How To Think In Graphs
Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win" - this iconic quote by John Lambert, General Manager of Microsoft's Threat Intelligence Center, has been quoted countless times and its point has been proven time and time again since the paradigm shift in identity security when the first open-source offensive attack path tooling - BloodHound - was created in 2016 by Andy Robbins, Rohan Vazarkar, and Will Schroeder. Defenders were dominated by attackers who now both were thinking and tooling in graphs, and the defenders' problem grew as the industry adopted more identity systems than ever. Modern attack path tooling has enabled defenders to turn the battlefield to their advantage again and the attacker's lead is narrowing. This talk is for both defenders and attackers who want to understand why the identity graph is necessary, their inherent advantages in the identity graph space, how to tool for the modern graph, and how to shift an entire organization to think in graphs.
Speaker

Martin Sohn Christensen
Security Researcher @ SpecterOps
Martin is a Security Researcher at SpecterOps specializing in identity attack paths with a focus on Microsoft technologies. He contributes to the information security community by sharing knowledge through blogs, international conferences, and is a contributor to various community tools including BloodHound CE, EntraOps, and is the co-creator of the BloodHound Query Library. Martin has a background in Microsoft system administration, information security consultancy, and BloodHound Enterpr... read more