BSidesCharm2025

Jenko Hwong

Jenko Hwong leads threat research and product at Widefield Security. He was formerly a Principal Threat Researcher at Netskope, speaks regularly at RSA and DEFCON, and helps with the Cloud VIllage CTF. He brings customer and product experiences from over 25 years in research, product management, and engineering at companies such as Cisco and TIBCO, as well as security startups in markets such as vulnerability scanning, anti-virus/anti-spam appliances, penetration-testing, threat intelligence, an


Session

04-12
12:00
50min
Fight Stealth with Stealth: Detecting post-breach activity in the Cloud
Jenko Hwong

Advanced and evolving cloud attacks (Blizzard) make breach seem inevitable. We describe a deception detection approach using canaries, with a bit of honey and razors, to implement stealthy tripwires to provide low-FP detections for post-breach lateral movement and privilege escalation.

Track 1