Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

50 Minute Watch Devon Ackerman |
Global Services Leader, DFIR, LevelBlue
Paul Asadoorian |
Principal Security Researcher, Eclypsium

With 300+ incident response experts responding to more than 1,500 engagements each year, LevelBlue sees how modern attackers evade detection by abusing trusted tools, processes, and human behavior.

Join Devon Ackerman, Global Services Leader of DFIR and former FBI Supervisory Special Agent, as he shares three real-world cases: Microsoft Graph API abuse for stealth data exfiltration, SEO poisoning that creates accidental insider threats, and help desk social engineering tied to MFA reset.

We discuss how each one could have been detected and the steps you can take to prevent similar attacks.

You’ll learn:

  • How attackers exploit trusted tools and everyday business processes to evade detection

  • Lessons from three real incident-response engagements and the indicators defenders may miss

  • Practical steps to close visibility gaps and strengthen detection against trust-based attacks

Watch the Webinar

Related Resources

Current: resourceswebinarsinside-1500-incidents-when-trusted-tools-become-attack-vectors
Resource: resourceswebinarsus-water-utility-cyberattacks-what-the-exposure-data-reveals
Webinar

US Water Utility Cyberattacks:​ What the Exposure Data Reveals

Current: resourceswebinarsinside-1500-incidents-when-trusted-tools-become-attack-vectors
Resource: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Webinar

Inside MAD-CAT: How We Recreated the Meow Attack for Security Testing

Current: resourceswebinarsinside-1500-incidents-when-trusted-tools-become-attack-vectors
Resource: resourceswebinarsttp-emea-briefing-q2-2026
Webinar

LevelBlue EMEA TTP Briefing Q2 2026