Detecting Adversary Intent: Analyzing Behavioral Tells in Admin Logs with Allison Wikoff

Detecting Adversary Intent: Analyzing Behavioral Tells in Admin Logs with Allison Wikoff

Adversaries are already logging into your network using your own admin credentials. In this episode, Caleb Tolin sits down with Allison Wikoff to move past the identity clichés and analyze the specific behavioral signals that separate routine IT maintenance from state-sponsored sabotage. They dissect why resilience is not a flash of genius during a crisis, but a mindset that organizations can adopt to stay ahead of dynamic threat actors. The conversation explores how attackers are increasingly bypassing traditional controls like MFA and leveraging non-human identities such as service accounts, APIs, and AI agents. These identities often operate with persistent access and elevated privileges, making them highly attractive targets. As AI continues to lower the barrier to entry, adversaries are moving faster and blending more effectively into normal activity, making detection significantly more challenging. The episode also examines how ransomware, espionage, and sabotage offer different behavioral tells, with data exfiltration now central across multiple threat types. In parallel, organizations must begin preparing for long-term risks like quantum computing, where encrypted data stolen today could be exposed in the future (i.e., “harvest now, decrypt later”_. Throughout the discussion, practical strategies take center stage. From strengthening identity hygiene and segmentation to improving visibility across users, systems, and third parties, the fundamentals remain critical. The key takeaway is clear. While the threat landscape is evolving, organizations that focus on identity, preparedness, and resilience will be best positioned to reduce risk and recover effectively. What You’ll Learn How attackers bypass MFA and blend in using legitimate credentials Which non-human identities are high-risk targets How threat actors are leveraging AI to lower the barrier to entry for cybercrime The difference between ransomware, espionage, and sabotage intent signals What “harvest now, decrypt later” means for quantum risk The three hygiene practices that still stop most attacks Episode Highlights [00:00:00] The Limits of MFA Why attackers are starting to work around multi-factor authentication [00:02:00] The Explosion of Non-Human Identities Service accounts, APIs, and AI agents as new attack surfaces [00:04:00] AI and the Speed of Threats How AI is accelerating reconnaissance and malware creation [00:05:00] Ransomware vs. Espionage Why data exfiltration is now central to both [00:06:00] Healthcare Under Pressure Why critical sectors face compounded cyber risk [00:08:00] Quantum Threats Explained Understanding “harvest now, decrypt later” [00:11:00] Identity Recovery Challenges Why restoring trust is harder than restoring systems [00:14:00] The 3 Security Fundamentals Identity hygiene, segmentation, and visibility

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(65)

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

Please enjoy this encore of Data Security Decoded. In this episode, host⁠⁠ ⁠Caleb Tolin⁠⁠⁠ explores the battlefield of enterprise defense, which has moved from simple data theft to ultra heinous cri...

15 Sep 29min

Agentic AI and Identity Sprawl

Agentic AI and Identity Sprawl

Please enjoy this encore of Data Security Decoded. In this episode of ⁠Data Security Decoded⁠, join host ⁠Caleb Tolin⁠ as he welcomes back ⁠Joe Hladik⁠, Head of Rubrik Zero Labs, to unpack the findi...

8 Sep 24min

AI Moves Fast. Privacy Has to Move Faster.

AI Moves Fast. Privacy Has to Move Faster.

Enjoy this encore of Data Security Decoded. AI promises speed, scale, and efficiency—but it also magnifies privacy risk in ways many organizations aren’t prepared for. In this episode, ⁠Caleb Tolin⁠...

25 Aug 25min

The Real Risks of Agentic AI in the Enterprise

The Real Risks of Agentic AI in the Enterprise

Please enjoy this encore of Data Security Decoded. As enterprises race to adopt AI, many are discovering that traditional security models no longer hold. In this episode of Data Security Decoded, ho...

18 Aug 27min

Top CISO Priorities and Global Digital Trust with Morgan Adamski

Top CISO Priorities and Global Digital Trust with Morgan Adamski

Please enjoy this encore of Data Security Decoded. Welcome to ⁠Data Security Decoded⁠. Join host ⁠Caleb Tolin⁠ in conversation with ⁠Morgan Adamski⁠ who leads Cyber, Data, and Tech Risk at PwC and i...

11 Aug 23min

Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest

Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest

This episode delivers operational insights from the frontlines of global telecommunications, drawing on Fred Lhoest's experience managing IT infrastructure across 60 countries at PCCW Global. The disc...

28 Jul 17min

Securing Research Infrastructure and Managing Shadow AI with Kevin Mortimer

Securing Research Infrastructure and Managing Shadow AI with Kevin Mortimer

This episode explores the technical hurdles of protecting academic research environments and navigating the shift to automated cloud architectures, drawing on Kevin Mortimer's twenty five years of tec...

21 Jul 29min

Shifting Security and Protecting the Pharma Supply Chain with Andy Hillis

Shifting Security and Protecting the Pharma Supply Chain with Andy Hillis

This episode provides a technical exploration of security engineering within highly scrutinized life sciences environments, drawing on Andy Hillis' decades of operational history at The Almac Group. T...

14 Jul 34min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
rss-pa-konto
rss-skravla-gar
pengepodden-2
livet-pa-veien-med-jan-erik-larssen
lederpodden
finansredaksjonen
tid-er-penger-en-podcast-med-peter-warren
stormkast-med-valebrokk-stordalen
rss-orjasater
pengesnakk
morgenkaffen-med-finansavisen
liberal-halvtime
utbytte
okonomiamatorene
rss-markedspuls-2