Uploaded May 2026 | Updated September 2026, 46 minutes ago
Josh Skorich (Spektion, US)
Vulnerability management programs are optimized for what can be named and matched: a product, a version, a CVE. But real environments contain significant software that exists outside practical CVE coverage: legacy tools from defunct vendors, obscure utilities embedded in base images, regional software without CNA relationships, and abandoned projects that still run in production. If a scanner can't fingerprint it, your pipeline produces no finding, no ticket, no owner. The risk is invisible by design.
This talk presents an endpoint-telemetry approach to finding and governing that blind spot, born from a career in red teaming where the most interesting findings were rarely in software with CVE coverage. Using host-level runtime events (process execution, privilege context, network connections), we can identify software that scanners miss and surface pre-CVE risk: exploit-relevant behaviors observable in production before any advisory exists. Think of the output as synthetic CVEs for software that the ecosystem doesn't cover. I'll walk through concrete examples, show what host telemetry can and cannot prove, and discuss how these findings integrate into existing VM workflows alongside traditional CVE-based results.
---
Josh Skorich is Founder and CTO at Spektion, working on runtime-based security for production environments. He spent over a decade in red teaming and adversary simulation, leading offensive security programs across financial systems, critical infrastructure, and cloud environments. His focus is bringing operational security reality into scalable, repeatable vulnerability governance.
Josh Skorich (Spektion, US)
Vulnerability management programs are optimized for what can be named and matched: a product, a version, a CVE. But real environments contain significant software that exists outside practical CVE coverage: legacy tools from defunct vendors, obscure utilities embedded in base images, regional software without CNA relationships, and abandoned projects that still run in production. If a scanner can't fingerprint it, your pipeline produces no finding, no ticket, no owner. The risk is invisible by design.
This talk presents an endpoint-telemetry approach to finding and governing that blind spot, born from a career in red teaming where the most interesting findings were rarely in software with CVE coverage. Using host-level runtime events (process execution, privilege context, network connections), we can identify software that scanners miss and surface pre-CVE risk: exploit-relevant behaviors observable in production before any advisory exists. Think of the output as synthetic CVEs for software that the ecosystem doesn't cover. I'll walk through concrete examples, show what host telemetry can and cannot prove, and discuss how these findings integrate into existing VM workflows alongside traditional CVE-based results.
---
Josh Skorich is Founder and CTO at Spektion, working on runtime-based security for production environments. He spent over a decade in red teaming and adversary simulation, leading offensive security programs across financial systems, critical infrastructure, and cloud environments. His focus is bringing operational security reality into scalable, repeatable vulnerability governance.










