Always Under Attack: Turning Purple Teaming into Continuous Security Validation
Joey takes one operational question and refuses to leave it: do your detections actually catch real attacks, right now? The session shows how HackerFlow answers that continuously instead of once a year, ingesting threat intelligence, turning it into threat-informed test plans, and running repeatable simulations mapped to MITRE ATT&CK using open-source C2 frameworks alongside a private C2 for more advanced tradecraft.
The part worth staying for is what gets tested. Commodity checks like basic PowerShell are easy for any EDR to catch, so the demo pushes into fileless and in-memory behaviour and realistic operator patterns, then shows whether detections fired, what telemetry was captured, and what the gap report looks like when they did not. That evidence trail is also what DORA and NIS2 conversations keep asking for.
Never Hunt Alone: A Threat Hunting Companion for the SOC
Threat hunting tends to live in the heads of two or three people, which makes it hard to schedule, hard to measure, and impossible to hand over. Adriaan and Atilla show how 7Hunter turns it into a workflow you can repeat: from a CTI lead or a hypothesis to an executable hunt in minutes, drawing on a library of more than 8,000 pre-built KQL queries and more than 75 investigation runbooks, all mapped to ATT&CK so coverage is something you can point at.
The demo covers one-click export to Microsoft Sentinel with the hunt created for you, an AI assistant running live KQL mid-investigation so iteration does not stall, and the public REST API for teams wiring hunts into SOAR pipelines.
The through line
Two sessions, two angles, one platform. HackerFlow proves whether an attack would be caught. 7Hunter goes looking for what already slipped past. Neither is worth much without the other, and both produce the same thing in the end: evidence of what your controls actually do, not what the datasheet says they do.
If either session raised a question about your own environment, the fastest way to get it answered is a working session with our team.