How To Think In Graphs

Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win" - this iconic quote by John Lambert, General Manager of Microsoft's Threat Intelligence Center, has been quoted countless times and its point has been proven time and time again since the paradigm shift in identity security when the first open-source offensive attack path tooling - BloodHound - was created in 2016 by Andy Robbins, Rohan Vazarkar, and Will Schroeder. Defenders were dominated by attackers who now both were thinking and tooling in graphs, and the defenders' problem grew as the industry adopted more identity systems than ever. Modern attack path tooling has enabled defenders to turn the battlefield to their advantage again and the attacker's lead is narrowing. This talk is for both defenders and attackers who want to understand why the identity graph is necessary, their inherent advantages in the identity graph space, how to tool for the modern graph, and how to shift an entire organization to think in graphs.

    Speaker

    FURTHER SESSIONS

  • 1979 called. They already figured it out.

  • A Few Dollars to Disappear: Breaking C2 Beaconing Detection

  • Ants, Bricks and Spiders: Threat Emulation on the VMware Stack

  • Capture The Flag

  • Join us in Amsterdam!

    November 19, 2026

    Hang out, learn something awesome and make new friends.

    Get Tickets