Loading…

Subject: Security Operations / Tools clear filter
arrow_back View All Dates
Sunday, September 13
 

10:30am CDT

From Logs to Logic: Building Detections That Don’t Suck
Sunday September 13, 2026 10:30am - 10:55am CDT
Most security teams have no shortage of logs, yet turning that data into reliable detections is a different problem entirely.

In reality, detection efforts often fall apart because of messy data, vague assumptions, and a haphazard approach to building and maintaining them. The outcome is all too familiar: overwhelmed analysts tuning out alerts, threats slipping through the cracks, and detections that look impressive in presentations but crumble under real-world pressure.


This presentation pulls back the curtain on how detection engineering actually works in the trenches. We'll start with raw telemetry data and walk through the process of translating attacker behavior into testable hypotheses, then converting those hypotheses into detection logic that gets refined through ongoing feedback.


I'll introduce a practical lifecycle for detection engineering, covering research, hypothesis development, creation, validation, deployment, and tuning. This structured approach ensures that detections aren't just built once and forgotten, but evolve alongside the threats they're designed to catch.


Finally, we'll bridge detection engineering with threat hunting and broader cyber operations. You'll walk away with a straightforward framework for building detections that are not just technically sound, but genuinely useful when it matters most.
Speakers
avatar for Kyle Barboza

Kyle Barboza

Senior Threat Informed Defense Engineer, Financial Services Company
Kyle is a detection engineer and cyber operations leader focused on turning raw telemetry into actionable defense. He specializes in threat detection, incident response, and building scalable detection programs using automation and detection-as-code principles.With experience leading... Read More →
Sunday September 13, 2026 10:30am - 10:55am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

11:00am CDT

Slaying the Sprawl: A Hero’s Guide to Building (or Re-Forging) a Cloud Security Program Without a 20-Person Guild
Sunday September 13, 2026 11:00am - 11:50am CDT
Whether you are standing before a pristine, untouched Cloud Kingdom or inherited a crumbling fortress held together by "Native Tooling" duct tape and hope, the quest remains the same: How do you defend the realm without hiring an army you can’t afford? 


In this 40-minute campaign, we aren’t just looking at the map, we’re looking at the scars. Building a cloud security program from scratch is one thing; evolving an established one while the dragons are already circling is another. Drawing from real-world lessons learned in the DevOps trenches, this session explores the "Day 0" decisions and the "Year 2" regrets of choosing between Native Security Tooling and a unified CNAPP.


We’ll sit around the tavern table to discuss the hard-won truths of cloud defense:


- The "Free" Sword’s Hidden Cost: Real-life tales of how "built-in" tools led to siloed alerts, requiring a 20-person "manual correlation guild" just to find a single critical risk.
- Re-Forging the Armor: For those with established programs—how to transition from a "Franken-stack" of point tools to a unified platform without breaking the kingdom’s production.
- The "Agentless" Treaty: Lessons learned from the "Agent Wars." How moving to agentless visibility (the Rogue's Cloak) saved our DevOps relationships and gave us 100% visibility in hours, not months.
- The Multi-Cloud Map: Navigating the treacherous terrain of AWS, Azure, and beyond without losing your mind or your budget to "Console Swapping" fatigue.


Whether you are a Solo Adventurer starting a new program or a War-Weary Veteran trying to consolidate a sprawling one, you’ll leave with a battle-tested blueprint for a security program that scales with your magic, not your headcount, HUZZAH!
Speakers
avatar for Steve Turner

Steve Turner

Cloud Security Architect, Zelis Healthcare
Steve leads cloud security at Zelis Healthcare. He started his career through the trial by fire that is MSP life. He pivoted to securing everything from waste facilities and transportation infrastructure to huge financial services organizations and even mixed in some industry analysis... Read More →
Sunday September 13, 2026 11:00am - 11:50am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

