RSAC™ Membership Library

Flush Worthy or Fight Ready? Catching Attackers in SaaS Logs!

Steve Schohn, Ofer Maor ● March 25, 2026

Ever felt SaaS logs are useless? This talk will expose 10 outrageous logging fails used by attackers to hide in plain sight: missing data, nonsense events, vanishing trails, and more. From M365 & Salesforce to Copilot & Gemini, each example will show the investigation roadblocks it creates, followed by enrichments, correlations and tricks to turn broken logs into detections and catch attackers.

Login/Signup to Continue Reading