Auvik Warns AI Can Erase Cyberattack Evidence
AI Is Changing the Cyber Forensics Challenge
Mike Vizard speaks with Steve Petryschuk, vice president of product and market strategy at Auvik, during Techstrong TV’s Black Hat 2026 coverage. The conversation looks at AI-powered cyberattacks and a troubling new concern for defenders. Attackers may use AI not only to launch attacks, but also to erase or obscure the forensic evidence that proves they were there.
Petryschuk explains that this is a natural extension of the same AI arms race shaping cybersecurity. Defenders are using AI to improve productivity, security operations and response. Attackers are also finding ways to use AI for speed, scale and stealth. That means security teams need to rethink what evidence they collect and how they confirm what changed.
Erased Evidence Still Leaves Signals Behind
The discussion explores what happens when logs and telemetry no longer provide a clean smoking gun. Petryschuk says teams may still be able to find surrounding evidence. Even if an attacker covers tracks, the environment may still show that something changed. The challenge is knowing what normal looked like before the incident.
That makes visibility more important. Security and IT teams need accurate inventories of assets, services, configurations and exposed systems. They also need enough context to compare the current state against a trusted baseline. Without that foundation, AI-powered cyberattacks can become harder to investigate and harder to contain.
The Network Perimeter Remains a Target
Petryschuk also points to threat activity around the network perimeter. Attackers continue to target edge devices and exposed services as a way into organizations. This is not a new tactic, but AI can increase the speed and scale of the activity. It can also make cleanup and evidence review more difficult.
Auvik’s perspective centers on improving visibility across the environment. Petryschuk says teams should understand what is exposed, what services are running and which assets need attention. That includes traditional infrastructure and the growing SaaS landscape. Better documentation gives defenders a clearer view of risk.
Defenders Need to Know What Good Looks Like
Mike and Petryschuk also discuss the speed of modern attacks. As activity moves closer to machine speed, human teams cannot rely only on manual review. They need systems that help them understand previous state, current state and the differences between the two. That comparison is central to detection, investigation and recovery.
For IT and security leaders, the takeaway is clear. AI-powered cyberattacks raise the value of network visibility, asset inventory and reliable telemetry. If attackers try to erase evidence, defenders need other ways to prove what happened. Auvik’s message is that knowing what good looks like may become one of the most important defenses of all.
Transcript
Hey guys, thanks for the intro. We're here with Steve Petryschuk, who's vice president of product and market strategy for Auvik, and we're having a chat about an interesting phenomenon, but it looks like the bad guys are using AI not only to attack us, but they're also using it to wipe away the forensics evidence, so we may never know that they were actually there. Steve, welcome to the show.
Thanks for having me on, Mike. Great to be here. So walk us through what's going on here, and how did this all come about, and if this is the case, then how the heck are we supposed to defend ourselves?
That's a great question. And I guess to get started it's only obvious that as we find ways to use AI for good, for productivity gains, for improved defensive security, it's only obvious that the bad actors will find ways to use it for bad, right? It's this old tit-for-tat game we've had in security landscape for quite a long time.
And so in a sense, the continued evolution of use of AI in offensive security, away from just the actual attack, would then start in to raise some of the tracks, is only natural, right? It's a natural progression as the tools continue to get better and stronger. So in theory, though, we were collecting telemetry data to find evidence in our logs that something was amiss, and if the bad guys are going in and removing that evidence, then what are the odds that we're going to be able to discover what's going on here?
I think we've got to look at some of the evidence that we can still maintain that may not be the ripest targets for erasing their tracks. If I am following an animal along in the forest or something like that, and they leave their tracks, if I try to cover those up, there's still evidence that something has changed, right? It's not exactly like it was before.
So it may not be the smoking gun that we've had before to say, "This is the exact evidence of a breach," but we can look for things around that. And the report where this was surfaced up in the CrowdStrike report definitely had a few recommendations that we can look at that tools like Auvik can help with to help get better visibility into what else may have happened. All right.
You mentioned the CrowdStrike report, so what's in this report, per se, and how does it pertain to this conversation? Good question. So, one of the findings in there was around threat actors continuing to target the network perimeter, and using that as a way into the organization.
And then covering their tracks from that sense. And I think that this isn't necessarily a new concept. They've always targeted edge devices.
That's sort of always been one path into the network beyond some of the social engineering, and other items that we can cover off on. But understanding what you have exposed, understanding what you have out there is an interesting connection between this targeting of the network perimeter and just being able to ensure that we know what is on our perimeter, we know what services and assets are exposed, so that we have that full documentation, and we're able to manage and maintain, and keep that infrastructure up to date. So if the tracks are maybe not as obvious, but there are indicators of some activity somewhere, what exactly am I supposed to be looking for?
