How do you find an attacker that has gained access to your system and is moving laterally with "normal" admin commands? I wrote a tool that organizes the results of several noisy EDR searches into lists and looks for a host or user that appears on a number of them. This is beyond the capability of any EDR interface that I'm aware of. The talk will mainly cover Carbon Black Response, but the techniques apply to most EDR platforms. I'll also talk a bit about using Sysmon to achieve the same goal.