Vectra AI
Attack labs
Hosted by
No items found.

Threat Briefing: The Post-Login Kill Chain | Auckland

Attackers don’t really “break in” anymore — they log in. And once they do, distinguishing normal user activity from malicious behaviour becomes significantly harder.

February 18, 2026
11:30am - 1:30pm NZDT

Britomart Place, Level 10/11 Auckland Central, Auckland 1010, New Zealand

Thank you for registering!
We've received your request and will get back to you soon.

If you do not hear from us in the next 48 hours, please check your spam folder!
Back to homepage

Agenda

Day 1: Thursday, July 9, 2026 (Full day)
9:00
Arrival and Networking
9:30
Welcome Opening
10:00
NDR: from luxury to necessity - overnight
10:30
Break
10:45
New features and latest release updates
11:30
Competitive
12:15
Lunch & Mingle
13:15
Win Sharing
14:00
Panel Discussion - Hunt Club Sharing
14:15
Break
Sales Track
14:45
New Partner Program and Certification
15:00
Vectra AI Value Proposition - Identity, Cloud & Network
15:45
Day 1 Exercise: Build your own Vectra AI Messaging
17:15
Wrap Up
SE Track
14:45
Roadmap Update
15:15
Fusion - What is it and why it is important
16:00
AI Assisted Investgations Hands on workshop
17:15
Wrap Up
Dinner
18:30
Team Dinner
Day 2: Friday, July 10, 2026 (9:00 AM – 1:00 PM)
Sales Track
9:00
Recap and Welcome
9:10
The Threat Landscape changed with Claude Mythos
9:40
360 Respond. What does this mean for our customer?
10:15
Break
10:30
MDR/MxDR Capability and SOC Use Case
11:00
Day 2 Exercise: Customer Profile
12:15
Group Winner Award
SE Track
9:00
Beyond NDR : Identy and Cloud
9:45
OSA - Red teaming for POV
10:30
Break
10:45
How to run a successful POV
11:45
Interactive Discussion
Closing
12:30
Joint Closing

This joint Vectra AI and Bastion Security threat briefing, From Valid Credentials to Full Control: The Post-Login Kill Chain, is designed for SOC teams responsible for detecting and responding to active threats in real-world environments. The session breaks down the post-login tactics, techniques, and procedures (TTPs) used by groups such as Scattered Spider and Salt Typhoon, highlighting where visibility commonly degrades across identity, network, and cloud control planes.

We’ll cover:

  • Real-world post-auth kill chain behaviors: identity discovery, privilege escalation, lateral movement, token/OAuth persistence, and data staging
  • Common blind spots: SSO/session telemetry gaps, SaaS audit log limitations, token visibility, and cross-domain correlation
  • What “good” looks like: behavioral baselines, anomaly thresholds, and high-fidelity post-login detections
  • MTTD/MTTR improvements: alert consolidation, playbooks, session revocation, MFA method hygiene, and rapid scoping
  • Case-based lessons on how dwell time drives operational disruption and extended recovery (e.g., Jaguar Land Rover)

Share

Meet the Team

Steve Carlin
Senior Security Engineer