Niladri Sekhar Hore
F50 - Lead Engineer - Threat Detection & Applied Intelligence (AI / ML)
Bengaluru, India
Actions
With more than a decade of experience across data engineering and cybersecurity, Niladri is a well-rounded professional currently serving as Lead Engineer – Threat Detection and Automation at StoneX Group. In this role, he works on strengthening cyber defense, improving observability, and building secure, scalable data and AI systems. His career spans key positions at global organizations such as Cognizant, Eli Lilly, Accenture, and KPMG, where he led initiatives in eDiscovery, digital forensics, GRC, security engineering, and cloud engineering.
Blending deep technical expertise with strategic thinking, he approaches complex challenges at the intersection of data, threat operations, and governance. His recent work focuses on areas like synthetic media abuse, deepfake detection, adversarial AI in enterprise settings, and the development of machine learning models and real-world AI systems that address tangible business problems, along with strong expertise in AI guardrails and model exploitation protection.
Links
Area of Expertise
Topics
Non-Human Identity Crisis: AI Agents as Unaccountable Actors in Enterprise Security
Abstract:
As AI agents become embedded in enterprise systems, they are increasingly performing actions traditionally associated with human users and service accounts—accessing data, invoking APIs, and executing workflows. However, these agents do not fit cleanly into existing identity and access management (IAM) models, creating a fundamental gap in how organizations enforce accountability, authorization, and auditability.
This talk introduces the concept of the “non-human identity crisis” in AI agents, where autonomous systems operate with delegated authority but without clear identity boundaries. We explore how AI agents blur the line between user intent and system execution, leading to ambiguous ownership of actions and breakdowns in traditional security controls.
Through practical scenarios, we demonstrate how AI agents leverage shared credentials, inherited permissions, and implicit trust to perform actions that cannot be easily attributed or governed. These challenges impact core security functions, including access control enforcement, audit logging, incident response, and compliance reporting.
The session analyzes how existing IAM frameworks—designed for humans and deterministic services—fail to address the dynamic and context-driven behavior of AI agents. We highlight gaps in identity propagation, session context, and authorization enforcement when decision-making is delegated to LLM-driven systems.
To address these challenges, we propose a set of design principles for managing AI agents as first-class identities. This includes binding user context to agent actions, enforcing explicit authorization at execution points, and enhancing audit trails to capture intent, decision flow, and action outcomes.
This talk provides a new lens for understanding AI agent security—not just as an application risk, but as a fundamental identity and trust problem that requires rethinking how enterprises model and secure non-human actors.
Key Takeaways:
1. Why AI agents do not fit into existing IAM and identity models
2. How lack of identity boundaries creates security and audit gaps
3. Challenges in attributing actions and enforcing accountability
4. Impact on compliance, logging, and incident response
5. Design principles for managing AI agents as secure, auditable identities
Session Format:
Technical and architectural deep dive with real-world scenarios.
Detection Engineering for AI Agents: Building SOC Visibility into Autonomous Systems
Abstract:
As AI agents become embedded across enterprise environments—interacting with internal systems, executing actions, and making autonomous decisions—they introduce a new and largely unmonitored attack surface. While much of the current focus in AI security is on preventing prompt injection and model manipulation, far less attention has been given to a critical question: how do we detect when an AI agent is being abused?
This talk presents a practical approach to detection engineering for AI agents, focusing on how security operations teams can gain visibility into autonomous systems and identify malicious or unintended behavior. Drawing from real-world architectures, we explore how AI agents interact with tools, APIs, and cloud services, and how these interactions can be instrumented, logged, and analyzed using existing security monitoring frameworks.
Through a series of realistic scenarios, we demonstrate how compromised or manipulated agents exhibit observable patterns—such as anomalous tool usage, unusual data access, and unexpected outbound communication—that can be detected using telemetry pipelines and SIEM-based analysis. Attendees will see how to translate agent activity into actionable security signals and build detection logic aligned with modern SOC practices.
The session also highlights the limitations of current logging and monitoring approaches, showing why traditional application telemetry is insufficient for agentic systems. We introduce a structured model for capturing agent behavior, including input/output tracing, tool invocation auditing, and context-aware event correlation.
Finally, we present practical strategies for implementing detection and response capabilities for AI agents, including alerting on high-risk behaviors, integrating agent telemetry into existing security workflows, and designing agents with observability in mind.
This talk bridges the gap between AI security research and operational security, equipping defenders with the tools and frameworks needed to monitor, detect, and respond to threats in autonomous AI systems.
Key Takeaways:
Why AI agents create a new blind spot for security operations
How to instrument and log AI agent behavior effectively
Detecting anomalous tool usage, data access, and agent-driven actions
Building SIEM detections and telemetry pipelines for agent activity
Practical approaches to integrating AI agents into existing SOC workflows
Session Format:
Technical deep dive with real-world scenarios and detection-focused demonstrations.
Niladri Sekhar Hore - The Deepfake Supply Chain
In an era where synthetic media and deepfakes are becoming tools of choice for adversaries, this session delivers a deep dive into the entire lifecycle of a synthetic media attack—from initial OSINT gathering to monetization through fraud and extortion. Drawing from real-world incidents, cutting-edge research, and red-team simulations, we’ll dissect how deepfake-based attacks are operationalized, bypass controls, and reshape the threat landscape across sectors.
Finally, the session presents a comprehensive defense framework—covering AI-driven detection techniques, content authenticity infrastructure (C2PA), security engineering controls, and organizational playbooks for executive impersonation response. By the end of this session, security professionals, risk leaders, and technical architects will be equipped with actionable strategies to detect, disrupt, and defend against synthetic media threats in the real world.
CODE BLUE 2025 Sessionize Event
Niladri Sekhar Hore
F50 - Lead Engineer - Threat Detection & Applied Intelligence (AI / ML)
Bengaluru, India
Links
Actions
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top