[Speakers]
Adversary Village at
DEF CON 34

Russell Harvey

Senior Consultant

Russell leads Purple Teams as a Master of Ceremonies (MC), a role that requires deep knowledge of both defensive and offensive tools and techniques. He also plays a key role in facilitating research and innovation within the purple team program, and helps develop payloads and automations for Purple Team engagements. Before his current role, Russell gained valuable experience at SRA in the CyberSOC, where he specialized in threat hunting, detection engineering, incident response, and served as a client lead.

Russell graduated from the Rochester Institute of Technology (RIT) in 2022 with a B.S. in Computing Security. His professional interests extend to malware development/reverse engineering, penetration testing, and operating system internals.

Detection Coverage Is a Hypothesis: Testing It Through Adversarial Execution Variance

15:00-16:55 PDT | Friday, Aug 7th 2026 | Adversary Village Workshop Stage, Las Vegas Convention Center
Hands-on Workshop

Co-presented with: Connor Jackson, Nahid Sarker

Abstract

Security teams routinely assume that known techniques are covered. This workshop interrogates that assumption through a structured purple team exercise conducted in an active lab environment. Participants will systematically execute the same adversarial techniques across multiple implementation variants, observing how subtle changes in execution method produce dramatically different telemetry, alter detection fidelity, and expose blind spots in EDR and SIEM tooling.


The workshop emphasizes stealthy execution tradecraft as a variable rather than a constant, treating each implementation as a testable hypothesis about defender visibility. Attendees will build detections, hunt across collected telemetry, and leave with guidance for evaluating detection coverage against technique variance in their own environments.

Workshop outline

1. Introductions
2. Looking at existing detection rules
- Out-of-the-box EDR detections
- Public SIGMA rules
- Custom rules seen in client environments
3. Discussion of execution variants
- What is a "technique"
- How we can perform a technique while reducing potential indicators of attack
4. Hands-On Workshop
- Participants will see several execution variants across common TTPs in a lab environment
- Participants will observe the difference in response and perform basic threat hunts to identify the attacks
- Participants will tune existing rules to cover missed variants
5. Take-aways / Questions

Agency.


Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!