Divide and Conquer: A Many Subgraphs Approach to Hybrid Attack Path Management | SO-CON 26

Divide and Conquer: A Many Subgraphs Approach to Hybrid Attack Path Management | SO-CON 26

Source: YouTube · SpecterOps · published Jun 4, 2026 · 28:31

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The talk introduces a "divide and conquer" methodology using subgraphs to reduce the complexity of hybrid attack path management, comparing the advent of OpenGraph to the revolutionary shift from paper maps to GPS navigation 0:00.

Key Takeaways:
• The core focus is applying graph theory and OpenGraph to simplify and manage hybrid attack paths 0:10.
• The speaker draws on past experience in road construction, likening traditional security path analysis to manually planning routes with paper maps 0:28.
• The introduction of OpenGraph is framed as a transformative tool, similar to how GPS devices like TomTom eliminated the need for tedious, early morning manual route planning for crews 0:47.

By breaking down complex attack paths into manageable subgraphs, security teams can achieve the same operational efficiency gains that GPS brought to physical navigation.

Sources:

  • 0:00 Introduction of the talk's title and core premise on reducing complexity.
  • 0:10 Mention of using graph theory and OpenGraph for attack paths.
  • 0:28 Background on the speaker's road construction navigation experience.
  • 0:47 Comparison of OpenGraph's impact to the efficiency of TomTom GPS devices.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Uh, so this is my talk called divide and conquer, a many sub graphs approach to hybrid attack path management. And in this talk I'm going to use some ideas from graph theory and open graph to look at reducing complexity in hybrid attack paths. So, before we get into that, um, when open graph came out, I was reminded of these maps that I used to use when I was doing, uh, uh, road construction in a previous job. So, I'd drive around all over Minnesota, Wisconsin, few other states, and um, as I was doing this, these GPS units came out, the, um, sorry. The TomTom here, and it like drastically changed my day-to-day. I didn't have to get up early and plan out the route for the entire crew. Um, and that's what I thought of when open graph came out. So, um, just for framing, I got pretty excited w…