines and already has provided solutions for customers from Banking, Financial Services, Healthcare and Government.

VCS operates a 24/7 Security Operations Center (SOC) and Threat Intelligence Center, alongside elite offensive security services such as Red Teaming and Penetration Testing. Our team of experts includes Asia’s top white-hat hackers — winners of Pwn2Own 2023 & 2024 and Rootcon 18 CTF, and contributors of over 400 zero-day vulnerabilities discovered in critical platforms like Microsoft, Google, and HP.

Combining cutting-edge technology with deep threat intelligence and hands-on expertise, VCS helps organizations detect, respond, and stay ahead of cyber threats — before attackers strike

viettelsecurity.com



Silver




PhilIT System Design Solutions Co. is a Filipino software development company that provides custom and tailor-fit cloud-based web application developed according to the rules and processes of any client. With PhilIT, your business will go digital, be managed with precision, and grow bigger.

www.philitsolutions.com




Netplay, Inc. is a trusted value-added distributor of cutting-edge cybersecurity solutions in the Philippines, proudly offering eScan’s award-winning endpoint security and XDR technologies. With a strong focus on protecting businesses of all sizes, Netplay delivers eScan’s AI-driven antivirus, comprehensive server protection, and advanced threat detection solutions. Backed by deep technical expertise and a commitment to customer success, Netplay empowers system integrators, IT teams, and enterprises to safeguard their digital environments from evolving cyber threats. Through strategic partnerships, dedicated support, and localized service, Netplay ensures seamless deployment and continuous protection across endpoints, networks, and servers in today’s complex threat landscape.

www.npi.ph/escan