SUNBURST was a rude awakening for many security teams, and it won't be the last time CISOs face tough questions about how an adversary evaded defenses and stayed hidden. With advanced threats persisting inside the network for months, security teams need a new plan. This session will discuss strategies to detect, investigate, and respond to post-compromise attack activities.