1:00pm CDT

The Only Way to Win Is by Learning: Deception Design, Read Through a Comedy Game Show
Sunday September 13, 2026 1:00pm - 1:50pm CDT
Most deception technology fails the same way a bad magic trick fails: the audience can see the strings. A pristine honeypot, a too-obvious credential, a decoy environment without any of the messy human fingerprints of a real network — these tip off skilled attackers in the first thirty seconds of contact and then sit unused, generating no intelligence and no value.
This talk argues that the people who have already solved this design problem are, improbably, the writers of Dropout's Game Changer — a comedy game show where contestants don't know the rules, and where the host's entire job is to design environments that intelligent, adaptive people will inhabit fully while being watched. The parallels to defensive cyber deception turn out to be precise and useful.
Working through concepts including verisimilitude and "coherent imperfection," choice architecture and the path of least resistance, flow-state engineering for sustained engagement past the initial probe, nested observation layers modeled on the show's "Bingo" episode, and the counterintuitive Tularosa finding that announcing deception makes it more effective, this session translates game-design craft into practical honeypot, honeytoken, and deception-fabric architecture any defender can deploy.
Attendees will leave with a design checklist for building deceptive environments that sustain coherence under adversarial pressure, a vocabulary for evaluating commercial deception platforms against actual attacker psychology, and an argument for why the best deception operators are, in a real sense, game designers.
The talk is interactive. The audience is already playing.
Speakers
avatar for Dylan Shroll

Dylan Shroll

Security Engineer, Revology
Dylan is a cybersecurity engineer with six-plus years across healthcare, financial services, lottery, and logistics — everywhere the stakes are high and the regulations are higher still. She specializes in LLM-powered cyber deception operations and behavior-science-driven secur... Read More →
Sunday September 13, 2026 1:00pm - 1:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

2:00pm CDT

The Contextualization Gap: Why Your SOC Has the Data But Not the Story
Sunday September 13, 2026 2:00pm - 2:25pm CDT
Security operations teams are not losing ground because they lack tools. They are losing ground because they have accumulated too many tools, each addressing a specific threat, each generating its own telemetry, with no architecture capable of connecting that data into a coherent, actionable picture of what is happening in the environment. The result is a team simultaneously overwhelmed by data and operationally blind to the threats moving through it. This is true for internal SOC teams and for MSSPs, and the burden manifests differently for each.


The core problem is structural: the five functions required to convert raw telemetry into a security decision, specifically aggregation, correlation, analysis, decision making, and execution, are not all human-speed functions. The first three demand machine-level speed and scale. 


1. Aggregation requires collecting and storing every data point from every endpoint and point solution, in raw form, before filtering occurs. 2. Correlation requires establishing real-time relationships across those data points at a scale no analyst team can match manually. 
3. Analysis requires assembling those relationships into a complete, contextualized picture of what is present, what it is doing, and whether it represents a threat. 


These three functions, performed at the volume and velocity modern environments generate, are beyond the operational capacity of any human element working without machine support.


Yet most organizations have humans attempting to manage all five steps, and both sides of the security operations equation pay for it.


Internal SOC teams silo the data conversation, leaving executive leadership, board members, and stakeholders without the context to authorize meaningful action. 


External providers face a version of the same problem: unable to build full context from fragmented data, they struggle to explain which data matters to the client, let alone guarantee the client is protected. They carry that uncertainty every day. 


In both cases, the human element absorbs the burden of functions it was never designed to perform, and the organization remains exposed.


This session presents the operational argument for a different architecture: one in which an AI and ML-driven security contextualization engine executes steps one through three against the full data lake in real time, and delivers the output (a contextualized, prioritized picture of environmental activity) to the human operator. 


The human element is not removed from the process. It is repositioned to the two steps where human judgment is irreplaceable: decision making and execution. The operator arrives at step four informed, not overwhelmed.


The session draws from documented deployments in resource-constrained environments, including a regional security operation that processed 35,331 threats, eliminated 351 classified at high severity, and maintained zero major security incidents, at 77% below the cost of an equivalent internal SOC. The outcomes were not produced by adding analysts. They were produced by correctly positioning the human element within the detection lifecycle.


Attendees will leave with a framework for auditing where their team is currently positioned in the five-step cycle, a model for what machine-executed contextualization makes operationally possible, and a practical starting point for closing that gap.
Speakers
avatar for Cyrus Walker

Cyrus Walker

Founder/CEO, Data Defenders
Thirty years of operational cybersecurity experience spanning municipal government, nonprofit, and healthcare sectors. Work includes forensic investigation, critical infrastructure protection, and the design and operation of shared regional security programs built for organizations... Read More →
Sunday September 13, 2026 2:00pm - 2:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
 
Blue Team Con 2026
From $0.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -