What if an attacker lived inside your network for seven months and your tools never noticed?
During a real breach assessment, Black Hills Information Security uncovered a stealthy intrusion using a COM-based persistence technique hidden in native Windows scheduled tasks. There were no obvious indicators of compromise. No suspicious process names. No malicious file hashes.
Just a quiet foothold designed to stay invisible.
🛝 Webcast Slides
https://www.blackhillsinfosec.com/wp-content/uploads/2026/03/SLIDES_CuriousCaseOfTheComburglar_BreachAssessment-2026-03-12.pdf
Chapters
- (00:00) - Intro - Breach Assessment - The Curious Case of the Comburglar - Troy Wojewoda
- (02:15) - Agenda
- (03:02) - What Is a Breach Assessment?
- (10:50) - 5 Pillars of Data Telemetry
- (16:23) - The Hunt Begins
- (29:15) - Attack Chain
- (38:39) - Timeline & Scope
- (45:21) - Threat Hunting Playbook
- (51:29) - Key Takeaways
- (53:52) - Q&A
Creators & Guests
Troy Wojewoda - Guest Jason Blanchard - Host Deb Wigley - Host Logan Bender - Guest Keith Chew - GuestChat with your fellow attendees in the BHIS Discord server:
https://discord.gg/bhis
in the #🔴live-chat channel
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
https://poweredbybhis.com
Click here to watch a video of this episode.
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com
Antisyphon Training
https://www.antisyphontraining.com/
Active Countermeasures
https://www.activecountermeasures.com
Wild West Hackin Fest
Fler avsnitt av BHIS Webcasts
Visa alla avsnitt av BHIS WebcastsBHIS Webcasts med Black Hills Information Security finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.
