Ghost Machines

20 Oct 2026
Pacific E
Incident Response
Abstract Proposal: What if an attacker could deploy an entire operating environment instead of relying solely on malware or remote access tools? This session explores “Ghost Machines” lightweight, disposable virtual machines that provide isolated workspaces for browsing, reconnaissance, remote access, tooling, and command execution. We’ll examine how AI and large language models could further enhance these environments, enabling autonomous task execution and decision support. Attendees will learn the forensic artifacts, visibility gaps, and detection opportunities associated with this emerging tradecraft.

Speakers
Jeff Stanton
Jeff Stanton, Sr. Cyber Threat Researcher / Intel - Adobe