General session image of Knowledge Forum D

From one system to thousands: threat hunting that scales when it counts.

When it counts, the question isn't whether you can search, but how fast you've searched everywhere. Even where no agent runs.

Topic

SIEM / Threat Analytics / SOCGovernance, Riskmanagement and ComplianceAwareness / Phishing / FraudEndpoint ProtectionIndustry 4.0 / IoT / Edge Computing

When & Where

calendar_month

Tue, 10/27/2026 04:00 PM - 04:15 PM

location_on

Forum D, Booth 7-742

Download session as iCaldownload_for_offline

Details

  • Format:

    Management lecture

  • Language:

    German

Session description

Speaker: Daniel Best

Thoroughly examining a single machine takes time. When it counts, the real question is different. How fast have you looked everywhere? An APT that's already inside doesn't sit still. It works its way onward and takes over system after system while you're still sitting at that one machine. Reach, forensic depth and speed. Checking thousands of systems at once, with detection logic included, without weeks of rollout. Even where no agent runs and classic defenses are blind. 

The presentation walks through a practical workflow: which forensic traces hold up at scale, how findings can be prioritized instead of drowning in false positives, and why the same investigation can deliver new results weeks later with updated detection logic.