Date: Wednesday, August 5
Time: 1:30 – 2:15 PM
Location: Pulse Stage 3
Modern enterprise security has become increasingly detection-driven. We've spent years encouraging organizations to assume compromise, invest in telemetry, and respond faster than attackers can operate. But hidden within that strategy is another assumption, one that we rarely question, that the security controls responsible for providing visibility can themselves always be trusted.
Today's attackers increasingly understand that assumption. Rather than immediately pursuing data or deploying ransomware, many first focus on degrading, bypassing, or manipulating the security tooling standing in their way. Driver abuse, telemetry tampering, Living-off-the-Land techniques, identity manipulation, trusted process abuse, and emerging research into sensor deception all demonstrate the same trend: visibility has become a target.
This session examines the common principles behind these techniques and explores what they reveal about the strengths and limitations of modern detection-first security architectures. Through practical examples and recent research, we'll explore how attackers disable, evade, deceive, delay, or overwhelm endpoint visibility, and what happens when those assumptions no longer hold.
The session concludes with practical guidance for building more resilient endpoint defenses by combining prevention, hardening, attack surface reduction, anti-tampering, least privilege, telemetry validation, and continuous security verification.
Speaker:
• Nicholas Jackson, Director of Cyber Security Services
• Yasser Fuentes, Principal Solutions Architect