August 1-6, 2026
Mandalay Bay, Las Vegas, NV, USA
Take Away The Trust Attackers Need
Visit Our Booth: 3333
DannyJenkins

ThreatLocker is proud to be the first and only Apex Partner of Black Hat, and we're excited to connect with you over the next few days.

If you've been on the conference circuit this year, you know what's dominated it: AI. AI vulnerability research. AI-generated exploits. Securing AI itself. AI-accelerated attacks. Keeping AI contained. As with any topic that takes over, at some point it starts to sound like noise.

So, my advice is simple. Listen carefully to the risks, then focus on what you can act on today. Nearly every incident we looked at this year came back to trust. Attackers need just a single entry point that grants them trust with room to move. Protecting from misplaced trust should not feel insurmountable, and you can begin tackling it immediately.

We'd love for you to stop by the ThreatLocker booth #3333 and talk through how we can help. My hope is that, at the end of the conference, you leave here with recommendations or solutions you can begin deploying next week.

To that end, here are a few proven-and-true controls worth revisiting. It's about implementing what we already know works.

Start with an accurate inventory. You cannot enforce policy on what you cannot see. Baseline every execution, script, network connection, and file access across your endpoints before you write a single rule. Include portable executables and interpreters that never register in add/remove programs.

Move to deny-by-default execution. Approve the applications, scripts, and libraries the business actually needs, then block everything else. Roll it out in monitor-only mode first so you can see what a policy would have stopped before it stops anything.

Extend least privilege to applications, not just users. Approved software remains the most common attack path. Contain what each application can reach, such as other processes, the registry, network egress, sensitive file paths. Word has no business spawning PowerShell. Those same boundaries are how you prevent AI from having excessive agency.

Eliminate standing administrative rights. Elevate the application, not the user, and make it time-bound. Persistent local admin turns one phished credential into privilege escalation and lateral movement.

Assume credentials will be stolen. Adversary-in-the-middle kits relay MFA codes, and a replayed session token skips authentication altogether. Bind authorization to an approved device so that a valid password, an approved prompt, and a live token still fail from unmanaged hardware.

Prioritize the patch window, not the patch count. Exploitation now follows disclosure within hours, so patching time must also accelerate. Rank by exposure  and by those known to be exploited in the wild. Confirm your tooling detects by file hash and not by registry keys, so that portable apps do not stay unpatched and invisible.

AI has changed how fast attackers can build. It has not changed the trust they need to launch an attack. Take that trust away and you replace detection with prevention, and speed matters far less.

Must-See Exhibitors & Sponsors at Black Hat USA 2026
Top Companies Leading the Way at Black Hat USA 2026

Discover More

Black Hat Events App
Arsenal
Trainings
August 1-6, 2026
Mandalay Bay, Las Vegas, NV, USA
Immerse yourself in four days of specialized training for all skill levels, an exclusive Summit Day, and our electrifying two-day main conference featuring 100+ cutting-edge Briefings, live Arsenal demos, and unparalleled networking opportunities.
© 2026 Informa USA, Inc., All Rights Reserved | Privacy Policy | Terms of Service