This talk will delve into Microsoft's innovative approach to adversary emulation, a cornerstone of our cybersecurity strategy. At the heart of our mission are "synthetic" adversary events, designed to test and fortify our operational capabilities across the entire threat lifecycle. These events challenge our detection mechanisms, incident escalation protocols, hunting strategies, containment practices, eviction processes, and drive systemic change via the Deputy CISO community. We will explore the full lifecycle of an operation, from the red team’s processes through GHOST and MSTIC’s engagement. We will highlight our approach to interrupt-driven systemic change, and discuss how unexpected adversary actions can catalyze pivotal improvements in our defenses.


  • Date:10/17/2024 10:24 AM
  • Location Redmond, WA, USA (Map)

Sorry, registration has ended.