Kumar Ashwin

[email protected]
Events
talk

The Breach Is Over. The Exposure Is Not

Host
Recon Village @ DEF CON 34
Location
DEF CON Creator Stage 2, Las Vegas Convention Center, Las Vegas, NV, USA
Audience
Security Researchers, Incident Responders, Threat Intelligence Teams, AppSec Teams
Duration
30 minutes
Co-presenters Anant Shrivastava

Breaches are often treated as discrete incidents: a leak is discovered, the most obvious credentials are rotated, incident response winds down, and attention shifts elsewhere. But the exposure often continues long after the breach is considered closed.

This talk looked at the long tail of breach data: the less familiar secret classes, environmental context, repository paths, service identifiers, deployment stages, and naming conventions that can continue to support reconnaissance even after the headline credentials are remediated.

We also discussed Shai-Hulud exposures as a concrete example of how software supply-chain incidents can leave behind durable reconnaissance value: package metadata, leaked tokens, repository context, automation traces, and naming patterns that remain useful to attackers after the initial compromise is considered contained.

The core argument was simple: recovery should be measured by the disappearance of usable exposure, not just by the closure of the original incident.