Lessons From Building a Cloud Attack Simulation Program - Pavel Lineitsev

Speaker: Pavel Lineitsev Pavel is a Senior Security Engineer on the Detection and Response team at Confluent, where he builds detection rules, designs logging pipelines, and investigates security incidents across multiple cloud providers. With nearly a decade of experience in cybersecurity, he has developed a deep focus on cloud security, detection engineering, and incident response. Talk: Cloud detection rules break silently. You write one, deploy it, and the only feedback is silence — which could mean no attacks, or could mean your rule stopped working three months ago. When you're maintaining rules across multiple cloud providers, the problem compounds: different telemetry, different log formats, etc. We wanted a better feedback loop, so we reached for attack simulation. We started with Threatest, Datadog's open-source framework for pairing cloud attack execution with detection validation. It gave us a solid foundation — but we hit its limits fast. We run a different SIEM, we needed custom attack techniques, and we wanted tighter control over execution and results. So we extended it. This talk is about what we built, what surprised us along the way, and the mistakes we'd avoid if we were starting over. If your team is weighing whether to invest in building something like this rather than buying a commercial alternative, we hope our experience gives you an honest picture of what that actually looks like. Recorded at fwd:cloudsec North America 2026 - Bellevue, WA https://fwdcloudsec.org/conference/no...

One Architectural Sin, Two Clouds, and a Universal Attack Technique for Data Hijacking - Yahav
▶︎

One Architectural Sin, Two Clouds, and a Universal Attack Technique for Data Hijacking - Yahav

Discovering New AWS Privilege Escalation Paths with an AI-Driven Workflow - Seth Art
▶︎

Discovering New AWS Privilege Escalation Paths with an AI-Driven Workflow - Seth Art

Artificial Intelligence 🤝 Natural Stupidity - Brandon Sherman
▶︎

Artificial Intelligence 🤝 Natural Stupidity - Brandon Sherman

Barbarians at the Gate: Visualizing and Blocking SDLC Infrastructure Threats with SITF - S Berkovich
▶︎

Barbarians at the Gate: Visualizing and Blocking SDLC Infrastructure Threats with SITF - S Berkovich

Passkeys Explained: Are They Actually Better Than Passwords?
▶︎

Passkeys Explained: Are They Actually Better Than Passwords?

Nora Tschirner: Interview mit Sicherheitsabstand | Die Harald Schmidt Show (ARD)
▶︎

Nora Tschirner: Interview mit Sicherheitsabstand | Die Harald Schmidt Show (ARD)

Who Are the Robots? Uncovering AI Agents Identities - Ron Popov & Clément Notin
▶︎

Who Are the Robots? Uncovering AI Agents Identities - Ron Popov & Clément Notin

Beyond the Checkbox: What Breaks When You Actually Stress-Test Cloud Incident Response - M Harvey
▶︎

Beyond the Checkbox: What Breaks When You Actually Stress-Test Cloud Incident Response - M Harvey

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains
▶︎

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

Do Apps Have Imposter Syndrome? Unmasking Token Theft Campaigns - Shahar Dorfman & Sapir Federovsky
▶︎

Do Apps Have Imposter Syndrome? Unmasking Token Theft Campaigns - Shahar Dorfman & Sapir Federovsky

🚗 BYD : The biggest SCAM of the car industry ?
▶︎

🚗 BYD : The biggest SCAM of the car industry ?

They Called Kung Fu “Dancing” Until Bruce Lee Entered the Ring Against 3 Karate Giants
▶︎

They Called Kung Fu “Dancing” Until Bruce Lee Entered the Ring Against 3 Karate Giants

Schrödinger’s Detection: Finding the "Zombie" Rules in Your SIEM - Gowthamaraj
▶︎

Schrödinger’s Detection: Finding the "Zombie" Rules in Your SIEM - Gowthamaraj

A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild - Steve Turner
▶︎

A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild - Steve Turner

The Insane Genius of a Formula 1 Gearbox
▶︎

The Insane Genius of a Formula 1 Gearbox

Conan O’Brien Delivers the Commencement Address | Harvard Commencement 2026
▶︎

Conan O’Brien Delivers the Commencement Address | Harvard Commencement 2026

Your Life As Every Cybersecurity Rank
▶︎

Your Life As Every Cybersecurity Rank

When One Vulnerability Cascades Across Cloud Infrastructure - Albin Vattakattu & Ryan Nolette
▶︎

When One Vulnerability Cascades Across Cloud Infrastructure - Albin Vattakattu & Ryan Nolette

Data Perimeters: Beyond the Marketing - Matt Luttrell
▶︎

Data Perimeters: Beyond the Marketing - Matt Luttrell

How Google Tracks Everything You Do and How to Stop It
▶︎

How Google Tracks Everything You Do and How to Stop It