AI-assisted attacks are no longer theoretical.
Attackers are using AI to move through environments faster, retain context, and compress work that once required handoffs between multiple operators. For defenders, the techniques may look familiar. The speed does not.
In this webinar, Abstract Security Director of Threat Engineering Justin Borland joins Aurora Starita to break down how security teams can detect threats involving Claude Code, Cowork, and AWS Bedrock.
• Why Claude Code OTel, CloudTrail, and CloudWatch each provide only part of the picture
• How TrustFall can turn a trusted repository and malicious MCP server configuration into code execution
• Why endpoint telemetry and enrichment are critical for detecting poisoned MCP servers
• How direct and indirect Bedrock agent hijacking work
• What a 72-hour AI-assisted cloud compromise changes for defenders
• Which logs and data sources security teams should enable first
•How correlating multiple MITRE ATT&CK IDs within a short window can expose high-velocity attacks
Whether your organization is adopting coding agents, running workloads through AWS Bedrock, or preparing for attackers whose capabilities are being accelerated by AI, this is worth 30 minutes.