Session

The Attacker Journey: Mapping Techniques Across Security Domains

Techniques classified as rare in global frameworks turn out to be endemic when you look across security domains. In one regional financial ecosystem, hardware-based attacks have been operationally recurrent for over a decade — visible to adjacent security teams long before cyber defenders recognized the pattern.

This talk shares the lessons learned from trying to solve this problem firsthand. Working in cyber defense and seeing attacks flow into adjacent domains with no shared visibility, we set out to build a cross-domain taxonomy modeled on MITRE ATT&CK to map attacker journeys that no single team could see alone. The talk covers what happened when existing global frameworks did not fit regional operational needs, the engineering mistakes and course corrections along the way, and what it took to reach operational use — including automated pipelines that generate cross-domain attack flows and prioritization. The focus is on the journey and what went wrong, not just the result.

A public case study from a Brazilian federal agency illustrates how the same pattern plays out across sectors. Attendees will leave with a concrete understanding of how fragmented visibility creates blind spots — regardless of which domains their organization defends.

Carlos Gonçalves

Principal Security Engineer @ Banco do Brasil

Brasília, Brazil

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top