Uploaded August 2026 | Updated September 2026, 1 hour ago
Pierre Audonnet (Microsoft, CA)
This session focuses on what AiTM activity looks like inside Entra ID: the key authentication events, token behaviors, and anomalies attackers leave behind. We then cover how to surface and interpret these signals, using KQL only as an example to navigate telemetry (especially since Entra ID logs are often unclear or incomplete).
Attendees leave with a clear takeaway: practical patterns, investigative cues, and a short list of effective mitigations to quickly detect and block AiTM techniques in real environments.
---
For the past decade, Pierre Audonne has worked with SOC teams of all sizes to help them detect, investigate, and respond to modern threats. Pierre's primary focus is the Microsoft identity stack (Entra ID and the full suite of on-premises Active Directory technologies). He specializes in understanding attacker tradecraft and translating it into practical detection strategies for defenders. When he's not helping my customers with their cyber fires, he's creating and teaching technical workshops and helping large organizations deploy Zero Trust architecture.
Pierre Audonnet (Microsoft, CA)
This session focuses on what AiTM activity looks like inside Entra ID: the key authentication events, token behaviors, and anomalies attackers leave behind. We then cover how to surface and interpret these signals, using KQL only as an example to navigate telemetry (especially since Entra ID logs are often unclear or incomplete).
Attendees leave with a clear takeaway: practical patterns, investigative cues, and a short list of effective mitigations to quickly detect and block AiTM techniques in real environments.
---
For the past decade, Pierre Audonne has worked with SOC teams of all sizes to help them detect, investigate, and respond to modern threats. Pierre's primary focus is the Microsoft identity stack (Entra ID and the full suite of on-premises Active Directory technologies). He specializes in understanding attacker tradecraft and translating it into practical detection strategies for defenders. When he's not helping my customers with their cyber fires, he's creating and teaching technical workshops and helping large organizations deploy Zero Trust architecture.










