BSides Joburg 2024

BSides Joburg 2024

I've seen you get hacked! (AI Real-Time Attack Simulation)
2024-07-20 , Track 1

Imagine running multiple threat models, attack trees and graphs – simultaneously - on real-time asset cartography, vulnerability data and threat intelligence. Leveraging AI for predictive analytics, you could proactively defend regardless of the dynamics and turbulence presented in the emerging technology, attacker or vulnerability landscape. This is how we did it - and what we learnt.


Attack simulation, emulation and modelling offer defenders insights into the potential for a risk to be realised. We can understand threats, vulnerabilities and impact helping us prioritise our remediation efforts. In a world where we are required to defend against asymmetric cyber-attack; how we use and focus limited security resources is an essential part of artful defence.

Most defenders use physical simulation (such as penetration testing) or emulation (such as virtual twins). Attack modelling require less resource, making it cost-effective and easy to scale. However, it is a point-in-time, desktop exercise, where risk is in the eye of the beholder. Therefore it produces a lower fidelity output. The question we asked ourselves: How can we improve modelling fidelity to perform continuous real-time cyber risk assessment?

In this talk we will demonstrate an AI-based platform developed to run simulations, in real-time, on network and internet data at scale. Classifying and prioritising threat and vulnerability incident response in a dynamic asset landscape. Could this empower you to have a predictive and proactive posture? Join the talk and demonstration to find out!

Nithen Naidoo is the founder of Snode Technologies, a South African Cyber Defence firm. Snode's homegrown technologies have won international recognition, most notable is the DTI’s South African Innovation Award in 2020.