Ghost Machines
Abstract Proposal: What if an attacker could deploy an entire operating environment instead of relying solely on malware or remote access tools? This session explores “Ghost Machines” lightweight, disposable virtual machines that provide isolated workspaces for browsing, reconnaissance, remote access, tooling, and command execution. We’ll examine how AI and large language models could further enhance these environments, enabling autonomous task execution and decision support. Attendees will learn the forensic artifacts, visibility gaps, and detection opportunities associated with this emerging tradecraft.