So I think the start of it is understand what the current landscape looks like. And so we might look at things like, what is my current IT asset inventory, whether that's a physical asset inventory in terms of devices and assets, whether it's a software asset inventory, knowing all of my installed software applications, knowing what SaaS applications people are using, know what my standard profile of traffic looks like. And so that's the first step in preparing for this eventual outcome, that might be, hey, we have to respond to an incident where I don't have that same amount of evidence.
And so if I know what good looks like today, assuming, of course, that today is good, that you're in good shape today, you can know what all the software applications are, what all the SaaS applications are, and that's keeping my house in order. Keeping that up-to-date asset inventory is, I think, the first step that we need to take to prepare ourselves for this eventuality that maybe we'll be looking back and trying to understand what changed. Well, I need to know what good looks like.
And so to do that, we need to start thinking about how do I get visibility across not just the physical asset inventory, but that whole software asset inventory. These are foundational things, right? They're the critical security controls in one and two, but they're still things that, depending on the size of the organization, and especially as you move down from the enterprise level, a lot of organizations still struggle with some aspects of those controls.
There's a lot of talk these days about advanced AI models, mythos, and all the things that may be coming down the pike. What should we actually be prepared for here? Because I think on the one hand, we all like to hope for the best, but we should probably prepare for the worst, but it's not clear to me that everybody has a clear understanding of, well, just what could the worst-case scenario be?
Yeah. So I think for me, the important differentiation is today, at least from what we can tell in the public realm, that the operator of the AI, at least today, we believe is still in control of the mission, right? There's someone directing these offensive tools to do something.
And so I think what we have to prepare ourselves for is that that might not always be the case. I don't have an answer on how to do that today. The person who answers that question will be probably well-rewarded within the industry.
But I think that's the eventuality that we need to start thinking about is how do we prepare ourselves for this environment where the operator of the AI may no longer be in control, and that'll be an interesting day when we get there, to say the least. And is it possible there's just going to be a lot more collateral damage? I may not even be the target of the attack, and if there's somebody launching something with An autonomous AI capability, they may have aimed it at one place, but it wound up hitting 100 other folks, and they were just kind of incidental damage along the way.
Are we going to see more of that? I think we will. Again, this isn't an entirely new phenomenon.
Maybe the pace that some of these attacks and the frequency at which we see them might increase. But we've always had malware dating back decades where it's been hundreds or thousands of incidental targets who weren't necessarily the primary target. So not necessarily a new phenomenon, but something we should definitely prepare ourselves for.
And there's obviously things that we can do as businesses to prepare for, or to prepare our people, for this eventual reality. Things like strengthening human resilience into that social engineering, right? Having less victims within our employee base.
And so, it'll start with the education of our teams, and we can maybe dive into that a little bit. Mm-hmm. Well, speaking of that, though, before we get there, is it your sense that there'll be new tactics and techniques created by the bad guys, or are they just pretty much going to start maximizing the ones they already have and just keep attacking with more volume, but the attacks themselves will be pretty much the same ones we've always seen?
Based on the behaviors that we've seen from AI to date, it's largely a rinse and repeat with minor iterations or variations. Not a ton of new techniques that we've been seeing. Maybe different combinations of things.
And so I think we'll continue to see that until we reach this, I would say, a point of AI maturity where there's more sentient AI, if you will, then that's where we'll get to the spot where there might be things that we haven't seen yet. But today, largely what we've seen is a lot of the same type of attacks we've seen in the past. Mm-hmm.
So the one thing that is apparent is these attacks are happening at machine speed, and we need to respond to them in machine speed, and humans are not able to keep pace with machine speed. So how are we supposed to kind of think about defending in this new era where everything is happening in seconds and minutes rather than minutes and hours or days? Yeah.
So I'll pull back to something I mentioned earlier, and that's understanding what good looks like today. Part of the response in any incident response is understanding what the previous state was, what the current state was, and what has changed. And that's often how we detect incidents within our environment.
That's also how we need to think about resolving them and getting to the root cause as well. Understanding how an attacker may have influenced my environment, what changes they may have made on their way in, can help me not only understand that whole root cause, but then also stop the attack from continuing and to prevent future similar attacks from happening. And so, I think if we look back at tools that we can use to help establish what good looks like today, whether that's from understanding my entire network asset inventory, understanding how things are connected, ensuring that I'm monitoring how my network is configured, what my traffic patterns look like on a normal basis, these are all the proper hygiene or the standard IT hygiene things that we all should be doing.
And so when we start there, it will eliminate time in the response cycle from understanding what the landscape looks like today. I have that information already in front of me, and leveraging tools that help me automate that process of asset discovery and of topology mapping and of configuration management give me that always up-to-date, pre-breach kind of viewpoint without me having to spend time digging through, looking for those answers after. And so a lot of this sort of shortening response time comes up to the preparation that I've done before there is an incident, and that's making sure that I eliminate as many blind spots as I can.
