Get our latest research in your inbox

New threat intelligence, detection engineering, and red team write-ups, delivered when we publish.

Both Cybersec Netherlands Talks, Now on Video

September 18, 2026Crimson7
eventscontinuous threat validationpurple teamingthreat huntingdetection engineeringHackerFlow7Hunter

Always Under Attack: Turning Purple Teaming into Continuous Security Validation

Joey Verleg, Head of Managed Services. Recorded Wednesday 9 September, Masterclass Theater 2. Runtime 27:40. Watch on YouTubePressing play loads the video from YouTube, which may set cookies.
Want this run against your own detections?Book a demo and we will walk HackerFlow through scenarios that match your stack.Book a demo

Joey takes one operational question and refuses to leave it: do your detections actually catch real attacks, right now? The session shows how HackerFlow answers that continuously instead of once a year, ingesting threat intelligence, turning it into threat-informed test plans, and running repeatable simulations mapped to MITRE ATT&CK using open-source C2 frameworks alongside a private C2 for more advanced tradecraft.

The part worth staying for is what gets tested. Commodity checks like basic PowerShell are easy for any EDR to catch, so the demo pushes into fileless and in-memory behaviour and realistic operator patterns, then shows whether detections fired, what telemetry was captured, and what the gap report looks like when they did not. That evidence trail is also what DORA and NIS2 conversations keep asking for.

Never Hunt Alone: A Threat Hunting Companion for the SOC

Adriaan Neijzen, Head of Offensive Security, with Atilla Balin, Defensive Security Consultant. Recorded Thursday 10 September, Masterclass Theater 2. Runtime 24:31. Watch on YouTubePressing play loads the video from YouTube, which may set cookies.
Want to see this against your own telemetry?Book a demo and we will run 7Hunter on hunts that matter to your SOC.Book a demo

Threat hunting tends to live in the heads of two or three people, which makes it hard to schedule, hard to measure, and impossible to hand over. Adriaan and Atilla show how 7Hunter turns it into a workflow you can repeat: from a CTI lead or a hypothesis to an executable hunt in minutes, drawing on a library of more than 8,000 pre-built KQL queries and more than 75 investigation runbooks, all mapped to ATT&CK so coverage is something you can point at.

The demo covers one-click export to Microsoft Sentinel with the hunt created for you, an AI assistant running live KQL mid-investigation so iteration does not stall, and the public REST API for teams wiring hunts into SOAR pipelines.

The through line

Two sessions, two angles, one platform. HackerFlow proves whether an attack would be caught. 7Hunter goes looking for what already slipped past. Neither is worth much without the other, and both produce the same thing in the end: evidence of what your controls actually do, not what the datasheet says they do.

If either session raised a question about your own environment, the fastest way to get it answered is a working session with our team.