Flush Worthy or Fight Ready? Catching Attackers in SaaS Logs!
Steve Schohn, Ofer Maor ● March 25, 2026
Ever felt SaaS logs are useless? This talk will expose 10 outrageous logging fails used by attackers to hide in plain sight: missing data, nonsense events, vanishing trails, and more. From M365 & Salesforce to Copilot & Gemini, each example will show the investigation roadblocks it creates, followed by enrichments, correlations and tricks to turn broken logs into detections and catch attackers.