The Colony Defense Strategy: Fast, Automated Cross-Tenant IOC Generation
Tuesday, September 15, 2026, 4:00 PM - 4:45 PM
Atrium Ballroom A

When tracking sophisticated campaigns like s1ngularity, Shai-Hulud, and TeamPCP, looking at a single environment feels like reading a book one random page at a time. In reality, we watched the Shai-Hulud campaign impact tenant after tenant. Weeks passed, and the TeamPCP signal began appearing in a similar relentless pattern across completely unrelated sectors. By pivoting threat data across these customer boundaries, isolated pages crystallized into a coherent story.
A similar cross-tenant pattern emerged for an Entra ID malicious toolkit we observed, where independent tenants experienced identical sign-in anomalies - reusing the same ASNs, custom Python useragents, and App-Resource Tuples.
The Colony Defense strategy turns this multi-tenant insight into a superpower. By aggregating raw telemetry-IPs, domains, ASNs, useragents, resource names, and command lines-into a centralized pipeline, we can correlate activity across different tenants to manufacture high-fidelity IOCs faster than ever before.


But speed requires precision; we filter the data down until we are left only with a manageable set of cross-tenant suspicious activities. At this end stage of the funnel, we utilize LLMs to replace the human in the loop, filtering out the benign edge cases to identify true threats and deploy the new IOCs fast.