Evolution of Threats: Analyzing Pre-Mortem Retrospective Lessons
Download resourcesAbout this session
Kristopher Russo, a senior threat researcher with Palo Alto Networks' Unit 42, walks through a decade of defensive wins (MFA, email security gateways, EDR) and shows how attackers have adapted around each one. He illustrates the shift with three composite incident scenarios built from real Unit 42 cases: a fake-invoice extortion scheme that talks victims into installing a legitimate remote management tool; a supply chain compromise resembling Scattered Spider's tradecraft that uses SMS phishing to steal MFA-approved credentials and pivot to downstream clients; and a nation-state or organized-crime intrusion that buys stolen access from initial access brokers, maps backups and cyber insurance limits, then deploys custom ransomware. He maps each stage to prevention, detection and containment gaps, then recommends countermeasures: continuous, attack-specific awareness training, real-time attack surface management, inward- and outward-facing threat intelligence, behavior analytics, zero trust segmentation, and AI-assisted SOAR playbooks that augment rather than replace analysts. He closes with a call to invest in people, process and platform consolidation, and to bring in experienced outside experts rather than learning every lesson the hard way.
Key takeaways
- Assume attackers will route around single controls: MFA can be bypassed by real-time phishing relays, EDR by signed remote-management tools, and email gateways by malware-free social engineering.
- Run continuous, attack-specific awareness training targeted at end users, help desk staff and outsourcers, not one-off annual modules, since social engineering now leads most successful intrusions.
- Maintain real-time, complete attack surface visibility (hardware, software, patch levels) and patch your highest-risk, crown-jewel systems immediately rather than on a fixed monthly cycle.
- Monitor the dark web and criminal forums for your own leaked credentials so you can invalidate them before a buyer uses them to log in through the front door.
- Adopt zero trust segmentation instead of flat network zones, and use AI to help build and maintain SOAR playbooks so analyst time goes to real incidents, not noise.
Speakers

With an information security career spanning nearly two decades, Kristopher Russo is an experienced practitioner in numerous cybersecurity disciplines, including security architecture, engineering, incident response, digital forensics, risk… Read moreRead less
With an information security career spanning nearly two decades, Kristopher Russo is an experienced practitioner in numerous cybersecurity disciplines, including security architecture, engineering, incident response, digital forensics, risk management, and cyber threat intelligence. Kristopher firmly believes information security should not impede business but instead enable safety and security in every transaction.
A researcher, speaker, and writer, Kristopher is a threat researcher with Palo Alto Network's Unit 42. Kristopher holds a degree in Information Security and Intelligence from Ferris State University. His insight can be found in various security publications such as Down the Security Rabbit Hole, The CyberWire, and Unit 42's research blog.
