Loading…

Saturday September 12, 2026 3:00pm - 3:25pm CDT
In today’s landscape of sophisticated cyberattacks, EDR (Endpoint Detection and Response) is an indispensable tool, but it’s not a complete solution. We are observing a rise in sophisticated cyberattacks that are difficult to detect based solely on endpoint behavior. By initiating breaches via VPNs—which are outside the scope of EDR monitoring—and utilizing stolen credentials to blend in through LotL methods, attackers are successfully evading traditional security measures. To address these challenges, the importance of monitoring identity-based behavior generated by Active Directory (AD)—known as ID alerts—is growing by the day.


In this session, we will share the “realities” of ID alert analysis from the front lines of a managed SOC that monitors and analyzes environments comprising tens of thousands of devices—primarily for major Japanese enterprises—24 hours a day, 365 days a year. Monitoring identity-based behavior in large-scale enterprise environments is a “headache” for operators due to vast amounts of noise and a lack of context. We will introduce our initiatives for utilizing correlation analysis and threat hunting to address these ID alerts. Attendees will learn “correlation analysis logic” and “hypothesis-based hunting” using Sigma rules—techniques that can be immediately applied in SOC operations the very next day—while filtering out the noise specific to large-scale environments.
Speakers
avatar for Shogo Hayashi

Shogo Hayashi

SOC Analyst, NTT Security
Shogo Hayashi is a SOC analyst at NTT Security (Japan) KK. He has been working in cybersecurity as a member of the Blue Team for 15 years. He specializes in responding to EDR and AD detections, developing detection rules, malware analysis, and cyber threat research. He has spoken... Read More →
avatar for Teruki Yoshikawa

Teruki Yoshikawa

Security Analyst, NTT Security
Teruki Yoshikawa is a security analyst at NTT Security (Japan) KK. He is responsible for monitoring NW/EDR alerts, while also being involved in malware analysis. He is actively engaged in security research. He has spoken at JSAC, NorthSec and has co-authored several white papers... Read More →
Saturday September 12, 2026 3:00pm - 3:25pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link