Blue Team | Unveiling Insider Threats Beyond the Logs

Blue Team | Unveiling Insider Threats Beyond the Logs

🎙 Oscar Cárcamo 👥 70K 📅 February 17, 2026 ⏱ 34 min 👁 318 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

insider threatdual-identity evasionhigh-fidelity threat huntingSIEM gapstelemetry

Summary

In this presentation from SANS Hack & Defend Summit 2025, Oscar Cárcamo, a senior consultant, discusses a real-world insider threat case that evaded traditional SIEM detection. The attacker used a ‘Dual-Identity Evasion Technique’ involving both physical and virtual authentication tokens to create parallel sessions, bypassing correlation rules. The talk highlights the challenges of telemetry chaos, including inconsistent log formats, time drift, and missing fields, which hindered detection. Cárcamo emphasizes the importance of high-fidelity data over volume, advocating for a proactive threat hunting approach that involves understanding log sources, refining data, and incorporating business rules. He presents a four-step cycle (analyze, define, refine, hunt) and shares key takeaways such as building event catalogs, checking time zones, and rotating analysts to mitigate fatigue. The presentation is based on a case where 2 million events were reduced to 50,000 relevant ones, illustrating the value of high-fidelity hunting.

144 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into a real insider threat scenario and offers a practical methodology for improving threat hunting. The argumentation is based on a detailed case study, which adds credibility. However, the presentation is largely anecdotal, with limited quantitative evidence or external validation. The speaker’s expertise is evident, but the lack of specific technical details or reproducible steps may limit its immediate applicability. The emphasis on high-fidelity data and the importance of understanding log sources is well-argued and relevant to practitioners.

Scientific Rigor, Source Quality, Title Accuracy

The talk is based on the speaker’s professional experience and does not cite external sources. The title accurately reflects the content, focusing on insider threats and the limitations of traditional log analysis. The presentation is well-structured and the speaker demonstrates deep knowledge of the subject. However, the lack of references and the reliance on a single case study reduce the scientific rigor. The audience comments are not provided, so no analysis of public reception is possible.

174 words

Title / Content Match

The title accurately reflects the content, focusing on insider threats and the limitations of traditional log analysis.

Quality & Reliability

7/10

The talk is based on a real incident and presents a practical methodology, but it is an expert opinion with limited verifiable data and no external references.

Key Moments

Contribution & Novelties

The talk introduces the ‘Dual-Identity Evasion Technique’ and emphasizes the importance of high-fidelity data over volume in threat hunting. It provides a practical framework for improving telemetry quality and incorporating business rules into detection. The case study illustrates the limitations of SIEM and the need for proactive hunting.

Pour aller plus loin :

  • MITRE ATT&CK — Framework for understanding adversary tactics and techniques.
  • SANS Institute — Training and resources on cybersecurity.
  • YARA — Pattern matching tool for malware identification.

79 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly higher scores in information quantity and quality, indicating a well-rounded presentation. The technical level is moderate, making it accessible to a broad audience.

Reliability 6/10