Uploaded August 2025 | Updated September 2026, 1 hour ago
Joe Slowik (The MITRE Corporation, US)
Joe Slowik has over 15 years of experience across multiple domains in computer network operations. Joe has previously led the CTI and ICS portions of the ATT&CK framework while also performing in-depth critical infrastructure threat research for the MITRE Corporation. Joe has also led threat intelligence and network detection engineering at Gigamon, performed independent security research at DomainTools and Dragos, and led the incident response team at Los Alamos National Laboratory. Joe got his start in security through various roles in the US Navy, and remains in New Mexico where he continues to advocate for threat-driven approaches to network security.
--
Information security, and especially threat intelligence, often elevates adversaries into unique, "sophisticated" entities practicing particular, specific tradecraft. However, the truth of the matter is that threat actor operations have undergone a great convergence in behaviors in the past several years. This great convergence results in commodity eCrime actors looking almost indistinguishable from state-sponsored entities in many phases of network intrusions. As a result, threat actors look less "unique" and begin to blend together into a nearly indistinguishable mess of tradecraft and tool reuse.In this discussion, we will explore how this convergence has come to pass, then review its implications. From a threat intelligence perspective, delineating between threat actors has become increasingly difficult as behaviors overlap, but from a defender perspective countering these entities has become somewhat simplified or at least focused given adversary overlap. However, such overlap does not take place in a vacuum. Particularly, threat actors have naturally evolved toward methodologies that inherently blend in with normal actions - from LOLBins to RMM abuse - creating significant problems for detection and response. We will conclude the discussion with an overview of how adversaries have converged on abuse of "benign" mechanisms and what this means for the future of both offense and defense in network security.
Joe Slowik (The MITRE Corporation, US)
Joe Slowik has over 15 years of experience across multiple domains in computer network operations. Joe has previously led the CTI and ICS portions of the ATT&CK framework while also performing in-depth critical infrastructure threat research for the MITRE Corporation. Joe has also led threat intelligence and network detection engineering at Gigamon, performed independent security research at DomainTools and Dragos, and led the incident response team at Los Alamos National Laboratory. Joe got his start in security through various roles in the US Navy, and remains in New Mexico where he continues to advocate for threat-driven approaches to network security.
--
Information security, and especially threat intelligence, often elevates adversaries into unique, "sophisticated" entities practicing particular, specific tradecraft. However, the truth of the matter is that threat actor operations have undergone a great convergence in behaviors in the past several years. This great convergence results in commodity eCrime actors looking almost indistinguishable from state-sponsored entities in many phases of network intrusions. As a result, threat actors look less "unique" and begin to blend together into a nearly indistinguishable mess of tradecraft and tool reuse.In this discussion, we will explore how this convergence has come to pass, then review its implications. From a threat intelligence perspective, delineating between threat actors has become increasingly difficult as behaviors overlap, but from a defender perspective countering these entities has become somewhat simplified or at least focused given adversary overlap. However, such overlap does not take place in a vacuum. Particularly, threat actors have naturally evolved toward methodologies that inherently blend in with normal actions - from LOLBins to RMM abuse - creating significant problems for detection and response. We will conclude the discussion with an overview of how adversaries have converged on abuse of "benign" mechanisms and what this means for the future of both offense and defense in network security.