" You've wasted 20 minutes that you could have really had that answer in 30 seconds on where exactly is this asset in my network. How automated can all this get? Because in theory, couldn't I, if I'm faced with an attack, just automatically default back to the last state of known good, and therefore maybe that becomes my first and foremost defense tactic, and then I can worry about what happened later?
Sure. I think that's an interesting idea is to revert back to the last known good state. And I think we would have to face the reality of how far back is that last known good state, and how confident am I that that state was actually good?
Which would be interesting questions that I don't know that a lot of businesses would have the answer for. Mm-hmm. Yeah.
Do you think that we're being proactive enough about all this? " And now it feels like maybe we're just waiting for some catastrophic event to occur, or is the other thing happening here where people are starting to realize maybe what the level of risk is, and they're starting to make the appropriate level of investments? Yeah.
So, there are really two topics that we can dive into when we think about AI and security, and that is we've been talking a lot about using AI in offensive and defensive security. But we haven't really-- This is sort of the first question dabbling into this idea of how do we govern AI usage within our organization and make sure that we secure that AI use within our organization. And I think there's definitely an argument that not enough is being done today to regulate or to govern AI within a lot of environments.
There's still a lot of organizations that have a sort of a yes or no, yes you can use it or no you can't kind of policy, and maybe aren't getting into the details of, well, what data are we enabling AI usage with? What models do we allow within our organization? What are we okay using a- ...
a third-party solution versus what are maybe some offline models we want to bring in-house to help show some of these AI efficiency gains with our team, but not necessarily expose our data. And again, the right answer might be different for different businesses, but it all sort of ties back to the are we doing enough to secure and govern AI usage within our businesses? And for a lot of organizations, I'd say the answer is probably no, we're not.
As a vendor myself, we see a lot of questions coming to our team around what data our Aurora AI accesses, and we have great answers to that question, and it comes up all the time, but very rarely am I getting a question of how do we limit the actions that the AI takes, or how do we limit the exposure to that data? So we're thinking about access to data, not necessarily thinking about what actions AI can take. And I think getting more granularity into these AI governance policies will be a really important thing for businesses moving forward.
Do we need to revisit the governance policies we have, or can we just want to apply them or extend them to what amounts to maybe some type of new non-human identity? Or is this something that is completely different? I would say it's not completely different.
There's an evolution of the existing policies that has to occur, right? Nothing is static. There's always going to be new versioning of the policies that come out, so it's an evolution of our policies, not necessarily something we would be able to apply our-- Things that worked five years ago won't necessarily work in today's world.
So ultimately, what's your best advice to cybersecurity professionals out there and the IT folks that they work with? Because I feel like a little bit there's this notion that maybe they're kind of feeling a little like deer in the headlights right now, and there's too many signals and not enough actionable insight. Yep, for sure.
So, I would say that the first I'll come back to is bring your house in order. Understand what that whole exposure landscape looks like. Treat SaaS increasingly more as a primary attack surface, right?
Auvik's own research, our IT trends report, found that 61% of IT professionals just report discovering new unauthorized SaaS applications monthly within their environments. So those are new exposures. Let's face it, like every SaaS tool these days is an AI tool.
So there's a ton of new exposures coming into my environment every week. So that'd be the first step, right? Get a better handle on what my attack surface looks like and make sure we're putting enough time into understanding what that SaaS landscape looks like.
The second bucket that I'd say we really need to focus on is continuing to improve our resilience against social engineering to make sure that we are communicating enough to all of our stakeholders about how they could be impacted by these AI-based attacks. I spend a lot of time talking to IT folks, and AI comes up in about 100% of conversations. I bet if I go to an average barbecue where I'm talking to family and friends and those type things, it's going to be way less than 100% of conversations that AI comes up in.
And so while we exist in this little bit of a bubble where we all understand AI, we understand some of the impacts, we understand some of the changes, the average worker in a lot of businesses may not have that same exposure or may not have that same knowledge to be able to recognize an AI-driven attack. And so continuing those education programs and evolving those education programs to include AI insights would be the second item. And then the last one is really just about that, understanding what good looks like today, understanding what that current state looks like, making sure that I have always up-to-date documentation so that I'm not spending time in the incident response process trying to figure out where a device is connected back in or how devices might be configured, that I have that well documented right from the beginning.
All right. Well, folks, you heard it here. Hey, things are going to be happening a lot faster.
There's just no two ways about that. But there's still no substitute for the fundamentals that give you the grounding you're going to need to respond in minutes and seconds. Hey, Steve, thanks for being on the show.
Thanks for having me. All right. And back to you guys in the studio.