
From one system to thousands: threat hunting that scales when it counts.
When it counts, the question isn't whether you can search, but how fast you've searched everywhere. Even where no agent runs.
Topic
When & Where
Details
Format:
Management lecture
Language:
German
Session description
Speaker: Daniel Best
Thoroughly examining a single machine takes time. When it counts, the real question is different. How fast have you looked everywhere? An APT that's already inside doesn't sit still. It works its way onward and takes over system after system while you're still sitting at that one machine. Reach, forensic depth and speed. Checking thousands of systems at once, with detection logic included, without weeks of rollout. Even where no agent runs and classic defenses are blind.
The presentation walks through a practical workflow: which forensic traces hold up at scale, how findings can be prioritized instead of drowning in false positives, and why the same investigation can deliver new results weeks later with updated detection logic.

