Evan Perotti

Evan Perotti

Lead Scientist

Security Risk Advisors

Friday, December 5, 2025
11:30-11:55
Liberty (Live Track 2)

About Evan Perotti

Evan Perotti is a Lead Scientist at Security Risk Advisors. He focuses on research and development, primarily within the offensive security space. His specialties include AWS security, Windows endpoint security, and purple teaming.

Talk Details

30 minIntermediate

Screaming about detection coverage in ALLCAPS!

Are your tools actually detecting on the right indicators? A common refrain in defense is that attacks should be addressed at the behavior level and avoid low-hanging indicators. From the hundreds of purple team exercises we conduct each year, we've evaluated all manner of endpoint security controls. And, invariably, they all suffer from diminished coverage when removing weaker indicators, like process command lines. It seems security vendors prefer taking the easy route. This talk will focus on separating attack behaviors from their specific implementations, evaluating detection robustness, and implementing atomic testing procedures to address these concepts. This talk will also cover open-source tooling we've released that is designed to help red teams put these concepts into practice for their organizations.

Session Information

Duration:30 min
Level:Intermediate
Track:Liberty (Live Track 2)
Time:11:30-11:55

Venue Information

Location:
Live! Casino & Hotel Philadelphia
900 Packer Ave, Philadelphia, PA

Date:
Friday, December 5, 2025