Detecting AI Threats Webinar

Justin Borland
Aurora Starita
Published on: 
September 3, 2026
On This Page
Share:
Try abstract today!
Abstract AI Gen. Composable platform diagram showing data sources, security data pipelines, detection fabric, data lakes, and AI SOC components including Hunt, SIEM Console, and Response & SOAR.

Get Abstracted!

AI-assisted attacks are no longer theoretical.

Attackers are using AI to move through environments faster, retain context, and compress work that once required handoffs between multiple operators. For defenders, the techniques may look familiar. The speed does not.

In this webinar, Abstract Security Director of Threat Engineering Justin Borland joins Aurora Starita to break down how security teams can detect threats involving Claude Code, Cowork, and AWS Bedrock.

Topics covered:

• Why Claude Code OTel, CloudTrail, and CloudWatch each provide only part of the picture

• How TrustFall can turn a trusted repository and malicious MCP server configuration into code execution

• Why endpoint telemetry and enrichment are critical for detecting poisoned MCP servers

• How direct and indirect Bedrock agent hijacking work

• What a 72-hour AI-assisted cloud compromise changes for defenders

• Which logs and data sources security teams should enable first

•How correlating multiple MITRE ATT&CK IDs within a short window can expose high-velocity attacks

Whether your organization is adopting coding agents, running workloads through AWS Bedrock, or preparing for attackers whose capabilities are being accelerated by AI, this is worth 30 minutes.