Detecting Adversary Intent: Analyzing Behavioral Tells in Admin Logs with Allison Wikoff

Detecting Adversary Intent: Analyzing Behavioral Tells in Admin Logs with Allison Wikoff

Adversaries are already logging into your network using your own admin credentials. In this episode, Caleb Tolin sits down with Allison Wikoff to move past the identity clichés and analyze the specific behavioral signals that separate routine IT maintenance from state-sponsored sabotage. They dissect why resilience is not a flash of genius during a crisis, but a mindset that organizations can adopt to stay ahead of dynamic threat actors. The conversation explores how attackers are increasingly bypassing traditional controls like MFA and leveraging non-human identities such as service accounts, APIs, and AI agents. These identities often operate with persistent access and elevated privileges, making them highly attractive targets. As AI continues to lower the barrier to entry, adversaries are moving faster and blending more effectively into normal activity, making detection significantly more challenging. The episode also examines how ransomware, espionage, and sabotage offer different behavioral tells, with data exfiltration now central across multiple threat types. In parallel, organizations must begin preparing for long-term risks like quantum computing, where encrypted data stolen today could be exposed in the future (i.e., “harvest now, decrypt later”_. Throughout the discussion, practical strategies take center stage. From strengthening identity hygiene and segmentation to improving visibility across users, systems, and third parties, the fundamentals remain critical. The key takeaway is clear. While the threat landscape is evolving, organizations that focus on identity, preparedness, and resilience will be best positioned to reduce risk and recover effectively. What You’ll Learn How attackers bypass MFA and blend in using legitimate credentials Which non-human identities are high-risk targets How threat actors are leveraging AI to lower the barrier to entry for cybercrime The difference between ransomware, espionage, and sabotage intent signals What “harvest now, decrypt later” means for quantum risk The three hygiene practices that still stop most attacks Episode Highlights [00:00:00] The Limits of MFA Why attackers are starting to work around multi-factor authentication [00:02:00] The Explosion of Non-Human Identities Service accounts, APIs, and AI agents as new attack surfaces [00:04:00] AI and the Speed of Threats How AI is accelerating reconnaissance and malware creation [00:05:00] Ransomware vs. Espionage Why data exfiltration is now central to both [00:06:00] Healthcare Under Pressure Why critical sectors face compounded cyber risk [00:08:00] Quantum Threats Explained Understanding “harvest now, decrypt later” [00:11:00] Identity Recovery Challenges Why restoring trust is harder than restoring systems [00:14:00] The 3 Security Fundamentals Identity hygiene, segmentation, and visibility

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(61)

Top CISO Priorities and Global Digital Trust with Morgan Adamski

Top CISO Priorities and Global Digital Trust with Morgan Adamski

Please enjoy this encore of Data Security Decoded. Welcome to ⁠Data Security Decoded⁠. Join host ⁠Caleb Tolin⁠ in conversation with ⁠Morgan Adamski⁠ who leads Cyber, Data, and Tech Risk at PwC and i...

11 Elo 23min

Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest

Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest

This episode delivers operational insights from the frontlines of global telecommunications, drawing on Fred Lhoest's experience managing IT infrastructure across 60 countries at PCCW Global. The disc...

28 Heinä 17min

Securing Research Infrastructure and Managing Shadow AI with Kevin Mortimer

Securing Research Infrastructure and Managing Shadow AI with Kevin Mortimer

This episode explores the technical hurdles of protecting academic research environments and navigating the shift to automated cloud architectures, drawing on Kevin Mortimer's twenty five years of tec...

21 Heinä 29min

Shifting Security and Protecting the Pharma Supply Chain with Andy Hillis

Shifting Security and Protecting the Pharma Supply Chain with Andy Hillis

This episode provides a technical exploration of security engineering within highly scrutinized life sciences environments, drawing on Andy Hillis' decades of operational history at The Almac Group. T...

14 Heinä 34min

Defending the Authentication Flow: Device Code Phishing with Selena Larson

Defending the Authentication Flow: Device Code Phishing with Selena Larson

This episode delivers critical battlefield stories regarding the operational reality of modern identity based threats. Selena Larson, Staff Threat Researcher and Lead, Intelligence Analysis and Strate...

30 Kesä 28min

Beyond the Doomsday: Operational Resilience, Identity Sprawl, and Back-to-Basics Cyber Defense

Beyond the Doomsday: Operational Resilience, Identity Sprawl, and Back-to-Basics Cyber Defense

In this comprehensive roundtable episode, a powerhouse panel of seasoned security professionals—Cynthia Kaiser, Matt Castriotta, Allison Wikoff, John Fokker, Amit Malik, and Joe Hladik—joins host Cale...

23 Kesä 35min

The Anatomy of Cloud Ransomware with Matt Castriotta

The Anatomy of Cloud Ransomware with Matt Castriotta

Are your cloud security controls actually protecting your infrastructure, or are they just keeping the lights on? With host Caleb Tolin, Matt Castriotta, Field CTO for Cloud at Rubrik, breaks down the...

9 Kesä 28min

Running the Inverted Offensive Campaign with Adam Karcher

Running the Inverted Offensive Campaign with Adam Karcher

What happens when the adversary’s dwell time is measured in years, but your defense is measured in tickets? Adam Karcher, FBI Supervisory Special Agent, Cyber Division, and a member of the Bureau’s AI...

26 Touko 35min

Suosittua kategoriassa Liike-elämä ja talous

sijotuskasti
mimmit-sijoittaa
psykopodiaa-podcast
rss-rahapodi
ostan-asuntoja-podcast
rahapuhetta
rss-inderes
rss-sami-miettinen-neuvottelija
sijoituspodi
rss-porssipuhetta
hyva-paha-johtaminen
rss-ammattipodcast
rss-johtajatabut-aiheita-joista-ei-ole-tapana-puhua
oppimisen-psykologia
rss-karon-grilli
rss-paasipodi
asuntoasiaa-paivakirjat
pomojen-suusta
rss-hilden-kaira-podcast
rss-oivalluksia-rahasta-elamasta