Segmentation Theater: Finding the routes attackers use with HD Moore

The air gap is dead, but the illusion of segmentation is thriving.

From the SANS Winter Cyber Solutions Fest 2026: Utilities and Critical Infrastructure event, HD Moore presents Segmentation Theater. Attackers don't respect network diagrams; they exploit edge device zero-days, abuse forgotten cellular backup links, and pivot through multi-homed systems that quietly route around every control you've deployed. Meanwhile, passive monitoring, vulnerability scanners, and OEM tools consistently miss the exposure paths that matter most.

HD Moore explains:

  • Real-world bypass techniques from recent incidents where segmentation catastrophically failed
  • Why traditional verification methods fail to identify hidden connectivity between IT, OT, and the internet
  • An attacker-centric model for segmentation verification that asks "What is reachable?" instead of "What should be isolated?"
  • Practical techniques to identify unintended pathways, prioritize critical chokepoints, and close routes before they become incidents

This session includes a live demonstration of active discovery techniques that reveal the hidden network paths defenders miss but attackers always find.

Meet Our Speakers

HD Moore

Founder & CEO, runZero

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Webcasts
Defending in the shadow era: when the CVE feed goes dark
HD Moore walks through the three eras of vulnerability management: the predictable cycles era, the triage ara of AI-scale discovery, and now the...
Webcasts
runZero Hour, Ep. 31: The New Rules of Risk: EPSS v5 and Agentic Adversaries
In this episode, learn how your security team can use EPSS v5 to inform daily risk decisions in a world increasingly targeted by the apex agentic...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Webcasts
runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.