Uploaded August 2026 | Updated September 2026, 3 weeks ago
What happens when advanced cyberattacks are no longer rare, but routine?
In the Black Hat USA 2026 Keynote “The End of Rare: Defending When Offense Is Cheap”, David Weston tackles the growing imbalance between increasingly affordable offensive capabilities and the rising demands placed on defenders to secure complex environments.
As AI, automation, and widely available offensive tooling continue to lower the cost of attack, the challenge is no longer how to stop every threat. It's how to build resilient systems that can withstand constant pressure.
Walk away with practical insights, a clear picture of the threat-landscape shift, and a concrete case for emergent defense in the AI era.
Keynote Speaker: David Weston | Agentic Security Leader, Microsoft
Learn more: blackhat.com/us-26/features/schedule/index.html#keynote-the-end-of-rare-defending-when-offense-is-cheap-56597
What happens when advanced cyberattacks are no longer rare, but routine?
In the Black Hat USA 2026 Keynote “The End of Rare: Defending When Offense Is Cheap”, David Weston tackles the growing imbalance between increasingly affordable offensive capabilities and the rising demands placed on defenders to secure complex environments.
As AI, automation, and widely available offensive tooling continue to lower the cost of attack, the challenge is no longer how to stop every threat. It's how to build resilient systems that can withstand constant pressure.
Walk away with practical insights, a clear picture of the threat-landscape shift, and a concrete case for emergent defense in the AI era.
Keynote Speaker: David Weston | Agentic Security Leader, Microsoft
Learn more: blackhat.com/us-26/features/schedule/index.html#keynote-the-end-of-rare-defending-when-offense-is-cheap-56597
![Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)
Event Tracing for Windows (ETW) is a built-in Windows logging and tracing framework that collects system and application events, providing detailed visibility into whats happening on a machine. In security, ETW is widely leveraged as one of the key telemetry sources for modern Endpoint Detection and Response (EDR) products because of the wealth of data it provides.
This trace data is generated by components known as providers. While four types exist—Managed Object Format (MOF), Windows software trace preprocessor (WPP), Manifest-based, and TraceLogging—Microsoft generally recommends using the two modern variants: Manifest-based and TraceLogging providers [1].
However, a significant knowledge gap exists. While Manifest-based providers are relatively well-understood [2], information regarding TraceLogging providers remains scarce. Consequently, it is questionable whether the security community is truly maximizing ETWs full potential.
To bridge this gap and enable defenders to better leverage ETW, we will present our findings on TraceLogging providers in the latest Windows. We will cover how to work with them, highlight providers potentially useful for security (e.g., AttackSurfaceMonitor), and walk through practical use cases.
Asuka Nakajima | Senior Security Research Engineer, Elastic
https://blackhat.com/asia-26/briefings/schedule/?#hidden-telemetry-uncovering-tracelogging-etw-providers-youre-not-using-yet-51991 Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)](https://i.ytimg.com/vi/ubFcs1M62P4/mqdefault.jpg)









