Session
A Deep Technical Dive into Enterprise-Grade Windows Trojan Defense with Microsoft Defender XDR
Modern Windows environments—managed through Intune, Microsoft Defender XDR, Windows 365, and Azure—continue to face rapidly evolving Trojan malware that bypasses traditional static and dynamic detection. In this deep technical session, I present a heuristic-based machine learning detection framework developed through my postgraduate research, engineered specifically for Microsoft enterprise security stacks.
This session delivers a 300–400 level deep dive into how heuristic features (API call sequences, opcode patterns, entropy scoring, DLL imports, PE header anomalies, and behavioral telemetry from Windows internals) can be combined with ML models such as XGBoost, SVM, Random Forest, and ensemble classifiers to identify advanced Trojans—including polymorphic, metamorphic, and adversarial AI-generated variants.
We will walk through a production-ready architecture showing how these ML models can be integrated with:
Microsoft Defender for Endpoint (custom threat indicators, behavioural rules, ASR mappings)
Microsoft Sentinel (UEBA correlation, analytics rules enriched with ML anomaly scores)
Azure Machine Learning (model training, deployment pipelines, real-time inference)
Windows 11 / Windows Server (ETW-based telemetry collection and feature extraction)
The session includes a live demonstration of the detection pipeline running against real Windows samples inside an isolated VM, showing feature extraction, ML scoring, and automated alerting into Defender or Sentinel.
Attendees will gain a practical blueprint for deploying next-generation malware detection capabilities across hybrid and cloud-native workplaces, MSP-managed environments, and enterprise Microsoft security ecosystems. This session is grounded in real research, real experiments, and real-world implementation scenarios.
Darlington Okeke
Cybersecurity Researcher | CEH | CPT | MSc Cyber Security | AI for Threat Detection
Cheltenham, United Kingdom
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top