The Breach Is Over. The Exposure Is Not
- Location
- DEF CON Creator Stage 2, Las Vegas Convention Center, Las Vegas, NV, USA
- Audience
- Security Researchers, Incident Responders, Threat Intelligence Teams, AppSec Teams
- Duration
- 30 minutes
Breaches are often treated as discrete incidents: a leak is discovered, the most obvious credentials are rotated, incident response winds down, and attention shifts elsewhere. But the exposure often continues long after the breach is considered closed.
This talk looked at the long tail of breach data: the less familiar secret classes, environmental context, repository paths, service identifiers, deployment stages, and naming conventions that can continue to support reconnaissance even after the headline credentials are remediated.
We also discussed Shai-Hulud exposures as a concrete example of how software supply-chain incidents can leave behind durable reconnaissance value: package metadata, leaked tokens, repository context, automation traces, and naming patterns that remain useful to attackers after the initial compromise is considered contained.
The core argument was simple: recovery should be measured by the disappearance of usable exposure, not just by the closure of the original incident.